docs(07): verify phase after the avatar bucket gap close

Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-23 10:52:45 +02:00
parent 3a15105a1b
commit e537b67a37
5 changed files with 79 additions and 106 deletions

View File

@@ -1,9 +1,9 @@
---
status: diagnosed
status: resolved
phase: 07-user-plugin-and-authentication
source: [07-01-SUMMARY.md, 07-02-SUMMARY.md, 07-03-SUMMARY.md, 07-04-SUMMARY.md, 07-05-SUMMARY.md, 07-06-SUMMARY.md, 07-07-SUMMARY.md]
source: [07-01-SUMMARY.md, 07-02-SUMMARY.md, 07-03-SUMMARY.md, 07-04-SUMMARY.md, 07-05-SUMMARY.md, 07-06-SUMMARY.md, 07-07-SUMMARY.md, 07-08-SUMMARY.md]
started: 2026-09-23T08:13:12Z
updated: 2026-09-23T08:32:06Z
updated: 2026-09-23T08:52:00Z
---
## Current Test
@@ -38,9 +38,9 @@ reported: |
### 5. Profile, password change, marketing consent, and avatar
expected: Authenticated update, change-password, and marketing-consent write the signed-in row. A password change keeps the presenting token and invalidates older ones. Avatar upload sniffs the first bytes, stores an attach.File, and fills has_avatar plus a 128px avatar_url; remove clears them.
result: issue
reported: "Profile update, marketing consent, and change-password work over curl (presenting JWT kept, older JWT 401 after a 2s iat gap). POST /_user/api/v1/avatar against the assembled app.Handler returns 500 {\"error\":true,\"message\":\"Internal server error\"}."
severity: blocker
result: pass
reported: |
Profile update, marketing consent, and change-password work over curl (presenting JWT kept, older JWT 401 after a 2s iat gap). After 07-08, TestAvatarAssembled boots app.Handler, POSTs a JPEG to /_user/api/v1/avatar (200, has_avatar true, non-empty avatar_url), then POSTs avatar/remove (has_avatar false).
### 6. Organisation fields arrive through GetApiArrayEvent
expected: Login, fetch, and register user objects include organisation_id, organisation_role, must_change_password, and preferred_locale from fonoteka's GetApiArray listener. The user plugin does not import fonoteka.
@@ -87,8 +87,8 @@ reported: |
## Summary
total: 12
passed: 11
issues: 1
passed: 12
issues: 0
pending: 0
skipped: 0
blocked: 0
@@ -96,22 +96,8 @@ blocked: 0
## Gaps
- truth: "Avatar upload sniffs the first bytes, stores an attach.File, and fills has_avatar plus a 128px avatar_url; remove clears them"
status: failed
reason: "User reported: Profile update, marketing consent, and change-password work over curl (presenting JWT kept, older JWT 401 after a 2s iat gap). POST /_user/api/v1/avatar against the assembled app.Handler returns 500 {\"error\":true,\"message\":\"Internal server error\"}."
status: resolved
reason: "07-08 published *blob.Bucket on serve and Handler; TestAvatarAssembled is 200 then remove."
severity: blocker
test: 5
root_cause: "app.Handler and surf.ServeCommand never call attach.OpenBucket/Publish, so Lookup[*blob.Bucket] fails and UploadAvatar writes an opaque 500. Unit tests pass only because they publish a memblob by hand. The ported avatar fixture is the missing-file 422, so replay never uploaded a file."
artifacts:
- path: "fonoteka.go/app/app.go"
issue: "Handler publishes *sql.DB/*gorm.DB then Activate/Assemble; it never opens or publishes *blob.Bucket"
- path: "summercms.go/surf/serve.go"
issue: "ServeCommand publishes the DB then Assemble; it never calls attach.OpenBucket/Publish"
- path: "fonoteka.go/plugins/golem15/user/controllers/api_controller.go"
issue: "UploadAvatar returns writeOpaque500 when the bucket is missing (lines 1153-1157)"
- path: "fonoteka.go/parity/migrate_test.go"
issue: "testConfig writes app.yaml/http.yaml only; storage.uploads.bucket_url is unset"
missing:
- "Call attach.OpenBucket + attach.Publish from surf.ServeCommand and app.Handler (fail boot on empty bucket_url)"
- "Give parity/test configs a mem:// storage.uploads.bucket_url so assembled tests boot"
- "Add an assembled-app upload test (JPEG/PNG multipart) that asserts 200 has_avatar and avatar_url, then remove"
debug_session: ".planning/debug/avatar-bucket-not-published.md"
debug_session: ".planning/debug/resolved/avatar-bucket-not-published.md"