23 KiB
gsd_state_version, milestone, milestone_name, status, stopped_at, last_updated, last_activity, progress
| gsd_state_version | milestone | milestone_name | status | stopped_at | last_updated | last_activity | progress | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1.0 | v1.0 | milestone | executing | Completed 06-11-PLAN.md | 2026-09-21T17:30:49.586Z | 2026-09-21 -- Phase 06 planning complete |
|
Project State
Project Reference
See: .planning/PROJECT.md (updated 2026-09-16)
Core value: An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test. Current focus: Phase 06 — http-routing-auth-groups-and-rate-limiting
Current Position
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING Plan: 11 of 11 Status: Ready to execute Last activity: 2026-09-21 -- Phase 06 planning complete
Progress: [██████████] 100%
Performance Metrics
Velocity:
- Total plans completed: 34
- Average duration: 21 min
- Total execution time: 104 min
By Phase:
| Phase | Plans | Total | Avg/Plan |
|---|---|---|---|
| 01 | 4 | - | - |
| 02 | 5 | - | - |
| 03 | 4 | - | - |
| 04 | 4 | - | - |
| 05 | 6 | - | - |
Recent Trend:
- Last 5 plans: 02-01 7 min, 02-02 12 min, 02-03 61 min, 02-04 9 min, 02-05 15 min
- Trend: -
Updated after each plan completion | Phase 03 P03-01 | 17 min | 2 tasks | 52 files | | Phase 03 P03-02 | 5 min | 2 tasks | 8 files | | Phase 03 P03-03 | 8 min | 2 tasks | 17 files | | Phase 03 P03-04 | 15 min | 2 tasks | 15 files | | Phase 04 P01 | 11 min | 3 tasks | 14 files | | Phase 04 P04-02 | 10 min | 3 tasks | 11 files | | Phase 04 P04-03 | 6 min | 3 tasks | 15 files | | Phase 04 P04-04 | 8 min | 3 tasks | 9 files | | Phase 05 P01 | 16 min | 4 tasks | 37 files | | Phase 05 P02 | 27 min | 3 tasks | 32 files | | Phase 05-data-layer-full-fidelity P03 | 15 min | 3 tasks | 28 files | | Phase 05 P04 | 18 min | 3 tasks | 18 files | | Phase 05 P05 | 18 min | 3 tasks | 18 files | | Phase 05 P06 | 23 min | 3 tasks | 12 files | | Phase 06 P01 | 25 min | 3 tasks | 26 files | | Phase 06 P02 | 14 min | 3 tasks | 16 files | | Phase 06 P03 | 20 min | 3 tasks | 24 files | | Phase 06 P05 | 13 min | 3 tasks | 13 files | | Phase 06 P06 | 1h 29m | 2 tasks | 3 files | | Phase 06 P07 | 12 min | 1 tasks | 4 files | | Phase 06 P08 | 1h 20m | 1 tasks | 3 files | | Phase 06 P09 | 4 min | 1 tasks | 2 files | | Phase 06 P10 | 3h 15m | 1 tasks | 2 files | | Phase 06 P11 | 12h 30m | 1 tasks | 1 files |
Accumulated Context
Roadmap Evolution
- Phase 2 edited: edited fields: depends_on (Phase 1), goal (summer parity:* on bonfire, no longer a parallel workstream)
Decisions
Decisions are logged in PROJECT.md Key Decisions table. Recent decisions affecting current work:
- Roadmap: gormigrate (not goose) is the migration tool, per STACK.md's more recent reasoning — ARCHITECTURE.md/PITFALLS.md text still says goose in places; treat gormigrate as authoritative when phases 3 and 5 are planned.
- Roadmap: two repos from day one —
summercms.go(framework, no app knowledge) andfonoteka.go(sibling app repo, go.work workspace of plugins). Every phase states which repo(s) it writes to. - Roadmap: the parity harness (Phase 2) and the first vertical slice (Phase 3) are sequenced immediately after kernel foundation, ahead of any further kernel broadening, to avoid the documented Scala-era bottom-up-kernel failure mode.
