docs(06-06): update plan tracking

This commit is contained in:
Jakub Zych
2026-09-20 13:33:11 +02:00
parent 7f627961b1
commit f5fd55f419
3 changed files with 17 additions and 14 deletions

View File

@@ -3,15 +3,15 @@ gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
stopped_at: Completed 06-05-PLAN.md
last_updated: "2026-09-19T22:19:43.824Z"
last_activity: 2026-09-19 -- Phase 6 planning complete
stopped_at: Completed 06-06-PLAN.md
last_updated: "2026-09-20T11:32:44.614Z"
last_activity: 2026-09-20
progress:
total_phases: 15
completed_phases: 5
completed_phases: 6
total_plans: 29
completed_plans: 28
percent: 33
completed_plans: 29
percent: 40
---
# Project State
@@ -26,9 +26,9 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
Plan: 5 of 5
Plan: 6 of 6
Status: Ready to execute
Last activity: 2026-09-19 -- Phase 6 planning complete
Last activity: 2026-09-20
Progress: [██████████] 100%
@@ -74,6 +74,7 @@ Progress: [██████████] 100%
| Phase 06 P02 | 14 min | 3 tasks | 16 files |
| Phase 06 P03 | 20 min | 3 tasks | 24 files |
| Phase 06 P05 | 13 min | 3 tasks | 13 files |
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
## Accumulated Context
@@ -171,6 +172,8 @@ Recent decisions affecting current work:
- [Phase 06]: Full route-table isolation uses surf.BuildRouter of the real plugins; app.Handler returns http.Handler and cannot call Routes() — app.Handler assembles an http.Handler; Routes() is on *surf.Router
- [Phase 06]: T-06-05 remains accept as originating 06-01 (the 06-05 plan three-accepts list omitted it) — Originating plan disposition is copied verbatim into 06-SECURITY-REVIEW.md
- [Phase 06]: PublicOnlyMode any-host-when-public is proven via skipReservedCheck httptest, not a live public IP dial — Unit tests must not require outbound network
- [Phase 06]: Keep inv_token outermost so valid credentials populate bouncer.Credential before the limiter selects tok:<id>. — The named bucket must retain per-token isolation for valid credentials instead of collapsing them onto the IP fallback.
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
### Pending Todos
@@ -192,6 +195,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-19T19:21:17.950Z
Stopped at: Completed 06-05-PLAN.md
Last session: 2026-09-20T11:32:06.433Z
Stopped at: Completed 06-06-PLAN.md
Resume file: None