Jakub Zych
ae9e11f65d
docs(07-01): complete framework auth primitives plan
2026-09-22 13:43:15 +02:00
Jakub Zych
8fcaff77cf
feat(07-01): add bcrypt, locale override, and validation rules
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:39:25 +02:00
Jakub Zych
bccd7f8f35
test(07-01): add failing tests for passwords, locale, and validation
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:36:08 +02:00
Jakub Zych
cad445a235
feat(07-01): add JWT mint, refresh, and blacklist primitives
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:34:58 +02:00
Jakub Zych
251f3cc4a0
test(07-01): add failing tests for JWT lifecycle primitives
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:33:37 +02:00
Jakub Zych
80eaeb87ea
docs(07): mark phase planned, annotate roadmap waves
2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3
docs(07): revise plans after checker review
2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2
docs(07): create phase plan
...
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)
Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863
docs(07): add pattern map
2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21
docs(07): add validation strategy
2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22
docs(07): research user plugin and authentication phase
2026-09-22 02:42:14 +02:00
Jakub Zych
5548b2fab4
docs(state): record phase 7 context session
2026-09-22 00:24:22 +02:00
Jakub Zych
1979c45083
docs(07): capture phase context
2026-09-22 00:24:21 +02:00
Jakub Zych
2fe5c1e920
docs(06): verify phase 6 passed, mark HTTP-04/06 complete
2026-09-21 19:51:58 +02:00
Jakub Zych
fb66398cb9
docs(06-14): complete gap-closure test and review plan
2026-09-21 19:49:47 +02:00
Jakub Zych
ae817ccbb9
docs(06-14): reopen and re-close phase 6 security review with T-06-28..35
2026-09-21 19:49:30 +02:00
Jakub Zych
e50e2dd632
test(06-14): fetchguard IANA boundary and zoned dial tests, surf edge coverage
2026-09-21 19:48:06 +02:00
Jakub Zych
f1218f2c84
test(06-14): regression coverage for surf and bouncer gap closure
2026-09-21 19:47:16 +02:00
Jakub Zych
1d2e00cf59
fix(06-14): actually reuse built middleware factories per name:param
...
The built cache added in 06-12 was declared but never consulted, so every
route re-invoked the factory on BuildRouter and again on compile.
2026-09-21 19:47:16 +02:00
Jakub Zych
54dd60953a
docs(06-13): complete fetchguard SSRF gap-closure plan
2026-09-21 19:45:03 +02:00
Jakub Zych
b1079ab8a4
fix(06-13): full IANA special-use SSRF tables and reject zoned dial targets
2026-09-21 19:44:51 +02:00
Jakub Zych
4bad1a43a2
docs(06-12): complete surf/bouncer gap-closure plan
2026-09-21 19:43:51 +02:00
Jakub Zych
8a9449df63
fix(06-12): reject typed-nil guards and fractional JWT subjects
2026-09-21 19:43:35 +02:00
Jakub Zych
4ad2ad29f2
fix(06-12): fail closed on invalid limiter definitions
2026-09-21 19:42:41 +02:00
Jakub Zych
a50e09ba34
fix(06-12): bound named middleware by body cap, cache factories, fail boot on bad body config and mux conflicts
2026-09-21 19:42:20 +02:00
Jakub Zych
46c7e4f98e
docs(06): create gap-closure plans 12-14
2026-09-21 19:30:50 +02:00
Jakub Zych
6e9188b5c7
docs(06): record verification gaps
2026-09-21 14:49:52 +02:00
Jakub Zych
c5b412c7e1
docs(06): add code review report
2026-09-21 14:31:47 +02:00
Jakub Zych
ef6d914e4c
docs(06-11): update plan tracking
2026-09-21 13:05:11 +02:00
Jakub Zych
2329e1f290
docs(06-11): complete post-gap security review plan
2026-09-21 13:03:41 +02:00
Jakub Zych
829e9989e3
docs(06-11): refresh Phase 6 security review
2026-09-21 13:02:41 +02:00
Jakub Zych
7118e4f280
docs(06-10): update plan tracking
2026-09-21 00:28:15 +02:00
Jakub Zych
943be2353d
docs(06-10): complete exact InvScope denial bodies plan
2026-09-21 00:26:51 +02:00
Jakub Zych
c9909ce412
docs(06-09): update plan tracking
2026-09-20 21:08:54 +02:00
Jakub Zych
158df899f6
docs(06-09): complete transactional panic recovery plan
...
