Commit Graph

770 Commits

Author SHA1 Message Date
Jakub Zych
5b06b20ac3 fix(12.2-05): mark a partly filled time-mode datepicker invalid
The partial-segment check read only DateField segments, so a time-mode
field (Reka TimeField, data-reka-time-field-segment) with some segments
typed was never flagged. Read both segment attributes. DatepickerField
tests cover both UI-SPEC backstops (Escape focus and disabled days, the
fixed-zone datetime round trip) and the partly filled time case.
2026-10-02 20:37:38 +02:00
Jakub Zych
c8d41a68c6 test(12.2-05): cover every Go behaviour of phase 12.2
- lagoon: Date and TimeOfDay through JSON, text and real DATE/TIME
  columns; Fill text fallback without changing earlier conversions;
  required on zero dates; deferred_bindings shape, store isolation and
  envelope; PurgeDeferred cut-off, after-commit blobs, SKIP LOCKED,
  skipped types and the deferred:purge command
- attach: Store limits, extensions, MIME patterns, default lists, key
  shape and blob cleanup; IsAllowedImage formats, polyglots, ceiling
- conga and pact: framework purge schedule entry and forged jobs; the
  six relation child hook interfaces
- cabana: fileupload and datepicker compile, upload, remove, caption,
  reorder and bounds; deferred commit order, rollback, applied-only and
  concurrent saves; relation contracts, forms, CRUD, deferral, schema
2026-10-02 20:34:23 +02:00
Jakub Zych
9c87a59532 docs(13): create phase plan
Six sequential plans: framework gaps, notifications/credentials/onboarding, wishlist, CSV, public views, unit tests and gate. Research open questions marked resolved per the plan-count checkpoint.
2026-10-02 20:12:35 +02:00
Jakub Zych
9d2b1c1848 test(12.2-05): prove relation child and protected file scoping through the router
- acme.deferred fixture plugin over testdata/deferred (test-only), two
  controllers, recording Form and Relation hooks, two admins
- TestRelationChildScope*: every child route answers 404 for another
  parent, a hidden parent and another admin's pending child, changes
  nothing; undeclared toolbar buttons 403 before SQL; pivot whitelist
- TestProtectedFile*: foreign, pending and public files 404; only jpeg,
  png, gif and webp inline; nosniff, no-store and sandbox CSP everywhere
2026-10-02 20:10:10 +02:00
Jakub Zych
162a8ec5a1 docs(12.2-04): update state and roadmap progress after plan 12.2-04 2026-10-02 19:58:42 +02:00
Jakub Zych
92d665f1b2 docs(12.2-04): complete the admin SPA dates, uploads and relation modals plan summary 2026-10-02 19:58:19 +02:00
Jakub Zych
69a37456f6 feat(12.2-04): edit related records in modals and defer relation work on new records
- RelationManager renders create/link/delete/unlink in declared order with
  one primary, opens the child modal (update or view form) or the pivot
  modal on row click, and deletes selected children behind a busy confirm
- RelationChildModal creates and edits children with its own session key
  (X-Child-Session-Key) so uploads and dates work inside it
- RelationPivotModal edits link details; the picker links one record with
  its pivot values when the relation has a pivot form
- deferrable managers render on the create screen with owner id 0, the
  form's X-Session-Key and the pending note, and mark the form dirty
- the registry resolves RelationManager lazily (child forms close an
  import cycle); DataTable gains openable rows and a trailing cell
- relation lang keys in en and pl; rebuilt boardwalk dist
2026-10-02 19:56:10 +02:00
Jakub Zych
a0c182745e feat(12.2-04): add the datepicker field and stored date and time list cells
- pin @internationalized/date 3.12.4 as a direct admin dependency (approved)
- dateFormat.ts parses and emits date, datetime (local display, UTC emit,
  ignoreTimezone wall clock) and time values without the global Date
- DatepickerField on Reka DatePicker and TimeField with locale segments,
  calendar popover, clear button, min/max and yearRange bounds
- list cells of type date and time render the stored string
- datepicker lang keys in en and pl; rebuilt boardwalk dist
2026-10-02 19:45:43 +02:00
Jakub Zych
d66812caef docs(13): map phase patterns 2026-10-02 19:39:34 +02:00
Jakub Zych
ea33296799 feat(12.2-04): add the fileupload field with deferred uploads on the form session key
- sessionKey.ts: one 32-byte base64url key per form mount, sent only in headers
- api/files.ts: FileRoutes over the record and child file routes, XHR upload with progress, 401 refresh and retry
- FileuploadField and FileCaptionModal per UI-SPEC section 3: dropzone, image grid, rows, per-item states, client pre-checks, reorder, protected previews
- FormView provides FORM_SESSION, counts pending changes as dirty and sends X-Session-Key on create and update
