Files
summercms/.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-VALIDATION.md
2026-09-24 15:56:40 +02:00

4.6 KiB

phase, slug, status, nyquist_compliant, wave_0_complete, created
phase slug status nyquist_compliant wave_0_complete created
09 backend-admin-authentication-and-schema-pipeline draft false false 2026-09-24

Phase 09 — Validation Strategy

Per-phase validation contract for feedback sampling during execution.


Test Infrastructure

Property Value
Framework Go 1.27 standard testing; existing Testcontainers-backed PostgreSQL integration harness
Config file none — package-local *_test.go files and repository go.work workspaces
Quick run command go test ./bouncer ./pact ./lagoon ./party ./surf
Full suite command go test ./... && (cd ../fonoteka.go && go test ./...)
Estimated runtime Focused package checks should complete within 60 seconds; full two-repository and Testcontainers runs may take several minutes

Sampling Rate

  • After every task commit: Run the narrowest affected package tests plus go vet ./... in the modified workspace.
  • After every plan wave: Run go test ./... in both summercms.go and fonoteka.go.
  • Before $gsd-verify-work: Full suites and the assembled admin authorization matrix must be green.
  • Max feedback latency: 60 seconds for task-level checks; multi-minute integration runs are reserved for wave and phase gates.

Per-Task Verification Map

Task ID Plan Wave Requirement Threat Ref Secure Behavior Test Type Automated Command File Exists Status
09-W0-01 TBD TBD AUTH-08 T-09-01 Backend tokens require the backend audience and secret; frontend/backend token crossover, empty secret, blacklist, and inactive/deleted principals fail closed unit + assembled integration `go test ./bouncer ./... -run 'Test.*(Admin Backend Audience
09-W0-02 TBD TBD ADMIN-01 T-09-02 Strict YAML parsing rejects unknown keys, unsupported field types, and invalid option providers before serving requests unit + golden fixture `go test ./pact/... -run 'Test.*(Field Form Schema
09-W0-03 TBD TBD ADMIN-02 T-09-03 Search, sort, relation, and renderer identifiers come only from compiled allowlists unit + integration `go test ./pact/... -run 'Test.*(Column List Search
09-W0-04 TBD TBD ADMIN-03 T-09-04 Relation linked/candidate queries are owner-scoped; link/unlink validates plugin-owned pivot fields PostgreSQL integration (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Relation' -count=1) ❌ W0 ⬜ pending
09-W0-05 TBD TBD ADMIN-04 T-09-05 CRUD hooks run in order, row scope applies before read/write, and bulk delete invokes each record lifecycle PostgreSQL integration `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*(Admin CRUD Bulk
09-W0-06 TBD TBD ADMIN-05 T-09-06 Settings read/write is permission-gated, singleton-scoped, fillable-only, and validated before persistence PostgreSQL integration (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Settings' -count=1) ❌ W0 ⬜ pending

Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky


Wave 0 Requirements

  • Framework schema compiler tests with golden JSON and malformed/unknown-key YAML fixtures.
  • Backend guard tests for empty secret, wrong audience, frontend/backend token swapping, blacklist, and inactive/deleted users.
  • Assembled raw-route authorization matrix covering every admin endpoint category and wildcard/superuser behavior.
  • Real-PostgreSQL tests for bulk-delete callbacks, relation pivot fields, candidate scoping, owner exclusion, and settings upsert.
  • Focused fixture and test naming finalized by the planner so every PLAN task maps to an executable command above.

Manual-Only Verifications

All Phase 9 backend behaviors are expected to have automated verification. Phase 10 owns browser rendering and interaction UAT for the generated schemas.


Validation Sign-Off

  • All tasks have <automated> verification or Wave 0 dependencies.
  • Sampling continuity: no three consecutive tasks lack automated verification.
  • Wave 0 covers all missing references.
  • No watch-mode flags appear in validation commands.
  • Task-level feedback latency is under 60 seconds.
  • nyquist_compliant: true is set after final plan/task IDs and commands are validated.

Approval: pending