Commit Graph

869 Commits

Author SHA1 Message Date
Jakub Zych
a1c6bb1ce6 feat(12.1-02): password and form-only fields, rules per operation and preset
- pact.FormVirtualFields lists form fields that are not model columns: never
  bound, filled or projected; their values reach the Form hooks through
  cabana.VirtualFieldsFromContext when the field's context allows the operation
- type: password is a masked field that must be listed as virtual
- pact.FormRules supplies the rule set per operation and replaces the model's
  Rules() for admin saves; a rule on a virtual field sees the submitted value
- preset on a text field follows another text field on the create form
- SPA: PasswordField, preset handling in FormView, empty password left out of
  an update
- README, docs, OpenAPI document, TS types and dist updated
2026-10-05 10:35:08 +02:00
Jakub Zych
a65c670574 feat(12.1-02): read-only preview screen with a status hint and record actions
- config_form.yaml preview block (optional headerPartial), reported in the form schema as preview
- fields with context: preview show only on the preview screen and are never written
- form messages preview and edit; recordActions without a preview block stops boot
- SPA route {id}/preview, PreviewView and PreviewField, record actions in the footer
- mapWinterUrl maps preview/:id; the update form returns to the preview
- summer-callout partial style classes for status hints
- README, docs, OpenAPI document, TS types and the embedded build updated
2026-10-05 00:10:48 +02:00
Jakub Zych
1c99de5013 docs(12.1-01): complete framework actions plan 2026-10-04 23:55:37 +02:00
Jakub Zych
71073bc8a2 feat(12.1-01): cabana.ForbiddenError answers a refused write with 403
- hooks and bulk, record, toolbar and widget actions may return it
- 403 forbidden with the localized message and field details; the write's
  transaction is rolled back; other errors stay the opaque 500
- form shows a refused save as a persistent banner and keeps the values;
  a refused delete is a toast
- smoke tests, OpenAPI notes, dist, README, docs
2026-10-04 23:53:34 +02:00
Jakub Zych
61d5fc72ad feat(12.1-01): list row states from one controller call per page
- pact.ListRowStates with the fixed RowState set deleted, negative, disabled
- list response meta.row_states keyed by row id; unknown values dropped
- list messages rowStateDeleted, rowStateNegative, rowStateDisabled
- update writes through the scope the load used, so a soft-deleted record
  a controller includes stays soft-deleted
- DataTable row state badges and text styles
- roster fixture, smoke tests, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:45:44 +02:00
Jakub Zych
e0ccced76a feat(12.1-01): declared record actions with an applicability rule
- pact.HasAdminRecordActions with AdminRecordAction (Applies, Run)
- config_form.yaml recordActions, compiled fail-loud
- show response meta.actions lists the permitted actions that apply
- POST .../{controller}/{id}/actions/{action}: record loaded and locked
  through the form scope; 404 out of scope, 409 when it does not apply
- RecordActions.vue with confirm and request flow (mounted by plan 02)
- roster fixture, smoke tests, OpenAPI, TS types, READMEs, docs
2026-10-04 23:37:30 +02:00
Jakub Zych
a879d6388c feat(12.1-01): declared bulk actions on admin lists
- pact.HasAdminBulkActions with AdminBulkAction, its input and result
- config_list.yaml bulkActions, compiled fail-loud, needs showCheckboxes
- POST .../{controller}/bulk/{action}: ids resolved and locked through the
  list scope in one transaction; partial selection is 409
- list schema offers declared actions per principal, with confirm text
- admin SPA bulk actions menu with confirm, busy state and failure toasts
- acme.roster fixture, tracer test, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:28:30 +02:00
Jakub Zych
ca9e9c0557 chore(config): allow executor commits on the default branch 2026-10-04 23:14:15 +02:00
Jakub Zych
