Commit Graph

21 Commits

Author SHA1 Message Date
Jakub Zych
2d7ac66605 docs(phase-07): add security threat verification 2026-09-23 18:19:43 +02:00
Jakub Zych
e537b67a37 docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:52:45 +02:00
Jakub Zych
b74484eabc docs(07-08): complete the avatar bucket publish plan
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:50:01 +02:00
Jakub Zych
33f716ddef docs(07-08): plan avatar bucket publish on serve and Handler 2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16 test(07): complete UAT - 11 passed, 1 issues 2026-09-23 10:33:16 +02:00
Jakub Zych
d20f99f2e6 docs(07-07): complete the user-api parity gap plan
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 00:01:18 +02:00
Jakub Zych
8a1a52915b fix(07): revise 07-07-PLAN.md for checker-found seeding blockers 2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db docs(07): plan gap closure for the pending user-api parity routes 2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816 docs(07): record the phase goal verification
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd docs(07-06): complete the unit coverage plan
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:21:31 +02:00
Jakub Zych
fa7bdb5f71 docs(07-05): complete the user API parity capture plan
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:44:05 +02:00
Jakub Zych
ecfcd23150 docs(07-04): complete the personal token and locale plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0 docs(07-03): complete the account management plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c docs(07-02): complete the user session plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d docs(07-01): complete framework auth primitives plan 2026-09-22 13:43:15 +02:00
Jakub Zych
3aed5c88c3 docs(07): revise plans after checker review 2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2 docs(07): create phase plan
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
  override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
  fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
  change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
  proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
  instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)

Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863 docs(07): add pattern map 2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21 docs(07): add validation strategy 2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22 docs(07): research user plugin and authentication phase 2026-09-22 02:42:14 +02:00
Jakub Zych
1979c45083 docs(07): capture phase context 2026-09-22 00:24:21 +02:00