docs: capture exploration — apparatus dissolved into framework

This commit is contained in:
Jakub Zych
2026-09-28 00:39:43 +02:00
parent 7ac75b918d
commit df45520dd8
4 changed files with 80 additions and 0 deletions

View File

@@ -0,0 +1,10 @@
---
title: Backend admin personal API tokens (deferred Apparatus PersonalApiToken)
date: 2026-09-28
priority: low
area: summercms.go admin auth
---
Apparatus provides personal API tokens for backend admins (`PersonalApiToken` model, `TokenAuthenticate` + `ForceJsonResponse` middleware, token create/revoke on the backend user form). Nothing in Płytarium calls it, so it is deferred past v1. The Phase 9 `backend` guard already accepts `Authorization: Bearer` for CLI and tests.
Revisit when a Golem15 project needs scripted access to the admin API. See `.planning/notes/apparatus-dissolved-into-framework.md`.

View File

@@ -0,0 +1,12 @@
---
title: Extend fetchguard into a guarded outbound http.Client (replaces Apparatus RequestSender)
date: 2026-09-28
priority: high
area: summercms.go/fetchguard
---
fetchguard today is a guarded HTTPS GET fetcher. Extend it into a guarded `http.Client` (or a client constructor) that supports POST, PUT, multipart file upload and bearer auth, keeping the dial-time private/reserved IP rejection.
- Replaces `Golem15\Apparatus\Classes\RequestSender` (see `.planning/notes/apparatus-dissolved-into-framework.md`).
- Consumers: feedback `G15OfficeClient` (JSON POST + multipart), golem `AIService`-style adapters (Anthropic/OpenAI-compatible) and the Discogs client.
- Needed before Phase 14 (INTG-01, INTG-02, feedback).

View File

@@ -0,0 +1,12 @@
---
title: Framework slog handler that redacts credentials (port RedactCredentialsTap)
date: 2026-09-28
priority: medium
area: summercms.go logging
---
Port `Golem15\Apparatus\Classes\Logging\RedactCredentialsTap` as a framework `slog.Handler` wrapper: redact attribute keys `api_key`, `apikey`, `authorization`, `bearer`, `password`, `secret`, `token`, `webhook_secret`, `admin_password` (case-insensitive, nested groups), and scrub its message regex patterns.
Also verify whether `surf`'s error path already gives `SafeExceptionResponse` behaviour (generic "Internal server error" outside debug, real message logged); add a small helper only if it does not.
See `.planning/notes/apparatus-dissolved-into-framework.md`.