af588aee2d docs: record quick task 261004-rou 2026-10-04 22:53:28 +02:00
Jakub Zych
9cbce01b46 docs(12.1): create phase plan 2026-10-04 19:41:08 +02:00
Jakub Zych
ea0fc6f191 docs(12.1): record plan-count checkpoint decisions 2026-10-04 17:39:39 +02:00
Jakub Zych
127ebd7a62 docs(state): record phase 12.1 UI-SPEC session 2026-10-04 17:29:25 +02:00
Jakub Zych
1577e02b0e docs(12.1): UI design contract 2026-10-04 17:29:20 +02:00
Jakub Zych
8a69c1ef1c docs(12.1): UI design contract 2026-10-04 16:07:57 +02:00
Jakub Zych
0b25a1da24 docs(phase-12.1): add validation strategy 2026-10-04 15:23:55 +02:00
Jakub Zych
3dedaac049 docs(12.1): research phase domain 2026-10-04 15:22:54 +02:00
Jakub Zych
a8f0cfd5f2 docs(state): record phase 12.1 context session 2026-10-04 14:52:45 +02:00
Jakub Zych
6bf1943f8a docs(12.1): capture phase context 2026-10-04 14:52:44 +02:00
Jakub Zych
ee547d27f9 docs(state): record phase 14.1 context session 2026-10-04 14:52:33 +02:00
Jakub Zych
9002ecb844 docs(14.1): capture phase context 2026-10-04 14:52:32 +02:00
Jakub Zych
c27f24d9e5 docs(state): record phase 15 context session 2026-10-04 14:30:26 +02:00
Jakub Zych
67e4406250 docs(15): capture phase context 2026-10-04 14:30:25 +02:00
Jakub Zych
0323aeb6fb docs(14): record code review disposition 2026-10-04 08:13:29 +02:00
Jakub Zych
f5cf6f2580 docs(14): align fix report titles with the review 2026-10-04 08:13:28 +02:00
Jakub Zych
d5a8ef7834 docs(14): record code review disposition 2026-10-04 08:13:17 +02:00
Jakub Zych
5d3299b26f docs(14): add code review fix report 2026-10-04 08:13:12 +02:00
Jakub Zych
b7d10a4448 test(14): verification report and human verification items as UAT 2026-10-04 03:13:37 +02:00
Jakub Zych
aa8ff53c0c docs(14): record code review disposition 2026-10-04 03:05:31 +02:00
Jakub Zych
549ffed415 docs(14): add code review report 2026-10-04 03:05:10 +02:00
Jakub Zych
fc4f70013b docs(14-06): update state and roadmap after the plan 2026-10-04 02:50:21 +02:00
Jakub Zych
e67dbaf895 docs(14-06): complete unit tests and Phase 14 gate plan 2026-10-04 02:49:59 +02:00
Jakub Zych
17b2ef1961 docs(14-06): Phase 14 validation signed off, requirements complete, API coverage confirmed, folded todos closed
- 14-VALIDATION.md: per-task map 14-01-T1 to 14-06-T4, all green, the
  measured coverage, validated, Nyquist-compliant, Wave 0 complete, the
  final --all and --removal results
- REQUIREMENTS.md: INTG-02 and API-08 Complete (JOBS-02, JOBS-03, SRCH-02,
  INTG-01, CLI-05 already were)
- COVERAGE.md: every INTEGRATE row's test confirmed by --named
- fetchguard-guarded-http-client and redacting-slog-handler moved to done
2026-10-04 02:47:53 +02:00
Jakub Zych
a1fccd39ad test(14-06): check-phase14.sh --evidence refuses an incomplete phase record
- every T-14 threat has one review row copying its plan's severity and
  disposition; a mitigated one names a test --named runs and a removal row
- the validation map is validated, Nyquist-compliant and Wave 0 complete,
  with no open row and only tests --named runs
- each COVERAGE.md INTEGRATE row names a run test, each OPT-OUT a reason
- REQUIREMENTS.md keeps no SDK wording for INTG-02 and no sitemap output
  for API-08; the ROADMAP Phase 14 repos and criteria name the album
  Discogs and recognize routes and both shared plugin repos
- --all runs it after the coverage stage
2026-10-04 02:11:39 +02:00
Jakub Zych
81543524be docs(14-06): Phase 14 security review maps every T-14 threat to its protection, test and removal check 2026-10-04 02:11:15 +02:00
Jakub Zych
4c042f7cd5 test(14-06): check-phase14.sh runs the named tests, the coverage floors and the removal harness
- --named runs every test the validation map and the security review name,
  by package, the fonoteka, discogs, golem and feedback suites with -race
- --coverage enforces the 80% floor on the framework packages, classes/
  discogs, console and every package of both shared plugins, and on each of
  the 132 Phase 14 functions of the fonoteka root, classes and
