Commit Graph

99 Commits

Author SHA1 Message Date
Jakub Zych
4ee4c4a2fc feat(03-01): add ServeMux groups, JWT verifier, and serve command
Named middleware resolves at boot, HS256 tokens are pinned with required
exp/sub, and both binaries expose a signal-aware serve command.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 20:04:13 +02:00
Jakub Zych
d0d845052b feat(03-01): add shared postgres pool and plugin migrations
Open one pgx stdlib *sql.DB, hand it to GORM, and run per-plugin
gormigrate sets with isolated history tables after an ICU pl-PL check.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 19:55:33 +02:00
Jakub Zych
15a8389e46 docs(03): create phase plan 2026-09-17 18:40:13 +02:00
Jakub Zych
de99bf3caa docs(state): record phase 3 context session 2026-09-17 17:47:08 +02:00
Jakub Zych
81174d0c25 docs(03): capture phase context 2026-09-17 17:47:07 +02:00
Jakub Zych
5f93129524 docs(02): add code review fix report
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:45:35 +02:00
Jakub Zych
f7b81b9dd7 fix(02): resolve symlinks before fixture and vars path checks (WR-07)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:44:23 +02:00
Jakub Zych
0ac9dc45d0 fix(02): scan leftover passwords and redact secrets in diffs (WR-04)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:43:01 +02:00
Jakub Zych
d3d202e0e2 fix(02): reject trailing JSON after the first decoded value (WR-03)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:59 +02:00
Jakub Zych
5cb2defe0f fix(02): compare redirect Location headers during replay (WR-02)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:39 +02:00
Jakub Zych
7e70afe819 fix(02): write fixtures exclusively and only on successful flush (WR-01)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:18 +02:00
Jakub Zych
5994e671b3 fix(02): stop short ids rewriting pagination and IPv4 (CR-01)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:39:45 +02:00
Jakub Zych
d27897c7e0 docs(02): add code review report 2026-09-17 14:23:53 +02:00
Jakub Zych
0f7ba926ea docs(phase-02): evolve PROJECT.md after phase completion 2026-09-17 14:23:12 +02:00
Jakub Zych
b3e609ea78 docs(phase-02): complete phase execution 2026-09-17 14:23:11 +02:00
Jakub Zych
8fe69ffc6b docs(02-05): mark plan complete in STATE and ROADMAP
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:17:22 +02:00
Jakub Zych
7303467602 docs(02-05): complete contract-security-integration-tests plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:15:37 +02:00
Jakub Zych
84a5f007e3 docs(02-05): record measured Phase 2 gate evidence
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:15:13 +02:00
Jakub Zych
066c3d3ab7 fix(02-05): wait for MariaDB with hex-only process credentials
- Avoid urlsafe passwords that start with a dash and break mariadbadmin -p
- Probe readiness with a quoted SQL SELECT against the disposable container

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:12:05 +02:00
Jakub Zych
a296e98d8e feat(02-05): add the repeatable Phase 2 vet, race and PHP gate
- Check root and fonoteka.go with vet, test and race plus TestParitySynthetic
- Audit the 154-route corpus and smoke parity:record/replay against loopback
- Provision a disposable MariaDB, pin PHP to 127.0.0.1:8423, and self-replay seed, routes and clients

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:09:16 +02:00
Jakub Zych
5ed920b7b1 test(02-05): cover proxy, scrub and CLI security boundaries
- Reject non-loopback bind/upstream, cap bodies, isolate concurrent sessions and refuse traversal
- Scrub JWT, inv_ tokens, cookies, client secrets and OAuth codes out of fixtures
- CLI discovery and replay errors exit nonzero without printing secrets

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:06:40 +02:00
Jakub Zych
59b5276cba test(02-05): lock down every response parity class with negative tests
- Record/replay baselines plus mutated fixtures for nil vs [], dates, tri-state bools, envelopes, money and ids
- Header, CSV/image byte, sidecar digest and two-flow continuation cases fail with path diagnostics
- Manifest coverage still reports later flows after a comparison failure

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:03:55 +02:00
Jakub Zych
6f0168ae1e docs(02-04): mark plan complete in STATE and ROADMAP 2026-09-17 13:59:51 +02:00
Jakub Zych
9a8fcc2c1e docs(02-04): complete honest-go-replay-with-testcontainers plan
Tasks completed: 2/2
- Replay a synthetic write/read flow against Postgres
- Expose the full corpus as honest selectable subtests

SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-04-SUMMARY.md
2026-09-17 13:59:04 +02:00
Jakub Zych
1f21982472 docs(02-03): mark plan complete in STATE and ROADMAP
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:47:58 +02:00
Jakub Zych
38dd34d221 docs(02-03): complete record-154-routes-and-client-flows plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:47:29 +02:00
Jakub Zych
7a6c669e3a fix(02-03): scrub PKCE and OAuth form fields by name
Value-based replace can miss a code_verifier when an authorization code is a substring of it, which 502'd MCP token capture.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:43:27 +02:00
Jakub Zych
2eb9b4b0c9 fix(02-03): surface reverse-proxy record failures in 502 bodies
Silent "upstream error" hid capture-rule failures during MCP token exchange.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:40:47 +02:00
Jakub Zych
8881df9f7a fix(02-03): capture OAuth code from JSON redirect URLs
Consent returns the callback URL in JSON, so replay can fill {{oauth:code}} from $.data.redirect_to before the token request.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:38:54 +02:00
Jakub Zych
22f02eed59 fix(02-03): mask OAuth client_id and unix issued_at
RFC 7591 registration returns a string client_id and unix client_id_issued_at; treating those as Carbon/integer foreign keys would fail PHP self-replay of MCP OAuth.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:36:30 +02:00
Jakub Zych
8f94b07986 fix(02-03): scrub PHP-escaped JSON secret values
PHP json_encode writes \/ so captured redirect URLs never matched the fixture body, leaving OAuth codes in client sessions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:32:11 +02:00
Jakub Zych
0307510b22 fix(02-03): mask collection_key and checkpoint in JSON diffs
Album sync payloads hash the collection and stamp a checkpoint that
change across seed runs and must not fail PHP self-replay.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:03:38 +02:00
Jakub Zych
4c1259aafd fix(02-03): keep a recorded seed when --update recaptures routes
Re-running bootstrap against an already seeded PHP instance 409s.
Route --update must not recapture a complete seed fixture.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:00:44 +02:00
Jakub Zych
39ddf787ce fix(02-03): re-record on --update and honor case capture rules
Ordered PHP self-replay needs regenerated share tokens captured into
vars, and --update must overwrite already-recorded route fixtures.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:00:14 +02:00
Jakub Zych
5b947c7454 fix(02-03): treat null foreign keys as valid masked ids
PHP album payloads leave discogs_id null. The id mask required an
integer and failed PHP self-replay on otherwise identical bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:52:06 +02:00
Jakub Zych
591a0d4681 fix(02-03): expand expected placeholders after replay capture
Unquoted numeric id placeholders made recorded JSON illegal to parse.
Replay now recaptures, persists vars, expands the expected body, and
diffs against the live response.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:51:24 +02:00
Jakub Zych
1ea3c59055 fix(02-03): scrub short captured ids only at token boundaries
Numeric seed ids like 1 were substring-replaced through /api/v1 paths
and 15-style JSON integers. Keep ReplaceAll for long secrets and isolate
short values so the corpus stays replayable.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:47:38 +02:00
Jakub Zych
4451c2f39f fix(02-03): resolve relative seed specs and skip only recorded seeds
Manifest seed paths are fixtures-relative. Skip re-hitting the backend
only when every seed step already has a recorded status so a hand-written
spec can be recorded in place.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:46:38 +02:00
Jakub Zych
eabbe00976 docs(02-02): record plan progress in STATE and ROADMAP
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:38:05 +02:00
Jakub Zych
0824f31d08 docs(02-02): complete capture-sessions-and-manifest-coverage plan
Tasks completed: 3/3
- Capture a complete named session through the proxy
- Replay stateful flows with safe capture and strict differences
- Record manifest route cases and report complete coverage

SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-02-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:37:17 +02:00
Jakub Zych
24c1f43e84 feat(02-02): record manifest route cases and report coverage
Drive ordered route cases through RecordFlow, resume in batches of
15, and print recorded/passing/failing/unrecorded coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:36:48 +02:00
Jakub Zych
aa165fe3d0 feat(02-02): capture, scrub, and strictly diff stateful flows
Resolve named placeholders from a private variable store, mask
dates and ids after shape checks, and keep comparing independent steps.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:32:49 +02:00
Jakub Zych
bb6a5a91c9 feat(02-02): capture named sessions through a loopback proxy
Record Nuxt/MCP traffic as ordered flows via parity:proxy, pin
loopback upstream, and refuse oversized or credential-shaped fixtures.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:27:57 +02:00
Jakub Zych
603270da08 docs(02-01): record plan progress in STATE and ROADMAP
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:23:12 +02:00
Jakub Zych
f9ba69c663 docs(02-01): complete record-and-replay one fixture plan
Tasks completed: 2/2
- Record and replay one route through the summer CLI
- Lock the one-route tide record and replay contract

SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-01-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:22:30 +02:00
Jakub Zych
f669d056c9 feat(02-01): lock the one-route tide record and replay contract
- Reject unknown YAML fields, empty names, duplicate steps and unsafe sidecars
- Treat JSON key order as insignificant and fail missing keys and token types at $.path
- Bound request bodies and refuse oversized or malformed input before writing a fixture

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:21:34 +02:00
Jakub Zych
f6e1b892bc feat(02-01): record and replay one route through the summer CLI
- Add a generic tide flow schema with YAML fixture IO and HTTP record/replay
- Register parity:record and parity:replay on the bonfire summer tool
- Diff JSON scalars at $.path and non-JSON bodies at the changed byte offset

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:20:22 +02:00
Jakub Zych
acd31ba28c docs(02): create verified phase plans 2026-09-17 01:57:41 +02:00
Jakub Zych
e3076950c3 docs(02): finalize parity research and validation map 2026-09-17 01:56:49 +02:00
Jakub Zych
a109b52ec6 docs(02): resolve parity proxy port split 2026-09-16 16:27:50 +02:00