---
phase: 03-first-vertical-slice-genres-end-to-end
plan: 04
type: execute
wave: 4
depends_on: ["03-03"]
files_modified:
- lagoon/connection_test.go
- lagoon/migrations_test.go
- lagoon/order_test.go
- surf/router_test.go
- surf/middleware_test.go
- surf/params_test.go
- bouncer/jwt_test.go
- bonfire/command_test.go
- examples/hello/hello_test.go
- ../fonoteka.go/parity/genre_integration_test.go
- ../fonoteka.go/parity/genre_security_test.go
- ../fonoteka.go/parity/parity_contract_test.go
- scripts/check-phase3.sh
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
autonomous: true
requirements: [DATA-01, DATA-02, HTTP-01, HTTP-02, QA-04]
must_haves:
truths:
- "D-01 through D-06: independent Postgres cases prove active-collection scoping, nonzero and zero counts, `non_empty`, 422, and database-default Polish order."
- "D-07 through D-15: auth and middleware tests prove no unauthenticated or locked request reaches the handler, all seven stages are ordered, and typed/constraint params give safe 404 behavior."
- "D-16 through D-20: migration isolation/up/down/seed and the unchanged recorded fixture pass with honest one-of-154 corpus accounting."
- "The roadmap's security-load-bearing JWT guard receives a documented security review with every high-severity threat mitigated or explicitly reported."
- "Root and app vet/test/race checks pass; the Phase 2 parity harness regression remains green."
artifacts:
- path: bouncer/jwt_test.go
provides: Adversarial token verification coverage
- path: surf/middleware_test.go
provides: Pipeline and missing guard boot coverage
- path: ../fonoteka.go/parity/genre_security_test.go
provides: Cross-plugin auth and tenant isolation coverage
- path: scripts/check-phase3.sh
provides: Repeatable full gate for both repositories
- path: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
provides: Security review evidence and findings
key_links:
- from: scripts/check-phase3.sh
to: ../fonoteka.go/parity/parity_test.go
via: focused ported-route and full corpus Go test
- from: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
to: bouncer/jwt_test.go
via: threat-to-test evidence
---
**As a** maintainer, **I want to** run one repeatable gate for the real genres route and its security boundaries, **so that** later endpoint work cannot silently break the first vertical slice.
Purpose: Finish the phase with dedicated meaningful unit, integration, parity, and security tests as required by CLAUDE.md.
Output: Tests for each risk, one check script, validation evidence, and security review findings.
@/home/jin/.codex/get-shit-done/workflows/execute-plan.md
@/home/jin/.codex/get-shit-done/templates/summary.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-03-SUMMARY.md
Plans 01–03 produce `lagoon`, `surf`, `bouncer`, a two-plugin app, a Postgres-backed genre handler, and a single ported route in `TestParityCorpus`. Phase 2's `scripts/check-phase2.sh` is the baseline harness regression command. All tests in this plan must assert externally observable behavior or security invariants, not duplicate source implementation details.
Task 1: Cover framework boundaries with adversarial unit and integration tests
lagoon/connection_test.go, lagoon/migrations_test.go, lagoon/order_test.go, surf/router_test.go, surf/middleware_test.go, surf/params_test.go, bouncer/jwt_test.go, bonfire/command_test.go, examples/hello/hello_test.go
lagoon/connection.go, lagoon/migrations.go, lagoon/order.go, surf/router.go, surf/middleware.go, surf/params.go, bouncer/jwt.go, bouncer/context.go, bonfire/command.go, examples/hello/hello_test.go, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
Add behavior-focused tests for one pgx stdlib SQL pool shared with GORM and closed on shutdown; wrong ICU provider/locale boot failure; two migration sets with separate history, ordered up/down and rollback isolation; no `AutoMigrate` schema source; allow listed ORDER BY identifiers/direction; ServeMux method/path/group and per-route middleware composition; fixed recover → CORS → locale → auth → password gate → org → rate → handler order, including preflight and panic 500 without leaked internals; missing named middleware boot failure; integer, regex and enum params with malformed and unknown ID 404; and command names `serve`, `migrate`, `migrate:status`, `migrate:rollback`. For JWT, test valid persisted subject plus missing token, malformed token, `alg:none`, wrong HMAC algorithm, bad signature, absent/expired `exp`, absent `sub`, unknown user, empty secret, and absence of token/secret text in errors. Use `httptest` and isolated Postgres where behavior requires the DB; do not create tests that merely assert a helper calls another helper. Keep root and app vet/test green before the commit.
go vet ./... && go test ./... && go test -race ./... && (cd ../fonoteka.go && go vet ./... && go test ./...)