- fileupload lang keys in en and pl, admin-spa docs note, deferred smoke test, rebuilt dist
2026-10-02 19:22:22 +02:00
Jakub Zych
1ebfe691a2 docs(13): research phase domain 2026-10-02 19:21:38 +02:00
Jakub Zych
cb653711f0 docs(12.2-03): update state and roadmap progress after plan 12.2-03 2026-10-02 19:09:54 +02:00
Jakub Zych
6cdfbd49d0 docs(12.2-03): complete the relation child CRUD and deferral plan summary 2026-10-02 19:09:26 +02:00
Jakub Zych
fe9e8baaf1 feat(12.2-03): defer relation work on unsaved records and add child file routes
- record id 0 with X-Session-Key manages deferrable relations: create, link, unlink, delete and pivot edits are held in deferred_bindings
- the record's create save applies relation bindings with the file bindings; an ineligible link is a 422 on the relation-manager field
- child forms upload files through .../records/{child}/files/{field} keyed by X-Child-Session-Key; the child save commits them
- boot refuses a deferrable relation with create whose related model no plugin lists in Models()
2026-10-02 19:08:16 +02:00
Jakub Zych
afb05b6ee4 feat(12.2-03): add parent-scoped child show, update, delete and pivot routes
- loadChild finds a child with one query carrying the parent predicate; a foreign child is 404
- GET/PUT .../records/{child} and POST .../delete (all or nothing) per relation kind
- hasMany link adopts NULL-key rows and unlink clears the key; pending created children are never candidates
- link accepts pivot values for one id through the pivot.form whitelist; GET/PUT .../pivot/{child}
- Link and Unlink share linkRelated/unlinkRelated for the deferred commit
2026-10-02 18:44:34 +02:00
Jakub Zych
48a5b8045a feat(12.2-03): add hasMany relation contracts, relation forms and child create
- RelationContract gains Kind (empty is belongsToMany) and ForeignKey, with kind-aware boot checks
- manage.form, view.form and pivot.form compile against the related or pivot model; $/ paths resolve inside the plugin
- view toolbarButtons accept create|update|delete|link|unlink, each the capability of its routes
- POST .../relations/{name}/records creates a child through the manage form; the server sets the hasMany key
- relation schema carries kind, deferrable and the localized forms; 17 new relation message keys in en and pl
2026-10-02 18:37:13 +02:00
Jakub Zych
0b4ef9c311 docs(12.2-02): update state and roadmap progress after plan 12.2-02 2026-10-02 18:21:05 +02:00
Jakub Zych
a4b3010e76 docs(12.2-02): complete the fileupload and datepicker admin API plan summary 2026-10-02 18:20:39 +02:00
Jakub Zych
67d4c7ff13 feat(12.2-02): add the datepicker field with server-side bounds and date list columns
- type: datepicker compiles the D-20 keys; format maps to displayFormat with WinterCMS's momentFormat table
- boot fails when the mode does not match the column's Go type (time.Time, lagoon.Date, lagoon.TimeOfDay)
- datepicker is a writable scalar field; minDate and maxDate are rechecked on save
- columns.yaml accepts type: date and type: time; Scanner/Valuer structs are columns, not relations
- conformance fixture carries date and datetime fields; README, forms and lists docs
2026-10-02 18:19:04 +02:00
Jakub Zych
bbb804961e docs(13): capture phase context 2026-10-02 18:17:03 +02:00
Jakub Zych
e54fd257ee feat(12.2-02): add file removal, caption, reorder and protected downloads
- DELETE, PUT and POST reorder under .../{id}/files/{field}, each scoped by one parent query (404 for a foreign file)
- protected download and thumb routes: is_public=false only, nosniff, private no-store, sandbox CSP, inline only for jpeg/png/gif/webp
- the save applies deferred removals, replaces attachOne files and rechecks maxFiles and required
- blobs of deleted files are removed after commit
- swagger2openapi emits binary content for file responses
- admin OpenAPI, TS types, conformance, README and attachments docs
2026-10-02 18:11:56 +02:00
Jakub Zych
044e0450ef feat(12.2-02): add the fileupload field with deferred uploads committed on save
- type: fileupload compiles the D-08 keys and binds to the model's attach.Relation at boot
- X-Session-Key (cabana.SessionKeyHeader) carries the form session key; RecordInput.SessionKey
- GET and POST .../{id}/files/{field}: list with pending uploads, multipart upload into attach.Store
- the create and update save attaches the session's pending files in its transaction
- swagger2openapi folds formData parameters into a multipart requestBody
- admin OpenAPI, TS types, conformance cases, README and forms docs
2026-10-02 18:04:34 +02:00
Jakub Zych
edda803dc1 docs(12.2-01): update state and roadmap progress after plan 12.2-01 2026-10-02 17:48:31 +02:00
Jakub Zych
f004d7d4fc docs(12.2-01): complete the storage foundations plan summary 2026-10-02 17:48:01 +02:00
