- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
through the openapi-fetch client typed by the generated schema
- Security review names the test that fails if each high control is removed.
- Validation rows now point at the phase gate commands.
- Roadmap shows 12/12 plans executed.
- GET schema/form localizes the compiled form after the permission check
- relation: genre resolves to the exported Go field without changing the YAML key
- Reject an empty selection and dedupe ids before locking rows in pk order
- Return deleted 0 when every requested row is already gone, without hooks
- Roll back mixed, hook, and cancelled batches so no partial delete commits
- Empty selections are 422 and duplicates run once in primary-key order
- A completed retry and an all-absent selection delete nothing and skip hooks
- Mixed, hook, cancel, and concurrent requests keep the batch atomic
- Mount show, create, update, and delete behind the backend permission check
- Run controller and model hooks once per operation and roll back on failure
- Treat missing and out-of-scope records the same, including idempotent delete
- Record routes must enforce permission before ids or bodies and return D-10 envelopes
- Create, update, and delete run Before and After hooks once inside the transaction
- Out-of-scope and missing records are indistinguishable, and hook failure rolls back
- Bind schema fields to model columns at activation and drop protected keys
- Create and update Fill, run BeforeValidate, then Validate before persistence
- Missing Fill or Validate capability and provider errors fail closed
- Create and update must Fill then Validate and return D-10 422 field errors
- Schema bindings exclude protected, cased, nested, and unknown keys
- Missing Fill or Validate capability fails closed with controller context
- Search, sort, filters, and pagination use compiled selectors and bound values
- Equal sort keys break ties on the primary key so adjacent pages do not overlap
- Unknown identifiers return validation_failed before SQL
- Search, sort, filters, and adjacent pages must return the D-11 envelope
- Empty and single results keep an array and the requested page size
- Unknown identifiers and injected values fail closed before unsafe SQL
- Switch, date-range, and model-scope filters must keep typed values
- Option labels localize without changing identifiers or cached keys
- Raw conditions, unknown scopes, and arbitrary methods fail activation
- Typed columns, actions, default sort, search term, and page sizes
- Omitted sortable defaults to true and empty collections marshal as arrays
- Unknown keys, bad defaults, and path escape fail before routes are served
- Columns, actions, default sort, and page sizes must compile to typed JSON
- Empty and single declarations stay arrays and keep source order
- Unsupported keys, actions, defaults, and path escape fail activation
- config_form.yaml and config_list.yaml point at models/<name>/fields.yaml and columns.yaml
- Duplicate model or controller assets fail before any new file is written
- make:admin-controller must emit config_form and config_list beside model fields and columns
- A pre-existing model asset must fail before any controller file is written
- Cached schemas stay source-key IR and each response carries its own meta.locale
- YAML option maps keep declaration order and scalar type; method options call DropdownOptions and fail boot without a provider
- The same cached schema must localize pl and en independently, including Accept-Language parent fallback and raw keys
- YAML option maps keep order and scalar type, and a method provider is required at boot
- Strict config_form and fields documents keep source order and JSON scalar types
- Unknown keys, partials, path escape, and a mismatched modelClass fail activation with plugin context
- List-only controllers still activate when config_form.yaml is absent
- All locked field kinds, empty and single documents, and source order fail closed
- Unknown keys, types, duplicates, path escape, modelClass, partials, and missing assets must name the plugin, controller, and file
- Refresh, logout, and me use a separate PostgreSQL jti blacklist and safe profile
- Login stamps last_login only after a successful check and throttles repeated attempts
- Add the admin jti table, reset cutoff, and Winter indexes without AutoMigrate
- Reapply the developer and publisher seed idempotently and allow repeated role codes
- Fresh migrate is missing tokens_valid_after and the admin blacklist table
- Reapplying the seed is not idempotent and role codes reject Winter duplicates