- 13-SECURITY-REVIEW.md: every T-13 threat with its strictest severity and
disposition, protecting code, named tests and the 31 removal checks,
all failing as required; the CSV export logging fix and the Phase 9
route inventory update
- 13-VALIDATION.md: per-task map 13-01-T1 to 13-06-T3 all green, the gate
command, coverage per package, Wave 0 ticked, status validated
- REQUIREMENTS.md: API-03, API-04, API-06 and API-07 complete
- deferred-items.md: 13-06 findings (process-wide job dispatcher, scalar
mapping body, tmpfs quota)
- Phase 13 repos name sm-user-plugin and summercms.go
- wishlist match/apply-release, the credential /test routes and the CSV
Discogs pick move to Phase 14 (D-01, D-02); notifications drop prune,
a Phase 14 console command (D-06); CSV and digest job bodies are Phase 14
- API-03, API-04, API-06, INTG-01 and INTG-02 follow; statuses untouched
Browser checks on sm-bm-app passed: datetime popover time, discard confirm, and list date formatting. Phase 12.2 UAT is complete.
Co-authored-by: Cursor <cursoragent@cursor.com>
Close the seven code-review findings in disposition and leave the phase pending on browser checks plus the v0.1.1 tag.
Co-authored-by: Cursor <cursoragent@cursor.com>
- 12.2-SECURITY-REVIEW.md maps T-12.2-01 to T-12.2-36 and the supply
chain rows to the controls as built and their passing tests, with the
parent-predicate removal check and the residual risks
- 12.2-VALIDATION.md: per-task map with real task ids, all green,
nyquist_compliant and wave_0_complete set
- deferred-items.md: out-of-scope findings for follow-up
Six sequential plans: framework gaps, notifications/credentials/onboarding, wishlist, CSV, public views, unit tests and gate. Research open questions marked resolved per the plan-count checkpoint.
- sessionKey.ts: one 32-byte base64url key per form mount, sent only in headers
- api/files.ts: FileRoutes over the record and child file routes, XHR upload with progress, 401 refresh and retry
- FileuploadField and FileCaptionModal per UI-SPEC section 3: dropzone, image grid, rows, per-item states, client pre-checks, reorder, protected previews
- FormView provides FORM_SESSION, counts pending changes as dirty and sends X-Session-Key on create and update
- fileupload lang keys in en and pl, admin-spa docs note, deferred smoke test, rebuilt dist
- 12-SECURITY-REVIEW.md maps T-12-01..T-12-34 and T-12-SC to a named test
and 25 removal checks, all seen failing with the protection removed
- 12-VALIDATION.md validated with the final per-task map, nyquist_compliant
- REQUIREMENTS.md: API-01 and API-02 complete
Five sequential plans: foundations (deferred_bindings, attach.Store,
lagoon.Date/TimeOfDay, purge), cabana datepicker and fileupload, relation
child CRUD with deferral, admin SPA, and unit and security tests.
Adds D-22..D-24 from the plan-count checkpoint and the pattern map.