Commit Graph

495 Commits

Author SHA1 Message Date
Jakub Zych
2a955d6447 docs(09-06): complete albums admin collection boundary plan 2026-09-24 20:22:07 +02:00
Jakub Zych
0caa86ec0b feat(09-06): keep relation required flags off unbound columns
- Schema JSON still reports required relations for the client
- Save validation only adds required for scalar writable fields
2026-09-24 20:19:29 +02:00
Jakub Zych
c63146accb feat(09-06): serve admin form schemas and match Winter relations
- GET schema/form localizes the compiled form after the permission check
- relation: genre resolves to the exported Go field without changing the YAML key
2026-09-24 20:10:48 +02:00
Jakub Zych
3e7738ff32 docs(09-05): complete schema-projected CRUD plan 2026-09-24 19:48:29 +02:00
Jakub Zych
50754808f6 feat(09-05): make bulk delete atomic, ordered, and retry-safe
- Reject an empty selection and dedupe ids before locking rows in pk order
- Return deleted 0 when every requested row is already gone, without hooks
- Roll back mixed, hook, and cancelled batches so no partial delete commits
2026-09-24 19:45:15 +02:00
Jakub Zych
247c3235f6 test(09-05): add failing tests for deterministic bulk delete
- Empty selections are 422 and duplicates run once in primary-key order
- A completed retry and an all-absent selection delete nothing and skip hooks
- Mixed, hook, cancel, and concurrent requests keep the batch atomic
2026-09-24 19:43:15 +02:00
Jakub Zych
e3e1c2546e feat(09-05): enforce scoped record lifecycle on admin routes
- Mount show, create, update, and delete behind the backend permission check
- Run controller and model hooks once per operation and roll back on failure
- Treat missing and out-of-scope records the same, including idempotent delete
2026-09-24 19:39:08 +02:00
Jakub Zych
94814d980b test(09-05): add failing tests for scoped record lifecycle
- Record routes must enforce permission before ids or bodies and return D-10 envelopes
- Create, update, and delete run Before and After hooks once inside the transaction
- Out-of-scope and missing records are indistinguishable, and hook failure rolls back
2026-09-24 19:38:23 +02:00
Jakub Zych
578bdc8d5d feat(09-05): project writable fields through Fill and Validate
- Bind schema fields to model columns at activation and drop protected keys
- Create and update Fill, run BeforeValidate, then Validate before persistence
- Missing Fill or Validate capability and provider errors fail closed
2026-09-24 19:28:36 +02:00
Jakub Zych
1e14da7bb5 test(09-05): add failing tests for writable fill and validate
- Create and update must Fill then Validate and return D-10 422 field errors
- Schema bindings exclude protected, cased, nested, and unknown keys
- Missing Fill or Validate capability fails closed with controller context
2026-09-24 19:25:18 +02:00
Jakub Zych
040f3ef81c docs(09-04): complete deterministic admin list queries plan 2026-09-24 19:07:01 +02:00
Jakub Zych
3efdcc1c59 fix(09-04): keep relation columns out of the default sort set
- A relation column is not sortable unless columns.yaml says so
- An explicit sortable relation orders the joined select column, then the primary key
2026-09-24 19:04:42 +02:00
Jakub Zych
6a57f63e81 feat(09-04): execute allowlisted deterministic list queries
- Search, sort, filters, and pagination use compiled selectors and bound values
- Equal sort keys break ties on the primary key so adjacent pages do not overlap
- Unknown identifiers return validation_failed before SQL
2026-09-24 19:03:44 +02:00
Jakub Zych
7f451c3572 test(09-04): add failing tests for deterministic list queries
- Search, sort, filters, and adjacent pages must return the D-11 envelope
- Empty and single results keep an array and the requested page size
- Unknown identifiers and injected values fail closed before unsafe SQL
2026-09-24 18:58:56 +02:00
Jakub Zych
d3a93073c9 feat(09-04): compile switch, date-range, and scope filters
- Filters keep typed values and only registered scope names
- Raw conditions and arbitrary methods fail activation
