Six sequential plans: framework gaps, notifications/credentials/onboarding, wishlist, CSV, public views, unit tests and gate. Research open questions marked resolved per the plan-count checkpoint.
101 lines
10 KiB
Markdown
101 lines
10 KiB
Markdown
---
|
|
phase: "13"
|
|
slug: "p-ytarium-api-wishlist-notifications-csv-credentials-public"
|
|
# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6)
|
|
# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117)
|
|
status: draft
|
|
nyquist_compliant: false
|
|
wave_0_complete: false
|
|
created: "2026-10-02"
|
|
---
|
|
|
|
# Phase 13 — Validation Strategy
|
|
|
|
> Per-phase validation contract for feedback sampling during execution.
|
|
|
|
---
|
|
|
|
## Test Infrastructure
|
|
|
|
| Property | Value |
|
|
|----------|-------|
|
|
| **Framework** | Go `testing` (+ testify, Go fuzzing), testcontainers Postgres |
|
|
| **Config file** | none — `fonoteka.go/parity/parity_test.go` TestMain starts Postgres |
|
|
| **Quick run command** | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka/... ./plugins/golem15/user/... -short -count=1` |
|
|
| **Full suite command** | `go vet ./... && go test ./... -count=1 && go -C ../fonoteka.go vet ./... && go -C ../fonoteka.go test ./... -count=1` |
|
|
| **Parity command** | `go -C ../fonoteka.go test ./parity -run 'TestParityCorpus|TestBroadcastGoldens|TestFonotekaNuxtFlows' -count=1` |
|
|
| **Phase gate** | `scripts/check-phase13.sh --self-test && scripts/check-phase13.sh --all` (run from summercms.go; the script lives in summercms.go/scripts like check-phase12.sh) |
|
|
| **Estimated runtime** | ~180 seconds (full suite with testcontainers) |
|
|
|
|
---
|
|
|
|
## Sampling Rate
|
|
|
|
- **After every task commit:** Run the quick run command plus `go vet` in the touched repo
|
|
- **After every plan wave:** Run the full suite command, the parity command and the corpus check
|
|
- **Before `/gsd-verify-work`:** `scripts/check-phase13.sh --all` must be green
|
|
- **Max feedback latency:** 180 seconds
|
|
|
|
---
|
|
|
|
## Per-Task Verification Map
|
|
|
|
Filled by the planner per task; the requirement → test map lives in `13-RESEARCH.md` § Validation Architecture.
|
|
|
|
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|
|
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
|
|
| 13-01-01 | 01 | 1 | API-03 (framework) | T-13-23 | Overlapping constrained routes dispatch to the right handler; app wishlist shapes dispatch | unit | `go test ./modules/surf -run '^(TestOverlappingConstrainedRoutes)$' -count=1 -v` ; `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestWishlistOverlapPatternsDispatch)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
|
| 13-01-02 | 01 | 1 | API-03, API-05 (framework) | T-13-22 | Unregistered job kinds queue while a worker runs and are never discarded; job contract pinned | integration | `go test ./modules/conga -run '^(TestUnregisteredKindWithWorker)$' -count=1 -v` ; `go -C ../fonoteka.go test ./plugins/golem15/fonoteka ./plugins/golem15/fonoteka/classes -run '^(TestJobContract|TestJobContractDispatchWhileWorkerRuns)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
|
| 13-01-03 | 01 | 1 | API-03, API-05 (framework) | T-13-24, T-13-25 | prohibited rule; Content-Disposition date and publication masks never hide a real diff | unit | `go test ./modules/lagoon ./modules/tide -run '^(TestValidateRequestProhibited|TestNormalizeContentDispositionDate|TestNormalizeNotificationPublication)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
|
| 13-01-04 | 01 | 1 | API-03..API-07 | T-13-26 | Queue override, rows dump, share:wishlist capture, ported case-status check, planning rewording | unit | `go -C ../fonoteka.go test ./parity -run '^(TestCheckCorpusPortedCaseStatus|TestParityCorpus)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
|
| 13-02-01 | 02 | 2 | API-04 | T-13-21 | Bell list newest 50, caller's rows only | parity + smoke | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestNotificationsRoutes)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-02-02 | 02 | 2 | API-04, API-06 | T-13-08, T-13-09, T-13-10, T-13-21 | Notifications read; credentials CRUD encrypted, secret-free, org checks, AI/Discogs resolution order | parity + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestNotificationsRoutes|TestCredentialsCRUD|TestCredentialSecretsNeverSerialized|TestResolveAIConfigPrecedence|TestDiscogsSharedMirror)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-02-03 | 02 | 2 | API-07 | T-13-18, T-13-19, T-13-20, T-13-27 | Single first owner; register hook; payload without passwords; inspection | parity flow + integration | `go -C ../fonoteka.go test ./plugins/golem15/user -run '^(TestRegisterEventPayload)$' -count=1 -v` ; `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestBootstrapConcurrent|TestRegisterInvitationListener|TestInspectInvitation)$' -count=1 -race -v` ; `TestFonotekaNuxtFlows/onboarding` | ❌ | ⬜ pending |
|
|
