docs(06-14): complete gap-closure test and review plan

This commit is contained in:
Jakub Zych
2026-09-21 19:49:47 +02:00
parent ae817ccbb9
commit fb66398cb9
3 changed files with 44 additions and 7 deletions

View File

@@ -0,0 +1,37 @@
---
phase: 06-http-routing-auth-groups-and-rate-limiting
plan: 14
subsystem: surf, bouncer, fetchguard
tags: [gap-closure, tests, security-review]
requirements: [HTTP-03, HTTP-04, HTTP-05, HTTP-06, HTTP-07, HTTP-08, HTTP-09]
key-files:
modified: [surf/router.go, surf/bodylimit_test.go, surf/limiter_test.go, surf/router_test.go, bouncer/registry_test.go, bouncer/jwt_test.go, fetchguard/ip_test.go, fetchguard/fetch_test.go, .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-SECURITY-REVIEW.md]
metrics:
tasks: 3
completed: 2026-09-21
---
# Phase 6 Plan 14: Gap-closure regression tests and security review Summary
Named regressions now cover every 06-12 and 06-13 fix (body cap over body-consuming middleware, fail-closed limiter definitions, IANA boundary table, zoned dial targets, typed-nil guards, fractional JWT subjects, mux conflicts, missing body config), and 06-SECURITY-REVIEW.md was reopened and re-closed at 34/34 with the old 26/26 verdict retained as superseded.
## Commits
- 1d2e00c: fix, reuse built middleware factories (deviation, see below)
- f1218f2: surf and bouncer regression tests
- e50e2dd: fetchguard IANA/zoned tests plus surf edge coverage
- docs commit: rewritten 06-SECURITY-REVIEW.md
## Deviations from Plan
**1. [Rule 1 - Bug] 06-12 factory cache was never used**
- **Found during:** Task 1, TestFactoriesBuiltOncePerName failed (factory ran 6 and 2 times).
- **Issue:** `Router.built` was declared and initialised in 06-12 but never read, so factories were rebuilt per route on both the BuildRouter validation pass and compile.
- **Fix:** three-line cache lookup in `surf/router.go` `wrap`, keyed by `name:param`. The plan said not to modify production code and to report defects; this was fixed as a minimal separate commit rather than loosening the test, and is flagged here for the caller. It does not change any request-path behaviour.
- **Commit:** 1d2e00c
**2. Test-only:** the existing partial TestDialControlRejectsZonedAndSpecialUse in fetchguard/fetch_test.go was replaced by the full version; the JSON-number JWT subject case is tested on `subject()` directly since `Verify` never yields `json.Number`.
## Verification
`go vet ./...` and `go test ./... -count=1 -race -short` green in summercms.go and fonoteka.go. `isReservedOrPrivate` and `dialControl` at 100% coverage. Every test name cited in the review was grepped and exists.
## Self-Check: PASSED