  controllers/api (two exemptions with their reasons)
- --removal applies 43 anchor-exact mutations, one or more per mitigated
  threat, requires the named test to fail on an assertion and restores
  each file byte for byte; the self-test plants each refusal
2026-10-04 02:11:15 +02:00
Jakub Zych
fc90ae2382 test(14-06): tide reports every sidecar refusal and multipart mismatch
- LoadUpstream names the file for a missing, unknown-field, wrong-version,
  method-less, relative-URL or out-of-range-status sidecar
- WriteUpstream writes nothing for an invalid sidecar or an uncreatable
  directory
- compareParts reports count, name, filename, content type, sha256 and
  value mismatches and a non-multipart body
2026-10-04 01:44:19 +02:00
Jakub Zych
88f7683b99 test(14-06): check-phase14.sh gates the phase over both repositories, the corpus and the named flows
- --self-test proves each detector fails on planted failing, skipped,
  zero-test, racy and non-JSON runs, a fourth pending route, a vendor SDK
  in the module graph and planted corpus secrets
- --go runs vet and tests in summercms.go and, with -race, in fonoteka.go
  including sm-golem-plugin and sm-feedback-plugin
- --parity requires 175 recorded, 172 ported and passing, 3 pending, every
  TestFonotekaNuxtFlows subtest, the sidecar replay, check_corpus secrets
  and the docs checks
2026-10-04 00:53:53 +02:00
Jakub Zych
c12641605c docs(14-05): update state and roadmap after the plan 2026-10-04 00:28:16 +02:00
Jakub Zych
5024e3ff42 docs(14-05): complete sm-feedback-plugin plan 2026-10-04 00:28:16 +02:00
Jakub Zych
b5d20b3bfd fix(14-05): surf answers OPTIONS on CORS paths with Laravel's HandleCors headers
- every OPTIONS on a CORS path: 204 with Cache-Control no-cache, private
- a preflight echoes the requested method (upper-cased) and headers when * allows any, with Vary and PHP's default Content-Type, as recorded from PHP
- README and the routing docs describe the answer
2026-10-04 00:00:01 +02:00
Jakub Zych
7eb0174612 docs(14-04): update state and roadmap after the plan 2026-10-03 23:39:37 +02:00
Jakub Zych
b3e4626d2d docs(14-04): complete sm-golem-plugin and AI recognition plan 2026-10-03 23:39:07 +02:00
Jakub Zych
7c2c43359f feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification
The golem SSRF guard checks a URL's resolved addresses before it connects,
as PHP's SSRFGuard does, with the same table the dial guard uses.
2026-10-03 22:49:19 +02:00
Jakub Zych
f519261da6 docs(14-03): complete Discogs routes plan 2026-10-03 22:25:35 +02:00
Jakub Zych
5101ecb49c feat(14-03): tide keeps binary upstream bodies and compares every *_url upload by shape
- A response body that is not valid UTF-8 (a cover image) is written as a
  YAML !!binary scalar, never masked and replayed byte for byte
- The upload URL normalizer covers every key ending in _url (cover_url),
  not only url and thumb_url
- README and parity-testing docs updated
2026-10-03 21:34:52 +02:00
Jakub Zych
2ee97c62f6 docs(14-02): update state, roadmap and requirements after the plan 2026-10-03 21:26:27 +02:00
Jakub Zych
f22c9144e6 docs(14-02): complete Discogs core, CSV and digest workers, prune and reindex plan 2026-10-03 21:26:02 +02:00
Jakub Zych
cdd8d710fa feat(14-02): conga.Describe reports a registered job's kind, queue, attempts and timeout
- lets a plugin test assert what its Jobs() registers, such as the CSV
  match job's 240 s timeout, without reaching into conga internals
- README API table, jobs docs page and an example
2026-10-03 20:56:49 +02:00
Jakub Zych
0a7635b12a fix(14-02): parity:upstream writes its sidecar on interrupt or SIGTERM
- the command context had no signal handling, so stopping the proxy
  killed it before Flush and no sidecar was ever written
- a background proxy (SIGINT ignored by the shell) now stops on SIGTERM
2026-10-03 20:06:42 +02:00
Jakub Zych
43b869d613 docs(14-01): complete framework helpers plan 2026-10-03 20:03:29 +02:00