Commit Graph

910 Commits

Author SHA1 Message Date
Jakub Zych
c6f68e4639 feat(admin): widget field payload and summer-result data channel (quick-261006-eyj)
- WidgetField posts the summer-action event's detail.payload as payload only
  when the detail carries one; a payload-less post body is unchanged
- after a successful action the response data is set on the element as the
  data attribute (removed when the answer has none) and announced with a
  summer-result event carrying {data, fill, message}; failures dispatch nothing
- WIDGET_RESULT_EVENT exported from formContext; unit tests for both directions
- modules/boardwalk/dist rebuilt
2026-10-06 11:16:46 +02:00
Jakub Zych
6af88f9df6 feat(cabana): widget action payload and data channel (quick-261006-eyj)
- pact.AdminActionInput.Payload (json.RawMessage) carries the widget's own
  JSON value untouched; pact.AdminActionResult.Data is passed through as data
- cabana decodes payload with a 64 KiB cap (422 on body), refuses it on the
  toolbar and record routes, and embeds Data once encoded with a 256 KiB cap
  (opaque 500 when larger or unencodable); fill stays filtered
- root .swaggo overrides json.RawMessage so swag keeps record_id and values;
  admin.json and schema.d.ts regenerated (payload?: unknown, data?: unknown)
- TestWidgetPayloadAndData covers pass-through, cap, refusal and data 500
- cabana and pact READMEs, partials-and-widgets and admin-spa docs updated
2026-10-06 11:13:16 +02:00
Jakub Zych
964145628a docs(14.2.1): add research and validation strategy 2026-10-06 10:57:17 +02:00
Jakub Zych
d2609e9499 docs(state): record phase 14.2.1 context session 2026-10-06 10:41:45 +02:00
Jakub Zych
6d2e5e6f4b docs(14.2.1): capture phase context 2026-10-06 10:41:43 +02:00
Jakub Zych
2449e36ef0 docs(state): record phase 15 context session 2026-10-06 01:29:02 +02:00
Jakub Zych
b1e101cdc0 docs(15): capture phase context 2026-10-06 01:28:58 +02:00
Jakub Zych
e18885fb14 docs(phase-14.1): sync machine state after complete
phase.complete marked 14.1 complete in state.json; keep it with the tracking files.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:49:53 +02:00
Jakub Zych
b439c8583a docs(phase-14.1): close 1 resolved todo
oauth-identities and /me now have a completed phase; the orphan-pending-routes todo is done.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:49:40 +02:00
Jakub Zych
9607796d8e docs(phase-14.1): complete phase execution
Corpus is 175/175/0. Tracking advances off 14.1; live Nuxt/MCP checks stay Phase 15.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:49:40 +02:00
Jakub Zych
eb84825724 docs(14.1): record code review and verification
WR-01 is fixed; WR-02 and the three info findings stay open. The phase
goal is 8/8 with corpus 175/175/0.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:48:08 +02:00
Jakub Zych
c7c796cb45 docs(14.1-02): complete OAuth identities unit-test plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:38:34 +02:00
Jakub Zych
0d1b5caf3d docs(14.1-01): complete OAuth identities and /me routes plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:25:29 +02:00
Jakub Zych
c3bbbcbb9f docs(14.1): reset STATE progress bar after planning
The planned-phase write left the previous phase's 100% bar; execution of 14.1 has not started.

