Commit Graph

617 Commits

Author SHA1 Message Date
Jakub Zych
4e05450f46 docs(11.1-05): log the scaffolder gaps found while porting the walkthrough
- same-second migrations sort by name and can run out of order
- make:admin-controller output does not boot and names the model after
  the controller
- the DO NOT EDIT header on editable files, and commands that cannot reach
  the application
2026-09-30 23:41:26 +02:00
Jakub Zych
63290c66d3 feat(11.1-05): pin the walkthrough to the scaffolder and link it from the concept map
- TestScaffoldLayout runs make:plugin, make:model, make:migration,
  make:admin-controller and make:command for acme.blog in a copy of
  examples/hello and compares the file set with docs/examples/blog
- the page lists the exact make commands, the go.mod a scaffolded plugin
  gets, what the scaffolder leaves to the developer and a checklist
- scaffolding.md no longer claims same-second migrations get consecutive
  timestamps; only same-name ones do
- coming-from-wintercms.md and index.md link the walkthrough
2026-09-30 23:41:00 +02:00
Jakub Zych
dd82b8a2ad feat(11.1-05): add the walkthrough's admin controller, publish command and published_at migration
- make:admin-controller, make:command and make:migration output, finished:
  the Posts controller serves models.Post behind acme.blog.access_posts,
  WinterCMS-style form and list YAML embedded through pact.AdminAssets,
  blog:publish sets published_at by slug with a bound parameter
- the posts route lists published posts only, newest first
- Docker tests migrate an ICU pl-PL database, roll back published_at, serve
  the route and run blog:publish with a published and an opened database
- the page gains the admin controller, console command and added-column
  sections
2026-09-30 23:35:44 +02:00
Jakub Zych
41a3190956 feat(11.1-05): add the acme.blog walkthrough plugin with its model, migration and posts route
- docs/examples/blog: scaffolder output for acme.blog (make:plugin, make:model)
  in the root module, with a Post model, a fill allow-list and NewPost, the
  create migration and GET /api/blog/posts paginated through lagoon
- short tests activate the plugin, check the route with surf, the fill
  allow-list and the migration order
- docs/setup/porting-a-plugin.md: registration, model, migrations and routes
  sections with src= copies of the plugin
- TestDocsRequiredPages requires setup/porting-a-plugin
2026-09-30 23:28:41 +02:00
Jakub Zych
4e83d06025 docs(11.1-04): complete framework content B plan 2026-09-30 23:20:20 +02:00
Jakub Zych
44bd1446f5 feat(11.1-04): add the Backend section, the remaining Services pages and the concept map links
- docs/backend: admin controllers, forms, lists and filters, relation
  manager, users and permissions, settings, partials and widgets, admin SPA
- docs/services: storage, outbound HTTP, realtime, Web Push, search, parity
  testing and the Frontend and AJAX (not provided) page
- Examples for cabana (with testdata/docs YAML), fetchguard, lighthouse and
  its centrifugo driver, flare, beachcomber and typesense, tide; lighthouse
  and beachcomber TestDocs* regions run on their Postgres harnesses
- concept map rows link their guide pages and the not-provided rows the
  Frontend and AJAX page; index lists Backend, Database and Services
- TestDocsRequiredPages asserts the D-08 section order
2026-09-30 23:18:35 +02:00
Jakub Zych
f7dfe68707 docs(11.1-04): log lagoon gaps found while writing the Database pages
- lagoon.Validate reports numeric min failures with the max message
- the lagoon README callback example sorts after the after-commit flush,
  and the pivot Preload ordering claim does not hold
2026-09-30 22:59:30 +02:00
Jakub Zych
efb35a2d35 feat(11.1-04): add the Database section and the core Services pages
- docs/database: models, migrations, queries and pagination, relations,
  casts and validation, attachments and transactions (lagoon.Transaction,
  lagoon.AfterCommit, nested savepoints, lagoon.OnDatabase)
- docs/services: configuration, events, routing with auth groups, rate
  limiting, authentication, the OAuth server, mail and localization
- runnable Examples for lagoon, attach, compass, surf, wire, bouncer,
  wristband, postcard, phrasebook and festival; lagoon TestDocs* regions
