docs(08-01): complete metadata RED infrastructure plan

This commit is contained in:
Jakub Zych
2026-09-23 19:20:35 +02:00
parent c578bb58d7
commit deee2cc8d7
3 changed files with 141 additions and 14 deletions

View File

@@ -3,14 +3,14 @@ gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
stopped_at: Phase 8 UI-SPEC approved
last_updated: "2026-09-23T16:42:33.535Z"
last_activity: 2026-09-23 -- Phase 08 planning complete
stopped_at: Completed 08-01-PLAN.md
last_updated: "2026-09-23T17:18:26.201Z"
last_activity: 2026-09-23
progress:
total_phases: 15
completed_phases: 7
total_plans: 55
completed_plans: 45
completed_plans: 46
percent: 47
---
@@ -21,16 +21,16 @@ progress:
See: .planning/PROJECT.md (updated 2026-09-16)
**Core value:** An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test.
**Current focus:** Phase 08 — oauth2 1 authorization server
**Current focus:** Phase 08 — oauth2-1-authorization-server
## Current Position
Phase: 08
Plan: Not started
Phase: 08 (oauth2-1-authorization-server) — EXECUTING
Plan: 2 of 10
Status: Ready to execute
Last activity: 2026-09-23 -- Phase 08 planning complete
Last activity: 2026-09-23
Progress: [██████████] 100%
Progress: [████████░░] 84%
## Performance Metrics
@@ -91,6 +91,7 @@ Progress: [██████████] 100%
| Phase 07 P07 | 3h 15m | 3 tasks | 28 files |
| Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files |
| Phase 07-user-plugin-and-authentication P08 | 25min | 3 tasks | 6 files |
| Phase 08 P01 | 25min | 2 tasks | 6 files |
## Accumulated Context
@@ -207,6 +208,9 @@ Recent decisions affecting current work:
- [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
- [Phase 07]: Both CLI serve and in-process Handler must publish *blob.Bucket; unit tests that call attach.Publish themselves cannot stand in for boot — Phase 5 shipped OpenBucket/Publish but never wired them. Phase 7 added HTTP avatar. UAT and corpus replay boot via Handler, so serve-only publish would leave the same 500.
- [Phase 07]: Assembled Handler avatar coverage lives in parity/ next to newConfiguredTarget, not in the user plugin package — The user plugin cannot import app.Handler without a reverse import. newConfiguredTarget is the same boot as replay.
- [Phase 08]: wristband.Options exposes only the four PHP-configurable metadata fields (service_documentation path, scopes_supported, token_endpoint_auth_methods_supported, authorization_response_iss_parameter_supported); response_types/grant_types/code_challenge_methods stay fixed protocol constants per D-06
- [Phase 08]: Plugin.Boot always constructs wristband.Server even with an empty app.url rather than failing loud, to avoid breaking the many existing fonoteka tests that boot without app.url configured; production must set app.url
- [Phase 08]: D-10 (oauth guard retirement) is recorded via TestOAuthMetadataRouteIsolation rather than editing Phase 6 historical docs, per 08-PATTERNS.md guidance to prefer a supersession note
### Pending Todos
@@ -228,6 +232,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-23T10:52:49.787Z
Stopped at: Phase 8 UI-SPEC approved
Resume file: .planning/phases/08-oauth2-1-authorization-server/08-UI-SPEC.md
Last session: 2026-09-23T17:18:26.184Z
Stopped at: Completed 08-01-PLAN.md
Resume file: None