From f453b80dc7e1fdad03e1b947e9c909b1fc7353a7 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Mon, 5 Oct 2026 19:26:11 +0200 Subject: [PATCH] docs(14.1): add validation strategy --- .../14.1-VALIDATION.md | 91 +++++++++++++++++++ 1 file changed, 91 insertions(+) create mode 100644 .planning/phases/14.1-oauth-identities-and-fonoteka-me-routes/14.1-VALIDATION.md diff --git a/.planning/phases/14.1-oauth-identities-and-fonoteka-me-routes/14.1-VALIDATION.md b/.planning/phases/14.1-oauth-identities-and-fonoteka-me-routes/14.1-VALIDATION.md new file mode 100644 index 0000000..48c4211 --- /dev/null +++ b/.planning/phases/14.1-oauth-identities-and-fonoteka-me-routes/14.1-VALIDATION.md @@ -0,0 +1,91 @@ +--- +phase: "14.1" +slug: "oauth-identities-and-fonoteka-me-routes" +# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6) +# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117) +status: draft +nyquist_compliant: false +wave_0_complete: false +created: "2026-10-05" +--- + +# Phase 14.1 — Validation Strategy + +> Per-phase validation contract for feedback sampling during execution. + +--- + +## Test Infrastructure + +| Property | Value | +|----------|-------| +| **Framework** | Go `testing` + testcontainers-go v0.44.0 (user plugin); parity `tide` replay in `fonoteka.go/parity` | +| **Config file** | none — `go test`; do not retarget Phase 14's `scripts/check-phase14.sh` | +| **Quick run command** | `go test ./plugins/golem15/user/... ./plugins/golem15/fonoteka/controllers/api/... -count=1` in fonoteka.go | +| **Full suite command** | `go vet ./... && go test ./... -count=1` in summercms.go; same plus `./plugins/golem15/user/... ./plugins/golem15/fonoteka/... ./parity/...` in fonoteka.go | +| **Estimated runtime** | ~90 seconds quick; several minutes full (parity + testcontainers) | + +--- + +## Sampling Rate + +- **After every task commit:** Run the quick run command above plus `go vet` on touched packages +- **After every plan wave:** Run the full suite in both repos +- **Before `$gsd-verify-work`:** Full suite must be green; `TestParityCorpus` prints `recorded 175/175 passing 175 failing 0 unrecorded 0 pending 0` +- **Max feedback latency:** 90 seconds (quick); full suite is the wave gate + +--- + +## Per-Task Verification Map + +Filled after plans exist. Seeded from RESEARCH.md Validation Architecture: + +| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status | +|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------| +| 14.1-W0 | 02 | 2 | API-09 | — | Three routes ported, 0 pending | parity | `go test ./parity -run TestParityCorpus -count=1` | ✅ extend | ⬜ pending | +| 14.1-W0 | 02 | 2 | HTTP-03 | T-14.1-SC | JWT-only identities; token group never gains them | unit | `go test ./plugins/golem15/fonoteka -count=1` | ✅ flip `assertAbsent` | ⬜ pending | +| 14.1-W0 | 02 | 2 | HTTP-01 | T-14.1-* | Missing, foreign, unknown provider → identical Winter 404 | unit | new `oauth_identities_test.go` | ❌ W0 | ⬜ pending | +| 14.1-W0 | 02 | 2 | D-06 / I18N-01 | T-14.1-* | Last identity 409 EN/PL | unit | same | ❌ W0 | ⬜ pending | +| 14.1-W0 | 01 | 1 | D-09 | — | `/me` unrestricted `collection_ids` null | unit + parity | rewrite MeToken test; new fixture | ✅ rewrite | ⬜ pending | +| 14.1-W0 | 02 | 2 | DATA-02 | — | Migration up/down, indexes, jsonb, FK | integration | `go test ./plugins/golem15/user/updates -count=1` | ❌ W0 | ⬜ pending | +| 14.1-W0 | 02 | 2 | DATA-07 | T-14.1-* | Encrypted tokens never in GET body | unit + parity | PHP test port + D-10 fixture | ❌ W0 | ⬜ pending | +| 14.1-W0 | 01 | 1 | HTTP-04 | T-14.1-* | DELETE `throttle:10,1` | unit | `assertRouteSurfaces` + middleware contains throttle | ✅ extend | ⬜ pending | +| 14.1-W0 | — | — | QA-05 | — | Nuxt/MCP unchanged | manual-only | Connected accounts + MCP `me()` against Go | N/A | ⬜ pending | + +*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky* + +--- + +## Wave 0 Requirements + +- [ ] `plugins/golem15/user/controllers/oauth_identities_test.go` — D-11 behaviours +- [ ] `plugins/golem15/user/updates/oauth_identities_test.go` — migration up/down +- [ ] Rewrite `me_token_controller_test.go` nil-collection assertion +- [ ] Rewrite `parity/parity_test.go` `assertPortedMismatch` +- [ ] D-10 fixtures + `fonotekaCaseExtras` / `fonoteka_reset.php` extras +- [ ] Flip `phase08_coverage_test.go` oauth identity `assertAbsent` +- [ ] sm-user-plugin README API + table row + +Existing infrastructure covers parity replay, testcontainers migration tests, and JWT group assembly. No new test framework. + +--- + +## Manual-Only Verifications + +| Behavior | Requirement | Why Manual | Test Instructions | +|----------|-------------|------------|-------------------| +| Nuxt Connected accounts tab still talks to Go | QA-05 | Consumers are frozen; no Go-side UI | Sign in, open Settings → Connected accounts; list/unlink against the Go backend | +| fonoteka-mcp `me()` still boots | QA-05 | MCP TypeScript client is unchanged | Call MCP `me()` against Go; extra `collection_ids` is ignored by its type | + +--- + +## Validation Sign-Off + +- [ ] All tasks have `` verify or Wave 0 dependencies +- [ ] Sampling continuity: no 3 consecutive tasks without automated verify +- [ ] Wave 0 covers all MISSING references +- [ ] No watch-mode flags +- [ ] Feedback latency < 90s (quick path) +- [ ] `nyquist_compliant: true` set in frontmatter + +**Approval:** pending