Files
summercms/.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-PLAN.md
2026-09-17 18:40:13 +02:00

11 KiB
Raw Blame History

phase, plan, type, wave, depends_on, files_modified, autonomous, requirements, must_haves
phase plan type wave depends_on files_modified autonomous requirements must_haves
03-first-vertical-slice-genres-end-to-end 04 execute 4
03-03
lagoon/connection_test.go
lagoon/migrations_test.go
lagoon/order_test.go
surf/router_test.go
surf/middleware_test.go
surf/params_test.go
bouncer/jwt_test.go
bonfire/command_test.go
examples/hello/hello_test.go
../fonoteka.go/parity/genre_integration_test.go
../fonoteka.go/parity/genre_security_test.go
../fonoteka.go/parity/parity_contract_test.go
scripts/check-phase3.sh
.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
.planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
true
DATA-01
DATA-02
HTTP-01
HTTP-02
QA-04
truths artifacts key_links
D-01 through D-06: independent Postgres cases prove active-collection scoping, nonzero and zero counts, `non_empty`, 422, and database-default Polish order.
D-07 through D-15: auth and middleware tests prove no unauthenticated or locked request reaches the handler, all seven stages are ordered, and typed/constraint params give safe 404 behavior.
D-16 through D-20: migration isolation/up/down/seed and the unchanged recorded fixture pass with honest one-of-154 corpus accounting.
The roadmap's security-load-bearing JWT guard receives a documented security review with every high-severity threat mitigated or explicitly reported.
Root and app vet/test/race checks pass; the Phase 2 parity harness regression remains green.
path provides
bouncer/jwt_test.go Adversarial token verification coverage
path provides
surf/middleware_test.go Pipeline and missing guard boot coverage
path provides
../fonoteka.go/parity/genre_security_test.go Cross-plugin auth and tenant isolation coverage
path provides
scripts/check-phase3.sh Repeatable full gate for both repositories
path provides
.planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md Security review evidence and findings
from to via
scripts/check-phase3.sh ../fonoteka.go/parity/parity_test.go focused ported-route and full corpus Go test
from to via
.planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md bouncer/jwt_test.go threat-to-test evidence
**As a** maintainer, **I want to** run one repeatable gate for the real genres route and its security boundaries, **so that** later endpoint work cannot silently break the first vertical slice.

Purpose: Finish the phase with dedicated meaningful unit, integration, parity, and security tests as required by CLAUDE.md. Output: Tests for each risk, one check script, validation evidence, and security review findings.

<execution_context> @/home/jin/.codex/get-shit-done/workflows/execute-plan.md @/home/jin/.codex/get-shit-done/templates/summary.md </execution_context>

