Commit Graph

826 Commits

Author SHA1 Message Date
Jakub Zych
f519261da6 docs(14-03): complete Discogs routes plan 2026-10-03 22:25:35 +02:00
Jakub Zych
5101ecb49c feat(14-03): tide keeps binary upstream bodies and compares every *_url upload by shape
- A response body that is not valid UTF-8 (a cover image) is written as a
  YAML !!binary scalar, never masked and replayed byte for byte
- The upload URL normalizer covers every key ending in _url (cover_url),
  not only url and thumb_url
- README and parity-testing docs updated
2026-10-03 21:34:52 +02:00
Jakub Zych
2ee97c62f6 docs(14-02): update state, roadmap and requirements after the plan 2026-10-03 21:26:27 +02:00
Jakub Zych
f22c9144e6 docs(14-02): complete Discogs core, CSV and digest workers, prune and reindex plan 2026-10-03 21:26:02 +02:00
Jakub Zych
cdd8d710fa feat(14-02): conga.Describe reports a registered job's kind, queue, attempts and timeout
- lets a plugin test assert what its Jobs() registers, such as the CSV
  match job's 240 s timeout, without reaching into conga internals
- README API table, jobs docs page and an example
2026-10-03 20:56:49 +02:00
Jakub Zych
0a7635b12a fix(14-02): parity:upstream writes its sidecar on interrupt or SIGTERM
- the command context had no signal handling, so stopping the proxy
  killed it before Flush and no sidecar was ever written
- a background proxy (SIGINT ignored by the shell) now stops on SIGTERM
2026-10-03 20:06:42 +02:00
Jakub Zych
43b869d613 docs(14-01): complete framework helpers plan 2026-10-03 20:03:29 +02:00
Jakub Zych
7700c6da28 docs(14-01): reword INTG-02, API-08 and the Phase 14 scope (D-06, D-07, D-13, D-14)
- INTG-02 names hand-rolled Anthropic and OpenAI-compatible adapters over the guarded client
- API-08 is feedback only; sitemap dropped for this application
- Phase 14 criteria list the album Discogs and recognize routes; Repos names the new core-plugin repos
- PROJECT moves golem and feedback to sm-*-plugin submodules
2026-10-03 20:02:04 +02:00
Jakub Zych
58e6324da8 feat(14-01): beachcomber DropIndex and EnsureIndex for reindex tooling
- optional IndexDropper reports whether a dropped index existed; DropIndex falls back to Flush
- optional IndexEnsurer creates an empty index from its schema; EnsureIndex is a no-op otherwise
- typesense implements both (404 is already absent; ensure reuses collection creation)
2026-10-03 20:01:36 +02:00
Jakub Zych
7241704e93 feat(14-01): sunscreen redacting slog handler installed by every generated main
- Wrap redacts sensitive keys at any depth and scrubs Bearer, sk- and x-api-key shapes
- InstallDefault is the first statement of the generated run; hello main regenerated
- surf test pins that recovered panics echo no credential
- sunscreen README, root modules row and the logging docs page
2026-10-03 20:01:36 +02:00
Jakub Zych
ee0004fb65 feat(14-01): record vendor calls with summer parity:upstream and replay them offline
- WriteUpstream masks vars, hashes long base64 JSON strings and refuses unmasked Authorization/X-Api-Key
- multipart requests recorded as ordered parts; the fake compares parts and hashed payloads
- loopback CONNECT recording proxy with a local ECDSA parity CA, script and forward modes
- parity:upstream command, README and parity docs
2026-10-03 19:55:42 +02:00
Jakub Zych
e6a67134d1 feat(14-01): fetchguard client covers PUT, multipart, bearer and a trusted mode
- TrustedMode (declared after PublicOnlyMode) lifts the scheme, host and dial checks for Client only
- PutJSON, PostMultipart with FormField/FormFile, Bearer
- tests for modes, redirects, multipart order, body cap and the scheme guard
- README, root modules row and outbound HTTP docs describe the client and its test seam
2026-10-03 19:42:37 +02:00
Jakub Zych
93b7142059 feat(14-01): guarded fetchguard client replayed through a tide upstream fake
- fetchguard.NewClient with Do, Send, Get and PostJSON over a capped, never-redirecting transport
- WithTransport: code-only context seam for offline replay; Result gains Header
- tide UpstreamSidecar, LoadUpstream, UpstreamPath and the asserting UpstreamFake
2026-10-03 19:39:58 +02:00
Jakub Zych
06d6fdc758 docs(roadmap): insert phase 14.1 for oauth identities and fonoteka me routes 2026-10-03 19:35:52 +02:00
Jakub Zych
ed4d4c380c docs(14): create phase plan 2026-10-03 18:56:43 +02:00
Jakub Zych
de5b01266b docs(14): add pattern map 2026-10-03 18:18:50 +02:00