  run on the package's Postgres harness through DocsDB
- 15 new required pages
2026-09-30 22:59:25 +02:00
Jakub Zych
9d37d56486 feat(11.1-04): add the Services section with a verified Queued jobs page
- docs/services/jobs.md: declaring, registering and dispatching jobs, the
  summer_jobs record, progress, cancellation and workers
- conga ExampleJob plus dispatch and status regions run by TestDocsDispatch
  on the package's Postgres harness (DocsApp in export_docs_test.go)
- concept map links the queued jobs row; services/jobs is a required page
2026-09-30 22:35:22 +02:00
Jakub Zych
69dd5764bb test(11): persist human verification items as UAT 2026-09-30 22:30:48 +02:00
Jakub Zych
468f40108f docs(11): verify gap closure 2026-09-30 22:30:43 +02:00
Jakub Zych
c6f6bdfcb8 docs(11): update code review report 2026-09-30 22:24:17 +02:00
Jakub Zych
93c735b8a2 fix(11-08): make transaction gates fail closed 2026-09-30 22:24:12 +02:00
Jakub Zych
9526b6b638 fix(11-08): bind nested callbacks to parent transaction 2026-09-30 22:24:04 +02:00
Jakub Zych
4d7823984e docs(11.1-03): update state, roadmap and requirements after plan 03 2026-09-30 22:18:45 +02:00
Jakub Zych
3131d7f3e1 docs(11.1-03): complete the Setup, Architecture, Plugins and Console docs plan 2026-09-30 22:18:00 +02:00
Jakub Zych
8254fb91a9 docs(11.1-03): log the bonfire duplicate command name gap as a todo 2026-09-30 22:16:51 +02:00
Jakub Zych
a896f3ff81 feat(11.1-03): add the Setup and Console docs sections
- setup: introduction, installation rewritten from install to serve,
  configuration with the keys an application sets
- console: introduction, setup and maintenance, scaffolding, writing
  commands, utilities; every command name is checker-verified
- bonfire ExampleCatalog shows arguments, bare and repeatable flags
- index links the section introductions; TestDocsRequiredPages lists
  the seven new pages
2026-09-30 22:16:36 +02:00
Jakub Zych
1f8f5e1b51 feat(11.1-03): add the Architecture and Plugins docs sections
- architecture: introduction, Go modules and workspaces, application
  lifecycle, request lifecycle
- plugins: registration, scheduling, extending, testing
- verified Examples for backpack services, towel request context,
  pact schedules and festival events
- TestDocsRequiredPages lists the eight new pages
2026-09-30 22:12:08 +02:00
Jakub Zych
d6003cd84b feat(11.1-03): add the Coming from WinterCMS concept map with a verified plugin example
- docs/setup/coming-from-wintercms.md maps WinterCMS concepts to checked
  pkg.Ident spans and lists what SummerCMS does not provide
- party BlogPlugin and ExamplePlugin, shown through src= fences
- TestDocsRequiredPages asserts required pages build as .html and .md
- index links the new page
2026-09-30 22:06:45 +02:00
Jakub Zych
f77b1d8688 docs(11.1-02): complete docs accuracy gates, theme and docs:serve plan
- SUMMARY with coverage, deviations and verification
- STATE, ROADMAP and REQUIREMENTS (DOCS-02, DOCS-04, DOCS-05, DOCS-08)
- deferred items: README summary backticks in leads
2026-09-30 22:00:46 +02:00
Jakub Zych
dd11bdb0c7 feat(11.1-02): add the documentation theme, chroma highlighting and docs:serve
- WinterCMS-style shell: header with search and theme toggle, grouped
  sidebar, on-page TOC, pager, page actions, callouts, heading
  permalinks, footer and a 404 page
- fenced code highlighted at build time by chroma/v2 into tok-* classes,
  with a copy button; no inline script, style or handler
- vendored DM Sans/DM Mono fonts and Lucide icons with their licences
- client-side search over search-index.json built with textContent only
- summer docs:serve builds into a temp dir, serves on loopback by default,
  returns 404.html with status 404 and rebuilds on change
2026-09-30 21:57:55 +02:00
Jakub Zych
d89e18bc8e docs(11.1): record the docs update rule and the wristband default todo
- CLAUDE.md: API, config-key and CLI changes update the affected docs
  pages; the docs checkers are named; config-key checking is deferred
- todo: wristband's default resource URL and comments name a consuming
  application
2026-09-30 21:41:11 +02:00
Jakub Zych
5d4c1e3046 feat(11.1-02): check links, commands, forbidden names and fence policy
