Compile regex and enum constraints at route registration so malformed and unknown IDs share a 404, and named rollback errors isolate one plugin's history.
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 2/2
- Count only albums visible in the active collection
- Match PHP filter, validation, ordering and JSON shape
SUMMARY: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
- Reject identifiers and directions outside the caller allow-list
- Emit ordinary ORDER BY without COLLATE so ICU pl-PL applies
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 2/2
- Initialize the real app database through plugin migrations
- Serve the seeded genre list behind real cross-plugin JWT middleware
SUMMARY: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
Named middleware resolves at boot, HS256 tokens are pinned with required
exp/sub, and both binaries expose a signal-aware serve command.
Co-authored-by: Cursor <cursoragent@cursor.com>
Open one pgx stdlib *sql.DB, hand it to GORM, and run per-plugin
gormigrate sets with isolated history tables after an ICU pl-PL check.
Co-authored-by: Cursor <cursoragent@cursor.com>
- Avoid urlsafe passwords that start with a dash and break mariadbadmin -p
- Probe readiness with a quoted SQL SELECT against the disposable container
Co-authored-by: Cursor <cursoragent@cursor.com>
- Check root and fonoteka.go with vet, test and race plus TestParitySynthetic
- Audit the 154-route corpus and smoke parity:record/replay against loopback
- Provision a disposable MariaDB, pin PHP to 127.0.0.1:8423, and self-replay seed, routes and clients
Co-authored-by: Cursor <cursoragent@cursor.com>
- Record/replay baselines plus mutated fixtures for nil vs [], dates, tri-state bools, envelopes, money and ids
- Header, CSV/image byte, sidecar digest and two-flow continuation cases fail with path diagnostics
- Manifest coverage still reports later flows after a comparison failure
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 2/2
- Replay a synthetic write/read flow against Postgres
- Expose the full corpus as honest selectable subtests
SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-04-SUMMARY.md
Value-based replace can miss a code_verifier when an authorization code is a substring of it, which 502'd MCP token capture.
Co-authored-by: Cursor <cursoragent@cursor.com>
Consent returns the callback URL in JSON, so replay can fill {{oauth:code}} from $.data.redirect_to before the token request.
Co-authored-by: Cursor <cursoragent@cursor.com>
RFC 7591 registration returns a string client_id and unix client_id_issued_at; treating those as Carbon/integer foreign keys would fail PHP self-replay of MCP OAuth.
Co-authored-by: Cursor <cursoragent@cursor.com>
Album sync payloads hash the collection and stamp a checkpoint that
change across seed runs and must not fail PHP self-replay.
Co-authored-by: Cursor <cursoragent@cursor.com>
Re-running bootstrap against an already seeded PHP instance 409s.
Route --update must not recapture a complete seed fixture.
Co-authored-by: Cursor <cursoragent@cursor.com>
PHP album payloads leave discogs_id null. The id mask required an
integer and failed PHP self-replay on otherwise identical bodies.
Co-authored-by: Cursor <cursoragent@cursor.com>
Unquoted numeric id placeholders made recorded JSON illegal to parse.
Replay now recaptures, persists vars, expands the expected body, and
diffs against the live response.
Co-authored-by: Cursor <cursoragent@cursor.com>
Numeric seed ids like 1 were substring-replaced through /api/v1 paths
and 15-style JSON integers. Keep ReplaceAll for long secrets and isolate
short values so the corpus stays replayable.
Co-authored-by: Cursor <cursoragent@cursor.com>
Manifest seed paths are fixtures-relative. Skip re-hitting the backend
only when every seed step already has a recorded status so a hand-written
spec can be recorded in place.
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 3/3
- Capture a complete named session through the proxy
- Replay stateful flows with safe capture and strict differences
- Record manifest route cases and report complete coverage
SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-02-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
Drive ordered route cases through RecordFlow, resume in batches of
15, and print recorded/passing/failing/unrecorded coverage.
Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve named placeholders from a private variable store, mask
dates and ids after shape checks, and keep comparing independent steps.
Co-authored-by: Cursor <cursoragent@cursor.com>
Record Nuxt/MCP traffic as ordered flows via parity:proxy, pin
loopback upstream, and refuse oversized or credential-shaped fixtures.
Co-authored-by: Cursor <cursoragent@cursor.com>