Files
summercms/.planning/phases/10.1-runtime-admin-extension-point/10.1-DISCUSSION-LOG.md
2026-09-28 00:54:55 +02:00

168 lines
6.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Phase 10.1: Runtime admin extension point - Discussion Log
> **Audit trail only.** Do not use as input to planning, research, or execution agents.
> Decisions are captured in CONTEXT.md — this log preserves the alternatives considered.
**Date:** 2026-09-28
**Phase:** 10.1-runtime-admin-extension-point
**Areas discussed:** Acceptance target, Widget contract, Partials and custom toolbar actions, Asset load and CSP
---
## Acceptance target
| Option | Description | Selected |
|--------|-------------|----------|
| Fixture plugin | Framework test plugin ships widget + partial + custom button | |
| Wait for a real plugin | Seams only; first consumer is user/media | |
| Fixture now, real consumer later | Fixture proves contract; real plugin is a later port | |
| Other: fonoteka statistics + Discogs widget | Real Albums list stats strip and Albums form Discogs widget | ✓ |
**User's choice:** Add a statistics partial to the fonoteka plugin above the list, and a custom `fields.yaml` widget that is a button to load data from Discogs (stub until Phase 14).
**Notes:** “Above the list” is list chrome, not `type: partial` in `fields.yaml`. Screens locked to Albums list + Albums form.
| Option | Description | Selected |
|--------|-------------|----------|
| Click hits a stub endpoint | Enabled button, POST, Phase 14 replaces stub | ✓ |
| Visible but disabled | No request until Phase 14 | |
| Click only runs widget JS | No new backend action | |
**User's choice:** Stub endpoint.
| Option | Description | Selected |
|--------|-------------|----------|
| Albums list + Albums form | One controller owns both proofs | ✓ |
| Collections list + Albums form | Two controllers load different assets | |
| You decide | Planner picks screens | |
**User's choice:** Albums list + Albums form.
| Option | Description | Selected |
|--------|-------------|----------|
| Defer custom toolbar | create/delete only until a real third action | |
| Add one Albums list action now | Third button, stub POST | ✓ |
| Fixture-only custom action | No Płytarium toolbar change | |
**User's choice:** Add one Albums list action now.
---
## Widget contract
| Option | Description | Selected |
|--------|-------------|----------|
| SPA owns HTTP | CustomEvent; FieldRenderer POSTs with CSRF | ✓ |
| Tiny same-origin helper | SummerAdmin.request() | |
| Widget fetch() itself | Widget must remember X-Requested-With | |
**User's choice:** SPA owns HTTP.
| Option | Description | Selected |
|--------|-------------|----------|
| Patch declared fields | YAML `fill` keys; fixture payload allowed | ✓ |
| Toast only | Form unchanged | |
| Only this field’s value | Widget bound as one field | |
**User's choice:** Patch declared fields.
| Option | Description | Selected |
|--------|-------------|----------|
| Winter-shaped type: widget | tag/path, action, fill; unknown keys fail boot | ✓ |
| type + path only | Action and fill live in Go | |
| You decide | Planner picks keys | |
**User's choice:** Winter-shaped `type: widget`.
| Option | Description | Selected |
|--------|-------------|----------|
| Attributes + fill snapshot | record-id, field, locale, current fill values | ✓ |
| record-id only | Widget cannot see current name/year | |
| You decide | Planner picks attributes | |
**User's choice:** Attributes + fill snapshot.
---
## Partials and custom toolbar actions
| Option | Description | Selected |
|--------|-------------|----------|
| List-header only | Leave form `type: partial` as a boot error | |
| List-header and form type: partial | Both in this phase | ✓ |
| You decide | Planner scopes it | |
**User's choice:** Both.
| Option | Description | Selected |
|--------|-------------|----------|
| Curated view model | Typed struct from controller; auto-escaped | ✓ |
| Record map + extras | More Winter-like; leak risk | |
| You decide | Planner picks data shape | |
**User's choice:** Curated view model.
| Option | Description | Selected |
|--------|-------------|----------|
| config_list.yaml slot | e.g. headerPartial names the template | ✓ |
| Controller Go API only | No YAML key | |
| You decide | Planner picks declaration | |
**User's choice:** YAML slot.
| Option | Description | Selected |
|--------|-------------|----------|
| Named action + stub POST | toolbar.buttons string list; controller registers extras | ✓ |
| Inline map in YAML | strings or {action, label, confirm} | |
| You decide | Planner picks YAML | |
**User's choice:** Named action + stub POST.
---
## Asset load and CSP
| Option | Description | Selected |
|--------|-------------|----------|
| On controller open | Winter addJs/addCss timing | ✓ |
| All registered assets at login | Simpler, more JS in the admin origin | |
| Per widget/partial only | Finest grain, define() timing issues | |
**User's choice:** On controller open.
| Option | Description | Selected |
|--------|-------------|----------|
| Embed only | air / summer watch rebuilds; no disk-in-prod | ✓ |
| Dev-mode disk override | Original 10.1 note; rejected | |
| You decide | Planner picks | |
**User's choice:** Embed only.
| Option | Description | Selected |
|--------|-------------|----------|
| Under admin prefix, script-src 'self' | No unsafe-inline, no extra hosts | ✓ |
| Allow nonce inline for widgets | Weaker than current hygiene | |
| You decide | Planner picks URL layout | |
**User's choice:** Prefix + `script-src 'self'`.
| Option | Description | Selected |
|--------|-------------|----------|
| Go method on the controller | addJs/addCss; new interface name | ✓ |
| YAML asset list | js:/css: in config | |
| You decide | Planner picks Go vs YAML | |
**User's choice:** Go method.
---
## the agent's Discretion
- Exact YAML key names, JS/CSS interface name, stub payload/toast copy, stats numbers, form-partial proof vehicle, custom-element tag naming, create vs update for the widget, asset URL layout, PartialHost vs T-10-16, toolbar action identifier.
## Deferred Ideas
- Phase 14: real Discogs client and non-stub payloads
- Dev-mode disk override (rejected for v1)
- WASM extension API (v2)
- Phase 10 leftovers: Ctrl+K, badge columns, Playwright, user/media nav