- wristband.Server.Metadata is a compiling 501 stub; TestPhase8RedMetadata
asserts the exact unwrapped PHP metadata document, headers and status and
fails with the PHASE8_RED:metadata sentinel (D-06)
- scripts/check-phase8-red.sh implements the shared go/shell RED contract
for the rest of Phase 8: exact selected test/package failure plus sentinel,
rejecting unrelated fail actions, compile/setup failures, panics,
malformed JSON, missing/duplicate sentinels and zero selection (D-04/D-18)
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com>
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com>
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.
Co-authored-by: Cursor <cursoragent@cursor.com>
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.
Co-authored-by: Cursor <cursoragent@cursor.com>
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.
Co-authored-by: Cursor <cursoragent@cursor.com>
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.
Co-authored-by: Cursor <cursoragent@cursor.com>
Replay of the user-api corpus needs lagoon::validate.* catalogs and
underscore-to-space attribute names so Go 422 bodies match Winter.
Co-authored-by: Cursor <cursoragent@cursor.com>
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.
Co-authored-by: Cursor <cursoragent@cursor.com>
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.
Co-authored-by: Cursor <cursoragent@cursor.com>
A minted token refreshes once, then the old jti is blacklisted. Memory and Postgres blacklists take concurrent Add and IsBlacklisted calls.
Co-authored-by: Cursor <cursoragent@cursor.com>
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.
Co-authored-by: Cursor <cursoragent@cursor.com>