--- phase: 07-user-plugin-and-authentication plan: 06 subsystem: testing tags: [bouncer, jwt, fonoteka, parity, race] requires: - phase: 07-user-plugin-and-authentication provides: session, account, token, and locale handlers plus the recorded user-api corpus provides: - mint/refresh/blacklist round-trip and concurrent blacklist tests - in-process register-to-logout sequence and per-scope token mints - signed-off 07-VALIDATION.md affects: [phase-7-verification] tech-stack: added: [] patterns: [phase gate is go test -race in both modules, including nested plugin modules] key-files: created: - bouncer/phase07_coverage_test.go - ../fonoteka.go/plugins/golem15/user/sequence_test.go modified: - .planning/phases/07-user-plugin-and-authentication/07-VALIDATION.md - ../fonoteka.go/parity/schema_diff_test.go key-decisions: - "user_throttle and jwt_blacklist are named allowed diffs against the frozen PHP schema snapshot" - "AUTH-01 through AUTH-04 and I18N-02 stay unchecked; user-api routes stay pending" patterns-established: - "Pattern: nested plugin modules are tested with explicit ./plugins/golem15/... paths" requirements-completed: [] duration: 40min completed: 2026-09-22 --- # Phase 7 Plan 06: Unit coverage Summary **Phase 7's session, token, and blacklist paths have direct tests, and `go test -race` is green in both modules.** ## Performance - **Duration:** 40 min - **Started:** 2026-09-22T16:50:00Z - **Completed:** 2026-09-22T17:20:32Z - **Tasks:** 3 - **Files modified:** 8 ## Accomplishments - Mint, verify, refresh, and blacklist round-trip, plus concurrent Memory and Postgres blacklist calls, pass under `-race`. - `TestSessionSequence` walks register, fetch, update, change-password, refresh, logout, and a 401 on the logged-out token. Token mint covers `read`, `write`, `ai`, and `read+write`. - `07-VALIDATION.md` task IDs are filled, Wave 0 and sign-off boxes are checked, and `nyquist_compliant` is true. - Corpus inventory stays recorded 169, ported 7, pending 162, failing 0. `TestParityCorpus` passes. ## Task Commits 1. **Task 1: Framework blacklist coverage** — `4754377` in `summercms.go` 2. **Task 2: Session sequence and token scopes** — `a9f3531` in `fonoteka.go` (lock and deferred-route tests already in `9e5a125`) 3. **Task 3: Validation sign-off** — this docs commit ## Files Created/Modified - `bouncer/phase07_coverage_test.go` — round-trip and concurrent blacklist tests - `plugins/golem15/user/sequence_test.go` — register through logout - `plugins/golem15/fonoteka/token_locale_test.go` — one mint per allowed scope set - `parity/schema_diff_test.go` — allowed extra tables for the user plugin - `parity/migrate_test.go` — user history is five migrations - `07-VALIDATION.md` — task IDs and green statuses ## Decisions Made The frozen PHP schema snapshot predates the user plugin. `user_throttle` and `jwt_blacklist` are allowed extra Go tables, with the reason written on the diff entry. `jwt_blacklist` is Go-only: PHP logout does not blacklist, and the recorded fetch-after-logout stays 200. Requirement checkboxes stay open. The user-api routes are still pending, and authenticated activate with a wrong code is still an HTML 500 in PHP while Go returns 200. ## Deviations from Plan ### Auto-fixed Issues **1. [Rule 1 - Bug] Schema and migration tests still described the pre-phase-7 user plugin** - **Found during:** Task 3 (full `go test -race`) - **Issue:** `TestSchemaMatchesPHPSnapshot` rejected `user_throttle` and `jwt_blacklist`. Migration status expected 2 user migrations; there are 5. `TestHiddenNeverMarshals` expected 2 user models; Throttle makes 3. `TestGenreSecurityBoundaries` booted without `http.body_limits`. - **Fix:** Named the two tables in `allowedDiffs`, expected 5 user migrations and 3 user models, and set the body-limit keys on that test config. - **Files modified:** `parity/schema_diff_test.go`, `parity/migrate_test.go`, `plugins/golem15/fonoteka/classes/hidden_marshal_test.go`, `parity/genre_security_test.go` - **Verification:** `go test ./... -race` and the nested plugin packages passed - **Committed in:** `280ff56` --- **Total deviations:** 1 auto-fixed **Impact on plan:** The gate was red on counts the phase itself had already shipped. No production code changed. ## Issues Encountered `summer parity:replay` requires `--target` and `--fixtures`. The in-process gate is `go test ./parity/ -run TestParityCorpus`, which reports passing 7, failing 0, pending 162. Pending user-api fixtures are loaded and not sent to the Go handler. ## User Setup Required None - no external service configuration required. ## Next Phase Readiness Phase 7 plans are done and ready for verification. AUTH-01, AUTH-02, AUTH-03, AUTH-04, and I18N-02 stay unchecked until that sign-off. The activate HTML 500 and fetch-after-logout 200 gaps stay recorded, not patched. ## Self-Check: PASSED - `go vet ./... && go test ./... -race` passed in `summercms.go`. - `go vet ./... && go test ./... -race` passed in `fonoteka.go`, including `./plugins/golem15/user`, `./plugins/golem15/fonoteka`, and `./plugins/golem15/fonoteka/...`. - `TestParityCorpus` inventory is recorded 169, ported 7, pending 162, failing 0. - Commits `4754377`, `a9f3531`, and `280ff56` are on master. `go.work.sum` is untracked and not committed.