docs(phase-9): complete phase execution
This commit is contained in:
@@ -69,7 +69,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|||||||
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
||||||
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
||||||
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
||||||
- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
- [x] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
||||||
|
|
||||||
### Płytarium API (API)
|
### Płytarium API (API)
|
||||||
|
|
||||||
@@ -107,11 +107,11 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|||||||
|
|
||||||
### Admin (ADMIN)
|
### Admin (ADMIN)
|
||||||
|
|
||||||
- [ ] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes
|
- [x] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes
|
||||||
- [ ] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers
|
- [x] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers
|
||||||
- [ ] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab
|
- [x] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab
|
||||||
- [ ] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks
|
- [x] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks
|
||||||
- [ ] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense)
|
- [x] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense)
|
||||||
- [x] **ADMIN-06**: A minimal Vue 3 + TypeScript SPA renders login, permission-gated navigation, lists, forms and the relation manager for Albums, Artists, Collections, Genres and Styles using generated types
|
- [x] **ADMIN-06**: A minimal Vue 3 + TypeScript SPA renders login, permission-gated navigation, lists, forms and the relation manager for Albums, Artists, Collections, Genres and Styles using generated types
|
||||||
- [x] **ADMIN-07**: A plugin extends the compiled admin SPA without a Node rebuild: controller-declared JS/CSS is served from the plugin's embedded files under `{backend.uri}/assets/` and loaded when that controller opens (CSP `script-src 'self'`); `type: widget` fields mount plugin custom elements whose actions the SPA posts with the admin cookie and CSRF header, patching only the declared `fill` fields; `type: partial` form fields and a `config_list.yaml` `headerPartial` render server-side with `html/template` from a controller view model and display without any raw-HTML sink; and controllers register named toolbar actions. Unknown YAML keys, missing templates and unregistered actions fail boot.
|
- [x] **ADMIN-07**: A plugin extends the compiled admin SPA without a Node rebuild: controller-declared JS/CSS is served from the plugin's embedded files under `{backend.uri}/assets/` and loaded when that controller opens (CSP `script-src 'self'`); `type: widget` fields mount plugin custom elements whose actions the SPA posts with the admin cookie and CSRF header, patching only the declared `fill` fields; `type: partial` form fields and a `config_list.yaml` `headerPartial` render server-side with `html/template` from a controller view model and display without any raw-HTML sink; and controllers register named toolbar actions. Unknown YAML keys, missing templates and unregistered actions fail boot.
|
||||||
|
|
||||||
@@ -211,7 +211,7 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|||||||
| AUTH-05 | Phase 8 | Complete |
|
| AUTH-05 | Phase 8 | Complete |
|
||||||
| AUTH-06 | Phase 8 | Complete |
|
| AUTH-06 | Phase 8 | Complete |
|
||||||
| AUTH-07 | Phase 8 | Complete |
|
| AUTH-07 | Phase 8 | Complete |
|
||||||
| AUTH-08 | Phase 9 | Pending |
|
| AUTH-08 | Phase 9 | Complete |
|
||||||
| API-01 | Phase 12 | Pending |
|
| API-01 | Phase 12 | Pending |
|
||||||
| API-02 | Phase 12 | Pending |
|
| API-02 | Phase 12 | Pending |
|
||||||
| API-03 | Phase 13 | Pending |
|
| API-03 | Phase 13 | Pending |
|
||||||
@@ -231,11 +231,11 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|||||||
| SRCH-02 | Phase 14 | Pending |
|
| SRCH-02 | Phase 14 | Pending |
|
||||||
| INTG-01 | Phase 14 | Pending |
|
| INTG-01 | Phase 14 | Pending |
|
||||||
| INTG-02 | Phase 14 | Pending |
|
| INTG-02 | Phase 14 | Pending |
|
||||||
| ADMIN-01 | Phase 9 | Pending |
|
| ADMIN-01 | Phase 9 | Complete |
|
||||||
| ADMIN-02 | Phase 9 | Pending |
|
| ADMIN-02 | Phase 9 | Complete |
|
||||||
| ADMIN-03 | Phase 9 | Pending |
|
| ADMIN-03 | Phase 9 | Complete |
|
||||||
| ADMIN-04 | Phase 9 | Pending |
|
| ADMIN-04 | Phase 9 | Complete |
|
||||||
| ADMIN-05 | Phase 9 | Pending |
|
| ADMIN-05 | Phase 9 | Complete |
|
||||||
| ADMIN-06 | Phase 10 | Complete |
|
| ADMIN-06 | Phase 10 | Complete |
|
||||||
| ADMIN-07 | Phase 10.1 | Complete |
|
| ADMIN-07 | Phase 10.1 | Complete |
|
||||||
| QA-01 | Phase 2 | Complete |
|
| QA-01 | Phase 2 | Complete |
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ Decimal phases appear between their surrounding integers in numeric order.
