docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04 and I18N-02 are marked complete. Do not auto-advance. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -1,42 +1,43 @@
|
||||
---
|
||||
phase: 07-user-plugin-and-authentication
|
||||
reviewed: 2026-09-22T17:26:00Z
|
||||
reviewed: 2026-09-23T08:52:00Z
|
||||
depth: standard
|
||||
files_reviewed: 4
|
||||
files_reviewed_list:
|
||||
- ../fonoteka.go/plugins/golem15/user/controllers/api_controller.go
|
||||
- ../fonoteka.go/parity/schema_diff_test.go
|
||||
- ../fonoteka.go/parity/manifest.yaml
|
||||
- bouncer/phase07_coverage_test.go
|
||||
- surf/serve.go
|
||||
- surf/serve_test.go
|
||||
- ../fonoteka.go/app/app.go
|
||||
- ../fonoteka.go/parity/avatar_assembled_test.go
|
||||
findings:
|
||||
critical: 0
|
||||
warning: 2
|
||||
info: 0
|
||||
total: 2
|
||||
status: issues_found
|
||||
warning: 0
|
||||
info: 1
|
||||
total: 1
|
||||
status: clean
|
||||
---
|
||||
|
||||
# Phase 7: Code Review Report
|
||||
|
||||
**Reviewed:** 2026-09-22T17:26:00Z
|
||||
**Reviewed:** 2026-09-23T08:52:00Z
|
||||
**Depth:** standard
|
||||
**Files Reviewed:** 4
|
||||
**Status:** issues_found
|
||||
**Files Reviewed:** 4 (07-08 gap-closure boot path)
|
||||
**Status:** clean
|
||||
|
||||
## Summary
|
||||
|
||||
The session, token, and lock tests match the handlers they name. Two response differences against the recorded PHP corpus are still in the Go handlers. Neither is a new crash or a secret leak. Both keep the user API routes pending.
|
||||
The UAT avatar 500 was a missing `attach.OpenBucket`/`Publish` on both HTTP boot paths. Serve and Handler now publish `*blob.Bucket` before Assemble. Assembled proof lives in `parity/avatar_assembled_test.go` and does not hand-publish a memblob. Earlier 07-06 review warnings (wrong-code activate 200, PHP fetch-after-logout 200) were closed by 07-07.
|
||||
|
||||
## Warnings
|
||||
|
||||
### 1. Wrong activation code returns 200
|
||||
|
||||
`Activate` ignores the error from `VerifyActivationCode` and always writes the user payload at status 200. The isolated PHP app throws and returns the HTML error page at status 500 for `POST /_user/api/v1/activate` with `{"code":"wrong"}` and for `POST /_user/api/v1/activate-by-code` with `1!nope`. The fixtures record the HTML. The Go handler was left as-is in 07-05.
|
||||
|
||||
### 2. Logout blacklists a token PHP still accepts
|
||||
|
||||
Go logout adds the presented jti to `jwt_blacklist`, so the next fetch is 401. PHP logout returns `{"message":"Logged out"}` and a following fetch with that bearer is still 200. `TestSessionSequence` locks in the Go behavior. The recorded fixtures lock in the PHP behavior. The routes stay `pending`.
|
||||
None.
|
||||
|
||||
## Info
|
||||
|
||||
None.
|
||||
### 1. Handler does not close the opened bucket
|
||||
|
||||
`surf.ServeCommand` defers `bucket.Close()`. `app.Handler` publishes the bucket and returns `http.Handler` with no cleanup hook, so a failed `party.Activate` after a successful Publish leaks the handle. In-process tests use `mem://`. Production CLI serve still closes. Not a user-facing bug.
|
||||
|
||||
## Prior findings (closed)
|
||||
|
||||
1. Wrong-code activate now serves Winter 500 HTML (`07-07`).
|
||||
2. Fetch after logout stays 401 in Go; the PHP 200 reused case is not in the ported corpus (`07-07`).
|
||||
|
||||
Reference in New Issue
Block a user