- [Phase 02]: tide is the framework-owned parity library and does not import Fonoteka — Phase 2 CONTEXT.md discretion; summercms.go must stay app-agnostic
- [Phase 02]: goccy/go-yaml v1.19.2 decodes fixtures with DisallowUnknownField; SaveFlow uses a dedicated encoder so nested literal bodies keep indent — goccy BytesMarshaler re-emitted |- scalars without nested indent; decode still uses the verified library
- [Phase 02]: JSON diffs ignore object key order and fail missing keys or token-type changes at $.path; non-JSON compares bytes at offset — D-13: structural JSON compare with UseNumber, exact bytes for non-JSON
- [Phase 02]: Proxy bind and upstream must be loopback HTTP; incoming Host/URL never selects the origin — T-02-01: pin PHP upstream, ignore client destination, cap bodies
- [Phase 02]: Capture rules and a private 0600 --vars store drive {{name}} substitution; unclassified credential shapes fail fixture writes — D-07 D-11 and T-02-02: never commit live JWT, inv_ tokens, OAuth codes or PKCE verifiers
- [Phase 02]: Carbon *_at values must match +00:00 before masking; Z, string ids, null vs [] and missing keys fail at $.path — D-13 D-15: assert shape before mask so parity classes stay visible
- [Phase 02]: 154 is the app manifest validated route count, not a framework constant; --next-batch above 15 is refused — D-16 and the 15-route resume workflow; keep tide generic
- [Phase 02]: Isolated PHP uses a parity-named SQLite file on 127.0.0.1:8423; record/reset refuse any other DB — T-02-05
- [Phase 02]: Client OAuth replay merges
/tmp/summercms-parity/pkce.varsafter seed; the verifier is not in git — D-07 D-11 - [Phase 02]: newTarget and seedHooks live in the app test package so Phase 3 can swap the synthetic handler for the real app and add a temporary genres SQL hook until POST genres is ported — D-10 D-12: framework tide stays app-agnostic; the handler/seed-hook seam is app-owned
- [Phase 02]: Pending never equals passing: TestParityCorpus reports recorded 154/154 passing 0 pending 154 and does not replay PHP fixtures against the synthetic handler — D-16: unported PHP routes must never count as a Go pass
- [Phase 02]: Unavailable Docker fails TestMain; testing.Short skips the container so the fast loop stays fast — QA-03 and D-12: no false green skip when Postgres cannot start
- [Phase 02]: Fresh PHP self-replay uses disposable MariaDB fonoteka_parity_* plus process-local hex credentials, never the developer DB or caller-supplied PHP_PARITY_TARGET — T-02-01 T-02-05: check-phase2.sh --fresh-php owns the origin and rejects PHP_PARITY_TARGET
- [Phase 02]: Client flows run on a second winter:up after dropping tables so they are not replayed after the mutating 154-route suite — D-16 and 02-03 seed-then-clients: keep route replay and Nuxt/MCP replay on disjoint schemas
- [Phase 02]: Capture-by-reference mismatch is a two-step share:item flow with a live token change on the second /show — D-11 D-13: contract tests exercise RecordFlow/ReplayFlow public APIs, not private helpers
- [Phase 03]: GORM and app services share one pgx-stdlib *sql.DB; the River LISTEN/NOTIFY pool is a Phase 11 seam and is not created in lagoon.Open — DATA-01: one shared pool now; dual-driver River listener deferred
- [Phase 03]: Generated app main stays framework-generic (lagoon.RuntimeCommands + surf.ServeCommand); fonoteka.go/app.Handler is the in-process boot seam for parity tests — summer build cannot import the app package; CLI serve and tests still assemble the same surf router
- [Phase 03]: Empty golem15.user.jwt.secret fails Boot; tests use a fixed test-only HS256 secret and do not issue tokens through a production API — D-11: missing secret must not fall back; token minting stays out of Phase 3
- [Phase 03]: lagoon.OrderBy takes a caller allow-list so the framework never hardcodes Fonoteka table names; the handler passes PHP PolishOrder::ALLOWED_COLUMNS — summercms.go must stay app-agnostic; PolishOrder columns live at the Fonoteka call site
- [Phase 03]: Duplicate non_empty query keys last-win, matching PHP parse_str; invalid then 1 is accepted, 1 then invalid is 422 — PHP parse_str last-wins confirmed with php -r; Go uses vals[len(vals)-1]
