Commit Graph

189 Commits

Author SHA1 Message Date
Jakub Zych
37fbcdc6de docs(phase-08): add validation strategy and resolve research decisions 2026-09-23 12:32:31 +02:00
Jakub Zych
a3a4636c29 docs(08): research OAuth authorization server 2026-09-23 12:14:03 +02:00
Jakub Zych
47b856b1c6 docs(state): record phase 8 context session 2026-09-23 11:37:14 +02:00
Jakub Zych
251ac038e2 docs(08): capture phase context 2026-09-23 11:37:13 +02:00
Jakub Zych
b435304570 docs(phase-7): complete phase execution
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:53:42 +02:00
Jakub Zych
e537b67a37 docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:52:45 +02:00
Jakub Zych
3a15105a1b docs(state): record 07-08 completion and tracking
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:51:26 +02:00
Jakub Zych
b74484eabc docs(07-08): complete the avatar bucket publish plan
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:50:01 +02:00
Jakub Zych
33f716ddef docs(07-08): plan avatar bucket publish on serve and Handler 2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16 test(07): complete UAT - 11 passed, 1 issues 2026-09-23 10:33:16 +02:00
Jakub Zych
1bd9f9e056 docs(state): record phase 9 context session 2026-09-23 10:24:37 +02:00
Jakub Zych
8268ff780d docs(09): capture phase context 2026-09-23 10:24:22 +02:00
Jakub Zych
d20f99f2e6 docs(07-07): complete the user-api parity gap plan
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 00:01:18 +02:00
Jakub Zych
dd3cb7ac29 docs(07): record gap-closure planning in state 2026-09-22 20:41:30 +02:00
Jakub Zych
8a1a52915b fix(07): revise 07-07-PLAN.md for checker-found seeding blockers 2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db docs(07): plan gap closure for the pending user-api parity routes 2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816 docs(07): record the phase goal verification
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd docs(07-06): complete the unit coverage plan
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:21:31 +02:00
Jakub Zych
fa7bdb5f71 docs(07-05): complete the user API parity capture plan
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:44:05 +02:00
Jakub Zych
ecfcd23150 docs(07-04): complete the personal token and locale plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0 docs(07-03): complete the account management plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c docs(07-02): complete the user session plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d docs(07-01): complete framework auth primitives plan 2026-09-22 13:43:15 +02:00
Jakub Zych
80eaeb87ea docs(07): mark phase planned, annotate roadmap waves 2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3 docs(07): revise plans after checker review 2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2 docs(07): create phase plan
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
  override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
  fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
  change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
  proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
  instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)

Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863 docs(07): add pattern map 2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21 docs(07): add validation strategy 2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22 docs(07): research user plugin and authentication phase 2026-09-22 02:42:14 +02:00
Jakub Zych
5548b2fab4 docs(state): record phase 7 context session 2026-09-22 00:24:22 +02:00
Jakub Zych
1979c45083 docs(07): capture phase context 2026-09-22 00:24:21 +02:00
Jakub Zych
2fe5c1e920 docs(06): verify phase 6 passed, mark HTTP-04/06 complete 2026-09-21 19:51:58 +02:00
Jakub Zych
fb66398cb9 docs(06-14): complete gap-closure test and review plan 2026-09-21 19:49:47 +02:00
Jakub Zych
ae817ccbb9 docs(06-14): reopen and re-close phase 6 security review with T-06-28..35 2026-09-21 19:49:30 +02:00
Jakub Zych
54dd60953a docs(06-13): complete fetchguard SSRF gap-closure plan 2026-09-21 19:45:03 +02:00
Jakub Zych
4bad1a43a2 docs(06-12): complete surf/bouncer gap-closure plan 2026-09-21 19:43:51 +02:00
Jakub Zych
46c7e4f98e docs(06): create gap-closure plans 12-14 2026-09-21 19:30:50 +02:00
Jakub Zych
6e9188b5c7 docs(06): record verification gaps 2026-09-21 14:49:52 +02:00
Jakub Zych
c5b412c7e1 docs(06): add code review report 2026-09-21 14:31:47 +02:00
Jakub Zych
ef6d914e4c docs(06-11): update plan tracking 2026-09-21 13:05:11 +02:00
Jakub Zych
2329e1f290 docs(06-11): complete post-gap security review plan 2026-09-21 13:03:41 +02:00
Jakub Zych
829e9989e3 docs(06-11): refresh Phase 6 security review 2026-09-21 13:02:41 +02:00
Jakub Zych
7118e4f280 docs(06-10): update plan tracking 2026-09-21 00:28:15 +02:00
Jakub Zych
943be2353d docs(06-10): complete exact InvScope denial bodies plan 2026-09-21 00:26:51 +02:00
Jakub Zych
c9909ce412 docs(06-09): update plan tracking 2026-09-20 21:08:54 +02:00
Jakub Zych
158df899f6 docs(06-09): complete transactional panic recovery plan
Tasks completed: 1/1
- Buffer route responses so panic recovery can discard partial output

SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-09-SUMMARY.md
2026-09-20 21:06:51 +02:00
Jakub Zych
8a265d8372 docs(06-08): update plan tracking
- Advance phase progress to 8 of 11 plans
- Record transition-address security decisions and execution metrics
- Mark HTTP-07 complete in requirements tracking
2026-09-20 21:00:45 +02:00
Jakub Zych
ac24ddd518 docs(06-08): complete transition-address SSRF closure plan
Tasks completed: 1/1
- Decode and reclassify embedded IPv4 at the dial-time SSRF boundary

SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-08-SUMMARY.md
2026-09-20 20:58:54 +02:00
Jakub Zych
3601a0ab09 docs(06-07): update plan tracking 2026-09-20 17:12:31 +02:00
Jakub Zych
bc43e9eabd docs(06-07): complete atomic limiter admission plan
Tasks completed: 1/1
- Make fixed-window admission atomic and inline keys server-controlled

SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-07-SUMMARY.md
2026-09-20 17:10:43 +02:00