The recorded PHP 401 for a missing bearer (realtime token no-bearer
case) carries Laravel's default Cache-Control header; the Go guard's
401 omitted it, so the replay failed on header.Cache-Control.
- CentrifugoRecorder records publish/broadcast requests (method, path,
whether the API key matched, JSON body) and binds loopback only
- BroadcastGolden load/write, NormalizePublications (timestamps, actor,
captured ids only) and DiffPublications (structural, key order ignored)
- RecordBroadcasts runs a flow or one step against a loopback backend
- summer parity:broadcasts wraps it; README documents format and rules
- pin the sync callbacks before gorm:commit_or_rollback_transaction: an
After-only anchor is appended past the commit and lagoon's after-commit
flush, so single-statement writes never synced
- give the gate and the document builder a clean session: Session with NewDB
and a Context clones the write's statement, and a later WithContext queried
through the written model's table
- typesense.StatusError carries method, path and status, never the body
- README: sync semantics, the three gates, delete on soft delete, and the
SQL re-gate required of SearchIDs callers
- Searchable, Engine, Gate and an init-time engine registry with the null engine
- GORM callbacks installed through lagoon.OnDatabase register an after-commit
sync that reloads the row and upserts or deletes its document
- Gates run before any request: engine configured, database published, app Gate
- hand-rolled net/http Typesense engine following the Scout wire contract
- module README and root modules row
- Broadcastable contract and Bind[T] bindings; event {action}.{alias},
default {model, actor, timestamp, ttl} payload, delete snapshot taken
before the row goes
- GORM callbacks installed via lagoon.OnDatabase enqueue a summer.broadcast
job on the write's *sql.Tx inside a savepoint; failures are logged and
never abort the write; zero-key batch writes are skipped
- WithoutBroadcasting[T] (ctx-scoped, per type) and Service.Emit for one
summary event; the one-attempt job namespaces channels and publishes or
broadcasts; the payload travels as a JSON string so JSONB keeps its order
- no jobs for the null driver or Centrifugo without an API key
- lighthouse: Service/From with realtime.driver selection, RegisterDriver
registry, null/log/memory drivers, Route/Surface/Mount, users and actors
- centrifugo: HTTP API client (apikey header, 2xx success, no request
without a key), five-generator HS256 TokenIssuer, TokenHandler with the
WinterCMS 401/503 bodies
- module README and root modules table row
- schedule:run runs a worker on the scheduled queue with every plugin's periodic jobs
- schedule:run --once runs entries due in the current app.timezone minute without River,
warns and skips unregistered commands, and returns the first command error
- summer schedule:run delegate forwards --once
- tests for --once minute matching, forged-entry skipping (T-11-09) and ByPeriod dedupe
- pact.HasSchedule with ScheduledCommand and Daily/DailyAt/Every cadences (no River import)
- bonfire.Call, Catalog and ErrUnknownCommand for in-process command runs
- conga Daily/Every wall-clock schedules in app.timezone, periodic jobs on every worker,
scheduled queue (MaxAttempts 1, unique by args within the cadence period)
- scheduled worker runs only entries matching the compiled table; unregistered
commands are skipped with a Warn log
- generated app main publishes bonfire.NewCatalog(commands); hello main regenerated
- OnDatabase runs a callback once the database is published (now, or when
lagoon.Publish runs), so GORM callbacks registered at Boot also install
under serve, where Boot runs before the database is opened
- Transaction runs AfterCommit callbacks in order after a successful commit;
nested calls are savepoints whose callbacks drop with them
- the lagoon:after_commit GORM callback flushes single-statement AfterCommit
work after GORM's own commit; outside a transaction it runs immediately
- Manager gains the apparatus JobManager surface: StartJob, UpdateJobState,
UpdateMetadata, FailJob, CancelJob (is_canceled + STOPPED + River JobCancel),
StopJob (STOPPED only), CheckIfCanceled and GetMetadata, all raw column
writes so updated_at is untouched
- serve starts the in-process worker unless queue.work_in_serve is false and
stops it on shutdown; an app without jobs gets an idle worker
- queue:work runs a foreground worker with repeatable --queue filters;
queue:clear deletes available, scheduled and retryable jobs of one queue
- the generated main appends conga.RuntimeCommands; summer delegates
queue:work and queue:clear; make:job scaffolds a conga.Job
The scaffolder's ensureToolchain keeps 'toolchain go1.27.0' in every
module; the River tidy in the previous commit removed it from the example
app and its plugins.
