embedded FS registration with explicit permissions
from
to
via
controllers/artists/config_form.yaml
models/artist/fields.yaml
strict model asset path
[flagged-unverified] Artist schema parity must not be achieved by silently omitting an unsupported Winter field, action, filter, or layout hint.
Phase Goal
As a backend administrator, I want to authenticate separately and manage resources described by Winter-shaped schemas, so that the administration surface stays permission-gated and reusable without coupling it to frontend users.
Port the complete Artists backend controller through the schema, permission, list, and CRUD pipeline.
Purpose: Expand the reusable admin framework to a second real catalog controller without weakening strict parity or operation authorization.
Output: Embedded Artist controller/model assets and assembled parity/behavior tests.
Artist config_form.yaml, config_list.yaml, fields.yaml, and columns.yaml
Assembled TestArtistsAdmin* schema, permission, list, and CRUD suite
Task 1: Port Artists form schema and controller registration
../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go, ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_form.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist/fields.yaml, ../fonoteka.go/plugins/golem15/fonoteka/admin_artists_test.go
/media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/controllers/artists/config_form.yaml, /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/models/artist/fields.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist.go, cabana/form_schema.go, cabana/registry.go
- Test 1: every source artist form field and layout/localization hint compiles in declaration order for pl/en.
- Test 2: controller registration resolves exact model/assets and rejects missing/mismatched paths.
- Test 3: form/schema/create/update operations enforce the declared Artist permissions before model or database access.
Create the Artists controller with D-05 Winter-shaped config and embedded model fields, transcribing every tracked source key rather than reducing the schema. Register the model factory, controller ID, route slug, and explicit D-03 operation permissions; retain raw locale keys for request-time translation; and exercise the generated form response plus permitted/denied create/update paths.
(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin(Form|Registration|WritePermissions)$' -count=1)
The command exits non-zero, reports no matching test, a source field/hint is absent, asset/model resolution is ambiguous, locale output contaminates another request, or permission denial occurs after model/database work.
The complete Artist form compiles from embedded assets and every write path is registered with the exact required permission.
Artists form/schema/write behavior is available through the shared framework.
Task 2: Port Artists list and prove inherited CRUD/bulk edges
../fonoteka.go/plugins/golem15/fonoteka/controllers/artists/config_list.yaml, ../fonoteka.go/plugins/golem15/fonoteka/models/artist/columns.yaml, ../fonoteka.go/plugins/golem15/fonoteka/admin_artists_test.go
/media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/controllers/artists/config_list.yaml, /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/models/artist/columns.yaml, ../fonoteka.go/plugins/golem15/fonoteka/controllers/artists_admin_controller.go, cabana/query.go, cabana/crud.go
- Test 1: every artist list column/filter/action/default compiles and returns deterministic localized JSON.
- Test 2: empty/single/equal-value adjacent list pages follow ADMIN-02 and exact identifiers are case-sensitive.
- Test 3: record CRUD and duplicate/empty/repeated bulk operations inherit ADMIN-04 projection, lifecycle, atomicity, and idempotency.
Port the full Artist list/controller asset contract, including all columns, row/bulk actions, search/sort/filter, pagination, and labels. Use only the shared list and CRUD engines: add no controller-local query strings or shortcut write path. Test the explicit edge cases on the assembled routes so framework guarantees are proven against the Artist model.
(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin(List|CRUD|Bulk)$' -count=1)
The command exits non-zero, reports no matching test, a source list element is absent, empty/single/equal/adjacent behavior drifts, case-changed identifiers work, or Artist CRUD/bulk bypasses shared projection/lifecycle/transaction logic.
Artists list and writes demonstrate the complete shared ADMIN-02/ADMIN-04 behavior without controller-local bypasses.
The Artists backend controller is complete and parity-tested end to end.
<threat_model>
Trust Boundaries
Boundary
Description
compiled Artist operation→route
Controller permission declarations become runtime middleware
STRIDE Threat Register
Threat ID
Category
Component
Severity
Disposition
Mitigation Plan
T-09-13
Elevation
Artists operation permission map
high
mitigate
Require an explicit registered permission for every generated operation, fail activation on omissions, and assert denial happens before provider/database work.
T-09-SC
Tampering
npm/pip/cargo installs
high
mitigate
No npm/pip/cargo install occurs; existing Go dependencies only, so the package-legitimacy gate remains closed.
</threat_model>
Run `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestArtistsAdmin' -count=1)`; it fails on non-zero exit, zero matched tests, source-schema omission, permission-map gap, or inherited edge/lifecycle drift.
<success_criteria>
Artist form/list assets preserve all tracked source behavior and strict compilation.
Every Artist operation has an explicit permission enforced before untrusted work.
ADMIN-01/02/04 edge contracts pass on assembled Artist routes.
</success_criteria>
Create `.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-07-SUMMARY.md` when done.