From fcc86ac45e1011c9bcb243cac965c8af44311ea1 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Mon, 5 Oct 2026 13:34:30 +0200 Subject: [PATCH] docs(12.1-03): update state and roadmap after the Users screen plan --- .planning/ROADMAP.md | 4 ++-- .planning/STATE.md | 20 +++++++++++++------- .planning/state.json | 2 +- 3 files changed, 16 insertions(+), 10 deletions(-) diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index ca52dca..68ecb2e 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -649,7 +649,7 @@ Plans: 5. The new code has unit tests, delivered in the phase's last plan. **Open questions (discuss-phase):** impersonate user in or out of scope (security-sensitive); a separate permission for granting the `admin` group (it makes a site admin); whether convert-guest is needed for the application's data. -**Plans:** 2/5 plans executed +**Plans:** 3/5 plans executed Plans: @@ -660,7 +660,7 @@ Plans: - [x] 12.1-02-PLAN.md — Framework preview and form seams (summercms.go): preview context, `permissioneditor`, `password`, form virtual fields, per-operation rules, writable foreign key, locked relation options, `invisible` columns, `preset`; ends with the tag v0.1.3 **Wave 3** *(blocked on Wave 2 completion)* -- [ ] 12.1-03-PLAN.md — Plugin foundation and the Users screen (sm-user-plugin): additive migrations, permissions, navigation, list, filters, preview, form, bulk and record actions, delete semantics, password and invite, avatar, frontend permission resolver, `last_seen`, and the takeover guard for members of privileged groups (D-30) +- [x] 12.1-03-PLAN.md — Plugin foundation and the Users screen (sm-user-plugin): additive migrations, permissions, navigation, list, filters, preview, form, bulk and record actions, delete semantics, password and invite, avatar, frontend permission resolver, `last_seen`, and the takeover guard for members of privileged groups (D-30) **Wave 4** *(blocked on Wave 3 completion)* - [ ] 12.1-04-PLAN.md — User Groups and Organisations screens, the `members` relation manager, the privileged-group guard on every `users_groups` write path (T-12-18), and the application's parity allow-list entry and submodule pointer on framework v0.1.3 diff --git a/.planning/STATE.md b/.planning/STATE.md index b358298..71af12d 100644 --- a/.planning/STATE.md +++ b/.planning/STATE.md @@ -4,16 +4,16 @@ milestone: v1.0 current_phase: "12.1" current_phase_name: User plugin admin screens status: executing -stopped_at: Completed 12.1-02-PLAN.md -last_updated: "2026-10-05T10:43:57.974Z" +stopped_at: Completed 12.1-03-PLAN.md +last_updated: "2026-10-05T11:34:10.203Z" last_activity: 2026-10-04 last_activity_desc: Phase 12.1 execution started -state_head: bd4960401df99db7e1e4bb43ba1ab9edcde6f658 +state_head: 76df9c5bd6124d79d84ed67359f46fa347a1d58f progress: total_phases: 22 completed_phases: 11 total_plans: 123 - completed_plans: 120 + completed_plans: 121 milestone_name: milestone --- @@ -29,7 +29,7 @@ See: .planning/PROJECT.md (updated 2026-09-16) ## Current Position Phase: 12.1 (User plugin admin screens) — EXECUTING -Plan: 3 of 5 +Plan: 4 of 5 Status: Ready to execute Last activity: 2026-10-04 — Phase 12.1 execution started @@ -174,6 +174,7 @@ Progress: [██████░░░░] 60% | Phase 14 P06 | 132 min | 4 tasks | 26 files | | Phase 12.1 P01 | 38min | 4 tasks | 61 files | | Phase 12.1 P02 | 12h 43m | 6 tasks | 77 files | +| Phase 12.1 P03 | 46min | 4 tasks | 40 files | ## Accumulated Context @@ -547,6 +548,10 @@ Recent decisions affecting current work: - [Phase 12.1]: 12.1-02: relation locks are enforced on form create and update only; relation-manager link and unlink routes do not ask RelationLockProvider (open for plan 05) - [Phase 12.1]: 12.1-02: the SPA sends a permissioneditor field on every update reduced to offered codes; a locked code with a stored value outside the mode's set makes every save a 403 (open for plan 05) - [Phase 12.1]: 12.1-02: pact.FilterOptions keeps its signature and is asked on the admin controller before the model +- [Phase 12.1]: Users admin controller and its guard live in sm-user-plugin: a privileged-group member's email, password and permanent delete need golem15.users.manage_privileged_groups; refusals are cabana.ForbiddenError (D-30) +- [Phase 12.1]: HasPermission ports Winter line by line: a leading asterisk is a wildcard on the asked code only; PermissionSet.Scan fails on content that is not a JSON object rather than read it as empty +- [Phase 12.1]: A user created in the admin gets has_self_set_password true and stays not activated; the invitation carries the login and the activation link, never the password +- [Phase 12.1]: Plugin admin tests boot the plugin alone through newAdminEnv; mail is read from the log driver because the mailer service cannot be replaced after party.Activate ### Pending Todos @@ -575,6 +580,7 @@ Recent decisions affecting current work: - Phase 8 UI gate: scripts/check-phase8-ui.mjs --final-gate's real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented (deliberate fatal() at check-phase8-ui.mjs:458, never authored by 08-05); stage_ui_harness must keep failing closed until a Playwright spec is authored. User approved Phase 8 closure on 2026-09-24 with this gap carried forward -- see 08-10-SUMMARY.md and .planning/phases/08-oauth2-1-authorization-server/deferred-items.md. - Push summercms.go master and tag v0.1.3 to origin (tag is local on df5cace by the user's tag-local choice); the sm-user-plugin push of plan 12.1-05 Task 3 waits until git ls-remote --tags origin v0.1.3 lists the tag - fonoteka.go plugins/golem15/fonoteka: TestPhase09SecurityRoutes and TestPhase10ControllerCopy fail against framework v0.1.3 (fixed route and message-key lists lack the Phase 12.1 additions); see .planning/phases/12.1-user-plugin-admin-screens/deferred-items.md +- fonoteka.go: four more application tests pin lists the user plugin's admin work changes (TestAdminMetadataFiltering, TestHiddenNeverMarshals, parity TestMigrateSeedsCanonicalGenres and TestRollbackLastIsolatesFonoteka) and TestSchemaMatchesPHPSnapshot needs the frontend-permissions allow-list entry; plan 12.1-04 owns them (deferred-items.md) ### Quick Tasks Completed @@ -598,6 +604,6 @@ Items acknowledged and carried forward from previous milestone close: ## Session Continuity -Last session: 2026-10-05T10:43:39.991Z -Stopped at: Completed 12.1-02-PLAN.md +Last session: 2026-10-05T11:34:09.660Z +Stopped at: Completed 12.1-03-PLAN.md Resume file: None diff --git a/.planning/state.json b/.planning/state.json index 38b3107..c711aff 100644 --- a/.planning/state.json +++ b/.planning/state.json @@ -99,5 +99,5 @@ "label": "Advance to the next step", "reason": "Phase 12.1 of 22 · executing" }, - "updated_at": "2026-10-05T10:43:37.111Z" + "updated_at": "2026-10-05T11:34:04.418Z" }