- 13-SECURITY-REVIEW.md: every T-13 threat with its strictest severity and
disposition, protecting code, named tests and the 31 removal checks,
all failing as required; the CSV export logging fix and the Phase 9
route inventory update
- 13-VALIDATION.md: per-task map 13-01-T1 to 13-06-T3 all green, the gate
command, coverage per package, Wave 0 ticked, status validated
- REQUIREMENTS.md: API-03, API-04, API-06 and API-07 complete
- deferred-items.md: 13-06 findings (process-wide job dispatcher, scalar
mapping body, tmpfs quota)
Six sequential plans: framework gaps, notifications/credentials/onboarding, wishlist, CSV, public views, unit tests and gate. Research open questions marked resolved per the plan-count checkpoint.
- sessionKey.ts: one 32-byte base64url key per form mount, sent only in headers
- api/files.ts: FileRoutes over the record and child file routes, XHR upload with progress, 401 refresh and retry
- FileuploadField and FileCaptionModal per UI-SPEC section 3: dropzone, image grid, rows, per-item states, client pre-checks, reorder, protected previews
- FormView provides FORM_SESSION, counts pending changes as dirty and sends X-Session-Key on create and update
- fileupload lang keys in en and pl, admin-spa docs note, deferred smoke test, rebuilt dist