4.6 KiB
4.6 KiB
phase, slug, status, nyquist_compliant, wave_0_complete, created
| phase | slug | status | nyquist_compliant | wave_0_complete | created |
|---|---|---|---|---|---|
| 09 | backend-admin-authentication-and-schema-pipeline | draft | false | false | 2026-09-24 |
Phase 09 — Validation Strategy
Per-phase validation contract for feedback sampling during execution.
Test Infrastructure
| Property | Value |
|---|---|
| Framework | Go 1.27 standard testing; existing Testcontainers-backed PostgreSQL integration harness |
| Config file | none — package-local *_test.go files and repository go.work workspaces |
| Quick run command | go test ./bouncer ./pact ./lagoon ./party ./surf |
| Full suite command | go test ./... && (cd ../fonoteka.go && go test ./...) |
| Estimated runtime | Focused package checks should complete within 60 seconds; full two-repository and Testcontainers runs may take several minutes |
Sampling Rate
- After every task commit: Run the narrowest affected package tests plus
go vet ./...in the modified workspace. - After every plan wave: Run
go test ./...in bothsummercms.goandfonoteka.go. - Before
$gsd-verify-work: Full suites and the assembled admin authorization matrix must be green. - Max feedback latency: 60 seconds for task-level checks; multi-minute integration runs are reserved for wave and phase gates.
Per-Task Verification Map
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---|---|---|---|---|---|---|---|---|---|
| 09-W0-01 | TBD | TBD | AUTH-08 | T-09-01 | Backend tokens require the backend audience and secret; frontend/backend token crossover, empty secret, blacklist, and inactive/deleted principals fail closed | unit + assembled integration | `go test ./bouncer ./... -run 'Test.*(Admin | Backend | Audience |
| 09-W0-02 | TBD | TBD | ADMIN-01 | T-09-02 | Strict YAML parsing rejects unknown keys, unsupported field types, and invalid option providers before serving requests | unit + golden fixture | `go test ./pact/... -run 'Test.*(Field | Form | Schema |
| 09-W0-03 | TBD | TBD | ADMIN-02 | T-09-03 | Search, sort, relation, and renderer identifiers come only from compiled allowlists | unit + integration | `go test ./pact/... -run 'Test.*(Column | List | Search |
| 09-W0-04 | TBD | TBD | ADMIN-03 | T-09-04 | Relation linked/candidate queries are owner-scoped; link/unlink validates plugin-owned pivot fields | PostgreSQL integration | (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Relation' -count=1) |
❌ W0 | ⬜ pending |
| 09-W0-05 | TBD | TBD | ADMIN-04 | T-09-05 | CRUD hooks run in order, row scope applies before read/write, and bulk delete invokes each record lifecycle | PostgreSQL integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*(Admin | CRUD | Bulk |
| 09-W0-06 | TBD | TBD | ADMIN-05 | T-09-06 | Settings read/write is permission-gated, singleton-scoped, fillable-only, and validated before persistence | PostgreSQL integration | (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Settings' -count=1) |
❌ W0 | ⬜ pending |
Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky
Wave 0 Requirements
- Framework schema compiler tests with golden JSON and malformed/unknown-key YAML fixtures.
- Backend guard tests for empty secret, wrong audience, frontend/backend token swapping, blacklist, and inactive/deleted users.
- Assembled raw-route authorization matrix covering every admin endpoint category and wildcard/superuser behavior.
- Real-PostgreSQL tests for bulk-delete callbacks, relation pivot fields, candidate scoping, owner exclusion, and settings upsert.
- Focused fixture and test naming finalized by the planner so every PLAN task maps to an executable command above.
Manual-Only Verifications
All Phase 9 backend behaviors are expected to have automated verification. Phase 10 owns browser rendering and interaction UAT for the generated schemas.
Validation Sign-Off
- All tasks have
<automated>verification or Wave 0 dependencies. - Sampling continuity: no three consecutive tasks lack automated verification.
- Wave 0 covers all missing references.
- No watch-mode flags appear in validation commands.
- Task-level feedback latency is under 60 seconds.
nyquist_compliant: trueis set after final plan/task IDs and commands are validated.
Approval: pending