feat(12.2-04): add the fileupload field with deferred uploads on the form session key

- sessionKey.ts: one 32-byte base64url key per form mount, sent only in headers
- api/files.ts: FileRoutes over the record and child file routes, XHR upload with progress, 401 refresh and retry
- FileuploadField and FileCaptionModal per UI-SPEC section 3: dropzone, image grid, rows, per-item states, client pre-checks, reorder, protected previews
- FormView provides FORM_SESSION, counts pending changes as dirty and sends X-Session-Key on create and update
- fileupload lang keys in en and pl, admin-spa docs note, deferred smoke test, rebuilt dist
This commit is contained in:
Jakub Zych
2026-10-02 19:22:22 +02:00
parent 1ebfe691a2
commit ea33296799
22 changed files with 2338 additions and 15 deletions

View File

@@ -0,0 +1,81 @@
---
phase: "13"
slug: "p-ytarium-api-wishlist-notifications-csv-credentials-public"
# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6)
# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117)
status: draft
nyquist_compliant: false
wave_0_complete: false
created: "2026-10-02"
---
# Phase 13 — Validation Strategy
> Per-phase validation contract for feedback sampling during execution.
---
## Test Infrastructure
| Property | Value |
|----------|-------|
| **Framework** | Go `testing` (+ testify, Go fuzzing), testcontainers Postgres |
| **Config file** | none — `fonoteka.go/parity/parity_test.go` TestMain starts Postgres |
| **Quick run command** | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka/... ./plugins/golem15/user/... -short -count=1` |
| **Full suite command** | `go vet ./... && go test ./... -count=1 && go -C ../fonoteka.go vet ./... && go -C ../fonoteka.go test ./... -count=1` |
| **Parity command** | `go -C ../fonoteka.go test ./parity -run 'TestParityCorpus|TestBroadcastGoldens|TestFonotekaNuxtFlows' -count=1` |
| **Phase gate** | `../fonoteka.go/scripts/check-phase13.sh --self-test && ../fonoteka.go/scripts/check-phase13.sh --all` |
| **Estimated runtime** | ~180 seconds (full suite with testcontainers) |
---
## Sampling Rate
- **After every task commit:** Run the quick run command plus `go vet` in the touched repo
- **After every plan wave:** Run the full suite command, the parity command and the corpus check
- **Before `/gsd-verify-work`:** `scripts/check-phase13.sh --all` must be green
- **Max feedback latency:** 180 seconds
---
## Per-Task Verification Map
Filled by the planner per task; the requirement → test map lives in `13-RESEARCH.md` § Validation Architecture.
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
| 13-01-01 | 01 | 1 | (framework) | T-13-23 | Overlapping constrained routes dispatch to the right handler | unit | `go test ./modules/surf -run TestOverlappingConstrainedRoutes -count=1` | ❌ W0 | ⬜ pending |
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
---
## Wave 0 Requirements
- [ ] `surf` constraint-aware overlap dispatch, plus a test (blocks every wishlist route)
- [ ] `conga` unregistered-kind insert while a worker runs, plus a test
- [ ] `lagoon` `prohibited` rule; tide Content-Disposition date and notification publication masks
- [ ] `php_parity.sh` `QUEUE_CONNECTION` override; `capture-rules.yaml` `share:wishlist` capture
- [ ] `fonoteka_reset.php` + `seedFonotekaCase` states: `wishlist`, `csv`, `credentials`, `empty`, `invite-for-register`
- [ ] `scripts/check-phase13.sh` (copy of the check-phase12 structure)
---
## Manual-Only Verifications
| Behavior | Requirement | Why Manual | Test Instructions |
|----------|-------------|------------|-------------------|
| Re-recording PHP fixtures against the isolated PHP instance | API-03..API-07 | Needs the local PHP stack running | Run `php_parity.sh` recordings per D-12 with the database queue override |
---
## Validation Sign-Off
- [ ] All tasks have `<automated>` verify or Wave 0 dependencies
- [ ] Sampling continuity: no 3 consecutive tasks without automated verify
- [ ] Wave 0 covers all MISSING references
- [ ] No watch-mode flags
- [ ] Feedback latency < 180s
- [ ] `nyquist_compliant: true` set in frontmatter
**Approval:** pending