- Every high-severity framework threat T-03-01, T-03-02, and T-03-03 has at least one failing-when-broken test.
- Both malformed and unknown typed IDs return 404, missing middleware fails boot, and an unauthenticated request cannot reach the genre handler.
- Root vet/test/race and app vet/test exit 0 at commit.
The reusable runtime's database, routing and authentication invariants are testable independently of the PHP fixture.
Task 2: Prove app isolation, recorded parity and security review in one final gate
../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/genre_security_test.go, ../fonoteka.go/parity/parity_contract_test.go, scripts/check-phase3.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/parity_test.go, ../fonoteka.go/parity/parity_contract_test.go, ../fonoteka.go/parity/fixtures/routes/get_genres_jwt.yaml, ../fonoteka.go/parity/manifest.yaml, ../fonoteka.go/parity/synthetic_test.go, scripts/check-phase2.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
Complete independent app test cases for owner, editor and foreign albums with positive counts; active-context fallback; `non_empty=0|1|invalid`; exact seeded genre order under database ICU `pl-PL`; empty `data:[]`; JWT 401 variants, locked-user 423, and CORS preflight. Add a corpus contract that checks 154 recorded, 1 real replay pass, 153 pending, 0 false passes and a deliberate mismatch failure against the unmodified fixture. Create `scripts/check-phase3.sh` to run root and app `go vet ./...`, `go test ./...`, `go test -race ./...`, the focused genres parity subtest, corpus audit, and Phase 2 harness regression; it must exit nonzero on any failure and never silently skip Docker. Perform the roadmap's security review of token verification, cross-plugin guard lookup, migration isolation, query tenant boundaries, and secret handling. Record each T-03 threat, source location, test evidence, finding and disposition in `03-SECURITY-REVIEW.md`; resolve high-severity findings before marking the gate green. Fill `03-VALIDATION.md` with actual task IDs, commands and observed results; set `nyquist_compliant: true` only after the full gate passes. Keep the PHP fixture, generic `tide` code and other 153 route statuses unchanged.
bash scripts/check-phase3.sh
- `bash scripts/check-phase3.sh` exits 0 with root and app vet/test/race green and one real ported parity pass.
- The corpus report is 154 recorded, 1 passing, 153 pending, 0 failing, 0 unrecorded; a deliberate response mutation fails a contract test.
- `03-SECURITY-REVIEW.md` maps all high-severity threats to passing tests or a resolved finding; no open high-severity JWT or cross-tenant issue remains.
- `03-VALIDATION.md` records observed evidence and only then has `nyquist_compliant: true`.
One command proves the first real Go route's parity and its security boundaries, with evidence ready for phase verification.
## Trust Boundaries
| Boundary | Description |
|---|---|
| Test fixture and adversarial HTTP inputs → running app | Tests must exercise real routing, auth and data boundaries. |
| Security review → phase acceptance | Unresolved high-severity findings cannot be hidden by a green happy-path fixture. |
## STRIDE Threat Register
| Threat ID | Category | Severity | Component | Disposition | Mitigation Plan |
|---|---|---|---|---|---|
| T-03-02 | Elevation of privilege | high | named middleware | mitigate | Missing-name and unauthenticated-route tests plus source review. |
| T-03-03 | Spoofing | high | JWT guard | mitigate | Full malformed/forged/expired/unknown-user matrix and secret handling review. |
| T-03-04 | Information disclosure | high | aggregate query | mitigate | Cross-tenant owner/editor/foreign album tests and query review. |
| T-03-06 | Tampering | high | parity acceptance | mitigate | Real replay, honest pass counter, deliberate mismatch test. |
Run the repeatable Phase 3 script from the framework root after both task commits. Inspect its output and the security review/validation artifacts before recording success.
All four Phase 3 roadmap criteria have direct passing evidence, the recorded PHP fixture is unchanged, and no high-severity security issue remains open.