Commit Graph

885 Commits

Author SHA1 Message Date
Jakub Zych
4e4ce40dbb docs(12.1-05): close plan 05 with SUMMARY after the executor died before writing it 2026-10-05 16:51:31 +02:00
Jakub Zych
93f0171e9c docs(12.1-05): security review and validation sign-off for Phase 12.1
- 12.1-SECURITY-REVIEW.md: every threat T-12.1-01 to T-12.1-40 and T-12.1-SC with its mitigation, test and observed result; T-12-18 revisited; the D-30 guard and its boundary; the eleven handed-over items; five findings that need a decision
- 12.1-VALIDATION.md: per-task map with real task ids and measured run times, signed off
- deferred-items.md: older framework files that name an application
2026-10-05 16:13:50 +02:00
Jakub Zych
83feeef9fa docs(12.1-05): state the limits of relation locks and locked permission codes
- a relation lock covers the form field only; a relation manager on the same relation does not ask the provider
- a locked permission code must be stored with a value its mode can send
2026-10-05 16:01:10 +02:00
Jakub Zych
3190b1ce59 test(12.1-05): complete the Phase 12.1 gate with the removal, coverage, app and evidence stages
- --go, --spa, --openapi, --dist, --docs and --hygiene on the pattern of the Phase 12.2 gate
- --app runs vet and the tests of every module of the application workspace, with the application's name masked in output
- --coverage refuses a package of pact, cabana or the user plugin below 80 percent
- --removal: 27 anchor-exact mutations, one per high or critical protection and one per fix; a dirty file is refused and every file is restored and compared with cmp
- --evidence ties every threat of the five plans to a review row, a test and a removal row
- --self-test plants an input for every detector
2026-10-05 16:01:10 +02:00
Jakub Zych
aced6c7df3 test(12.1-05): unit tests for the list, form, preview and routing behaviours of Phase 12.1 in the SPA
- list: the bulk menu in the toolbar and on the list view with its three failure rows, row states and invisible columns in the table
- form: the forbidden banner, password and preset on the form view, locked relation options, the save body of password and permission fields
- preview view: context fields, hidden tabs, the status hint, the footer with zero, one and several actions, load failures
- routing: the preview route and mapWinterUrl
- backstops: focus returns to the bulk menu trigger; preview URL mapping and the route replacement; locked relation options
- the slug preset runs on the table the user plugin's slug test uses
2026-10-05 15:36:00 +02:00
Jakub Zych
84efdc09e0 test(12.1-05): unit tests for the Phase 12.1 SPA components
- BulkActionsMenu, RowStateBadges, RecordActions, PreviewField, FormErrorBanner, PasswordField and PermissionEditorField, each mounted on its own
- backstop: a row state outside the fixed set renders no badge and no class
- backstop: the permission editor's emission rules per mode, the locked row and codes outside the options
2026-10-05 15:29:44 +02:00
Jakub Zych
2e94cbf9f8 test(12.1-05): unit tests for bulk and record actions, row state, forbidden, preview and the form seams
- bulk action: empty, duplicate, unordered, absent, partial, out-of-scope, rollback, concurrent runs, permissions, CSRF, body cap
- record action: scope, Applies, strict body, offered order, rollback, Applies error
- ForbiddenError from every Form hook, the bulk delete and the relation link and child hooks
- permission editor modes, locked codes and provider errors; relation locks on create, update and belongsTo
- TestPhase121BootErrors: every boot error of plans 01 and 02 with plugin, controller and file
- pact: the action, row state and filter contracts on a sample controller
2026-10-05 14:48:34 +02:00
Jakub Zych
c076b4c059 test(12.1-05): threat test for the Phase 12.1 framework contracts and the first gate stages
- TestPhase121Threats: one subtest per mitigated threat T-12.1-01 to T-12.1-15
- roster fixture: sentinel names and knobs for failing hooks and providers
- scripts/check-phase12.1.sh: fail-closed go test detector, --self-test and --security
2026-10-05 14:30:31 +02:00
Jakub Zych
52f864ebfc docs(12.1-04): update state and roadmap after the groups and organisations plan 2026-10-05 14:10:11 +02:00
Jakub Zych
3f4a01ddf8 docs(12.1-04): complete groups field, User Groups and Organisations plan 2026-10-05 14:09:34 +02:00
Jakub Zych
fcc86ac45e docs(12.1-03): update state and roadmap after the Users screen plan 2026-10-05 13:34:30 +02:00
Jakub Zych
76df9c5bd6 docs(12.1-03): complete plugin foundation and Users screen plan 2026-10-05 13:33:50 +02:00
Jakub Zych
b8cdb7cc92 docs(12.1-02): update state and roadmap after the v0.1.3 tag