- relative links and anchors resolve against the renderer's heading IDs
- summer and ./bin/<app> command names come from the real command
  constructors through docsite.Options.Commands; a nil set is a problem
- consuming-application names fail in page sources and built outputs
- go fences in docs/ pages need src=, callouts are NOTE, TIP or WARNING,
  docs/ headings are plain ASCII
- gate gains --claude and self-test plants for each new rule
2026-09-30 21:40:46 +02:00
Jakub Zych
f4605292b5 feat(11.1-02): check module identifiers in docs and READMEs
- go/parser index of every modules/ package and sub-package, with methods,
  fields, interface methods and promoted members
- code spans in docs pages, module READMEs and the root README fail
  Check and docs:build when the named identifier does not exist
- scripts/check-phase11.1.sh with preconditions, deps, docs, forbidden,
  go and a self-test that plants one violation per rule
2026-09-30 21:35:56 +02:00
Jakub Zych
9dcc101776 docs(11.1-01): update state and roadmap after the docs tracer plan 2026-09-30 21:28:40 +02:00
Jakub Zych
e75490e892 docs(11.1-01): complete docs generator tracer plan summary 2026-09-30 21:28:05 +02:00
Jakub Zych
dc6a03c714 feat(11.1-01): verify src= code blocks and add summer docs:sync
- src= fences name a file, a Go declaration or Example body, or a docs:start region
- confinement: relative clean paths inside the root, no dotfiles or .env,
  no nested go.mod modules, Examples need // Output:, test regions must run
- a drifted or missing snippet is a problem, so docs:build writes nothing
- docs:sync rewrites drifted fence bodies in place
- fences render in figure.code with a source caption; .md fences keep only the language
- bonfire ExampleCall is the first verified example, shown in setup/installation
2026-09-30 21:26:52 +02:00
Jakub Zych
e433dcf0c9 feat(11.1-01): publish every module README as an API reference page
- discover modules/<m> with non-test Go files; a missing README is a readme: problem
- one GitHub-compatible slug parser.IDs for heading anchors, passed per page
- rewrite links to .md pages and module READMEs to site .html and .md URLs
- search-index.json gains one entry per H2 with 300-char plain text
- add the api section to docs/site.yaml; docsite.Pages exposes reading order
- tests: TestSlugIDs, TestReadmeIngestion, TestEveryModuleInSidebar, TestDocsAIOutputsInSync
2026-09-30 21:21:56 +02:00
Jakub Zych
6dacddc040 feat(11.1-01): add summer docs:build with the docsite generator core
- internal/docsite loads docs/ with strict site.yaml and frontmatter decoding
- goldmark GFM pipeline renders pages into an embedded html/template shell
- emits .html pages, .md siblings, llms.txt, llms-full.txt, search-index.json
- output guard refuses unmarked non-empty dirs and --out inside --src or root
- docs/index.md and docs/setup/installation.md; /site/ is gitignored
2026-09-30 21:18:32 +02:00
Jakub Zych
63bcbc31b0 docs(11-08): complete gap plan summary 2026-09-30 21:10:08 +02:00
Jakub Zych
e6777bda97 fix(11-08): record T-11-31 and T-11-32 in the security review
- check-phase11.sh --evidence refused the 11-08 threats missing from the
  review; adds both rows, the RC-14 removal check and the CR-01 fix row
2026-09-30 21:00:20 +02:00
Jakub Zych
d4fc957f8f fix(11-08): add the T-11-31 removal check to the phase gate
- RC-14 removes the foreign-transaction refusal in lagoon.AfterCommit and
  requires TestTransactionAfterCommit to fail
2026-09-30 21:00:20 +02:00
Jakub Zych
8e0083ed41 fix(11-08): document foreign and nested transaction refusal
- lagoon.Transaction doc and README state that a nested call over a root
  handle returns an error instead of opening an independent transaction
- beachcomber README no longer promises an immediate sync inside a plain
  GORM transaction; it is warned and skipped since 11-08
2026-09-30 21:00:20 +02:00
Jakub Zych
2766f34d99 test(11-08): keep sync failure coverage managed 2026-09-30 20:49:31 +02:00
Jakub Zych
6f57604028 docs(11.1): create phase plan
Six plans (tracer generator, site UX and checkers, content A, content B,
acme/blog walkthrough, unit tests). SC4/DOCS-04 narrowed to docs/ pages per
D-18; README Go fence conversion logged as a todo.