|
|||||||
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21)
|
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21)
|
||||||
- [x] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password (completed 2026-09-22)
|
- [x] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password (completed 2026-09-22)
|
||||||
- [x] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector (completed 2026-09-23)
|
- [x] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector (completed 2026-09-23)
|
||||||
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
|
- [x] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager (completed 2026-10-01)
|
||||||
- [x] **Phase 10: Admin Vue SPA** - Login, navigation, lists, forms and relation manager for five controllers (completed 2026-09-27)
|
- [x] **Phase 10: Admin Vue SPA** - Login, navigation, lists, forms and relation manager for five controllers (completed 2026-09-27)
|
||||||
- [ ] **Phase 11: Jobs, realtime and search infrastructure** - River, Centrifugo and Typesense sync brought up before the API phases that need them
|
- [ ] **Phase 11: Jobs, realtime and search infrastructure** - River, Centrifugo and Typesense sync brought up before the API phases that need them
|
||||||
- [ ] **Phase 12: Płytarium API — Collections and Albums** - Core content endpoints ported with byte-level parity
|
- [ ] **Phase 12: Płytarium API — Collections and Albums** - Core content endpoints ported with byte-level parity
|
||||||
@@ -375,7 +375,7 @@ Plans:
|
|||||||
4. The relation-manager schema supports search/link/unlink/manage-or-view lists for Collections' editors tab, replacing the `partial` field entirely.
|
4. The relation-manager schema supports search/link/unlink/manage-or-view lists for Collections' editors tab, replacing the `partial` field entirely.
|
||||||
5. Admin CRUD endpoints expose `listExtendQuery`/`formExtendQuery`/`formBeforeCreate`/`formBeforeUpdate`/`relationExtendManageQuery` hooks, bulk delete runs each record's lifecycle hooks, and the Settings model binds to a settings screen through the same schema pipeline.
|
5. Admin CRUD endpoints expose `listExtendQuery`/`formExtendQuery`/`formBeforeCreate`/`formBeforeUpdate`/`relationExtendManageQuery` hooks, bulk delete runs each record's lifecycle hooks, and the Settings model binds to a settings screen through the same schema pipeline.
|
||||||
|
|
||||||
**Plans**: 12/12 plans executed
|
**Plans**: 12/12 plans complete
|
||||||
**Research flag:** yes
|
**Research flag:** yes
|
||||||
|
|
||||||
Plans:
|
Plans:
|
||||||
@@ -703,7 +703,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
|||||||
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
||||||
| 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 |
|
| 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 |
|
||||||
| 8. OAuth2.1 authorization server | 10/10 | Complete | 2026-09-23 |
|
| 8. OAuth2.1 authorization server | 10/10 | Complete | 2026-09-23 |
|
||||||
| 9. Backend admin authentication and schema pipeline | 12/12 | In Progress| |
|
| 9. Backend admin authentication and schema pipeline | 12/12 | Complete | 2026-10-01 |
|
||||||
| 10. Admin Vue SPA | 5/5 | Complete | 2026-09-27 |
|
| 10. Admin Vue SPA | 5/5 | Complete | 2026-09-27 |
|
||||||
| 11. Jobs, realtime and search infrastructure | 8/8 | In Progress| |
|
| 11. Jobs, realtime and search infrastructure | 8/8 | In Progress| |
|
||||||
| 11.1. SummerCMS documentation for humans and AI agents | 7/7 | In Progress| |
|
| 11.1. SummerCMS documentation for humans and AI agents | 7/7 | In Progress| |
|
||||||
|
|||||||
@@ -7,11 +7,11 @@ status: verifying
|
|||||||
stopped_at: Completed 11.2-03-PLAN.md
|
stopped_at: Completed 11.2-03-PLAN.md
|
||||||
last_updated: "2026-10-01T14:40:47.065Z"
|
last_updated: "2026-10-01T14:40:47.065Z"
|
||||||
last_activity: 2026-10-01
|
last_activity: 2026-10-01
|
||||||
last_activity_desc: Phase 11.2 execution started
|
last_activity_desc: Phase 09 re-verified and marked complete (review fixes applied)
|
||||||
state_head: c07db9a321d44d655179cf2e50a00afe0ababdb3
|
state_head: c07db9a321d44d655179cf2e50a00afe0ababdb3
|
||||||
progress:
|
progress:
|
||||||
total_phases: 20
|
total_phases: 20
|
||||||
completed_phases: 9
|
completed_phases: 10
|
||||||
total_plans: 96
|
total_plans: 96
|
||||||
completed_plans: 96
|
completed_plans: 96
|
||||||
milestone_name: milestone
|
milestone_name: milestone
|
||||||
|
|||||||
@@ -46,7 +46,7 @@
|
|||||||
{
|
{
|
||||||
"number": "9",
|
"number": "9",
|
||||||
"name": "Backend admin authentication and schema pipeline",
|
"name": "Backend admin authentication and schema pipeline",
|
||||||
"status": "in_progress"
|
"status": "complete"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"number": "10",
|
"number": "10",
|
||||||
@@ -99,5 +99,5 @@
|
|||||||
"label": "Advance to the next step (verify)",
|
"label": "Advance to the next step (verify)",
|
||||||
"reason": "Phase 11.2 of 20 · ready to verify"
|
"reason": "Phase 11.2 of 20 · ready to verify"
|
||||||
},
|
},
|
||||||
"updated_at": "2026-10-01T14:40:43.793Z"
|
"updated_at": "2026-10-01T21:19:02.996Z"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user