@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md @.planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md @.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md @.planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md @.planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md @.planning/phases/03-first-vertical-slice-genres-end-to-end/03-03-SUMMARY.md Plans 01–03 produce `lagoon`, `surf`, `bouncer`, a two-plugin app, a Postgres-backed genre handler, and a single ported route in `TestParityCorpus`. Phase 2's `scripts/check-phase2.sh` is the baseline harness regression command. All tests in this plan must assert externally observable behavior or security invariants, not duplicate source implementation details. Task 1: Cover framework boundaries with adversarial unit and integration tests lagoon/connection_test.go, lagoon/migrations_test.go, lagoon/order_test.go, surf/router_test.go, surf/middleware_test.go, surf/params_test.go, bouncer/jwt_test.go, bonfire/command_test.go, examples/hello/hello_test.go lagoon/connection.go, lagoon/migrations.go, lagoon/order.go, surf/router.go, surf/middleware.go, surf/params.go, bouncer/jwt.go, bouncer/context.go, bonfire/command.go, examples/hello/hello_test.go, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md Add behavior-focused tests for one pgx stdlib SQL pool shared with GORM and closed on shutdown; wrong ICU provider/locale boot failure; two migration sets with separate history, ordered up/down and rollback isolation; no `AutoMigrate` schema source; allow listed ORDER BY identifiers/direction; ServeMux method/path/group and per-route middleware composition; fixed recover → CORS → locale → auth → password gate → org → rate → handler order, including preflight and panic 500 without leaked internals; missing named middleware boot failure; integer, regex and enum params with malformed and unknown ID 404; and command names `serve`, `migrate`, `migrate:status`, `migrate:rollback`. For JWT, test valid persisted subject plus missing token, malformed token, `alg:none`, wrong HMAC algorithm, bad signature, absent/expired `exp`, absent `sub`, unknown user, empty secret, and absence of token/secret text in errors. Use `httptest` and isolated Postgres where behavior requires the DB; do not create tests that merely assert a helper calls another helper. Keep root and app vet/test green before the commit. go vet ./... && go test ./... && go test -race ./... && (cd ../fonoteka.go && go vet ./... && go test ./...) - Every high-severity framework threat T-03-01, T-03-02, and T-03-03 has at least one failing-when-broken test. - Both malformed and unknown typed IDs return 404, missing middleware fails boot, and an unauthenticated request cannot reach the genre handler. - Root vet/test/race and app vet/test exit 0 at commit. The reusable runtime's database, routing and authentication invariants are testable independently of the PHP fixture. Task 2: Prove app isolation, recorded parity and security review in one final gate ../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/genre_security_test.go, ../fonoteka.go/parity/parity_contract_test.go, scripts/check-phase3.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md ../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/parity_test.go, ../fonoteka.go/parity/parity_contract_test.go, ../fonoteka.go/parity/fixtures/routes/get_genres_jwt.yaml, ../fonoteka.go/parity/manifest.yaml, ../fonoteka.go/parity/synthetic_test.go, scripts/check-phase2.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md Complete independent app test cases for owner, editor and foreign albums with positive counts; active-context fallback; `non_empty=0|1|invalid`; exact seeded genre order under database ICU `pl-PL`; empty `data:[]`; JWT 401 variants, locked-user 423, and CORS preflight. Add a corpus contract that checks 154 recorded, 1 real replay pass, 153 pending, 0 false passes and a deliberate mismatch failure against the unmodified fixture. Create `scripts/check-phase3.sh` to run root and app `go vet ./...`, `go test ./...`, `go test -race ./...`, the focused genres parity subtest, corpus audit, and Phase 2 harness regression; it must exit nonzero on any failure and never silently skip Docker. Perform the roadmap's security review of token verification, cross-plugin guard lookup, migration isolation, query tenant boundaries, and secret handling. Record each T-03 threat, source location, test evidence, finding and disposition in `03-SECURITY-REVIEW.md`; resolve high-severity findings before marking the gate green. Fill `03-VALIDATION.md` with actual task IDs, commands and observed results; set `nyquist_compliant: true` only after the full gate passes. Keep the PHP fixture, generic `tide` code and other 153 route statuses unchanged. bash scripts/check-phase3.sh - `bash scripts/check-phase3.sh` exits 0 with root and app vet/test/race green and one real ported parity pass. - The corpus report is 154 recorded, 1 passing, 153 pending, 0 failing, 0 unrecorded; a deliberate response mutation fails a contract test. - `03-SECURITY-REVIEW.md` maps all high-severity threats to passing tests or a resolved finding; no open high-severity JWT or cross-tenant issue remains. - `03-VALIDATION.md` records observed evidence and only then has `nyquist_compliant: true`. One command proves the first real Go route's parity and its security boundaries, with evidence ready for phase verification.

<threat_model>

Trust Boundaries

Boundary Description
Test fixture and adversarial HTTP inputs → running app Tests must exercise real routing, auth and data boundaries.
Security review → phase acceptance Unresolved high-severity findings cannot be hidden by a green happy-path fixture.

STRIDE Threat Register

Threat ID Category Severity Component Disposition Mitigation Plan
T-03-02 Elevation of privilege high named middleware mitigate Missing-name and unauthenticated-route tests plus source review.
T-03-03 Spoofing high JWT guard mitigate Full malformed/forged/expired/unknown-user matrix and secret handling review.
T-03-04 Information disclosure high aggregate query mitigate Cross-tenant owner/editor/foreign album tests and query review.
T-03-06 Tampering high parity acceptance mitigate Real replay, honest pass counter, deliberate mismatch test.
</threat_model>
Run the repeatable Phase 3 script from the framework root after both task commits. Inspect its output and the security review/validation artifacts before recording success.

<success_criteria> All four Phase 3 roadmap criteria have direct passing evidence, the recorded PHP fixture is unchanged, and no high-severity security issue remains open. </success_criteria>

Create `.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-SUMMARY.md` after completion.