|
|
|
|
@@ -69,7 +69,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|
|
|
|
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
|
|
|
|
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
|
|
|
|
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
|
|
|
|
- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
|
|
|
|
- [x] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
|
|
|
|
|
|
|
|
|
### Płytarium API (API)
|
|
|
|
|
|
|
|
|
|
@@ -107,11 +107,11 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|
|
|
|
|
|
|
|
|
### Admin (ADMIN)
|
|
|
|
|
|
|
|
|
|
- [ ] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes
|
|
|
|
|
- [ ] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers
|
|
|
|
|
- [ ] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab
|
|
|
|
|
- [ ] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks
|
|
|
|
|
- [ ] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense)
|
|
|
|
|
- [x] **ADMIN-01**: fields.yaml is parsed (goccy/go-yaml) into a JSON form schema with text, textarea, checkbox, switch, dropdown (model-method options), relation (nameFrom, emptyOption), plus span, tabs, context and attributes
|
|
|
|
|
- [x] **ADMIN-02**: columns.yaml is parsed into a JSON list schema with searchable, sortable, relation columns and datetime/switch renderers
|
|
|
|
|
- [x] **ADMIN-03**: A relation-manager schema (search, link, unlink, manage/view lists) replaces the one `partial` field in Collections' editors tab
|
|
|
|
|
- [x] **ADMIN-04**: Admin CRUD endpoints per controller expose extension hooks (listExtendQuery, formExtendQuery, formBeforeCreate, formBeforeUpdate, relationExtendManageQuery), and bulk delete runs each record's lifecycle hooks
|
|
|
|
|
- [x] **ADMIN-05**: A settings model binds to a settings screen through the same schema pipeline (search_use_typesense)
|
|
|
|
|
- [x] **ADMIN-06**: A minimal Vue 3 + TypeScript SPA renders login, permission-gated navigation, lists, forms and the relation manager for Albums, Artists, Collections, Genres and Styles using generated types
|
|
|
|
|
- [x] **ADMIN-07**: A plugin extends the compiled admin SPA without a Node rebuild: controller-declared JS/CSS is served from the plugin's embedded files under `{backend.uri}/assets/` and loaded when that controller opens (CSP `script-src 'self'`); `type: widget` fields mount plugin custom elements whose actions the SPA posts with the admin cookie and CSRF header, patching only the declared `fill` fields; `type: partial` form fields and a `config_list.yaml` `headerPartial` render server-side with `html/template` from a controller view model and display without any raw-HTML sink; and controllers register named toolbar actions. Unknown YAML keys, missing templates and unregistered actions fail boot.
|
|
|
|
|
|
|
|
|
|
@@ -211,7 +211,7 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|
|
|
|
| AUTH-05 | Phase 8 | Complete |
|
|
|
|
|
| AUTH-06 | Phase 8 | Complete |
|
|
|
|
|
| AUTH-07 | Phase 8 | Complete |
|
|
|
|
|
| AUTH-08 | Phase 9 | Pending |
|
|
|
|
|
| AUTH-08 | Phase 9 | Complete |
|
|
|
|
|
| API-01 | Phase 12 | Pending |
|
|
|
|
|
| API-02 | Phase 12 | Pending |
|
|
|
|
|
| API-03 | Phase 13 | Pending |
|
|
|
|
|
@@ -231,11 +231,11 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|
|
|
|
| SRCH-02 | Phase 14 | Pending |
|
|
|
|
|
| INTG-01 | Phase 14 | Pending |
|
|
|
|
|
| INTG-02 | Phase 14 | Pending |
|
|
|
|
|
| ADMIN-01 | Phase 9 | Pending |
|
|
|
|
|
| ADMIN-02 | Phase 9 | Pending |
|
|
|
|
|
| ADMIN-03 | Phase 9 | Pending |
|
|
|
|
|
| ADMIN-04 | Phase 9 | Pending |
|
|
|
|
|
| ADMIN-05 | Phase 9 | Pending |
|
|
|
|
|
| ADMIN-01 | Phase 9 | Complete |
|
|
|
|
|
| ADMIN-02 | Phase 9 | Complete |
|
|
|
|
|
| ADMIN-03 | Phase 9 | Complete |
|
|
|
|
|
| ADMIN-04 | Phase 9 | Complete |
|
|
|
|
|
| ADMIN-05 | Phase 9 | Complete |
|
|
|
|
|
| ADMIN-06 | Phase 10 | Complete |
|
|
|
|
|
| ADMIN-07 | Phase 10.1 | Complete |
|
|
|
|
|
| QA-01 | Phase 2 | Complete |
|
|
|
|
|
|