Jakub Zych
1c7538d54c docs(14): record plan-time decisions from research checkpoint 2026-10-03 18:15:27 +02:00
Jakub Zych
5353aa28a5 docs(phase-14): add research and validation strategy 2026-10-03 17:49:00 +02:00
Jakub Zych
0795515914 docs(state): record phase 14 context session 2026-10-03 17:27:21 +02:00
Jakub Zych
2746bf5ac5 docs(14): capture phase context 2026-10-03 17:27:17 +02:00
Jakub Zych
3c9516b080 test(13): persist human verification items as UAT 2026-10-03 12:04:54 +02:00
Jakub Zych
8b4f03a36c docs(13): record code review disposition 2026-10-03 11:56:30 +02:00
Jakub Zych
412bc30daf docs(13): add code review report 2026-10-03 11:56:22 +02:00
Jakub Zych
bbc3e13d56 docs(13-06): record plan completion in state and roadmap 2026-10-03 11:45:26 +02:00
Jakub Zych
bcd099566b docs(13-06): complete the Phase 13 unit tests, gate and sign-off plan 2026-10-03 11:45:03 +02:00
Jakub Zych
931c02db31 docs(13-06): sign off the Phase 13 security review and validation
- 13-SECURITY-REVIEW.md: every T-13 threat with its strictest severity and
  disposition, protecting code, named tests and the 31 removal checks,
  all failing as required; the CSV export logging fix and the Phase 9
  route inventory update
- 13-VALIDATION.md: per-task map 13-01-T1 to 13-06-T3 all green, the gate
  command, coverage per package, Wave 0 ticked, status validated
- REQUIREMENTS.md: API-03, API-04, API-06 and API-07 complete
- deferred-items.md: 13-06 findings (process-wide job dispatcher, scalar
  mapping body, tmpfs quota)
2026-10-03 11:43:39 +02:00
Jakub Zych
ad79b3cca9 test(13-06): run TestOverlapConstraintFallsThrough in the gate's named stage
- The evidence stage refused T-13-23's review row because the named stage
  did not run the test its removal check RC-01 relies on
2026-10-03 11:32:35 +02:00
Jakub Zych
12b961b1c0 test(13-06): add the fail-closed Phase 13 gate
- scripts/check-phase13.sh with --self-test, --go, --parity, --named,
  --removal, --coverage, --evidence and --all, modelled on check-phase12
- Parity reads the replay's own coverage line: 157 ported and passing,
  0 failing, 14 recorded and not ported; every TestFonotekaNuxtFlows
  subtest, the three wishlist goldens, docs checks and the corpus scan
- Coverage floors of 80% for surf, conga, lagoon, tide and the four
  application packages, the user plugin's classes and every function of
  controllers/registration.go, and the controllers package's pre-phase value
- 31 anchor-exact removal checks with cmp restore, dirty-file refusal and
  a signal-safe restore; FORCE_COLOR unset by the gate itself
2026-10-03 11:27:44 +02:00
Jakub Zych
22a5ebdeda test(13-06): pin that a family falls through a member whose constraint fails
- TestOverlapConstraintFallsThrough: an earlier member that matches the
  literals but not its Where constraint must let a later member answer;
  the routes.php pairs cannot show this, since each member's own handler
  re-checks its constraints and the pairs differ in their literals (T-13-23)
2026-10-03 11:27:44 +02:00
Jakub Zych
4ed45c1b03 test(13-06): cover the Phase 13 framework edges in surf, conga, lagoon and tide
- surf: a transitive three-route family, HEAD and sorted Allow on family
  paths, a family across two plugins with per-member middleware, refused
  trailing-slash and multi-segment shapes
- conga: refusal messages name kind and queue, a configured queue counts
  as served, a delayed unregistered dispatch waits scheduled
- lagoon: prohibited under a wildcard, on a dotted path and after bail
- tide: quoted, RFC 5987 and multi-date download names; a captured id
  beside a masked notification id
2026-10-03 11:01:58 +02:00
Jakub Zych
5d0ce7f5bb docs(13-05): record plan completion in state and roadmap 2026-10-03 10:30:46 +02:00
Jakub Zych
80c6d5f5d0 docs(13-05): complete public share routes plan 2026-10-03 10:30:18 +02:00
Jakub Zych
ca7a6630cd docs(13-04): record plan completion in state and roadmap 2026-10-03 09:52:43 +02:00
Jakub Zych
47168ed909 docs(13-04): complete CSV export and import plan 2026-10-03 09:52:22 +02:00
Jakub Zych
3c43c4dc19 docs(13-03): record plan completion in state and roadmap 2026-10-03 08:24:57 +02:00
Jakub Zych
d1d5ee2012 docs(13-03): complete wishlist plan 2026-10-03 08:24:27 +02:00
Jakub Zych
7ccabf5394 docs(13-02): record plan completion in state and roadmap 2026-10-03 07:30:05 +02:00
Jakub Zych