- Request localization copies labels and leaves identifiers unchanged
2026-09-24 18:53:52 +02:00
Jakub Zych
cb832eb70c test(09-04): add failing tests for typed list filters
- Switch, date-range, and model-scope filters must keep typed values
- Option labels localize without changing identifiers or cached keys
- Raw conditions, unknown scopes, and arbitrary methods fail activation
2026-09-24 18:50:17 +02:00
Jakub Zych
aab4398ce4 feat(09-04): compile ordered Winter list schemas
- Typed columns, actions, default sort, search term, and page sizes
- Omitted sortable defaults to true and empty collections marshal as arrays
- Unknown keys, bad defaults, and path escape fail before routes are served
2026-09-24 18:46:53 +02:00
Jakub Zych
fd591ed3a7 test(09-04): add failing tests for ordered list schemas
- Columns, actions, default sort, and page sizes must compile to typed JSON
- Empty and single declarations stay arrays and keep source order
- Unsupported keys, actions, defaults, and path escape fail activation
2026-09-24 18:43:26 +02:00
Jakub Zych
db3d7222e9 docs(09-03): complete typed winter form schema plan 2026-09-24 18:27:51 +02:00
Jakub Zych
68715fc260 feat(09-03): scaffold Winter admin controller layout
- config_form.yaml and config_list.yaml point at models/<name>/fields.yaml and columns.yaml
- Duplicate model or controller assets fail before any new file is written
2026-09-24 18:25:20 +02:00
Jakub Zych
af8e58a038 test(09-03): add failing tests for Winter admin controller scaffolding
- make:admin-controller must emit config_form and config_list beside model fields and columns
- A pre-existing model asset must fail before any controller file is written
2026-09-24 18:24:06 +02:00
Jakub Zych
da8828ef38 feat(09-03): localize form schemas and resolve dropdown options
- Cached schemas stay source-key IR and each response carries its own meta.locale
- YAML option maps keep declaration order and scalar type; method options call DropdownOptions and fail boot without a provider
2026-09-24 18:21:59 +02:00
Jakub Zych
ad1b76085a test(09-03): add failing tests for form locale and dropdown options
- The same cached schema must localize pl and en independently, including Accept-Language parent fallback and raw keys
- YAML option maps keep order and scalar type, and a method provider is required at boot
2026-09-24 18:20:21 +02:00
Jakub Zych
4c814e5f63 feat(09-03): compile ordered Winter form schemas
- Strict config_form and fields documents keep source order and JSON scalar types
- Unknown keys, partials, path escape, and a mismatched modelClass fail activation with plugin context
- List-only controllers still activate when config_form.yaml is absent
2026-09-24 18:17:45 +02:00
Jakub Zych
ea3f0705f4 test(09-03): add failing test for strict form schema compilation
- All locked field kinds, empty and single documents, and source order fail closed
- Unknown keys, types, duplicates, path escape, modelClass, partials, and missing assets must name the plugin, controller, and file
2026-09-24 18:12:53 +02:00
Jakub Zych
af3312aa92 docs(09-02): complete backend identity lifecycle plan
- Record the migration, JWT lifecycle, and admin command results
2026-09-24 17:59:31 +02:00
Jakub Zych
5f218977e4 feat(09-02): add admin create and reset-password commands
- Commands hash with bcrypt, validate role codes, and revoke tokens on reset
- Generated app main appends cabana.RuntimeCommands exactly once
2026-09-24 17:56:34 +02:00
Jakub Zych
d27f442c49 test(09-02): add failing tests for admin create and reset commands
- admin:create and admin:reset-password are not registered yet
- Generated app main does not append cabana runtime commands
2026-09-24 17:54:42 +02:00
Jakub Zych
9740c3dcdb feat(09-02): implement backend JWT lifecycle, throttle, and auth logs
- Refresh, logout, and me use a separate PostgreSQL jti blacklist and safe profile
- Login stamps last_login only after a successful check and throttles repeated attempts
2026-09-24 17:50:41 +02:00
Jakub Zych
