docs(06-03): complete raw groups, wire, CORS, and body-limit plan

- Operator-confirmed 128MiB body limits (134217728); D-18/T-06-13 closed
- HTTP-06, HTTP-08, HTTP-09 marked complete
This commit is contained in:
Jakub Zych
2026-09-19 21:01:07 +02:00
parent 30539b954f
commit f61776d0a6
4 changed files with 236 additions and 15 deletions

View File

@@ -55,10 +55,10 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
- [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection)
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
- [x] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
- [ ] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
- [ ] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
- [ ] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
### Authentication and users (AUTH)
@@ -188,10 +188,10 @@ Which phases cover which requirements. Updated during roadmap creation.
| HTTP-03 | Phase 6 | Complete |
| HTTP-04 | Phase 6 | Complete |
| HTTP-05 | Phase 6 | Complete |
| HTTP-06 | Phase 6 | Pending |
| HTTP-06 | Phase 6 | Complete |
| HTTP-07 | Phase 6 | Pending |
| HTTP-08 | Phase 6 | Pending |
| HTTP-09 | Phase 6 | Pending |
| HTTP-08 | Phase 6 | Complete |
| HTTP-09 | Phase 6 | Complete |
| AUTH-01 | Phase 7 | Pending |
| AUTH-02 | Phase 7 | Pending |
| AUTH-03 | Phase 7 | Pending |