139 lines
11 KiB
Markdown
139 lines
11 KiB
Markdown
---
|
||
phase: 03-first-vertical-slice-genres-end-to-end
|
||
plan: 04
|
||
type: execute
|
||
wave: 4
|
||
depends_on: ["03-03"]
|
||
files_modified:
|
||
- lagoon/connection_test.go
|
||
- lagoon/migrations_test.go
|
||
- lagoon/order_test.go
|
||
- surf/router_test.go
|
||
- surf/middleware_test.go
|
||
- surf/params_test.go
|
||
- bouncer/jwt_test.go
|
||
- bonfire/command_test.go
|
||
- examples/hello/hello_test.go
|
||
- ../fonoteka.go/parity/genre_integration_test.go
|
||
- ../fonoteka.go/parity/genre_security_test.go
|
||
- ../fonoteka.go/parity/parity_contract_test.go
|
||
- scripts/check-phase3.sh
|
||
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
|
||
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
|
||
autonomous: true
|
||
requirements: [DATA-01, DATA-02, HTTP-01, HTTP-02, QA-04]
|
||
must_haves:
|
||
truths:
|
||
- "D-01 through D-06: independent Postgres cases prove active-collection scoping, nonzero and zero counts, `non_empty`, 422, and database-default Polish order."
|
||
- "D-07 through D-15: auth and middleware tests prove no unauthenticated or locked request reaches the handler, all seven stages are ordered, and typed/constraint params give safe 404 behavior."
|
||
- "D-16 through D-20: migration isolation/up/down/seed and the unchanged recorded fixture pass with honest one-of-154 corpus accounting."
|
||
- "The roadmap's security-load-bearing JWT guard receives a documented security review with every high-severity threat mitigated or explicitly reported."
|
||
- "Root and app vet/test/race checks pass; the Phase 2 parity harness regression remains green."
|
||
artifacts:
|
||
- path: bouncer/jwt_test.go
|
||
provides: Adversarial token verification coverage
|
||
- path: surf/middleware_test.go
|
||
provides: Pipeline and missing guard boot coverage
|
||
- path: ../fonoteka.go/parity/genre_security_test.go
|
||
provides: Cross-plugin auth and tenant isolation coverage
|
||
- path: scripts/check-phase3.sh
|
||
provides: Repeatable full gate for both repositories
|
||
- path: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
|
||
provides: Security review evidence and findings
|
||
key_links:
|
||
- from: scripts/check-phase3.sh
|
||
to: ../fonoteka.go/parity/parity_test.go
|
||
via: focused ported-route and full corpus Go test
|
||
- from: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
|
||
to: bouncer/jwt_test.go
|
||
via: threat-to-test evidence
|
||
---
|
||
|
||
<objective>
|
||
**As a** maintainer, **I want to** run one repeatable gate for the real genres route and its security boundaries, **so that** later endpoint work cannot silently break the first vertical slice.
|
||
|
||
Purpose: Finish the phase with dedicated meaningful unit, integration, parity, and security tests as required by CLAUDE.md.
|
||
Output: Tests for each risk, one check script, validation evidence, and security review findings.
|
||
</objective>
|
||
|
||
<execution_context>
|
||
@/home/jin/.codex/get-shit-done/workflows/execute-plan.md
|
||
@/home/jin/.codex/get-shit-done/templates/summary.md
|
||
</execution_context>
|
||
|
||
<context>
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md
|
||
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-03-SUMMARY.md
|
||
|
||
<interfaces>
|
||
Plans 01–03 produce `lagoon`, `surf`, `bouncer`, a two-plugin app, a Postgres-backed genre handler, and a single ported route in `TestParityCorpus`. Phase 2's `scripts/check-phase2.sh` is the baseline harness regression command. All tests in this plan must assert externally observable behavior or security invariants, not duplicate source implementation details.
|
||
</interfaces>
|
||
</context>
|
||
|
||
<tasks>
|
||
|
||
<task type="auto">
|
||
<name>Task 1: Cover framework boundaries with adversarial unit and integration tests</name>
|
||
<files>lagoon/connection_test.go, lagoon/migrations_test.go, lagoon/order_test.go, surf/router_test.go, surf/middleware_test.go, surf/params_test.go, bouncer/jwt_test.go, bonfire/command_test.go, examples/hello/hello_test.go</files>
|
||
<read_first>lagoon/connection.go, lagoon/migrations.go, lagoon/order.go, surf/router.go, surf/middleware.go, surf/params.go, bouncer/jwt.go, bouncer/context.go, bonfire/command.go, examples/hello/hello_test.go, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md</read_first>
|
||
<action>Add behavior-focused tests for one pgx stdlib SQL pool shared with GORM and closed on shutdown; wrong ICU provider/locale boot failure; two migration sets with separate history, ordered up/down and rollback isolation; no `AutoMigrate` schema source; allow listed ORDER BY identifiers/direction; ServeMux method/path/group and per-route middleware composition; fixed recover → CORS → locale → auth → password gate → org → rate → handler order, including preflight and panic 500 without leaked internals; missing named middleware boot failure; integer, regex and enum params with malformed and unknown ID 404; and command names `serve`, `migrate`, `migrate:status`, `migrate:rollback`. For JWT, test valid persisted subject plus missing token, malformed token, `alg:none`, wrong HMAC algorithm, bad signature, absent/expired `exp`, absent `sub`, unknown user, empty secret, and absence of token/secret text in errors. Use `httptest` and isolated Postgres where behavior requires the DB; do not create tests that merely assert a helper calls another helper. Keep root and app vet/test green before the commit.</action>
|
||
<verify><automated>go vet ./... && go test ./... && go test -race ./... && (cd ../fonoteka.go && go vet ./... && go test ./...)</automated></verify>
|
||
<acceptance_criteria>
|
||
- Every high-severity framework threat T-03-01, T-03-02, and T-03-03 has at least one failing-when-broken test.
