Jakub Zych
b74484eabc
docs(07-08): complete the avatar bucket publish plan
...
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:50:01 +02:00
Jakub Zych
44900f0d16
feat(07-08): publish the uploads bucket on serve
...
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 10:43:47 +02:00
Jakub Zych
33f716ddef
docs(07-08): plan avatar bucket publish on serve and Handler
2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16
test(07): complete UAT - 11 passed, 1 issues
2026-09-23 10:33:16 +02:00
Jakub Zych
1bd9f9e056
docs(state): record phase 9 context session
2026-09-23 10:24:37 +02:00
Jakub Zych
8268ff780d
docs(09): capture phase context
2026-09-23 10:24:22 +02:00
Jakub Zych
d20f99f2e6
docs(07-07): complete the user-api parity gap plan
...
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-23 00:01:18 +02:00
Jakub Zych
31634f706f
feat(07-07): localize lagoon validation with Laravel-shaped Polish messages
...
Replay of the user-api corpus needs lagoon::validate.* catalogs and
underscore-to-space attribute names so Go 422 bodies match Winter.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 23:56:58 +02:00
Jakub Zych
dd3cb7ac29
docs(07): record gap-closure planning in state
2026-09-22 20:41:30 +02:00
Jakub Zych
8a1a52915b
fix(07): revise 07-07-PLAN.md for checker-found seeding blockers
2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db
docs(07): plan gap closure for the pending user-api parity routes
2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816
docs(07): record the phase goal verification
...
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd
docs(07-06): complete the unit coverage plan
...
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 19:21:31 +02:00
Jakub Zych
4754377442
feat(07-06): prove mint, refresh, and blacklist under concurrency
...
A minted token refreshes once, then the old jti is blacklisted. Memory and Postgres blacklists take concurrent Add and IsBlacklisted calls.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 19:20:14 +02:00
Jakub Zych
fa7bdb5f71
docs(07-05): complete the user API parity capture plan
...
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 18:44:05 +02:00
Jakub Zych
7d5d8659ec
feat(07-05): allow the second parity test password
...
Change-password recordings need a distinct new password that the fixture scrubber still accepts.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 18:43:27 +02:00
Jakub Zych
ecfcd23150
docs(07-04): complete the personal token and locale plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0
docs(07-03): complete the account management plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c
docs(07-02): complete the user session plan
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d
docs(07-01): complete framework auth primitives plan
2026-09-22 13:43:15 +02:00
Jakub Zych
8fcaff77cf
feat(07-01): add bcrypt, locale override, and validation rules
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:39:25 +02:00
Jakub Zych
bccd7f8f35
test(07-01): add failing tests for passwords, locale, and validation
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:36:08 +02:00
Jakub Zych
cad445a235
feat(07-01): add JWT mint, refresh, and blacklist primitives
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:34:58 +02:00
Jakub Zych
251f3cc4a0
test(07-01): add failing tests for JWT lifecycle primitives
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-09-22 13:33:37 +02:00
Jakub Zych
80eaeb87ea
docs(07): mark phase planned, annotate roadmap waves
2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3
docs(07): revise plans after checker review
2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2
docs(07): create phase plan
...
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)
Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863
docs(07): add pattern map
2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21
docs(07): add validation strategy
2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22
docs(07): research user plugin and authentication phase
2026-09-22 02:42:14 +02:00
Jakub Zych
5548b2fab4
docs(state): record phase 7 context session
2026-09-22 00:24:22 +02:00
Jakub Zych
1979c45083
docs(07): capture phase context
2026-09-22 00:24:21 +02:00
Jakub Zych
2fe5c1e920
docs(06): verify phase 6 passed, mark HTTP-04/06 complete
2026-09-21 19:51:58 +02:00
Jakub Zych
fb66398cb9
docs(06-14): complete gap-closure test and review plan
2026-09-21 19:49:47 +02:00
Jakub Zych
ae817ccbb9
docs(06-14): reopen and re-close phase 6 security review with T-06-28..35
2026-09-21 19:49:30 +02:00
Jakub Zych
e50e2dd632
test(06-14): fetchguard IANA boundary and zoned dial tests, surf edge coverage
2026-09-21 19:48:06 +02:00
Jakub Zych
f1218f2c84
test(06-14): regression coverage for surf and bouncer gap closure
2026-09-21 19:47:16 +02:00
Jakub Zych
1d2e00cf59
fix(06-14): actually reuse built middleware factories per name:param
...
The built cache added in 06-12 was declared but never consulted, so every
route re-invoked the factory on BuildRouter and again on compile.
2026-09-21 19:47:16 +02:00
Jakub Zych
54dd60953a
docs(06-13): complete fetchguard SSRF gap-closure plan
2026-09-21 19:45:03 +02:00
Jakub Zych
b1079ab8a4
fix(06-13): full IANA special-use SSRF tables and reject zoned dial targets
2026-09-21 19:44:51 +02:00
Jakub Zych
4bad1a43a2
docs(06-12): complete surf/bouncer gap-closure plan
2026-09-21 19:43:51 +02:00
Jakub Zych
8a9449df63
fix(06-12): reject typed-nil guards and fractional JWT subjects
2026-09-21 19:43:35 +02:00
Jakub Zych
4ad2ad29f2
fix(06-12): fail closed on invalid limiter definitions
2026-09-21 19:42:41 +02:00
Jakub Zych
a50e09ba34
fix(06-12): bound named middleware by body cap, cache factories, fail boot on bad body config and mux conflicts
2026-09-21 19:42:20 +02:00
Jakub Zych
46c7e4f98e
docs(06): create gap-closure plans 12-14
2026-09-21 19:30:50 +02:00
Jakub Zych
6e9188b5c7
docs(06): record verification gaps
2026-09-21 14:49:52 +02:00
Jakub Zych
c5b412c7e1
docs(06): add code review report
2026-09-21 14:31:47 +02:00
Jakub Zych
ef6d914e4c
docs(06-11): update plan tracking
2026-09-21 13:05:11 +02:00
Jakub Zych
2329e1f290
docs(06-11): complete post-gap security review plan
2026-09-21 13:03:41 +02:00
Jakub Zych
829e9989e3
docs(06-11): refresh Phase 6 security review
2026-09-21 13:02:41 +02:00