From ea0fc6f191b74f54ac6defcf706075cde83eef40 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Sun, 4 Oct 2026 17:39:39 +0200 Subject: [PATCH] docs(12.1): record plan-count checkpoint decisions --- .../phases/12.1-user-plugin-admin-screens/12.1-CONTEXT.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.planning/phases/12.1-user-plugin-admin-screens/12.1-CONTEXT.md b/.planning/phases/12.1-user-plugin-admin-screens/12.1-CONTEXT.md index 68a0a0e..3be561e 100644 --- a/.planning/phases/12.1-user-plugin-admin-screens/12.1-CONTEXT.md +++ b/.planning/phases/12.1-user-plugin-admin-screens/12.1-CONTEXT.md @@ -54,6 +54,12 @@ Out of scope: impersonating a user, the guest concept and convert-guest, MailBlo ### Release and ordering - **D-25:** Framework first. The cabana and SPA work (D-09 to D-12, D-16) lands in the early plans with module READMEs, `docs/` pages, the admin OpenAPI document, generated TS types and the rebuilt `dist/`, and is tagged **v0.1.3** (`v0.1.2` already exists). The plugin screens build on that tag. Framework fixtures use neutral names and never name the application. +### Plan-count checkpoint (confirmed 2026-10-04, after research) +- **D-26:** The phase has five plans: (01) framework actions: declared bulk actions, record actions, row state and a 403 error type; (02) framework preview context, `permissioneditor` and the form seams, ending in tag v0.1.3; (03) plugin foundation and the Users screen; (04) User Groups and Organisations screens, the privileged-group guard (T-12-18) and the application's bump to v0.1.3; (05) unit tests, the phase gate script and the security review. +- **D-27:** All seven extra framework seams from RESEARCH.md "Framework Gaps Beyond CONTEXT.md" are accepted into v0.1.3: G1 `password` field type, G2 form virtual fields, G3 writable foreign-key opt-in on a relation field, G4 `cabana.ForbiddenError` and locked relation options, G5 admin validation rules, G6 `invisible` list columns, G7 `preset`. — **Reversibility:** costly — each grows the `pact`/cabana contract or the typed schema. +- **D-28:** G5 is solved with an optional controller interface that returns the rule set per operation, not with a wrapper record type in the plugin. +- **D-29:** The research recommendations for the remaining open questions are accepted: User Groups keep the standard form delete, guarded per D-06, with pivot cleanup; `last_seen` is written on login and on refresh, at most once per five minutes, and a failed write never fails auth; a user created in the admin starts not activated and only the `activate` actions set `is_activated`; bulk `activate` skips users that are already active and reports the affected count. + ### Claude's Discretion - The code of the extra permission in D-04 (for example `golem15.users.manage_privileged_groups`), its label and tab, and the config key name for the privileged list. - YAML keys and Go interface names for bulk actions, record actions, preview and row state, provided they follow the existing fail-loud rules (unknown keys and unregistered actions are boot errors), sit under the `{prefix}/api/v1/{vendor}/{plugin}/{controller}/...` scheme, use `requireAjax` on writes and carry swag annotations.