Commit Graph

351 Commits

Author SHA1 Message Date
Jakub Zych
e537b67a37 docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:52:45 +02:00
Jakub Zych
3a15105a1b docs(state): record 07-08 completion and tracking
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:51:26 +02:00
Jakub Zych
b74484eabc docs(07-08): complete the avatar bucket publish plan
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:50:01 +02:00
Jakub Zych
44900f0d16 feat(07-08): publish the uploads bucket on serve
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:43:47 +02:00
Jakub Zych
33f716ddef docs(07-08): plan avatar bucket publish on serve and Handler 2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16 test(07): complete UAT - 11 passed, 1 issues 2026-09-23 10:33:16 +02:00
Jakub Zych
1bd9f9e056 docs(state): record phase 9 context session 2026-09-23 10:24:37 +02:00
Jakub Zych
8268ff780d docs(09): capture phase context 2026-09-23 10:24:22 +02:00
Jakub Zych
d20f99f2e6 docs(07-07): complete the user-api parity gap plan
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 00:01:18 +02:00
Jakub Zych
31634f706f feat(07-07): localize lagoon validation with Laravel-shaped Polish messages
Replay of the user-api corpus needs lagoon::validate.* catalogs and
underscore-to-space attribute names so Go 422 bodies match Winter.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 23:56:58 +02:00
Jakub Zych
dd3cb7ac29 docs(07): record gap-closure planning in state 2026-09-22 20:41:30 +02:00
Jakub Zych
8a1a52915b fix(07): revise 07-07-PLAN.md for checker-found seeding blockers 2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db docs(07): plan gap closure for the pending user-api parity routes 2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816 docs(07): record the phase goal verification
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd docs(07-06): complete the unit coverage plan
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:21:31 +02:00
Jakub Zych
4754377442 feat(07-06): prove mint, refresh, and blacklist under concurrency
A minted token refreshes once, then the old jti is blacklisted. Memory and Postgres blacklists take concurrent Add and IsBlacklisted calls.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:20:14 +02:00
Jakub Zych
fa7bdb5f71 docs(07-05): complete the user API parity capture plan
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:44:05 +02:00
Jakub Zych
7d5d8659ec feat(07-05): allow the second parity test password
Change-password recordings need a distinct new password that the fixture scrubber still accepts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:43:27 +02:00
Jakub Zych
ecfcd23150 docs(07-04): complete the personal token and locale plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0 docs(07-03): complete the account management plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c docs(07-02): complete the user session plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d docs(07-01): complete framework auth primitives plan 2026-09-22 13:43:15 +02:00
Jakub Zych
8fcaff77cf feat(07-01): add bcrypt, locale override, and validation rules
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:39:25 +02:00
Jakub Zych
bccd7f8f35 test(07-01): add failing tests for passwords, locale, and validation
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:36:08 +02:00
Jakub Zych
cad445a235 feat(07-01): add JWT mint, refresh, and blacklist primitives
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:34:58 +02:00
Jakub Zych
251f3cc4a0 test(07-01): add failing tests for JWT lifecycle primitives
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:33:37 +02:00
Jakub Zych
80eaeb87ea docs(07): mark phase planned, annotate roadmap waves 2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3 docs(07): revise plans after checker review 2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2 docs(07): create phase plan
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
  override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
  fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
  change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
  proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
  instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)

Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863 docs(07): add pattern map 2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21 docs(07): add validation strategy 2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22 docs(07): research user plugin and authentication phase 2026-09-22 02:42:14 +02:00
Jakub Zych
5548b2fab4 docs(state): record phase 7 context session 2026-09-22 00:24:22 +02:00
Jakub Zych
1979c45083 docs(07): capture phase context 2026-09-22 00:24:21 +02:00
Jakub Zych
2fe5c1e920 docs(06): verify phase 6 passed, mark HTTP-04/06 complete 2026-09-21 19:51:58 +02:00
Jakub Zych
fb66398cb9 docs(06-14): complete gap-closure test and review plan 2026-09-21 19:49:47 +02:00
Jakub Zych
ae817ccbb9 docs(06-14): reopen and re-close phase 6 security review with T-06-28..35 2026-09-21 19:49:30 +02:00
Jakub Zych
e50e2dd632 test(06-14): fetchguard IANA boundary and zoned dial tests, surf edge coverage 2026-09-21 19:48:06 +02:00
Jakub Zych
f1218f2c84 test(06-14): regression coverage for surf and bouncer gap closure 2026-09-21 19:47:16 +02:00
Jakub Zych
1d2e00cf59 fix(06-14): actually reuse built middleware factories per name:param
The built cache added in 06-12 was declared but never consulted, so every
route re-invoked the factory on BuildRouter and again on compile.
2026-09-21 19:47:16 +02:00
Jakub Zych
54dd60953a docs(06-13): complete fetchguard SSRF gap-closure plan 2026-09-21 19:45:03 +02:00
Jakub Zych
b1079ab8a4 fix(06-13): full IANA special-use SSRF tables and reject zoned dial targets 2026-09-21 19:44:51 +02:00
Jakub Zych
4bad1a43a2 docs(06-12): complete surf/bouncer gap-closure plan 2026-09-21 19:43:51 +02:00
Jakub Zych
8a9449df63 fix(06-12): reject typed-nil guards and fractional JWT subjects 2026-09-21 19:43:35 +02:00
Jakub Zych
4ad2ad29f2 fix(06-12): fail closed on invalid limiter definitions 2026-09-21 19:42:41 +02:00
Jakub Zych
a50e09ba34 fix(06-12): bound named middleware by body cap, cache factories, fail boot on bad body config and mux conflicts 2026-09-21 19:42:20 +02:00
Jakub Zych
46c7e4f98e docs(06): create gap-closure plans 12-14 2026-09-21 19:30:50 +02:00
Jakub Zych
6e9188b5c7 docs(06): record verification gaps 2026-09-21 14:49:52 +02:00
Jakub Zych
c5b412c7e1 docs(06): add code review report 2026-09-21 14:31:47 +02:00
Jakub Zych
ef6d914e4c docs(06-11): update plan tracking 2026-09-21 13:05:11 +02:00