Files
summercms/.planning/phases/12.1-user-plugin-admin-screens/12.1-VERIFICATION.md

74 lines
6.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
phase: 12.1-user-plugin-admin-screens
verified: 2026-10-05T15:10:00Z
status: human_needed
score: 5/5 roadmap success criteria verified against code; SC-5 gate --all recorded PASS on production HEAD 93f0171
overrides_applied: 0
human_verification:
- test: "Walk Users, User Groups and Organisations in light and dark mode as an admin holding golem15.users.access_users and golem15.users.access_groups but not golem15.users.manage_privileged_groups"
expected: "Screens match the UI-SPEC (row-state badges with text, one status callout on preview, record actions before the primary edit button, segmented permission control, locked admin group with its note). Filter and search Users; open a banned and a deactivated user's preview; run Activate, Unban and a bulk Ban; create a user with an invitation; open Permissions; try to add the admin group; edit a group's permissions; add and remove an organisation member."
why_human: "Visual fit with the design system in both themes cannot be asserted by unit tests (plan 12.1-05 Task 3 human-check)."
- test: "D-30 on a user in the admin group: name-only save; email save; password save; Delete; bulk delete with another user"
expected: "Name-only save succeeds. Email and password each show the forbidden banner with the marked field, keep what was typed, save nothing. Delete and bulk delete each show a danger toast and delete nobody."
why_human: "End-to-end feel of the forbidden banner and toasts is a browser check."
covered_files:
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-01-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-01-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-02-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-02-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-03-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-03-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-04-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-04-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-05-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-05-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-SECURITY-REVIEW.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-VALIDATION.md"
- "scripts/check-phase12.1.sh"
- "modules/cabana/phase121_threats_test.go"
- "modules/cabana/crud.go"
- "modules/cabana/actions.go"
- "modules/cabana/http.go"
covered_digest: "v2:sha256:1a19afd9501bbb04b76e0b4f5c618c381209b491ba2f9157eded678b9eea15ac"
covered_files_note: "verification.fingerprint covers only paths under the summercms.go root. Plugin and application state at verification: sm-user-plugin 2b04cda (clean, 21 commits ahead of origin 0fe5b91), fonoteka.go 93b8b75 (pointer equals plugin HEAD). Framework tag v0.1.3 is local on df5cace and not on origin."
behavior_unverified: 0
---
# Phase 12.1: User plugin admin screens Verification Report
**Phase Goal:** Backend admins manage frontend users, user groups and organisations in the admin SPA without SQL, so the PHP backend is not needed for user administration after cutover. The Users, User Groups and Organisations screens of the PHP user plugin are ported to `golem15.user`, driven by its `fields.yaml`/`columns.yaml`.
**Verified:** 2026-10-05T15:10:00Z
**Status:** human_needed
**Re-verification:** No, initial verification
Plan 05 production commits were already on `master` (`c076b4c`..`93f0171`); this run only wrote the missing SUMMARY and the phase-gate artifacts. The verifier checked code and ran the fast gate stages. It did not re-run the 12-minute `--all` (already PASS on the same production HEAD).
## Goal Achievement
| # | Success criterion | Status | Evidence |
| --- | --- | --- | --- |
| SC1 | Users, User Groups and Organisations each have a list and a create/update form from PHP YAML, in admin navigation, permission-gated | ✓ VERIFIED | Controllers `users_admin_controller.go`, `usergroups_admin_controller.go`, `organisations_admin_controller.go`; YAML under `models/user`, `usergroup`, `organisation`; three side items in `admin_navigation.go` (`users`, `usergroups`, `organisations`). Plugin subtest `T-12.1-18` requires the matching permission on every route |
| SC2 | A user's groups via a relation field; an organisation's members via a relation manager | ✓ VERIFIED | `AdminRelationLocks` on the users controller (line 380); `controllers/organisations/config_relation.yaml`; plugin tests `TestAdminUserGroupsField`, `TestAdminOrganisationMembers` |
| SC3 | activate, unban, unsuspend, delete and list bulk actions as in PHP Users.php | ✓ VERIFIED | Plugin tests `TestAdminUserActions`, `TestAdminUserForceDelete`; threat subtests T-12.1-23, T-12.1-30, T-12.1-39 |
| SC4 | T-12-18 revisited: the admin form is the first writer of `users_groups`; privileged membership needs the extra permission | ✓ VERIFIED | `AdminRelationLocks` + `checkRelationLocks`; plugin `T-12.1-28` comment cites T-12-18 by that id; `T-12.1-30` asserts no other writer; removal RC-19 |
| SC5 | The new code has unit tests, delivered in the last plan | ✓ VERIFIED | `TestPhase121Threats` in cabana (T-12.1-01..15) and plugin (18-25, 27-31, 34, 38, 39). Coverage recorded: pact 100%, cabana 86.6%, plugin packages 83–95.7%. `scripts/check-phase12.1.sh --all` PASS 2026-10-05. This session: `--self-test`, `--evidence` (41 threats, 27 removal rows), `--hygiene` all exit 0 |
## Artifacts
| Artifact | Status |
| --- | --- |
| Five plan SUMMARYs | ✓ |
| `scripts/check-phase12.1.sh` executable | ✓ |
| `12.1-SECURITY-REVIEW.md` threats_open 0 | ✓ (`--evidence` this session) |
| `12.1-VALIDATION.md` nyquist_compliant true | ✓ no TBD row |
| `12.1-REVIEW.md` + disposition | ✓ 0 findings |
| Plugin push | pending: `v0.1.3` is not on origin |
## Gaps
None that falsify a success criterion.
Status is `human_needed`, not `passed`, because the plan-05 visual walk and D-30 browser check are still outstanding, and because sm-user-plugin is unpublished until the framework tag is on origin. Those are not code gaps.
_Verifier: orchestrator inline on resume close-out. Did not spawn gsd-verifier (typed GSD agents unavailable). Did not re-run `--all` or `--removal`._