diff --git a/.planning/REQUIREMENTS.md b/.planning/REQUIREMENTS.md index 46e3bcd..7c67d62 100644 --- a/.planning/REQUIREMENTS.md +++ b/.planning/REQUIREMENTS.md @@ -69,7 +69,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b - [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge - [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers - [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged -- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access +- [x] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access ### Płytarium API (API) @@ -107,11 +107,11 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b ### Admin (ADMIN) -- [ ] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes -- [ ] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers -- [ ] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab -- [ ] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks -- [ ] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense) +- [x] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes +- [x] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers +- [x] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab +- [x] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks +- [x] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense) - [x] **ADMIN-06**: A minimal Vue 3 + TypeScript SPA renders login, permission-gated navigation, lists, forms and the relation manager for Albums, Artists, Collections, Genres and Styles using generated types - [x] **ADMIN-07**: A plugin extends the compiled admin SPA without a Node rebuild: controller-declared JS/CSS is served from the plugin's embedded files under `{backend.uri}/assets/` and loaded when that controller opens (CSP `script-src 'self'`); `type: widget` fields mount plugin custom elements whose actions the SPA posts with the admin cookie and CSRF header, patching only the declared `fill` fields; `type: partial` form fields and a `config_list.yaml` `headerPartial` render server-side with `html/template` from a controller view model and display without any raw-HTML sink; and controllers register named toolbar actions. Unknown YAML keys, missing templates and unregistered actions fail boot. @@ -211,7 +211,7 @@ Which phases cover which requirements. Updated during roadmap creation. | AUTH-05 | Phase 8 | Complete | | AUTH-06 | Phase 8 | Complete | | AUTH-07 | Phase 8 | Complete | -| AUTH-08 | Phase 9 | Pending | +| AUTH-08 | Phase 9 | Complete | | API-01 | Phase 12 | Pending | | API-02 | Phase 12 | Pending | | API-03 | Phase 13 | Pending | @@ -231,11 +231,11 @@ Which phases cover which requirements. Updated during roadmap creation. | SRCH-02 | Phase 14 | Pending | | INTG-01 | Phase 14 | Pending | | INTG-02 | Phase 14 | Pending | -| ADMIN-01 | Phase 9 | Pending | -| ADMIN-02 | Phase 9 | Pending | -| ADMIN-03 | Phase 9 | Pending | -| ADMIN-04 | Phase 9 | Pending | -| ADMIN-05 | Phase 9 | Pending | +| ADMIN-01 | Phase 9 | Complete | +| ADMIN-02 | Phase 9 | Complete | +| ADMIN-03 | Phase 9 | Complete | +| ADMIN-04 | Phase 9 | Complete | +| ADMIN-05 | Phase 9 | Complete | | ADMIN-06 | Phase 10 | Complete | | ADMIN-07 | Phase 10.1 | Complete | | QA-01 | Phase 2 | Complete | diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index 959e48a..e23fba0 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -21,7 +21,7 @@ Decimal phases appear between their surrounding integers in numeric order. - [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21) - [x] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password (completed 2026-09-22) - [x] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector (completed 2026-09-23) -- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager +- [x] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager (completed 2026-10-01) - [x] **Phase 10: Admin Vue SPA** - Login, navigation, lists, forms and relation manager for five controllers (completed 2026-09-27) - [ ] **Phase 11: Jobs, realtime and search infrastructure** - River, Centrifugo and Typesense sync brought up before the API phases that need them - [ ] **Phase 12: Płytarium API — Collections and Albums** - Core content endpoints ported with byte-level parity @@ -375,7 +375,7 @@ Plans: 4. The relation-manager schema supports search/link/unlink/manage-or-view lists for Collections' editors tab, replacing the `partial` field entirely. 5. Admin CRUD endpoints expose `listExtendQuery`/`formExtendQuery`/`formBeforeCreate`/`formBeforeUpdate`/`relationExtendManageQuery` hooks, bulk delete runs each record's lifecycle hooks, and the Settings model binds to a settings screen through the same schema pipeline. -**Plans**: 12/12 plans executed +**Plans**: 12/12 plans complete **Research flag:** yes Plans: @@ -703,7 +703,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 → | 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 | | 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 | | 8. OAuth2.1 authorization server | 10/10 | Complete | 2026-09-23 | -| 9. Backend admin authentication and schema pipeline | 12/12 | In Progress| | +| 9. Backend admin authentication and schema pipeline | 12/12 | Complete | 2026-10-01 | | 10. Admin Vue SPA | 5/5 | Complete | 2026-09-27 | | 11. Jobs, realtime and search infrastructure | 8/8 | In Progress| | | 11.1. SummerCMS documentation for humans and AI agents | 7/7 | In Progress| | diff --git a/.planning/STATE.md b/.planning/STATE.md index af42933..104ba85 100644 --- a/.planning/STATE.md +++ b/.planning/STATE.md @@ -7,11 +7,11 @@ status: verifying stopped_at: Completed 11.2-03-PLAN.md last_updated: "2026-10-01T14:40:47.065Z" last_activity: 2026-10-01 -last_activity_desc: Phase 11.2 execution started +last_activity_desc: Phase 09 re-verified and marked complete (review fixes applied) state_head: c07db9a321d44d655179cf2e50a00afe0ababdb3 progress: total_phases: 20 - completed_phases: 9 + completed_phases: 10 total_plans: 96 completed_plans: 96 milestone_name: milestone diff --git a/.planning/state.json b/.planning/state.json index 5294399..d763c11 100644 --- a/.planning/state.json +++ b/.planning/state.json @@ -46,7 +46,7 @@ { "number": "9", "name": "Backend admin authentication and schema pipeline", - "status": "in_progress" + "status": "complete" }, { "number": "10", @@ -99,5 +99,5 @@ "label": "Advance to the next step (verify)", "reason": "Phase 11.2 of 20 · ready to verify" }, - "updated_at": "2026-10-01T14:40:43.793Z" + "updated_at": "2026-10-01T21:19:02.996Z" }