Jakub Zych
8818d7b023 feat(12.2-01): add deferred:purge, its daily framework schedule and relation child hooks
- deferred:purge [--days] in lagoon.RuntimeCommands (purge_days, default 5)
- lagoon.FrameworkSchedule entry at purge_at (default 03:00, empty disables)
- conga prepends framework entries as summercms.lagoon[i]:<command>
- pact.Relation{Before,After}{Create,Update,Delete} optional hooks
- lagoon, conga and pact READMEs, scheduling and setup docs
2026-10-02 17:45:41 +02:00
Jakub Zych
f48a886f94 feat(12.2-01): add lagoon.Date and lagoon.TimeOfDay with Fill and required support
- Date (DATE) and TimeOfDay (TIME) with Scanner, Valuer, JSON and text forms
- Fill falls back to encoding.TextUnmarshaler for string sources after
  every existing conversion, so time.Time and the new types fill from JSON
- required treats a zero time.Time, Date or TimeOfDay as empty
- lagoon README, models and casts-and-validation docs
2026-10-02 17:40:48 +02:00
Jakub Zych
19f4cf8232 feat(12.2-01): add deferred bindings, guarded upload store and purge
- deferred_bindings migration set under summercms.deferred with backend_user_id
- lagoon.DeferredBind/Unbind/Bindings/Forget/Slaves scoped by DeferredKey
- lagoon.PurgeDeferred with SKIP LOCKED batches and after-commit blob deletes
- attach.Store with the ported image guard, extension and MIME limits
- attach.Relation, attach.HasRelations, attach.BlobKeys, File.ThumbKey
- lagoon README and attachments docs
2026-10-02 17:36:43 +02:00
Jakub Zych
79e2a43095 test(12): persist human verification items as UAT 2026-10-02 17:08:58 +02:00
Jakub Zych
1ea63ef1ee docs(12): record code review disposition 2026-10-02 17:08:31 +02:00
Jakub Zych
44a25dd380 docs(12): add code review report 2026-10-02 17:08:18 +02:00
Jakub Zych
560a16983c docs(12-05): update state and roadmap progress after plan 12-05 2026-10-02 16:57:41 +02:00
Jakub Zych
c97cc094d5 docs(12-05): complete the Phase 12 security proof, coverage and gate plan 2026-10-02 16:56:55 +02:00
Jakub Zych
1f4e1e01c4 docs(12-05): sign off the Phase 12 security review, validation and API-01/API-02
- 12-SECURITY-REVIEW.md maps T-12-01..T-12-34 and T-12-SC to a named test
  and 25 removal checks, all seen failing with the protection removed
- 12-VALIDATION.md validated with the final per-task map, nyquist_compliant
- REQUIREMENTS.md: API-01 and API-02 complete
2026-10-02 16:55:29 +02:00
Jakub Zych
f4ec94531f docs(12.2): create phase plan
Five sequential plans: foundations (deferred_bindings, attach.Store,
lagoon.Date/TimeOfDay, purge), cabana datepicker and fileupload, relation
child CRUD with deferral, admin SPA, and unit and security tests.
Adds D-22..D-24 from the plan-count checkpoint and the pattern map.
2026-10-02 16:53:42 +02:00
Jakub Zych
6f4386c2f9 chore(12-05): add the fail-closed Phase 12 gate
scripts/check-phase12.sh, modelled on check-phase11.sh:
- --go: vet and test both repositories, golang.org/x/image pinned at v0.46.0
- --parity: 99 ported routes in the manifest, TestParityCorpus with its
  coverage subtest, all four broadcast goldens, both Nuxt flows,
  check_corpus --require-recorded --check-secrets and a secret scan of the
  fuzz seed corpus
- --named: every test 12-VALIDATION.md names, by exact name, the fonoteka
  plugin's under -race
- --removal: 25 anchor-exact mutations behind 12-SECURITY-REVIEW.md, each
  required to fail its named test on an assertion; a dirty file is
  refused and every file is restored and compared with cmp
- --coverage: an 80% floor per Phase 12 package in both repositories
- --evidence: one review row per T-12 threat, a removal row per high
  mitigated threat, a green validation file naming only tests the gate runs
- --self-test: every detector, plant and harness branch fails closed
2026-10-02 16:39:03 +02:00
Jakub Zych
6e30624ece test(12-05): bring the Phase 12 framework packages to full unit coverage
- lagoon: Go-typed request values (typed slices and maps, sized integers,
  floats, file pointers, typed path lookups), regex delimiters, mimes
  sniffing (jpg/jpeg, SVG, PHP names, unreadable content),
  UploadedFileFromHeader, the rule builders, custom catalog lines with
  :input/:index/:position, and exists: against Postgres (text compare,
  inferred and NULL columns, arrays, unsafe identifiers, missing tables)
- lagoon/attach: thumbnails in every mode from PNG, GIF and JPEG originals,
  bucket URL normalisation, OpenBucket/Publish refusals, URL helpers and
  static prefix stripping
- tide: part validation and encoding edges, symlinks out of the fixture
  directory, Content-Type handling, every response mask and the coverage
  report helpers

Coverage: lagoon 84.4%, lagoon/attach 87.7%, tide 81.4%, beachcomber
84.3%, beachcomber/typesense 95.9%.