Tasks completed: 1/1
- Buffer route responses so panic recovery can discard partial output
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-09-SUMMARY.md
2026-09-20 21:06:51 +02:00
Jakub Zych
93d63c351b
fix(06-09): buffer route responses before recovery
...
- Discard partial route output when house or raw handlers panic
- Commit private headers status and body only after successful return
2026-09-20 21:05:44 +02:00
Jakub Zych
f6ba67a693
test(06-09): add failing panic response regressions
...
- Exercise house and raw handlers that write secrets before panicking
- Cover successful explicit and implicit response commits
2026-09-20 21:04:02 +02:00
Jakub Zych
8a265d8372
docs(06-08): update plan tracking
...
- Advance phase progress to 8 of 11 plans
- Record transition-address security decisions and execution metrics
- Mark HTTP-07 complete in requirements tracking
2026-09-20 21:00:45 +02:00
Jakub Zych
ac24ddd518
docs(06-08): complete transition-address SSRF closure plan
...
Tasks completed: 1/1
- Decode and reclassify embedded IPv4 at the dial-time SSRF boundary
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-08-SUMMARY.md
2026-09-20 20:58:54 +02:00
Jakub Zych
99fa932d43
fix(06-08): classify IPv6 transition addresses
...
- Decode embedded IPv4 from NAT64 well-known and local-use prefixes
- Reapply private and reserved IPv4 policy to 6to4 destinations
- Fail closed on malformed RFC 6052 local-use encodings
2026-09-20 18:14:12 +02:00
Jakub Zych
1cd76fcd95
test(06-08): add failing transition address regressions
...
- Cover private and public IPv4 embeddings across NAT64 and 6to4
- Exercise unsafe transition literals through the production dial control
- Require classifier-owned IPv4-mapped normalization
2026-09-20 17:15:57 +02:00
Jakub Zych
3601a0ab09
docs(06-07): update plan tracking
2026-09-20 17:12:31 +02:00
Jakub Zych
bc43e9eabd
docs(06-07): complete atomic limiter admission plan
...
Tasks completed: 1/1
- Make fixed-window admission atomic and inline keys server-controlled
SUMMARY: .planning/phases/06-http-routing-auth-groups-and-rate-limiting/06-07-SUMMARY.md
2026-09-20 17:10:43 +02:00
Jakub Zych
6852a8f8c3
fix(06-07): make limiter admission atomic
...
- Replace split store checks with one mutex-guarded Attempt operation
- Use domainless trusted-client keys for anonymous inline throttles
- Preserve fixed-window headers, expiry, stacking, and principal isolation
2026-09-20 17:02:53 +02:00
Jakub Zych
5bcd7ba011
test(06-07): add failing atomic limiter regressions
...
- Coordinate concurrent store and middleware attempts behind start barriers
- Prove Host rotation and inline policy changes share anonymous budgets
2026-09-20 17:00:28 +02:00
Jakub Zych
47e9c44b2a
docs(06): create gap closure plans
2026-09-20 16:14:21 +02:00
Jakub Zych
c187d6f735
docs(06): reopen phase after verification gaps
2026-09-20 14:00:36 +02:00
Jakub Zych
dd78e0d6b3
docs(06): record gap-closure re-verification
2026-09-20 13:57:07 +02:00
Jakub Zych
067a3ffb2b
docs(06): add code review report
2026-09-20 13:49:19 +02:00
Jakub Zych
3c57a88344
chore(gsd): disable unsupported worktree isolation
2026-09-20 13:33:17 +02:00