Files
summercms/.planning/phases/14.2.1-translate-plugin/14.2.1-VALIDATION.md
Jakub Zych 249b4d10ca docs(14.2.1-04): complete translate tests, gate, and security review
Record the last-plan SUMMARY, closed high-threat review, validation sign-off, and 4/4 roadmap progress.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-06 14:23:06 +02:00

90 lines
5.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
phase: "14.2.1"
slug: "translate-plugin"
status: validated
nyquist_compliant: true
wave_0_complete: true
created: "2026-10-06"
validated: "2026-10-06"
---
# Phase 14.2.1 — Validation Strategy
> Per-phase validation contract. Signed off after plan 14.2.1-04 tests and
> `scripts/check-phase14.2.1.sh` stages were executed.
---
## Test Infrastructure
| Property | Value |
|----------|-------|
| **Framework** | Go `testing` + testcontainers-go v0.44.0 (Postgres) + Vitest for admin SPA |
| **Config file** | none — `go test ./...`; gate `scripts/check-phase14.2.1.sh` |
| **Quick run command** | `go -C ../sm-translate-plugin test ./... -short -count=1` plus `go test ./modules/cabana ./modules/surf -short -count=1` |
| **Full suite command** | `bash scripts/check-phase14.2.1.sh --all` |
| **Estimated runtime** | ~60 seconds (short); ~15–25 minutes (full + race, Postgres) |
---
## Sampling Rate
- **After every task commit:** named verify command in that plan's task
- **After every plan wave:** `go vet` + `go test ./... -count=1` in the repo that changed
- **Before `$gsd-verify-work`:** `bash scripts/check-phase14.2.1.sh --all`
- **Max feedback latency:** 60 seconds (short)
---
## Per-Task Verification Map
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
| 14.2.1-W0 | 04 | 0 | D-05 | T-14.2.1-05 | Locales admin requires `golem15.translate.manage_locales` | integration | `go -C ../sm-translate-plugin test . -run TestLocalesAdminForbidden -count=1` | ✅ `locales_admin_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-06 | T-14.2.1-09 | `type: mltext` and `type: mlmarkdown` compile; unknown type fails boot | unit | `go test ./modules/cabana -run TestMLFieldTypes -count=1` | ✅ `modules/cabana/ml_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-07 | T-14.2.1-01 | URL prefix wins; invalid code ignored; session/cookie flag; not header-only | unit | `go -C ../sm-translate-plugin test ./classes -run TestTranslatorResolve -count=1` | ✅ `classes/translator_resolve_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-08 | — | Seed inserts `en` (default, enabled) and `pl` (enabled, not default); not `de` | integration | `go -C ../sm-translate-plugin test ./updates -run TestSeedEnPl -count=1` | ✅ `updates/migrations_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-09/D-12 | T-14.2.1-07 | `Translatable()` + get/set + `WithLocale` | unit | `go -C ../sm-translate-plugin test ./classes -run TestTranslatableGetSet -count=1` | ✅ `classes/translatable_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-10 | T-14.2.1-04 | Tables `golem15_translate_locales\|attributes\|indexes\|messages` exist after migrate | integration | `go -C ../sm-translate-plugin test ./updates -run TestTranslateTables -count=1` | ✅ `updates/migrations_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-11 | — | Missing `pl` falls back to default locale column | unit | `go -C ../sm-translate-plugin test ./classes -run TestFallbackDefaultLocale -count=1` | ✅ `classes/translatable_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | D-17 | T-14.2.1-13 | Host/plugin Activate with user+translate | smoke | `go -C ../sm-grzybyfunkcjonalne-app test ./... -run TestBootUserTranslate -count=1` | ✅ `boot_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | T-SEC-01 | T-14.2.1-07 | Unlisted locale never stored | unit | `go -C ../sm-translate-plugin test ./classes -run TestInvalidLocaleRejected -count=1` | ✅ `classes/translatable_test.go` | ✅ green |
| 14.2.1-W0 | 04 | 0 | T-SEC-02 | T-14.2.1-09 | Nested ML body not dropped | unit | `go test ./modules/cabana -run TestMLNestedSave -count=1` | ✅ `modules/cabana/ml_test.go` | ✅ green |
| 14.2.1-04-1 | 04 | 4 | D-17 | T-14.2.1-18 | Production-path e2e on real Postgres | e2e | `go -C ../sm-translate-plugin test . -run '^(TestTranslateEndToEnd)$' -count=1` | ✅ `integration_test.go` | ✅ green |
| 14.2.1-04-2 | 04 | 4 | D-07 | T-14.2.1-15 | Concurrent request locale isolation | unit | `go -C ../sm-translate-plugin test ./classes -race -run TestTranslatorConcurrentIsolation -count=1` | ✅ `classes/translator_resolve_test.go` | ✅ green |
| 14.2.1-04-3 | 04 | 4 | D-12 | T-14.2.1-12 | Unsafe markdown rejected | unit | `go test ./modules/cabana -run TestMarkdownRejectsUnsafeHTML -count=1` | ✅ `modules/cabana/markdown_test.go` | ✅ green |
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
---
## Wave 0 Requirements
- [x] `sm-translate-plugin` module and test files listed above
- [x] `modules/cabana` ML compile/save tests
- [x] `modules/surf` Resolver-present vs absent locale tests (`TestLocaleResolver`)
- [x] Plugin Postgres harness (fail-closed TestMain / testcontainers)
- [x] No new test framework install
---
## Manual-Only Verifications
| Behavior | Requirement | Why Manual | Test Instructions | Status |
|----------|-------------|------------|-------------------|--------|
| Gitea remote `git@git.golem15.com:golem15/sm-translate-plugin.git` | D-15 | Requires user credentials | Created in plan 01; clone URL exists | ✅ done (01) |
| Locales admin in the proof-host SPA | D-17 | Needs running host + admin login | Boot the proof host; sign in as an administrator holding `golem15.translate.manage_locales`; open Locales; confirm English then Polski; edit name/enabled; a user without the permission cannot open the controller | ⬜ end-of-phase UAT |
---
## Validation Sign-Off
- [x] All tasks have `<automated>` verify or Wave 0 dependencies
- [x] Sampling continuity: no 3 consecutive tasks without automated verify
- [x] Wave 0 covers all MISSING references
- [x] No watch-mode flags
- [x] Feedback latency < 60s (short)
- [x] `nyquist_compliant: true` set in frontmatter
**Approval:** validated 2026-10-06 (executor 14.2.1-04). Human UAT for Locales SPA remains end-of-phase.