Co-authored-by: Cursor <cursoragent@cursor.com>
v0.1.4
2026-10-05 19:49:12 +02:00
Jakub Zych
7fc13f7155 docs(14.1): mark phase planned 2026-10-05 19:49:01 +02:00
Jakub Zych
5c65a94db0 docs(14.1): revise plans from checker
Slash-form -run is the only way go test executes the nested phase08 jwt-surface subtest, so verify can emit its PASS line.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 19:45:21 +02:00
Jakub Zych
57fdaa0d85 docs(14.1): revise plans from checker 2026-10-05 19:40:40 +02:00
Jakub Zych
3bd461ec68 docs(14.1): create phase plan 2026-10-05 19:36:32 +02:00
Jakub Zych
a160bda55a docs(quick-261005-qvk): map Winter icon-* names onto lucide for plugin navigation 2026-10-05 19:31:22 +02:00
Jakub Zych
1f228f85bd docs(14.1): add pattern map 2026-10-05 19:29:31 +02:00
Jakub Zych
a00dafaf65 fix(admin): map Winter icon-* names onto lucide for plugin navigation
Ported plugins send Winter icon-* class names on nav and settings; the SPA
never loads Font Awesome, so unknown names rendered as empty squares. Map
BM Studies, Quizzes, icon-pencil, and a closed Winter backend alias table
onto named @lucide/vue 1.17.0 exports, keep Square for unknown names, and
rebuild the embedded boardwalk dist.
2026-10-05 19:28:35 +02:00
Jakub Zych
f453b80dc7 docs(14.1): add validation strategy 2026-10-05 19:26:11 +02:00
Jakub Zych
0ea0c787a5 docs(14.1): research phase domain 2026-10-05 19:24:49 +02:00
Jakub Zych
104a1c9f0b docs(12.1): add verification covered_digest so the report is not stale 2026-10-05 16:54:01 +02:00
Jakub Zych
30336e44c6 docs(12.1): verification, UAT, and code-review close-out 2026-10-05 16:53:16 +02:00
Jakub Zych
4e4ce40dbb docs(12.1-05): close plan 05 with SUMMARY after the executor died before writing it 2026-10-05 16:51:31 +02:00
Jakub Zych
93f0171e9c docs(12.1-05): security review and validation sign-off for Phase 12.1
- 12.1-SECURITY-REVIEW.md: every threat T-12.1-01 to T-12.1-40 and T-12.1-SC with its mitigation, test and observed result; T-12-18 revisited; the D-30 guard and its boundary; the eleven handed-over items; five findings that need a decision
- 12.1-VALIDATION.md: per-task map with real task ids and measured run times, signed off
- deferred-items.md: older framework files that name an application
2026-10-05 16:13:50 +02:00
Jakub Zych
83feeef9fa docs(12.1-05): state the limits of relation locks and locked permission codes
- a relation lock covers the form field only; a relation manager on the same relation does not ask the provider
- a locked permission code must be stored with a value its mode can send
2026-10-05 16:01:10 +02:00
Jakub Zych
3190b1ce59 test(12.1-05): complete the Phase 12.1 gate with the removal, coverage, app and evidence stages
- --go, --spa, --openapi, --dist, --docs and --hygiene on the pattern of the Phase 12.2 gate
- --app runs vet and the tests of every module of the application workspace, with the application's name masked in output
- --coverage refuses a package of pact, cabana or the user plugin below 80 percent
- --removal: 27 anchor-exact mutations, one per high or critical protection and one per fix; a dirty file is refused and every file is restored and compared with cmp
- --evidence ties every threat of the five plans to a review row, a test and a removal row
- --self-test plants an input for every detector
2026-10-05 16:01:10 +02:00
Jakub Zych
aced6c7df3 test(12.1-05): unit tests for the list, form, preview and routing behaviours of Phase 12.1 in the SPA
- list: the bulk menu in the toolbar and on the list view with its three failure rows, row states and invisible columns in the table
- form: the forbidden banner, password and preset on the form view, locked relation options, the save body of password and permission fields
- preview view: context fields, hidden tabs, the status hint, the footer with zero, one and several actions, load failures
- routing: the preview route and mapWinterUrl
- backstops: focus returns to the bulk menu trigger; preview URL mapping and the route replacement; locked relation options
