docs(06-11): update plan tracking
This commit is contained in:
@@ -18,7 +18,7 @@ Decimal phases appear between their surrounding integers in numeric order.
|
||||
- [x] **Phase 3: First vertical slice — genres end to end** - `GET /_fonoteka/api/v1/genres` passes the parity diff through every layer (completed 2026-09-17)
|
||||
- [x] **Phase 4: CLI scaffolding, i18n and mail** - Scaffolding commands, translated/pluralized strings, mail templates (completed 2026-09-18)
|
||||
- [x] **Phase 5: Data layer full fidelity** - All 25 models and their squashed migrations with fillable/hidden/cast/soft-delete discipline (completed 2026-09-18)
|
||||
- [ ] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure
|
||||
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21)
|
||||
- [ ] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password
|
||||
- [ ] **Phase 8: OAuth2.1 authorization server** - zitadel/oidc server for fonoteka-mcp and the ChatGPT connector
|
||||
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
|
||||
@@ -256,7 +256,7 @@ Plans:
|
||||
|
||||
**Wave 7** *(gap closure; blocked on 06-07..06-10)*
|
||||
|
||||
- [ ] 06-11-PLAN.md — Re-run Phase 6 security gates and refresh the stale threat verdict
|
||||
- [x] 06-11-PLAN.md — Re-run Phase 6 security gates and refresh the stale threat verdict
|
||||
|
||||
### Phase 7: User plugin and authentication
|
||||
|
||||
@@ -425,7 +425,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
||||
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
|
||||
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||
| 6. HTTP routing, auth groups and rate limiting | 10/11 | In Progress| |
|
||||
| 6. HTTP routing, auth groups and rate limiting | 11/11 | Complete | 2026-09-21 |
|
||||
| 7. User plugin and authentication | 0/TBD | Not started | - |
|
||||
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||
|
||||
@@ -3,15 +3,15 @@ gsd_state_version: 1.0
|
||||
milestone: v1.0
|
||||
milestone_name: milestone
|
||||
status: executing
|
||||
stopped_at: Completed 06-10-PLAN.md
|
||||
last_updated: "2026-09-20T22:28:10.242Z"
|
||||
last_activity: 2026-09-20
|
||||
stopped_at: Completed 06-11-PLAN.md
|
||||
last_updated: "2026-09-21T11:04:40.366Z"
|
||||
last_activity: 2026-09-21
|
||||
progress:
|
||||
total_phases: 15
|
||||
completed_phases: 5
|
||||
completed_phases: 6
|
||||
total_plans: 34
|
||||
completed_plans: 33
|
||||
percent: 33
|
||||
completed_plans: 34
|
||||
percent: 40
|
||||
---
|
||||
|
||||
# Project State
|
||||
@@ -26,17 +26,17 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
||||
## Current Position
|
||||
|
||||
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
|
||||
Plan: 5 of 11
|
||||
Status: Ready to execute
|
||||
Last activity: 2026-09-20
|
||||
Plan: 11 of 11
|
||||
Status: Execution complete — ready to verify
|
||||
Last activity: 2026-09-21
|
||||
|
||||
Progress: [██████████] 97%
|
||||
Progress: [██████████] 100%
|
||||
|
||||
## Performance Metrics
|
||||
|
||||
**Velocity:**
|
||||
|
||||
- Total plans completed: 31
|
||||
- Total plans completed: 34
|
||||
- Average duration: 21 min
|
||||
- Total execution time: 104 min
|
||||
|
||||
@@ -79,6 +79,7 @@ Progress: [██████████] 97%
|
||||
| Phase 06 P08 | 1h 20m | 1 tasks | 3 files |
|
||||
| Phase 06 P09 | 4 min | 1 tasks | 2 files |
|
||||
| Phase 06 P10 | 3h 15m | 1 tasks | 2 files |
|
||||
| Phase 06 P11 | 12h 30m | 1 tasks | 1 files |
|
||||
|
||||
## Accumulated Context
|
||||
|
||||
@@ -187,6 +188,8 @@ Recent decisions affecting current work:
|
||||
- [Phase 06]: Success commit replaces only route-owned header keys — Unrelated headers already placed on the destination by outer wrappers such as path-scoped CORS must survive.
|
||||
- [Phase 06]: Use wire.WriteJSON for both InvScope denial branches — The shared writer is the established PHP-compatible no-newline serialization path.
|
||||
- [Phase 06]: Assert exact denial bytes before JSON shape checks — Whitespace normalization would hide response-contract regressions.
|
||||
- [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
|
||||
- [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|<ClientIP>, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u:<id> keys.
|
||||
|
||||
### Pending Todos
|
||||
|
||||
@@ -208,6 +211,6 @@ Items acknowledged and carried forward from previous milestone close:
|
||||
|
||||
## Session Continuity
|
||||
|
||||
Last session: 2026-09-20T22:27:07.576Z
|
||||
Stopped at: Completed 06-10-PLAN.md
|
||||
Last session: 2026-09-21T11:04:05.263Z
|
||||
Stopped at: Completed 06-11-PLAN.md
|
||||
Resume file: None
|
||||
|
||||
Reference in New Issue
Block a user