0953308e26 test(09-02): add failing tests for the backend auth lifecycle
- Login does not stamp last_login and logout, refresh, and me are unmounted
- Repeated logins are not throttled and auth events are not logged
2026-09-24 17:47:15 +02:00
Jakub Zych
06a7292dea feat(09-02): implement exact backend identity migrations
- Add the admin jti table, reset cutoff, and Winter indexes without AutoMigrate
- Reapply the developer and publisher seed idempotently and allow repeated role codes
2026-09-24 17:40:34 +02:00
Jakub Zych
448faa465f test(09-02): add failing tests for backend identity migrations
- Fresh migrate is missing tokens_valid_after and the admin blacklist table
- Reapplying the seed is not idempotent and role codes reject Winter duplicates
2026-09-24 17:38:53 +02:00
Jakub Zych
0ed980e332 docs(09-01): complete separate-admin genre list tracer plan 2026-09-24 17:23:23 +02:00
Jakub Zych
18b2e85106 feat(09-01): reject cross-audience tokens on both guards
- Frontend verification accepts a missing audience for PHP tokens
- An explicit audience must match the guard, even when the secret is shared
2026-09-24 17:20:57 +02:00
Jakub Zych
8c1de83f01 test(09-01): add failing audience crossover and authorization-order tests
- Same-secret backend token is still accepted by the frontend guard
- Permission denial must not invoke the schema or database callback
- Admin error bodies must not echo secrets or raw tokens
2026-09-24 17:19:57 +02:00
Jakub Zych
dfa00f7e3a feat(09-01): implement separate-admin genre list tracer
- Audience-aware mint, verify, refresh, and backend guard keep frontend tokens compatible
- Cabana mounts raw admin login, list schema, and record list behind admin.jwt.secret
- Framework migration seeds Winter backend users and developer/publisher roles
2026-09-24 17:17:19 +02:00
Jakub Zych
01d3871510 docs(09): create phase plan 2026-09-24 16:45:45 +02:00
Jakub Zych
1fbf492450 docs(09): resolve research planning rules 2026-09-24 15:57:19 +02:00
Jakub Zych
316bd4088f docs(phase-9): add validation strategy 2026-09-24 15:56:40 +02:00
Jakub Zych
f99950bf95 docs(09): research phase domain 2026-09-24 15:47:45 +02:00
Jakub Zych
310a4cd7a8 docs(08): add code review report 2026-09-24 01:16:02 +02:00
Jakub Zych
95e8ccde3d docs(phase-08): evolve PROJECT.md after phase completion 2026-09-24 01:14:16 +02:00
Jakub Zych
23f295824c docs(phase-08): complete phase execution 2026-09-24 01:13:55 +02:00
Jakub Zych
0fcd06fde8 docs(08-10): complete coverage, security review and final gate plan
Phase 8 closed on user approval (Playwright UI matrix gap carried forward).
AUTH-05/06/07 marked complete; ROADMAP and STATE reflect 10/10 plans done.
2026-09-24 01:04:00 +02:00
Jakub Zych
482944b160 docs(08-10): add the coverage, security-review and final-gate summary
Documents the 103-method audit closure, the self-performed 11/11-closed
security review (with disclosure), the real defects check-phase8.sh's first
end-to-end run found and fixed, and the checkpoint decision to close Phase 8
with the Playwright UI matrix gap carried forward.
2026-09-24 01:02:48 +02:00
Jakub Zych
2d551c09d7 docs(08-10): record the checkpoint decision and carry the Playwright UI matrix gap forward
scripts/check-phase8.sh's final gate ran once with every stage green except
stage_ui_harness's Playwright browser matrix, a deliberate fatal() never
authored by 08-05. The user approved closing Phase 8 with this gap carried
forward; 08-VALIDATION.md flips 08-W0-07 green, marks 08-W0-08 partially
verified, and sets nyquist_compliant: false honestly. deferred-items.md
records what the follow-up spec needs to do.
2026-09-24 00:56:20 +02:00
Jakub Zych
e562bf6f5b fix(08-10): correct check-phase8-mcp-client.mjs's connected-apps field name and revoke ordering
Two real defects surfaced by the gate's first live run against the real
fonoteka-mcp SDK:

- stage_revoke looked up the connected app by a.name; ConnectedAppsIndex
  actually serializes client_name (confirmed against
  controllers/api/connected_app_controller.go serializeConnectedApp).