2026-10-02 15:54:44 +02:00
Jakub Zych
d1650e8213 docs(12.2): UI design contract 2026-10-02 15:52:22 +02:00
Jakub Zych
3ac1d64ab4 fix(12-05): cast floats to strings with PHP's 14-digit precision in request validation
PHP 8's (string) cast of a float formats with the precision ini (14
significant digits, %.14G), not the shortest round-trip form: 1/3 is
0.33333333333333, 1e14 is 1.0E+14 and 5e-324 is 4.9406564584125E-324.
phpFloatString, used for the string form of JSON floats in size, in, regex
and integer checks, printed up to 17 digits and switched to the exponent
form only from 1e15. TestPHPFloatStringMatchesPHPCast pins 27 values to
php -r output.
2026-10-02 15:46:24 +02:00
Jakub Zych
36983bc87e fix(12-05): match Laravel's in and not_in rules on array values
A 162-case truth table recorded from WinterCMS's validator (the vendored
winter/storm Factory, Laravel 9) found three divergences, all on arrays:

- in compared array elements loosely; Laravel uses array_diff, an exact
  string comparison, so ["1.0"] is not in 1,2;
- not_in failed when any element was listed; Laravel's validateNotIn is
  !validateIn, so an array passes unless every element is listed;
- not_in failed an array without the array rule; Laravel passes it.

validate_rules_test.go keeps the whole table (accepted, array keys,
boolean, numeric, integer, in/not_in, sizes by type, regex, dates and
comparisons, url, presence, nested and map wildcards, bail and order).
2026-10-02 15:42:47 +02:00
Jakub Zych
92b12fee4c docs(phase-12.2): add validation strategy 2026-10-02 15:24:48 +02:00
Jakub Zych
1c476d243f docs(12.2): research phase domain 2026-10-02 15:24:00 +02:00
Jakub Zych
1307060e15 fix(12-05): store WinterCMS's broken-image thumbnail for an unusable original (T-12-16)
A photo whose original is missing, does not decode or declares more than
4096x4096 pixels made attach.File.Thumb return an error, and every listing
that shows the photo answered 500 from then on: one 100-byte PNG uploaded
by any household member broke GET collections and the album for everyone.

Thumb now follows WinterCMS's File::makeThumb catch branch: it logs the
reason at warn level, stores WinterCMS's BrokenImage picture (exported as
attach.BrokenImagePNG) under the thumbnail key and returns its URL. Invalid
arguments, storage errors and encode failures are still errors.
2026-10-02 15:15:26 +02:00
Jakub Zych
2f71aeb534 docs(state): record phase 12.2 context session 2026-10-02 15:01:26 +02:00
Jakub Zych
4712e94a12 docs(12.2): capture phase context 2026-10-02 15:01:25 +02:00
Jakub Zych
37595fb6b2 docs(12-04): update state and roadmap progress after plan 12-04 2026-10-02 14:44:17 +02:00
Jakub Zych
3cf2b38a8c docs(12-04): complete albums, search and lookups plan 2026-10-02 14:43:34 +02:00
Jakub Zych
44526f0bca docs: insert Phase 12.2 admin form fields with deferred binding (v0.1.1) 2026-10-02 14:36:41 +02:00
Jakub Zych
6649763590 chore(12-04): require every album broadcast golden to pass
All four goldens run through the album handlers now: no pending skip is expected
and the named check requires created and updated to pass.
2026-10-02 14:30:13 +02:00
Jakub Zych
7ac6c05ab3 chore(12-04): expect only the updated broadcast golden to skip
The album store handler asserts the created golden now; updated stays pending
until the update handler lands.
2026-10-02 14:01:32 +02:00
Jakub Zych
18ead668ec docs(12-03): update state and roadmap progress after plan 12-03 2026-10-02 13:18:30 +02:00