Commit Graph

23 Commits

Author SHA1 Message Date
Jakub Zych
ef448da1cc test(10-05): cover every Phase 10 Go change with branch-level tests
- bouncer TestPhase10CookieGuard: cookie read without Bearer, Bearer wins,
  empty cookie, frontend audience and blacklisted jti rejected
- boardwalk TestPhase10BoardwalkServing: HEAD, query strings, encoded
  traversal, index by name, nested prefix, MIME fallback, constructor errors
- cabana TestPhase10Coverage: mounted unsafe routes vs the CSRF walk, option
  and filter edges, read-only labels, relation message defaults, bundle
  fallback locale, cookie refresh of an expired token in the refresh window
- phrasebook override precedence, new locale, Bundle merge order, Forms shapes
- surf prefix collision for deeper paths and the default /backend prefix
- swagger2openapi TestUnionRewrite and converter branch tests
- framework tests no longer name the application (acme fixtures instead)
2026-09-27 18:05:28 +02:00
Jakub Zych
dafdb18234 feat(10-01): harden the admin cookie session and prefix boot guards
- refresh and logout read the Bearer header first, then the summer_admin
  cookie; a cookie refresh rotates the cookie without a token in the body and
  logout always expires the cookie
- backend.cookie_secure (default true) may drop Secure outside production only
- activation rejects controller vendor segments api, assets, login, settings
- BuildRouter rejects non-cabana routes at or under the admin prefix
- SPA single-flights refresh on 401, replays once, and refreshes proactively
  at 80 percent of expires_in; dist rebuilt
- scripts/check-admin-dist.sh rebuilds the SPA and fails on dist drift
- tests: TestPhase10CookieAuth, TestPhase10CSRF, TestPhase10Prefix,
  TestPhase10AdminPrefixCollision, boardwalk serving and header tests
2026-09-27 15:34:19 +02:00
Jakub Zych
dfa00f7e3a feat(09-01): implement separate-admin genre list tracer
- Audience-aware mint, verify, refresh, and backend guard keep frontend tokens compatible
- Cabana mounts raw admin login, list schema, and record list behind admin.jwt.secret
- Framework migration seeds Winter backend users and developer/publisher roles
2026-09-24 17:17:19 +02:00
Jakub Zych
44900f0d16 feat(07-08): publish the uploads bucket on serve
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:43:47 +02:00
Jakub Zych
8fcaff77cf feat(07-01): add bcrypt, locale override, and validation rules
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:39:25 +02:00
Jakub Zych
bccd7f8f35 test(07-01): add failing tests for passwords, locale, and validation
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:36:08 +02:00
Jakub Zych
e50e2dd632 test(06-14): fetchguard IANA boundary and zoned dial tests, surf edge coverage 2026-09-21 19:48:06 +02:00
Jakub Zych
f1218f2c84 test(06-14): regression coverage for surf and bouncer gap closure 2026-09-21 19:47:16 +02:00
Jakub Zych
1d2e00cf59 fix(06-14): actually reuse built middleware factories per name:param
The built cache added in 06-12 was declared but never consulted, so every
route re-invoked the factory on BuildRouter and again on compile.
2026-09-21 19:47:16 +02:00
Jakub Zych
4ad2ad29f2 fix(06-12): fail closed on invalid limiter definitions 2026-09-21 19:42:41 +02:00
Jakub Zych
a50e09ba34 fix(06-12): bound named middleware by body cap, cache factories, fail boot on bad body config and mux conflicts 2026-09-21 19:42:20 +02:00
Jakub Zych
93d63c351b fix(06-09): buffer route responses before recovery
- Discard partial route output when house or raw handlers panic
- Commit private headers status and body only after successful return
2026-09-20 21:05:44 +02:00
Jakub Zych
f6ba67a693 test(06-09): add failing panic response regressions
- Exercise house and raw handlers that write secrets before panicking
- Cover successful explicit and implicit response commits
2026-09-20 21:04:02 +02:00
Jakub Zych
6852a8f8c3 fix(06-07): make limiter admission atomic
- Replace split store checks with one mutex-guarded Attempt operation
- Use domainless trusted-client keys for anonymous inline throttles
- Preserve fixed-window headers, expiry, stacking, and principal isolation
2026-09-20 17:02:53 +02:00
Jakub Zych
5bcd7ba011 test(06-07): add failing atomic limiter regressions
- Coordinate concurrent store and middleware attempts behind start barriers
- Prove Host rotation and inline policy changes share anonymous budgets
2026-09-20 17:00:28 +02:00
Jakub Zych
98dd09847a test(06-05): close framework coverage gaps in bouncer, surf, wire, fetchguard
- Registry neither-interface, nil-registry, and authenticate default
- MemoryStore sweep actually drops expired entries
- RegisterHouseMiddlewareFactory duplicate-name failure
- pathScopedCORS unmatched path plus empty-raw-group introspection
- Time UnmarshalJSON +00:00/Z and PublicOnlyMode host/IP cases
2026-09-19 21:08:04 +02:00
Jakub Zych
30539b954f feat(06-03): add path-scoped CORS and per-route body limits
- CORS matches Laravel path globs (api/* includes nested segments); unlisted paths get no headers
- Non-raw routes wrap http.MaxBytesReader from http.body_limits.default_bytes; body.limit:N overrides innermost
- Raw routes stay uncapped at this layer
2026-09-19 20:10:02 +02:00
Jakub Zych
fa7e6d1870 feat(06-03): add raw groups, house middleware, and route:list
- GroupRaw plus sticky raw inheritance and registration-time house-envelope refusal via pact.HasHouseMiddleware
- Recover on raw routes writes a bare 500; non-raw keeps the house JSON body
- Router.Routes() and surf.RouteListCommand; generated main registers route:list
2026-09-19 19:55:32 +02:00
Jakub Zych
68c6ab85c5 feat(06-02): add fixed-window limiter, Store, and ClientIP
- MemoryStore mirrors Laravel tooManyAttempts-before-hit first-hit-wins
- FixedWindowLimiter + throttle factory; success and 429 rate-limit headers
- Trusted-proxy ClientIP; remove noOpLimit; keep Limiter interface seam
2026-09-19 19:35:53 +02:00
Jakub Zych
d376b1be2d feat(06-01): grow router verbs, factories, and guard registry
- Add Post/Put/Patch/Delete on pact.Router and surf Router/Group
- Resolve name:param middleware via RegisterMiddlewareFactory
- Add bouncer.Registry with Guard, CredentialGuard, UnauthorizedWriter
- Re-express jwt as NewJWTGuard without changing Middleware bodies
2026-09-19 18:59:12 +02:00
Jakub Zych
92255a46ed test(03-04): cover framework database, routing and JWT boundaries
- Shared pgx/GORM pool, ICU locale fail, and isolated plugin migrations
- Seven-stage middleware order, missing-guard boot failure, typed 404s
- Adversarial JWT matrix including alg:none, empty secret, and no leak

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 20:29:46 +02:00
Jakub Zych
8e3bf266d8 feat(03-03): add typed path params and per-plugin rollback
Compile regex and enum constraints at route registration so malformed and unknown IDs share a 404, and named rollback errors isolate one plugin's history.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 20:19:59 +02:00
Jakub Zych
4ee4c4a2fc feat(03-01): add ServeMux groups, JWT verifier, and serve command
Named middleware resolves at boot, HS256 tokens are pinned with required
exp/sub, and both binaries expose a signal-aware serve command.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 20:04:13 +02:00