- the slug preset runs on the table the user plugin's slug test uses
2026-10-05 15:36:00 +02:00
Jakub Zych
84efdc09e0 test(12.1-05): unit tests for the Phase 12.1 SPA components
- BulkActionsMenu, RowStateBadges, RecordActions, PreviewField, FormErrorBanner, PasswordField and PermissionEditorField, each mounted on its own
- backstop: a row state outside the fixed set renders no badge and no class
- backstop: the permission editor's emission rules per mode, the locked row and codes outside the options
2026-10-05 15:29:44 +02:00
Jakub Zych
2e94cbf9f8 test(12.1-05): unit tests for bulk and record actions, row state, forbidden, preview and the form seams
- bulk action: empty, duplicate, unordered, absent, partial, out-of-scope, rollback, concurrent runs, permissions, CSRF, body cap
- record action: scope, Applies, strict body, offered order, rollback, Applies error
- ForbiddenError from every Form hook, the bulk delete and the relation link and child hooks
- permission editor modes, locked codes and provider errors; relation locks on create, update and belongsTo
- TestPhase121BootErrors: every boot error of plans 01 and 02 with plugin, controller and file
- pact: the action, row state and filter contracts on a sample controller
2026-10-05 14:48:34 +02:00
Jakub Zych
c076b4c059 test(12.1-05): threat test for the Phase 12.1 framework contracts and the first gate stages
- TestPhase121Threats: one subtest per mitigated threat T-12.1-01 to T-12.1-15
- roster fixture: sentinel names and knobs for failing hooks and providers
- scripts/check-phase12.1.sh: fail-closed go test detector, --self-test and --security
2026-10-05 14:30:31 +02:00
Jakub Zych
52f864ebfc docs(12.1-04): update state and roadmap after the groups and organisations plan 2026-10-05 14:10:11 +02:00
Jakub Zych
3f4a01ddf8 docs(12.1-04): complete groups field, User Groups and Organisations plan 2026-10-05 14:09:34 +02:00
Jakub Zych
fcc86ac45e docs(12.1-03): update state and roadmap after the Users screen plan 2026-10-05 13:34:30 +02:00
Jakub Zych
76df9c5bd6 docs(12.1-03): complete plugin foundation and Users screen plan 2026-10-05 13:33:50 +02:00
Jakub Zych
b8cdb7cc92 docs(12.1-02): update state and roadmap after the v0.1.3 tag
- plan 3 of 5 next; decisions of plan 02 recorded
- pending: push master and v0.1.3; two application inventory tests
2026-10-05 12:44:03 +02:00
Jakub Zych
bd4960401d docs(12.1-02): complete framework preview and form seams plan
- summary with the v0.1.3 tag, gate times and contract names
- deferred item for two application inventory tests
- WINDOWS entry 9 fixed: RecordActions.vue is mounted
2026-10-05 12:43:23 +02:00
Jakub Zych
df5cace852 feat(12.1-02): writable foreign keys, locked relation options, invisible columns
- FieldRelationContract.WritableForeignKey makes a belongsTo field over a
  protected foreign key writable; the protected key list is unchanged
- cabana.RelationLockProvider names related ids an administrator may not add
  or remove: options and labels carry locked, and a create or update that
  changes the locked subset is 403 before any row is written
- columns.yaml invisible keeps a column searchable and out of the rows
- a controller implementing pact.FilterOptions serves a scope filter's
  choices before the model
- SPA: locked chips and options in RelationField, DataTable skips invisible
  columns
- README, docs, OpenAPI document, TS types and dist updated
v0.1.3
2026-10-05 10:58:38 +02:00
Jakub Zych
f50d9b8f10 feat(12.1-02): permissioneditor field in radio or checkbox mode
- type: permissioneditor with mode radio (1, -1) or checkbox (1); the
  controller serves the options per request through
  cabana.PermissionEditorProvider and reads and stores the values
- a save answers 422 for a non-object, an unknown code or a value outside the
  mode's set and 403 for a changed locked code; stored codes that are not
  offered are kept
- record responses carry the stored permissions as an object
- SPA: PermissionEditorField with sections by tab, locked rows and a read-only
  mode for the preview