2026-09-30 20:33:51 +02:00
Jakub Zych
a33b1ada80 fix(11-08): refuse unmanaged after-commit work 2026-09-30 20:14:42 +02:00
Jakub Zych
f7b6b0c313 fix(11-08): make cabana writes commit-safe 2026-09-30 20:14:23 +02:00
Jakub Zych
9033d81721 docs(11.1): record plan-count checkpoint decisions, DOCS requirements and pattern map 2026-09-30 19:39:50 +02:00
Jakub Zych
30d3bfec67 docs(11): create phase gap plan 2026-09-30 16:14:17 +02:00
Jakub Zych
dd97fd12a6 docs(11): add phase verification report (gaps found) 2026-09-30 15:31:09 +02:00
Jakub Zych
b7b48f8771 docs(phase-11): revert premature Complete requirements after gaps found 2026-09-30 15:31:09 +02:00
Jakub Zych
61da4d1a4c fix(11): let the Phase 10 gate accept the Phase 12 pending goldens
- 11-06 records TestBroadcastGoldens/created and /updated and reports them
  as skipped until Phase 12; the Phase 10 detector refused any skip, so
  check-phase10.sh --all failed on the fonoteka.go suite
- mirrors 73cfed7 (check-phase10.1.sh): the detector accepts exactly those
  skips when their output carries 'pending: Phase 12'; the self-test proves
  a pending skip passes and one without the text fails
2026-09-30 15:22:00 +02:00
Jakub Zych
5fa062d554 docs(11): record code review disposition 2026-09-30 15:18:21 +02:00
Jakub Zych
2fb0f7d328 docs(11): add code review report 2026-09-30 15:18:20 +02:00
Jakub Zych
4cc6fd7a42 docs(11-07): record plan 11-07 progress, decisions and requirements 2026-09-30 14:57:33 +02:00
Jakub Zych
45fb00af1a docs(11-07): complete Phase 11 unit tests and gate plan 2026-09-30 14:56:53 +02:00
Jakub Zych
73cfed74ed fix(11-07): let the Phase 10.1 gate accept the Phase 12 pending goldens
- 11-06 records TestBroadcastGoldens/created and /updated and reports them
  as skipped until Phase 12; the 10.1 detector refused any skip, so
  check-phase10.1.sh --all failed on the fonoteka.go suite
- the detector now accepts exactly those skips when their output carries
  'pending: Phase 12' (the same rule check-phase11.sh enforces); the
  self-test proves a pending skip passes and one without the text fails
2026-09-30 14:55:16 +02:00
Jakub Zych
a34c6ece18 docs(11-07): security review with removal checks and the validated test map
- 11-SECURITY-REVIEW.md: T-11-01..T-11-30 and T-11-SC with each plan's
  severity and disposition, mitigation, test and result; RC-01..RC-13
  removal checks for every high mitigated threat; the three defects fixed
  in 11-07
- 11-VALIDATION.md: task ids, plans and waves per row, commands run,
  status validated, nyquist_compliant and wave_0_complete true
2026-09-30 14:49:36 +02:00
Jakub Zych
7743487b76 test(11-07): add the fail-closed Phase 11 gate and removal harness
- scripts/check-phase11.sh: --self-test, --hygiene, --go, --postgres,
  --named, --evidence, --all (prints 'phase11 all passed') and --removal
- the go test -json detector refuses failures, skips, zero tests and
  'no tests to run'; only the two Phase 12 broadcast goldens may skip, and
  only with their pending text
- hygiene refuses application names in the Phase 11 framework files, the
  Centrifugo/Typesense/Web Push client libraries, a direct cron
  requirement, River other than v0.47.0 and a module without README or
  root row; each rule returns on its first violation and the self-test
  proves each refuses its own plant and accepts look-alikes
- --removal: anchor-exact mutations for the high threats, each required to
  fail its named test on an assertion and restored byte for byte (cmp)
2026-09-30 14:42:38 +02:00