--- phase: 09-backend-admin-authentication-and-schema-pipeline plan: 07 type: execute wave: 7 depends_on: [09-06] files_modified: - ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go - ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_form.yaml - ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_list.yaml - ../fonoteka.go/plugins/golem15/fonoteka/models/artist/fields.yaml - ../fonoteka.go/plugins/golem15/fonoteka/models/artist/columns.yaml - ../fonoteka.go/plugins/golem15/fonoteka/admin_artists_test.go autonomous: true requirements: [ADMIN-01, ADMIN-02, ADMIN-04] estimate: tokens: 16000 raw_tokens: 16000 tasks: 2 confidence: low must_haves: truths: - "The Artists backend controller preserves every tracked Winter form/list field, column, action, filter, layout hint, and locale key through D-05/D-06 strict embedded compilation." - "Artist form and list endpoints enforce their D-03 operation permissions before controller/provider/database work and use the shared D-10 envelope." - "Artist list and CRUD inherit ADMIN-01/02/04 edge contracts: non-null empty/single arrays, stable equal ordering, exact identifiers, writable projection, lifecycle hooks, and atomic retry-safe bulk behavior." artifacts: - path: "../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go" provides: "Artists controller registration and operation permission map" - path: "../fonoteka.go/plugins/golem15/fonoteka/models/artist/fields.yaml" provides: "Complete artist form definition" - path: "../fonoteka.go/plugins/golem15/fonoteka/models/artist/columns.yaml" provides: "Complete artist list definition" key_links: - from: "controllers/artists_admin_controller.go" to: "cabana controller registry" via: "embedded FS registration with explicit permissions" - from: "controllers/artists/config_form.yaml" to: "models/artist/fields.yaml" via: "strict model asset path" prohibitions: - "[flagged-unverified] Artist schema parity must not be achieved by silently omitting an unsupported Winter field, action, filter, or layout hint." --- ## Phase Goal **As a** backend administrator, **I want to** authenticate separately and manage resources described by Winter-shaped schemas, **so that** the administration surface stays permission-gated and reusable without coupling it to frontend users. Port the complete Artists backend controller through the schema, permission, list, and CRUD pipeline. Purpose: Expand the reusable admin framework to a second real catalog controller without weakening strict parity or operation authorization. Output: Embedded Artist controller/model assets and assembled parity/behavior tests. @/home/jin/.codex/gsd-core/workflows/execute-plan.md @/home/jin/.codex/gsd-core/templates/summary.md @.planning/PROJECT.md @.planning/ROADMAP.md @.planning/STATE.md @.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-CONTEXT.md @.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-06-SUMMARY.md @../fonoteka.go/plugins/golem15/fonoteka/models/artist.go @cabana/form_schema.go @cabana/list_schema.go @cabana/crud.go ## Artifacts this phase produces - `fonoteka.ArtistsAdminController` - Artist `config_form.yaml`, `config_list.yaml`, `fields.yaml`, and `columns.yaml` - Assembled `TestArtistsAdmin*` schema, permission, list, and CRUD suite Task 1: Port Artists form schema and controller registration ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go, ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_form.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist/fields.yaml, ../fonoteka.go/plugins/golem15/fonoteka/admin_artists_test.go /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/controllers/artists/config_form.yaml, /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/models/artist/fields.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist.go, cabana/form_schema.go, cabana/registry.go - Test 1: every source artist form field and layout/localization hint compiles in declaration order for pl/en. - Test 2: controller registration resolves exact model/assets and rejects missing/mismatched paths. - Test 3: form/schema/create/update operations enforce the declared Artist permissions before model or database access. Create the Artists controller with D-05 Winter-shaped config and embedded model fields, transcribing every tracked source key rather than reducing the schema. Register the model factory, controller ID, route slug, and explicit D-03 operation permissions; retain raw locale keys for request-time translation; and exercise the generated form response plus permitted/denied create/update paths. (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin(Form|Registration|WritePermissions)$' -count=1) The command exits non-zero, reports no matching test, a source field/hint is absent, asset/model resolution is ambiguous, locale output contaminates another request, or permission denial occurs after model/database work. The complete Artist form compiles from embedded assets and every write path is registered with the exact required permission. Artists form/schema/write behavior is available through the shared framework. Task 2: Port Artists list and prove inherited CRUD/bulk edges ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_list.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist/columns.yaml, ../fonoteka.go/plugins/golem15/fonoteka/admin_artists_test.go /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/controllers/artists/config_list.yaml, /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/models/artist/columns.yaml, ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go, cabana/query.go, cabana/crud.go - Test 1: every artist list column/filter/action/default compiles and returns deterministic localized JSON. - Test 2: empty/single/equal-value adjacent list pages follow ADMIN-02 and exact identifiers are case-sensitive. - Test 3: record CRUD and duplicate/empty/repeated bulk operations inherit ADMIN-04 projection, lifecycle, atomicity, and idempotency. Port the full Artist list/controller asset contract, including all columns, row/bulk actions, search/sort/filter, pagination, and labels. Use only the shared list and CRUD engines: add no controller-local query strings or shortcut write path. Test the explicit edge cases on the assembled routes so framework guarantees are proven against the Artist model. (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin(List|CRUD|Bulk)$' -count=1) The command exits non-zero, reports no matching test, a source list element is absent, empty/single/equal/adjacent behavior drifts, case-changed identifiers work, or Artist CRUD/bulk bypasses shared projection/lifecycle/transaction logic. Artists list and writes demonstrate the complete shared ADMIN-02/ADMIN-04 behavior without controller-local bypasses. The Artists backend controller is complete and parity-tested end to end. ## Trust Boundaries | Boundary | Description | |----------|-------------| | compiled Artist operation→route | Controller permission declarations become runtime middleware | ## STRIDE Threat Register | Threat ID | Category | Component | Severity | Disposition | Mitigation Plan | |-----------|----------|-----------|----------|-------------|-----------------| | T-09-13 | Elevation | Artists operation permission map | high | mitigate | Require an explicit registered permission for every generated operation, fail activation on omissions, and assert denial happens before provider/database work. | | T-09-SC | Tampering | npm/pip/cargo installs | high | mitigate | No npm/pip/cargo install occurs; existing Go dependencies only, so the package-legitimacy gate remains closed. | Run `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin' -count=1)`; it fails on non-zero exit, zero matched tests, source-schema omission, permission-map gap, or inherited edge/lifecycle drift. - Artist form/list assets preserve all tracked source behavior and strict compilation. - Every Artist operation has an explicit permission enforced before untrusted work. - ADMIN-01/02/04 edge contracts pass on assembled Artist routes. Create `.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-07-SUMMARY.md` when done.