- README, docs, OpenAPI document, TS types and dist updated
2026-10-05 10:44:50 +02:00
Jakub Zych
a1c6bb1ce6 feat(12.1-02): password and form-only fields, rules per operation and preset
- pact.FormVirtualFields lists form fields that are not model columns: never
  bound, filled or projected; their values reach the Form hooks through
  cabana.VirtualFieldsFromContext when the field's context allows the operation
- type: password is a masked field that must be listed as virtual
- pact.FormRules supplies the rule set per operation and replaces the model's
  Rules() for admin saves; a rule on a virtual field sees the submitted value
- preset on a text field follows another text field on the create form
- SPA: PasswordField, preset handling in FormView, empty password left out of
  an update
- README, docs, OpenAPI document, TS types and dist updated
2026-10-05 10:35:08 +02:00
Jakub Zych
a65c670574 feat(12.1-02): read-only preview screen with a status hint and record actions
- config_form.yaml preview block (optional headerPartial), reported in the form schema as preview
- fields with context: preview show only on the preview screen and are never written
- form messages preview and edit; recordActions without a preview block stops boot
- SPA route {id}/preview, PreviewView and PreviewField, record actions in the footer
- mapWinterUrl maps preview/:id; the update form returns to the preview
- summer-callout partial style classes for status hints
- README, docs, OpenAPI document, TS types and the embedded build updated
2026-10-05 00:10:48 +02:00
Jakub Zych
1c99de5013 docs(12.1-01): complete framework actions plan 2026-10-04 23:55:37 +02:00
Jakub Zych
71073bc8a2 feat(12.1-01): cabana.ForbiddenError answers a refused write with 403
- hooks and bulk, record, toolbar and widget actions may return it
- 403 forbidden with the localized message and field details; the write's
  transaction is rolled back; other errors stay the opaque 500
- form shows a refused save as a persistent banner and keeps the values;
  a refused delete is a toast
- smoke tests, OpenAPI notes, dist, README, docs
2026-10-04 23:53:34 +02:00
Jakub Zych
61d5fc72ad feat(12.1-01): list row states from one controller call per page
- pact.ListRowStates with the fixed RowState set deleted, negative, disabled
- list response meta.row_states keyed by row id; unknown values dropped
- list messages rowStateDeleted, rowStateNegative, rowStateDisabled
- update writes through the scope the load used, so a soft-deleted record
  a controller includes stays soft-deleted
- DataTable row state badges and text styles
- roster fixture, smoke tests, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:45:44 +02:00
Jakub Zych
e0ccced76a feat(12.1-01): declared record actions with an applicability rule
- pact.HasAdminRecordActions with AdminRecordAction (Applies, Run)
- config_form.yaml recordActions, compiled fail-loud
- show response meta.actions lists the permitted actions that apply
- POST .../{controller}/{id}/actions/{action}: record loaded and locked
  through the form scope; 404 out of scope, 409 when it does not apply
- RecordActions.vue with confirm and request flow (mounted by plan 02)
- roster fixture, smoke tests, OpenAPI, TS types, READMEs, docs
2026-10-04 23:37:30 +02:00
Jakub Zych
a879d6388c feat(12.1-01): declared bulk actions on admin lists
- pact.HasAdminBulkActions with AdminBulkAction, its input and result
- config_list.yaml bulkActions, compiled fail-loud, needs showCheckboxes
- POST .../{controller}/bulk/{action}: ids resolved and locked through the
  list scope in one transaction; partial selection is 409
- list schema offers declared actions per principal, with confirm text
- admin SPA bulk actions menu with confirm, busy state and failure toasts
- acme.roster fixture, tracer test, OpenAPI, TS types, dist, READMEs, docs
2026-10-04 23:28:30 +02:00
Jakub Zych
ca9e9c0557 chore(config): allow executor commits on the default branch 2026-10-04 23:14:15 +02:00
Jakub Zych
af588aee2d docs: record quick task 261004-rou 2026-10-04 22:53:28 +02:00