- Pin River v0.47.0 (riverdatabasesql, rivertype) and tidy the example modules
- lagoon.Migrate runs the summercms.conga set: River schema v7 and summer_jobs
with the apparatus columns plus an internal river_job_id link
- conga.Manager.Dispatch writes the summer_jobs row (status IN_PROGRESS) and the
River job on the caller's *sql.Tx; a rollback leaves neither
- conga.Job wraps typed job functions so plugins never import River
- conga.StartWorker runs one client on riverdatabasesql.NewWithPgxListener with
a single-connection LISTEN pool; the final failed attempt sets ERROR
- TestListenPickupLatency: 30s poll, pickup under 1s; poll-only control 2s miss
widgetAction derives the form from the request (create without record_id,
update with one) and answers 404 when the field's context hides the
widget on that form, reusing contextAllows as the save path does. An
update-only action can no longer run with a nil record through a direct
POST.
formSchema now filters type: widget fields by the action's permissions,
the same D-12 filtering listSchema applies to toolbarActions, so an admin
without the action permission no longer gets a button that always
answers 403, and the action name is not revealed. The filtered fields are
a new slice, so the cached schema is never modified.
isJSONScalar now encodes each value and keeps it only when the encoding
is a string, number, boolean or null, so a named scalar whose MarshalJSON
writes an array or object, NaN and the infinities are dropped. writeJSON
encodes into a buffer before the status line, so an encode failure is a
logged 500 with the generic envelope instead of a 200 with a truncated
body.
refusedViewModel compared only the top-level type with the controller's
model. It now walks the type through pointers, slices, arrays, maps,
struct fields and the results of exported methods, and the values held
in interface-typed members, refusing the controller's model, any other
GORM model (TableName, a gorm tag, gorm.Model, gorm.DeletedAt) and
html/template's trusted content types anywhere in that structure.
loadControllerAssets no longer activates stylesheets. activateStyles,
called only by the router, records the controller on screen, and new
links are created disabled unless they belong to it, so a list or form
schema that resolves after its view was left adds its links disabled
instead of switching plugin CSS to the wrong controller. Rebuilt the
embedded admin dist.
The router now drives stylesheet activation after every confirmed
navigation: the list, create and record routes enable their controller's
links, and settings, login, not-found and a controller whose schema has
not arrived yet enable none. Rebuilt the embedded admin dist.
lagoon.Fill now returns a *lagoon.FillTypeError naming the key when a
requested value cannot be stored in its column (a fraction, exponent or
overflow for an integer field, or a value of the wrong type). The admin
save path maps it to a validation_failed 422 on that field instead of a
500 CapabilityError; genuine capability failures keep the 500.
- 10.1-SECURITY-REVIEW.md: T-10.1-01 to T-10.1-22 and T-10.1-SC with
mitigation, test or gate stage, observed result and 23 removal checks
- 10.1-VALIDATION.md: every plan task mapped to its command, all green
under check-phase10.1.sh --all; nyquist_compliant and wave 0 complete
- Phase 10 deferred item for the parity failures marked resolved
scripts/check-phase10.1.sh: --self-test, --go, --security, --postgres,
--spa, --openapi, --dist, --hygiene, --evidence and --all.
- phase101_detect refuses failed, skipped, zero-test, non-JSON and
build-failed runs and required tests that did not pass
- hygiene_101 refuses HTML-string parsers in admin/src, network, cookie
or storage access in application plugin asset JS, and script, style or
inline handler markup in application partial templates; each rule is
proven by its own self-test plant
- --evidence requires a review row and, for every high threat, a named
test and a removal check row
TestMigrateSeedsCanonicalGenres and TestSchemaMatchesPHPSnapshot pass
since fonoteka.go 21c0f12, and the detector refuses an allow-listed
failure that passes, so check-phase10.sh --go failed. The gate now
allow-lists nothing.
- WidgetField: skeleton and aria-busy, the 5000 ms whenDefined timeout,
script failure, attributes only, fill-values and locale sync, one POST
while busy, fill-key-only patching, danger toasts, unmount
- PartialHost and partialNodes: exhaustive tag, attribute and URL
allowlist, depth and node caps, skeleton sizes, empty, failure,
busy refetch and ?id= only with a record
- PartialField, ListToolbar, ListView, registry, formState, FormField and
FormView: group labels, registered toolbar actions, header refetch
rules, form context provision and asset loading
The URL parser resolves %2e%2e like .., so /{base}/assets/%2e%2e/api/...
passed assetAllowed and would load from outside the asset prefix. A
segment is now a dot segment after decoding %2e, in any case.
- tests/app/pluginAssets.test.ts covers the URL check, loadScript,
loadStyles, activateStyles and loadControllerAssets
- modules/boardwalk/dist rebuilt
- lagoon.Fill converts a json.Number (from a UseNumber decoder, as cabana's
save path uses) into integer, unsigned and float fields; a fraction or an
overflow is an error
- before this, saving a type: number field into an *int column was a 500
- README documents the conversion