--- phase: quick-261004-rou plan: 01 status: complete completed: 2026-10-04 commits: sm-user-plugin: 0fe5b91 fonoteka: d1abcab --- # Quick 261004-rou Summary `golem15.user` now owns application-wide API tokens: persistence, minting, authentication, scopes, management routes/commands, and current user-group permission grants. Raw secrets remain one-time-only and only SHA-256 hashes are persisted. Fonoteka now uses that shared model and guard while preserving its `inv_` prefix, `inv_token`/`inv.scope:*` middleware contracts, collection pins, OAuth behavior, and existing endpoints. Its transition migration preserves legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token foreign keys, and supports a lossless rollback. BM's management API was refactored to consume `user.api_token`, `user.scope:*`, and current group permissions. Per user direction, BM and Quizzes were not committed; the tested BM changes and User submodule bump remain in the BM working tree for its dedicated dev-agent to review and commit. ## Verification - sm-user-plugin: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...` - Fonoteka application: `go test ./...`, `go vet ./...` - Fonoteka plugin: `go test ./...`, `go vet ./...` - BM plugin handoff: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`, `git diff --check` - Migration test covers legacy-token data, an ID collision, OAuth FK retarget, and reverse rollback. - BM end-to-end test proves the same shared token follows live group-permission grants and revocation. No SummerCMS framework change was required.