- plan 3 of 5 next; decisions of plan 02 recorded
- pending: push master and v0.1.3; two application inventory tests
2026-10-05 12:44:03 +02:00
Jakub Zych
bd4960401d docs(12.1-02): complete framework preview and form seams plan
- summary with the v0.1.3 tag, gate times and contract names
- deferred item for two application inventory tests
- WINDOWS entry 9 fixed: RecordActions.vue is mounted
2026-10-05 12:43:23 +02:00
Jakub Zych
df5cace852 feat(12.1-02): writable foreign keys, locked relation options, invisible columns
- FieldRelationContract.WritableForeignKey makes a belongsTo field over a
  protected foreign key writable; the protected key list is unchanged
- cabana.RelationLockProvider names related ids an administrator may not add
  or remove: options and labels carry locked, and a create or update that
  changes the locked subset is 403 before any row is written
- columns.yaml invisible keeps a column searchable and out of the rows
- a controller implementing pact.FilterOptions serves a scope filter's
  choices before the model
- SPA: locked chips and options in RelationField, DataTable skips invisible
  columns
- README, docs, OpenAPI document, TS types and dist updated
v0.1.3
2026-10-05 10:58:38 +02:00
Jakub Zych
f50d9b8f10 feat(12.1-02): permissioneditor field in radio or checkbox mode
- type: permissioneditor with mode radio (1, -1) or checkbox (1); the
  controller serves the options per request through
  cabana.PermissionEditorProvider and reads and stores the values
- a save answers 422 for a non-object, an unknown code or a value outside the
  mode's set and 403 for a changed locked code; stored codes that are not
  offered are kept
- record responses carry the stored permissions as an object
- SPA: PermissionEditorField with sections by tab, locked rows and a read-only
  mode for the preview
- README, docs, OpenAPI document, TS types and dist updated
2026-10-05 10:44:50 +02:00
Jakub Zych
a1c6bb1ce6 feat(12.1-02): password and form-only fields, rules per operation and preset
- pact.FormVirtualFields lists form fields that are not model columns: never
  bound, filled or projected; their values reach the Form hooks through
  cabana.VirtualFieldsFromContext when the field's context allows the operation
- type: password is a masked field that must be listed as virtual
- pact.FormRules supplies the rule set per operation and replaces the model's
  Rules() for admin saves; a rule on a virtual field sees the submitted value
- preset on a text field follows another text field on the create form
- SPA: PasswordField, preset handling in FormView, empty password left out of
  an update
- README, docs, OpenAPI document, TS types and dist updated
2026-10-05 10:35:08 +02:00
Jakub Zych
a65c670574 feat(12.1-02): read-only preview screen with a status hint and record actions
- config_form.yaml preview block (optional headerPartial), reported in the form schema as preview
- fields with context: preview show only on the preview screen and are never written
- form messages preview and edit; recordActions without a preview block stops boot
- SPA route {id}/preview, PreviewView and PreviewField, record actions in the footer
- mapWinterUrl maps preview/:id; the update form returns to the preview
- summer-callout partial style classes for status hints
- README, docs, OpenAPI document, TS types and the embedded build updated
2026-10-05 00:10:48 +02:00
Jakub Zych
1c99de5013 docs(12.1-01): complete framework actions plan 2026-10-04 23:55:37 +02:00
Jakub Zych
71073bc8a2 feat(12.1-01): cabana.ForbiddenError answers a refused write with 403
- hooks and bulk, record, toolbar and widget actions may return it
- 403 forbidden with the localized message and field details; the write's
  transaction is rolled back; other errors stay the opaque 500
- form shows a refused save as a persistent banner and keeps the values;
  a refused delete is a toast
- smoke tests, OpenAPI notes, dist, README, docs
2026-10-04 23:53:34 +02:00
Jakub Zych
61d5fc72ad feat(12.1-01): list row states from one controller call per page
- pact.ListRowStates with the fixed RowState set deleted, negative, disabled
- list response meta.row_states keyed by row id; unknown values dropped
- list messages rowStateDeleted, rowStateNegative, rowStateDisabled
- update writes through the scope the load used, so a soft-deleted record
  a controller includes stays soft-deleted
- DataTable row state badges and text styles
- roster fixture, smoke tests, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:45:44 +02:00
Jakub Zych
e0ccced76a feat(12.1-01): declared record actions with an applicability rule
- pact.HasAdminRecordActions with AdminRecordAction (Applies, Run)