69019c33d0 docs(13-02): complete notifications, credentials and onboarding plan 2026-10-03 07:29:37 +02:00
Jakub Zych
ac54df6c0e docs(13-01): record plan completion in state and roadmap 2026-10-03 06:42:26 +02:00
Jakub Zych
1c303f1511 docs(13-01): complete framework gaps, job contract and parity scaffolding plan 2026-10-03 06:41:58 +02:00
Jakub Zych
aa2786470a docs(13-01): reword Phase 13 and 14 criteria for the locked boundary
- Phase 13 repos name sm-user-plugin and summercms.go
- wishlist match/apply-release, the credential /test routes and the CSV
  Discogs pick move to Phase 14 (D-01, D-02); notifications drop prune,
  a Phase 14 console command (D-06); CSV and digest job bodies are Phase 14
- API-03, API-04, API-06, INTG-01 and INTG-02 follow; statuses untouched
2026-10-03 06:37:11 +02:00
Jakub Zych
2b94dfd2d2 feat(13-01): add the prohibited rule and dated-download and notification masks
- lagoon.ValidateRequest supports Laravel 9 prohibited (!required, not
  implicit); with no catalog line its message is validation.prohibited
- tide compares Content-Disposition with real calendar dates masked on both
  sides; a different name, an invalid date or a one-sided date still diffs
- tide.NormalizePublications masks a Carbon +00:00 $.data.payload.created_at
  and an uncaptured positive integer $.data.payload.id as {{id}}
- the album-date test's outside-album sibling moves off payload.created_at,
  which now has its own mask
- READMEs and docs describe the rule and both masks
2026-10-03 06:32:46 +02:00
Jakub Zych
55a4092019 feat(13-01): queue jobs whose worker ships later while a worker runs
- a kind no plugin registered always inserts through the insert-only River
  client, so Dispatch and Enqueue no longer fail River's unknown-kind check
  while the in-process worker runs
- while a worker runs, such a kind must name a queue no worker serves;
  an empty queue, default, scheduled, a configured queue or a registered
  job's queue is ErrUnregisteredKindQueue and nothing is written
- README and docs/services/jobs.md describe jobs whose worker ships later
2026-10-03 06:28:40 +02:00
Jakub Zych
fbdeb20126 feat(13-01): register overlapping constrained routes in surf
- compile groups routes ServeMux refuses side by side into overlap families
  and registers each under one generated method-less pattern
- the family handler tries members in registration order on literals and
  Where constraints, sets their path values and runs their own wrapped chain
- no match answers the bare 404; a method mismatch answers ServeMux's 405
  and Allow for the same table without the overlap
- unsupported shapes (same shape, {name...}, shadowing route) fail at boot
- README and docs/services/routing.md describe the behaviour
2026-10-03 06:22:20 +02:00
Jakub Zych
6525d967c5 docs(12.2): record BM UAT approval after v0.1.2 fixes
Browser checks on sm-bm-app passed: datetime popover time, discard confirm, and list date formatting. Phase 12.2 UAT is complete.

Co-authored-by: Cursor <cursoragent@cursor.com>
v0.1.2
2026-10-03 05:59:06 +02:00
Jakub Zych
55314e41f8 fix(admin): datetime popover clock, unsaved confirm, inferred list dates
BM UAT on v0.1.1 showed a date-only calendar for datetime fields, a stuck discard dialog, and raw ISO timestamps when columns.yaml omitted type. The picker now edits time in the popover, confirm sits above the calendar, and omitted time.Time / Date / TimeOfDay columns compile as datetime / date / time.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-03 05:58:24 +02:00
Jakub Zych
8031fd1c16 docs(12.2): record v0.1.1 tag and defer UAT to BM
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-02 23:27:52 +02:00
Jakub Zych
5c38d96f8b docs(12.2): record review fixes and persist human UAT
Close the seven code-review findings in disposition and leave the phase pending on browser checks plus the v0.1.1 tag.

Co-authored-by: Cursor <cursoragent@cursor.com>
v0.1.1
2026-10-02 23:13:49 +02:00
Jakub Zych
516f9c9025 fix(12.2): close code-review blockers on uploads, JSON caps, and pivot fill
Keep form save behind in-flight uploads, make retries idempotent via X-Upload-Id, cap remaining JSON bodies, and surface pending pivot type errors instead of zeroing them.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-02 23:10:48 +02:00
Jakub Zych
6bfc0faa8a docs(phase-12.2): add/update security threat verification 2026-10-02 22:35:37 +02:00