Jakub Zych
37fbcdc6de
docs(phase-08): add validation strategy and resolve research decisions
2026-09-23 12:32:31 +02:00
Jakub Zych
a3a4636c29
docs(08): research OAuth authorization server
2026-09-23 12:14:03 +02:00
Jakub Zych
47b856b1c6
docs(state): record phase 8 context session
2026-09-23 11:37:14 +02:00
Jakub Zych
251ac038e2
docs(08): capture phase context
2026-09-23 11:37:13 +02:00
Jakub Zych
b435304570
docs(phase-7): complete phase execution
...
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:53:42 +02:00
Jakub Zych
e537b67a37
docs(07): verify phase after the avatar bucket gap close
...
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:52:45 +02:00
Jakub Zych
3a15105a1b
docs(state): record 07-08 completion and tracking
...
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:51:26 +02:00
Jakub Zych
b74484eabc
docs(07-08): complete the avatar bucket publish plan
...
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:50:01 +02:00
Jakub Zych
33f716ddef
docs(07-08): plan avatar bucket publish on serve and Handler
2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16
test(07): complete UAT - 11 passed, 1 issues
2026-09-23 10:33:16 +02:00
Jakub Zych
1bd9f9e056
docs(state): record phase 9 context session
2026-09-23 10:24:37 +02:00
Jakub Zych
8268ff780d
docs(09): capture phase context
2026-09-23 10:24:22 +02:00
Jakub Zych
d20f99f2e6
docs(07-07): complete the user-api parity gap plan
...
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 00:01:18 +02:00
Jakub Zych
dd3cb7ac29
docs(07): record gap-closure planning in state
2026-09-22 20:41:30 +02:00
Jakub Zych
8a1a52915b
fix(07): revise 07-07-PLAN.md for checker-found seeding blockers
2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db
docs(07): plan gap closure for the pending user-api parity routes
2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816
docs(07): record the phase goal verification
...
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd
docs(07-06): complete the unit coverage plan
...
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 19:21:31 +02:00
Jakub Zych
fa7bdb5f71
docs(07-05): complete the user API parity capture plan
...
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 18:44:05 +02:00
Jakub Zych
ecfcd23150
docs(07-04): complete the personal token and locale plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0
docs(07-03): complete the account management plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c
docs(07-02): complete the user session plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d
docs(07-01): complete framework auth primitives plan
2026-09-22 13:43:15 +02:00
Jakub Zych
80eaeb87ea
docs(07): mark phase planned, annotate roadmap waves
2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3
docs(07): revise plans after checker review
2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2
docs(07): create phase plan
...
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)
Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863
docs(07): add pattern map
2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21
docs(07): add validation strategy
2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22
docs(07): research user plugin and authentication phase
2026-09-22 02:42:14 +02:00
Jakub Zych
5548b2fab4
docs(state): record phase 7 context session
2026-09-22 00:24:22 +02:00
Jakub Zych
1979c45083
docs(07): capture phase context
2026-09-22 00:24:21 +02:00
Jakub Zych
2fe5c1e920
docs(06): verify phase 6 passed, mark HTTP-04/06 complete
2026-09-21 19:51:58 +02:00
Jakub Zych
fb66398cb9
docs(06-14): complete gap-closure test and review plan
2026-09-21 19:49:47 +02:00
Jakub Zych
ae817ccbb9
docs(06-14): reopen and re-close phase 6 security review with T-06-28..35
2026-09-21 19:49:30 +02:00
Jakub Zych
54dd60953a
docs(06-13): complete fetchguard SSRF gap-closure plan
2026-09-21 19:45:03 +02:00
Jakub Zych
4bad1a43a2
docs(06-12): complete surf/bouncer gap-closure plan
2026-09-21 19:43:51 +02:00
Jakub Zych
46c7e4f98e
docs(06): create gap-closure plans 12-14
2026-09-21 19:30:50 +02:00
Jakub Zych
6e9188b5c7
docs(06): record verification gaps
2026-09-21 14:49:52 +02:00
Jakub Zych
c5b412c7e1
docs(06): add code review report
2026-09-21 14:31:47 +02:00
Jakub Zych
ef6d914e4c
docs(06-11): update plan tracking
2026-09-21 13:05:11 +02:00
Jakub Zych
2329e1f290
docs(06-11): complete post-gap security review plan
2026-09-21 13:03:41 +02:00
Jakub Zych
829e9989e3
docs(06-11): refresh Phase 6 security review
2026-09-21 13:02:41 +02:00
Jakub Zych
7118e4f280
docs(06-10): update plan tracking
2026-09-21 00:28:15 +02:00
Jakub Zych
943be2353d
docs(06-10): complete exact InvScope denial bodies plan
2026-09-21 00:26:51 +02:00
Jakub Zych
c9909ce412
docs(06-09): update plan tracking
2026-09-20 21:08:54 +02:00
Jakub Zych
158df899f6
docs(06-09): complete transactional panic recovery plan
...
Tasks completed: 1/1
- Buffer route responses so panic recovery can discard partial output
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-09-SUMMARY.md
2026-09-20 21:06:51 +02:00
Jakub Zych
8a265d8372
docs(06-08): update plan tracking
...
- Advance phase progress to 8 of 11 plans
- Record transition-address security decisions and execution metrics
- Mark HTTP-07 complete in requirements tracking
2026-09-20 21:00:45 +02:00
Jakub Zych
ac24ddd518
docs(06-08): complete transition-address SSRF closure plan
...
Tasks completed: 1/1
- Decode and reclassify embedded IPv4 at the dial-time SSRF boundary
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-08-SUMMARY.md
2026-09-20 20:58:54 +02:00
Jakub Zych
3601a0ab09
docs(06-07): update plan tracking
2026-09-20 17:12:31 +02:00
Jakub Zych
bc43e9eabd
docs(06-07): complete atomic limiter admission plan
...
Tasks completed: 1/1
- Make fixed-window admission atomic and inline keys server-controlled
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-07-SUMMARY.md
2026-09-20 17:10:43 +02:00