- Even with that fixed, stage_revoke ran after stage_replay, by which
  point RevokeLineage's forward walk (presenting the pre-refresh spent
  secret) had already cascade-revoked the live post-refresh access token
  too -- correct, intentional T-08-REFRESH-REPLAY behavior, and the exact
  same effect 08-09-PLAN.md's own mcp-lifecycle fixture ordering already
  documented ('connected-apps would already be empty if list ran after
  replay'). stage_refresh now captures the connected-app id while the
  session is still live; stage_revoke DELETEs that id directly instead of
  re-listing (ConnectedAppsDestroy has no revoked_at filter on its own
  lookup, so this still exercises the real endpoint, idempotently, against
  the id the real MCP-driven session actually owned).
2026-09-24 00:51:28 +02:00
Jakub Zych
fef037efe8 fix(08-10): close real defects found by check-phase8.sh's first end-to-end run
08-10 Task 3 is the first time this gate has actually been executed
against real Docker/Postgres/the real fonoteka CLI/the real fonoteka-mcp
process. Four independent, previously-undetected defects surfaced:

- stage_postgres never set POSTGRES_INITDB_ARGS for the ICU pl-PL locale
  lagoon.Use requires (every other Postgres testcontainer in this project
  already does); the app failed to boot at all.
- stage_app_boot's seed step POSTed to
  /_fonoteka/api/v1/onboarding/bootstrap, a route routes.go never mounts
  (its own comment marks that group deliberately empty, pending a later
  phase). The gate's test user/collection are now seeded directly with
  SQL, matching every app-level OAuth test's own real-Postgres seeding.
- phase8_workdir() assigned PHASE8_WORKDIR from inside a function body
  that is always invoked via command substitution (a subshell): the
  assignment never escaped back to the calling shell, so every separate
  caller (stage_postgres, stage_app_boot, each phase8_mcp_stage call, ...)
  minted its own fresh mktemp directory. This silently fragmented one
  run's state (app.log, the MCP client's gate-state.json) across dozens
  of directories that never saw each other's writes -- the MCP client's
  dcr stage could never see discovery's saved metadata. PHASE8_WORKDIR is
  now set once, directly, in run_full_gate before any stage runs.
- gate-state.json (the MCP client's shared cross-invocation state) holds
  raw live secrets by design and is never redacted; stage_secret_scan
  correctly flagged it. It is now deleted once the MCP lifecycle stages
  are done with it, before the scan runs -- the scan itself stays exactly
  as strict as it already was.

stage_security_review also now refuses a nonzero threats_open count or a
missing required T-08-* row, not just a missing/unverified file, and gains
--security-review-only, a focused mode for Task 2's own verify command.
2026-09-24 00:51:17 +02:00
Jakub Zych
0c173df25c docs(08-10): add the Phase 8 security review; mark Wave 0 green
08-SECURITY-REVIEW.md: status: verified, 11/11 T-08 threats closed,
0 open, 0 accepted risks. Performed directly by the 08-10 executor
(no Task/Agent tool available this run, per the plan's documented
fallback) with re-executed named-test evidence for every threat; found
and fixed one real gap during the review (see the paired fix commit).

08-VALIDATION.md: 08-W0-01 through 08-W0-06 flip to green with their
automated commands re-run; nyquist_compliant and wave_0_complete are
now true. 08-W0-07/08-W0-08 (the full scripts/check-phase8.sh gate)
stay pending until 08-10 Task 3 actually executes it.
2026-09-24 00:12:36 +02:00
Jakub Zych
034f63907d feat(08-10): fail-closed 08-SECURITY-REVIEW.md checks in check-phase8.sh
stage_security_review now also refuses a nonzero threats_open count and
any missing required T-08-* threat row, not just a missing/unverified
file. Adds --security-review-only, a focused mode running just this
stage (Task 2's own verify command) with no services booted.
2026-09-24 00:12:28 +02:00