- config_form.yaml recordActions, compiled fail-loud
- show response meta.actions lists the permitted actions that apply
- POST .../{controller}/{id}/actions/{action}: record loaded and locked
  through the form scope; 404 out of scope, 409 when it does not apply
- RecordActions.vue with confirm and request flow (mounted by plan 02)
- roster fixture, smoke tests, OpenAPI, TS types, READMEs, docs
2026-10-04 23:37:30 +02:00
Jakub Zych
a879d6388c feat(12.1-01): declared bulk actions on admin lists
- pact.HasAdminBulkActions with AdminBulkAction, its input and result
- config_list.yaml bulkActions, compiled fail-loud, needs showCheckboxes
- POST .../{controller}/bulk/{action}: ids resolved and locked through the
  list scope in one transaction; partial selection is 409
- list schema offers declared actions per principal, with confirm text
- admin SPA bulk actions menu with confirm, busy state and failure toasts
- acme.roster fixture, tracer test, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:28:30 +02:00
Jakub Zych
ca9e9c0557 chore(config): allow executor commits on the default branch 2026-10-04 23:14:15 +02:00
Jakub Zych
af588aee2d docs: record quick task 261004-rou 2026-10-04 22:53:28 +02:00
Jakub Zych
9cbce01b46 docs(12.1): create phase plan 2026-10-04 19:41:08 +02:00
Jakub Zych
ea0fc6f191 docs(12.1): record plan-count checkpoint decisions 2026-10-04 17:39:39 +02:00
Jakub Zych
127ebd7a62 docs(state): record phase 12.1 UI-SPEC session 2026-10-04 17:29:25 +02:00
Jakub Zych
1577e02b0e docs(12.1): UI design contract 2026-10-04 17:29:20 +02:00
Jakub Zych
8a69c1ef1c docs(12.1): UI design contract 2026-10-04 16:07:57 +02:00
Jakub Zych
0b25a1da24 docs(phase-12.1): add validation strategy 2026-10-04 15:23:55 +02:00
Jakub Zych
3dedaac049 docs(12.1): research phase domain 2026-10-04 15:22:54 +02:00
Jakub Zych
a8f0cfd5f2 docs(state): record phase 12.1 context session 2026-10-04 14:52:45 +02:00
Jakub Zych
6bf1943f8a docs(12.1): capture phase context 2026-10-04 14:52:44 +02:00
Jakub Zych
ee547d27f9 docs(state): record phase 14.1 context session 2026-10-04 14:52:33 +02:00
Jakub Zych
9002ecb844 docs(14.1): capture phase context 2026-10-04 14:52:32 +02:00
Jakub Zych
c27f24d9e5 docs(state): record phase 15 context session 2026-10-04 14:30:26 +02:00
Jakub Zych
67e4406250 docs(15): capture phase context 2026-10-04 14:30:25 +02:00
Jakub Zych
0323aeb6fb docs(14): record code review disposition 2026-10-04 08:13:29 +02:00
Jakub Zych
f5cf6f2580 docs(14): align fix report titles with the review 2026-10-04 08:13:28 +02:00
Jakub Zych
d5a8ef7834 docs(14): record code review disposition 2026-10-04 08:13:17 +02:00
Jakub Zych
5d3299b26f docs(14): add code review fix report 2026-10-04 08:13:12 +02:00
Jakub Zych
b7d10a4448 test(14): verification report and human verification items as UAT 2026-10-04 03:13:37 +02:00
Jakub Zych
aa8ff53c0c docs(14): record code review disposition 2026-10-04 03:05:31 +02:00
Jakub Zych
549ffed415 docs(14): add code review report 2026-10-04 03:05:10 +02:00
Jakub Zych
fc4f70013b docs(14-06): update state and roadmap after the plan 2026-10-04 02:50:21 +02:00
Jakub Zych
e67dbaf895 docs(14-06): complete unit tests and Phase 14 gate plan 2026-10-04 02:49:59 +02:00
Jakub Zych
17b2ef1961 docs(14-06): Phase 14 validation signed off, requirements complete, API coverage confirmed, folded todos closed
- 14-VALIDATION.md: per-task map 14-01-T1 to 14-06-T4, all green, the
  measured coverage, validated, Nyquist-compliant, Wave 0 complete, the
  final --all and --removal results
- REQUIREMENTS.md: INTG-02 and API-08 Complete (JOBS-02, JOBS-03, SRCH-02,
  INTG-01, CLI-05 already were)
- COVERAGE.md: every INTEGRATE row's test confirmed by --named
- fetchguard-guarded-http-client and redacting-slog-handler moved to done
2026-10-04 02:47:53 +02:00
Jakub Zych
a1fccd39ad test(14-06): check-phase14.sh --evidence refuses an incomplete phase record
- every T-14 threat has one review row copying its plan's severity and
  disposition; a mitigated one names a test --named runs and a removal row
- the validation map is validated, Nyquist-compliant and Wave 0 complete,
  with no open row and only tests --named runs
- each COVERAGE.md INTEGRATE row names a run test, each OPT-OUT a reason
- REQUIREMENTS.md keeps no SDK wording for INTG-02 and no sitemap output
  for API-08; the ROADMAP Phase 14 repos and criteria name the album
  Discogs and recognize routes and both shared plugin repos
- --all runs it after the coverage stage
2026-10-04 02:11:39 +02:00
Jakub Zych
81543524be docs(14-06): Phase 14 security review maps every T-14 threat to its protection, test and removal check 2026-10-04 02:11:15 +02:00