12 KiB
phase, plan, subsystem, tags, requires, provides, affects, actuals, tech-stack, key-files, key-decisions, patterns-established, requirements-completed, coverage, duration, completed, status, plan_head_before, plan_head_after
| phase | plan | subsystem | tags | requires | provides | affects | actuals | tech-stack | key-files | key-decisions | patterns-established | requirements-completed | coverage | duration | completed | status | plan_head_before | plan_head_after | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 09-backend-admin-authentication-and-schema-pipeline | 06 | admin |
|
|
|
|
|
|
|
|
|
|
|
29min | 2026-09-24 | complete | 3e7738ff32 |
0caa86ec0b |
Phase 9 Plan 06: Albums Admin Collection Boundary Summary
Albums admin form, list, and writes bind only the active collection of the one active frontend user matched by the backend account email.
Performance
- Duration: 29 min
- Started: 2026-09-24T17:50:44Z
- Completed: 2026-09-24T18:20:13Z
- Tasks: 3
- Files modified: 15
Accomplishments
- Embedded the Winter Albums form and list YAML and served the localized form at
GET /_admin/api/v1/golem15/fonoteka/albums/schema/form. - Format options keep Album::FORMATS scalars and phrase keys; genre and style options are active rows ordered by name then id.
- Create and update set
collection_idfromResolveBackendAlbumCollectionUser. Lists, shows, updates, and bulk deletes cannot see another collection.
TDD Gate Compliance
Each task has a RED test(09-06) commit before its GREEN feat(09-06) commit. RED evidence checks returned RED_EVIDENCE_OK for TestAlbumsAdminForm, TestAlbumsAdminDropdowns, and TestAlbumsAdminCollectionMatch.
Task Commits
- Task 1: Port complete Albums form and controller registration -
60a4b10(test, fonoteka.go),c63146a(feat, summercms.go),652bfda(feat, fonoteka.go) - Task 2: Port Albums list and typed option providers -
81f1aa4(test, fonoteka.go),5de760d(feat, fonoteka.go) - Task 3: Enforce exact active-collection user resolution -
6004c6a(test, fonoteka.go),0caa86e(feat, summercms.go),15dfefa(feat, fonoteka.go)
The summercms.go ledger 3e7738ff..0caa86e contains the two framework commits above. Fonoteka commits are in fonoteka.go 60a4b10..15dfefa.
Files Created/Modified
fonoteka.go/plugins/golem15/fonoteka/controllers/albums_admin_controller.go- Albums controller, permissions, dropdowns, and collection hooksfonoteka.go/plugins/golem15/fonoteka/classes/backend_album_collection.go- exact normalized email resolutionfonoteka.go/plugins/golem15/fonoteka/models/album/fields.yaml- Winter album form, copied unchangedfonoteka.go/plugins/golem15/fonoteka/models/album/columns.yaml- Winter album columns, copied unchangedfonoteka.go/plugins/golem15/fonoteka/models/album.go-Genreassociation andgetFormatOptionscabana/http.go-GET .../schema/formbehind the existing permission checkcabana/query.goandcabana/list_schema.go- case-insensitive relation field matchcabana/crud.go- required validation limited to scalar writable fieldsfonoteka.go/plugins/golem15/fonoteka/admin_albums_test.go- assembled PostgreSQL proof
Decisions Made
- D-14 stores
collection_id, the active collection of the matched frontend user. The albums table has nouser_idcolumn, so none was added. pact.Option.Valueis a string, so genre and style ids are decimal strings. Format values stay the Winter scalars (LP,EP 7", and the rest).- Served list JSON keeps
relation: genre. Joins and preloads use the exported Go fieldGenre. artistsstaysrequired: trueon the form schema. Save validation does not require it, because the admin CRUD path cannot bind a relation.
Deviations from Plan
Auto-fixed Issues
1. [Rule 3 - Blocking] Embedded the list YAML while registering the controller
- Found during: Task 1
- Issue: Activation compiles
config_list.yamlfor every admin controller. Registering Albums with only the form files failed boot. - Fix: Copied the Winter list and columns YAML in the same commit as the form.
- Files modified:
controllers/albums/config_list.yaml,models/album/columns.yaml - Verification:
TestAlbumsAdminRegistrationandTestAlbumsAdminList - Committed in:
652bfda
2. [Rule 2 - Missing Critical] Served the form schema over HTTP
- Found during: Task 1
- Issue: Form compilation existed, but no route served it, so permission-denied form requests could not be proven.
- Fix: Added
GET /{vendor}/{plugin}/{controller}/schema/formusing the sameprotectgate as the list schema. - Files modified:
cabana/http.go - Verification:
TestAlbumsAdminFormandTestAlbumsAdminPermissionOrder - Committed in:
c63146a
3. [Rule 1 - Bug] Matched Winter relation names to exported Go fields
- Found during: Task 1
- Issue:
relation: genredid not match fieldGenre, so the unchanged columns YAML could not activate. - Fix: Accept an exact field name, otherwise a case-insensitive relation match. JSON still says
genre. - Files modified:
cabana/list_schema.go,cabana/query.go,models/album.go - Verification:
go test ./cabanaandTestAlbumsAdminList - Committed in:
c63146a,652bfda
4. [Rule 2 - Missing Critical] Did not save-validate unbound relation required flags
- Found during: Task 3
- Issue:
artists.requiredmade every album create 422 before the collection hook ran. The field is not a writable column. - Fix: Merge
requiredinto save rules only for scalar writable field types. The schema JSON is unchanged. - Files modified:
cabana/crud.go - Verification:
go test ./cabanaandTestAlbumsAdminCollectionMatch - Committed in:
0caa86e
Total deviations: 4 auto-fixed (1 bug, 2 missing critical, 1 blocking) Impact on plan: Required for unchanged Winter YAML to boot and for album creates to reach the collection hook. No new album columns and no extra controllers.
Issues Encountered
TestPhase8RedMCPMe and TestOAuthToolsMeRouteIsolation fail because GET /_admin/api/v1/auth/me ends in /me. That route was already mounted with the admin API before this plan. It was left unchanged.
ADMIN-01, ADMIN-02, and ADMIN-04 stay pending in REQUIREMENTS.md. Later plans in this phase still declare them.
User Setup Required
None - no external service configuration required.
Next Phase Readiness
Ready for 09-07. Albums is the only new admin controller. Artists, Styles, and Collections controllers were not added. Genre remains the existing list tracer.
Self-Check: PASSED
- FOUND:
fonoteka.go60a4b10,652bfda,81f1aa4,5de760d,6004c6a,15dfefa - FOUND:
summercms.goc63146a,0caa86e - FOUND: albums controller, form YAML, columns YAML, and
backend_album_collection.go
Phase: 09-backend-admin-authentication-and-schema-pipeline Completed: 2026-09-24