|
||
- Both malformed and unknown typed IDs return 404, missing middleware fails boot, and an unauthenticated request cannot reach the genre handler.
|
||
- Root vet/test/race and app vet/test exit 0 at commit.
|
||
</acceptance_criteria>
|
||
<done>The reusable runtime's database, routing and authentication invariants are testable independently of the PHP fixture.</done>
|
||
</task>
|
||
|
||
<task type="auto">
|
||
<name>Task 2: Prove app isolation, recorded parity and security review in one final gate</name>
|
||
<files>../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/genre_security_test.go, ../fonoteka.go/parity/parity_contract_test.go, scripts/check-phase3.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md</files>
|
||
<read_first>../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/parity_test.go, ../fonoteka.go/parity/parity_contract_test.go, ../fonoteka.go/parity/fixtures/routes/get_genres_jwt.yaml, ../fonoteka.go/parity/manifest.yaml, ../fonoteka.go/parity/synthetic_test.go, scripts/check-phase2.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md</read_first>
|
||
<action>Complete independent app test cases for owner, editor and foreign albums with positive counts; active-context fallback; `non_empty=0|1|invalid`; exact seeded genre order under database ICU `pl-PL`; empty `data:[]`; JWT 401 variants, locked-user 423, and CORS preflight. Add a corpus contract that checks 154 recorded, 1 real replay pass, 153 pending, 0 false passes and a deliberate mismatch failure against the unmodified fixture. Create `scripts/check-phase3.sh` to run root and app `go vet ./...`, `go test ./...`, `go test -race ./...`, the focused genres parity subtest, corpus audit, and Phase 2 harness regression; it must exit nonzero on any failure and never silently skip Docker. Perform the roadmap's security review of token verification, cross-plugin guard lookup, migration isolation, query tenant boundaries, and secret handling. Record each T-03 threat, source location, test evidence, finding and disposition in `03-SECURITY-REVIEW.md`; resolve high-severity findings before marking the gate green. Fill `03-VALIDATION.md` with actual task IDs, commands and observed results; set `nyquist_compliant: true` only after the full gate passes. Keep the PHP fixture, generic `tide` code and other 153 route statuses unchanged.</action>
|
||
<verify><automated>bash scripts/check-phase3.sh</automated></verify>
|
||
<acceptance_criteria>
|
||
- `bash scripts/check-phase3.sh` exits 0 with root and app vet/test/race green and one real ported parity pass.
|
||
- The corpus report is 154 recorded, 1 passing, 153 pending, 0 failing, 0 unrecorded; a deliberate response mutation fails a contract test.
|
||
- `03-SECURITY-REVIEW.md` maps all high-severity threats to passing tests or a resolved finding; no open high-severity JWT or cross-tenant issue remains.
|
||
- `03-VALIDATION.md` records observed evidence and only then has `nyquist_compliant: true`.
|
||
</acceptance_criteria>
|
||
<done>One command proves the first real Go route's parity and its security boundaries, with evidence ready for phase verification.</done>
|
||
</task>
|
||
|
||
</tasks>
|
||
|
||
<threat_model>
|
||
## Trust Boundaries
|
||
|
||
| Boundary | Description |
|
||
|---|---|
|
||
| Test fixture and adversarial HTTP inputs → running app | Tests must exercise real routing, auth and data boundaries. |
|
||
| Security review → phase acceptance | Unresolved high-severity findings cannot be hidden by a green happy-path fixture. |
|
||
|
||
## STRIDE Threat Register
|
||
|
||
| Threat ID | Category | Severity | Component | Disposition | Mitigation Plan |
|
||
|---|---|---|---|---|---|
|
||
| T-03-02 | Elevation of privilege | high | named middleware | mitigate | Missing-name and unauthenticated-route tests plus source review. |
|
||
| T-03-03 | Spoofing | high | JWT guard | mitigate | Full malformed/forged/expired/unknown-user matrix and secret handling review. |
|
||
| T-03-04 | Information disclosure | high | aggregate query | mitigate | Cross-tenant owner/editor/foreign album tests and query review. |
|
||
| T-03-06 | Tampering | high | parity acceptance | mitigate | Real replay, honest pass counter, deliberate mismatch test. |
|
||
</threat_model>
|
||
|
||
<verification>
|
||
Run the repeatable Phase 3 script from the framework root after both task commits. Inspect its output and the security review/validation artifacts before recording success.
|
||
</verification>
|
||
|
||
<success_criteria>
|
||
All four Phase 3 roadmap criteria have direct passing evidence, the recorded PHP fixture is unchanged, and no high-severity security issue remains open.
|
||
</success_criteria>
|
||
|
||
<output>
|
||
Create `.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-SUMMARY.md` after completion.
|
||
</output>
|