| 13-03-01 | 03 | 3 | API-03 | T-13-05 | Own wishlist list/show on both groups with the reservation mask | parity + smoke | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestWishlistOwnListAndShow)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-03-02 | 03 | 3 | API-03 | T-13-28 | Item writes, prohibited 422, item-added once per path, digest coalescing, share/settings/household | parity + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestWishlistItemAddedOncePerPath|TestDigestCoalescing|TestWishlistShareSettingsHousehold)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-03-03 | 03 | 3 | API-03 | T-13-04, T-13-05, T-13-06, T-13-07, T-13-29, T-13-30 | Subscriptions, secret reservations, reveal, purchase with mail after commit, peers, overlap routes assembled | parity + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestReserveConcurrent|TestRevealIdempotent|TestReservationMask|TestWishlistSubscriptions|TestPurchaseSideEffects|TestPurchaseMailAfterCommit|TestWishlistOverlapRoutesAssembled)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-03-04 | 03 | 3 | API-03 | T-13-28 | nuxt-wishlist and mcp-wishlist flows, digest rows, publication goldens | parity flow | `go -C ../fonoteka.go test ./parity -run '^(TestFonotekaNuxtFlows|TestBroadcastGoldens)$' -count=1 -v` | ❌ | ⬜ pending |
|
|
| 13-04-01 | 04 | 4 | API-05 | T-13-14 | Export with PHP fputcsv quoting, BOM, header, formula guard | parity + unit | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka/classes/csv -run '^(TestPHPFputcsv)$' -count=1 -v` ; `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCsvExport)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-04-02 | 04 | 4 | API-05 | T-13-12, T-13-13, T-13-15 | Parser truth tables across encodings and limits; private storage; import scope | unit + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka/classes/csv -run '^(TestCsvParserTruthTable|TestCsvDetectorTruthTable)$' -count=1 -v` ; `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCsvStoreAndShow|TestCsvImportScope)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-04-03 | 04 | 4 | API-05 | T-13-16, T-13-17, T-13-31 | Commit CAS, job rows, cancel, Discogs seam, nuxt-csv flow | parity flow + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCsvCommitCAS|TestCsvJobRows|TestCsvCancel|TestCsvRowPickSeam)$' -count=1 -race -v` ; `TestFonotekaNuxtFlows/nuxt-csv` | ❌ | ⬜ pending |
|
|
| 13-05-01 | 05 | 5 | API-07 | T-13-01, T-13-03, T-13-33 | Public resolve, exact headers, pubfail counter, D-14 layout | parity + smoke | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestPublicResolve|TestPubfailCounter)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-05-02 | 05 | 5 | API-03, API-07 | T-13-01, T-13-02 | Public albums, facets, field set, per-route buckets | parity + smoke | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestPublicBucketsPerRoute|TestPublicAlbumFieldSet)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-05-03 | 05 | 5 | API-07 | T-13-01, T-13-03 | public-anonymous and public-pubfail flows | parity flow | `go -C ../fonoteka.go test ./parity -run '^(TestFonotekaNuxtFlows)$' -count=1 -v` | ❌ | ⬜ pending |
|
|
| 13-06-01 | 06 | 6 | API-03..API-07 (C-01) | T-13-07, T-13-23 | Route table: groups, scopes, constraints, throttles, Phase 14 routes absent | unit | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestRouteTablePhase13)$' -count=1 -race -v` | ❌ | ⬜ pending |
|
|
| 13-06-02 | 06 | 6 | API-03..API-07 (C-04) | all mitigated T-13 | Request-DTO fuzz over every write route; one test per threat | fuzz + integration | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(FuzzWriteEndpoints|TestPhase13Threats)$' -count=1 -race -v` | ✅ extend | ⬜ pending |
|
|
| 13-06-03 | 06 | 6 | API-03..API-07 | T-13-34, T-13-35, T-13-36 | Coverage, fail-closed gate, security review, validation sign-off | gate | `scripts/check-phase13.sh --self-test && scripts/check-phase13.sh --all && scripts/check-phase13.sh --removal` | ❌ | ⬜ pending |
|
|
|
|
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
|
|
|
|
---
|
|
|
|
## Wave 0 Requirements
|
|
|
|
- [ ] `surf` constraint-aware overlap dispatch, plus a test (blocks every wishlist route)
|
|
- [ ] `conga` unregistered-kind insert while a worker runs, plus a test
|
|
- [ ] `lagoon` `prohibited` rule; tide Content-Disposition date and notification publication masks
|
|
- [ ] `php_parity.sh` `QUEUE_CONNECTION` override; `capture-rules.yaml` `share:wishlist` capture
|
|
- [ ] `fonoteka_reset.php` + `seedFonotekaCase` states: `wishlist`, `csv`, `credentials`, `empty`, `invite-for-register`
|
|
- [ ] `scripts/check-phase13.sh` (copy of the check-phase12 structure)
|
|
|
|
---
|
|
|
|
## Manual-Only Verifications
|
|
|
|
| Behavior | Requirement | Why Manual | Test Instructions |
|
|
|----------|-------------|------------|-------------------|
|
|
| Re-recording PHP fixtures against the isolated PHP instance | API-03..API-07 | Needs the local PHP stack running | Run `php_parity.sh` recordings per D-12 with the database queue override |
|
|
|
|
---
|
|
|
|
## Validation Sign-Off
|
|
|
|
- [ ] All tasks have `<automated>` verify or Wave 0 dependencies
|
|
- [ ] Sampling continuity: no 3 consecutive tasks without automated verify
|
|
- [ ] Wave 0 covers all MISSING references
|
|
- [ ] No watch-mode flags
|
|
- [ ] Feedback latency < 180s
|
|
- [ ] `nyquist_compliant: true` set in frontmatter
|
|
|
|
**Approval:** pending
|