- Add a Documentation section outside the GSD-managed blocks
- Module API, config, CLI or dependency changes update the module README in the same change
- New modules ship a standard README and a row in the root modules table
- READMEs name no consuming application and only identifiers that exist
- Describe SummerCMS as a framework: key concepts, requirements, repository layout
- Verified quick start on examples/hello with the required config and known issues
- Modules table linking all 18 module READMEs with their summary sentences
- Module path plus local replace pattern, development commands, design notes
Quick 260927-q23 (CR-01), unit coverage that runs under -short.
- bouncer: TestRefreshAudienceForSubject covers active, pre/post cutoff,
missing, nil provider, non-numeric sub, provider error, and proves
token-only refusals never reach the provider
- bouncer: TestJWTGuardTokensValidAfter pins the unchanged "User not found"
message and errors.Is(err, ErrSubjectRejected)
- cabana: TestPhase10Coverage subtest pins cookie expiry on subject
refusals, no cookies over Bearer or on a provider error, and the
post-cutoff success path
Fixes review finding CR-01 (quick 260927-q23): POST {prefix}/api/v1/auth/refresh
minted a new token without loading the admin, so a session kept alive by the
SPA's refresh-on-401 survived admin:reset-password, deactivation and deletion.
This broke Phase 9 truth T-09-04.
- bouncer: extract the JWT guard's subject lookup into subjectPrincipal and
issuedBeforeCutoff (same order and messages), add ErrSubjectRejected
- bouncer: add RefreshAudienceFor, which runs the guard's subject checks
after the token-only checks and before minting; Refresh and
RefreshAudience are unchanged (nil hook)
- cabana: share one lazyBackendUsers provider between the backend guard and
refresh; a cookie refresh refused for its subject expires summer_admin
- test: TestAdminRefreshRevocation (Postgres, real admin:reset-password)
- 10-SECURITY-REVIEW.md: T-10-01..T-10-25 and T-10-SC with mitigation,
test or gate stage, observed result, residual risk and the removal
(mutation) checks behind every high threat
- 10-VALIDATION.md: executed task commands, gate statuses, Wave 0 done,
nyquist_compliant after scripts/check-phase10.sh --all passed