docs(14.1): add validation strategy

This commit is contained in:
Jakub Zych
2026-10-05 19:26:11 +02:00
parent 0ea0c787a5
commit f453b80dc7

View File

@@ -0,0 +1,91 @@
---
phase: "14.1"
slug: "oauth-identities-and-fonoteka-me-routes"
# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6)
# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117)
status: draft
nyquist_compliant: false
wave_0_complete: false
created: "2026-10-05"
---
# Phase 14.1 — Validation Strategy
> Per-phase validation contract for feedback sampling during execution.
---
## Test Infrastructure
| Property | Value |
|----------|-------|
| **Framework** | Go `testing` + testcontainers-go v0.44.0 (user plugin); parity `tide` replay in `fonoteka.go/parity` |
| **Config file** | none — `go test`; do not retarget Phase 14's `scripts/check-phase14.sh` |
| **Quick run command** | `go test ./plugins/golem15/user/... ./plugins/golem15/fonoteka/controllers/api/... -count=1` in fonoteka.go |
| **Full suite command** | `go vet ./... && go test ./... -count=1` in summercms.go; same plus `./plugins/golem15/user/... ./plugins/golem15/fonoteka/... ./parity/...` in fonoteka.go |
| **Estimated runtime** | ~90 seconds quick; several minutes full (parity + testcontainers) |
---
## Sampling Rate
- **After every task commit:** Run the quick run command above plus `go vet` on touched packages
- **After every plan wave:** Run the full suite in both repos
- **Before `$gsd-verify-work`:** Full suite must be green; `TestParityCorpus` prints `recorded 175/175 passing 175 failing 0 unrecorded 0 pending 0`
- **Max feedback latency:** 90 seconds (quick); full suite is the wave gate
---
## Per-Task Verification Map
Filled after plans exist. Seeded from RESEARCH.md Validation Architecture:
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
| 14.1-W0 | 02 | 2 | API-09 | — | Three routes ported, 0 pending | parity | `go test ./parity -run TestParityCorpus -count=1` | ✅ extend | ⬜ pending |
| 14.1-W0 | 02 | 2 | HTTP-03 | T-14.1-SC | JWT-only identities; token group never gains them | unit | `go test ./plugins/golem15/fonoteka -count=1` | ✅ flip `assertAbsent` | ⬜ pending |
| 14.1-W0 | 02 | 2 | HTTP-01 | T-14.1-* | Missing, foreign, unknown provider → identical Winter 404 | unit | new `oauth_identities_test.go` | ❌ W0 | ⬜ pending |
| 14.1-W0 | 02 | 2 | D-06 / I18N-01 | T-14.1-* | Last identity 409 EN/PL | unit | same | ❌ W0 | ⬜ pending |
| 14.1-W0 | 01 | 1 | D-09 | — | `/me` unrestricted `collection_ids` null | unit + parity | rewrite MeToken test; new fixture | ✅ rewrite | ⬜ pending |
| 14.1-W0 | 02 | 2 | DATA-02 | — | Migration up/down, indexes, jsonb, FK | integration | `go test ./plugins/golem15/user/updates -count=1` | ❌ W0 | ⬜ pending |
| 14.1-W0 | 02 | 2 | DATA-07 | T-14.1-* | Encrypted tokens never in GET body | unit + parity | PHP test port + D-10 fixture | ❌ W0 | ⬜ pending |
| 14.1-W0 | 01 | 1 | HTTP-04 | T-14.1-* | DELETE `throttle:10,1` | unit | `assertRouteSurfaces` + middleware contains throttle | ✅ extend | ⬜ pending |
| 14.1-W0 | — | — | QA-05 | — | Nuxt/MCP unchanged | manual-only | Connected accounts + MCP `me()` against Go | N/A | ⬜ pending |
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
---
## Wave 0 Requirements
- [ ] `plugins/golem15/user/controllers/oauth_identities_test.go` — D-11 behaviours
- [ ] `plugins/golem15/user/updates/oauth_identities_test.go` — migration up/down
- [ ] Rewrite `me_token_controller_test.go` nil-collection assertion
- [ ] Rewrite `parity/parity_test.go` `assertPortedMismatch`
- [ ] D-10 fixtures + `fonotekaCaseExtras` / `fonoteka_reset.php` extras
- [ ] Flip `phase08_coverage_test.go` oauth identity `assertAbsent`
- [ ] sm-user-plugin README API + table row
Existing infrastructure covers parity replay, testcontainers migration tests, and JWT group assembly. No new test framework.
---
## Manual-Only Verifications
| Behavior | Requirement | Why Manual | Test Instructions |
|----------|-------------|------------|-------------------|
| Nuxt Connected accounts tab still talks to Go | QA-05 | Consumers are frozen; no Go-side UI | Sign in, open Settings → Connected accounts; list/unlink against the Go backend |
| fonoteka-mcp `me()` still boots | QA-05 | MCP TypeScript client is unchanged | Call MCP `me()` against Go; extra `collection_ids` is ignored by its type |
---
## Validation Sign-Off
- [ ] All tasks have `<automated>` verify or Wave 0 dependencies
- [ ] Sampling continuity: no 3 consecutive tasks without automated verify
- [ ] Wave 0 covers all MISSING references
- [ ] No watch-mode flags
- [ ] Feedback latency < 90s (quick path)
- [ ] `nyquist_compliant: true` set in frontmatter
**Approval:** pending