- [Phase 03]: Invalid stored context is rewritten to the lowest-ID accessible kind=collection row; auto-provisioning stays out of this slice — Plan 03-02 ports only the JWT default resolve path; CollectionProvisioner is Phase 12
- [Phase 03]: Route constraints compile regex and enum allow-lists at registration; request path text is only matched — D-15 T-03-07: PHP ->where() maps onto surf.Where/WhereIn; malformed and unknown IDs share a 404
- [Phase 03]: A ported route with a trusted seed_hook skips the global PHP bootstrap replay — D-20: unported register/login and POST genres; the hook mints a test-only JWT
- [Phase 03]: Corpus passing increments only after the ported subtest succeeds; pending never counts as passing — QA-04 T-03-06: 154 recorded, 1 passing, 153 pending
- [Phase 03]: Colliding fixture IDs are derived from CanonicalGenres seed order (rock=1, electronic=2, jazz=4) — D-20: set id:token, id:wishlist-album, id:genre from PHP seed order, not user input
- [Phase 03]: Phase 3 gate inlines TestParitySynthetic and CLI record/replay; PHP --fresh-php stays the Phase 2 sign-off because four wishlist album_count routes currently fail on live PHP — check-phase2.sh --fresh-php reports 150/154 on wishlist album_count expected 1 vs live 2. Phase 3 did not change PHP, tide, or those fixtures, so the Phase 3 gate must not fail on that drift.
- [Phase 03]: testcontainers-go v0.44.0 is the STACK-named test dependency for framework lagoon isolation tests, matching the app TestMain — DATA-01 isolation tests need a real ICU pl-PL Postgres. The app already used testcontainers; the framework module now pins the same STACK versions so lagoon tests do not share the app TestMain.
- [Phase 03]: High-severity T-03-01 through T-03-04 and T-03-06 are closed with failing-when-broken tests; token issuing remains test-only until Phase 7 — Roadmap required a security review of the JWT guard. 03-SECURITY-REVIEW.md maps each threat to a passing test; minting tokens through a production API is out of this slice.
- [Phase 04]: registry.gen.go is regenerated by scanning Code generated by summer make files, not by rewriting plugin.go — D-12: handwritten plugin.go stays byte-identical; existing plugins get a one-time accessor hint
- [Phase 04]: make:model table names are vendor_plugin_plural_snake with explicit gormigrate CREATE/DROP TABLE — D-13: timestamps on the model; --no-migration omits only the create-table file
- [Phase 04]: models sibling-import check runs in build.App before go build and reports plugin ID, file, and import — D-11: limited to classes/controllers/console/jobs/middleware/updates of the same plugin module
- [Phase 04]: go-i18n is used only to choose a CLDR category label; YAML message text never enters its template engine — D-03: PHP :name placeholders must remain literal
- [Phase 04]: A per-locale i18n.Bundle is cached so matcher/plural rules follow the requested tag, not the English default bundle — A single English default bundle made Polish few/many look invalid
- [Phase 04]: Fallback order is requested, parent, app.fallback_locale, then the raw key; framework defaults remain en/en — D-04 D-05: no Polish framework default and no extra core-locale step
- [Phase 04]: Goldmark v1.8.6 is used without html.WithUnsafe; final HTML is rejected if script/iframe, event handlers, or javascript/vbscript/data schemes remain — D-07 and T-04-08: Goldmark default rejects raw HTML; a second pass keeps layout HTML trusted only as template.HTML
- [Phase 04]: postcard.Mailer is published after Register and before Boot; each HasMailTemplates catalog is validated at that plugin Boot transition — D-20 D-21: plugin Boot can Lookup the mailer; missing files fail as party: boot with the dotted name
- [Phase 04]: mail.smtp.tls defaults to mandatory STARTTLS; none/notls is opt-in for Mailpit and is never inferred — D-18 T-04-10: no silent production TLS downgrade; Mailpit needs explicit NoTLS
- [Phase 04]: Mailpit image is axllent/mailpit:v1.31.1; receipt is polled from /api/v1/messages then /api/v1/message/{ID} — D-19: a successful Send claim requires observed receipt through a separate HTTP API; pin a released Mailpit tag
- [Phase 04]: fstest.MapFS WalkDir cannot host '..' keys; malformed lang paths are extra-segment and wrong-suffix files — MapFS Open/WalkDir follows .. into an infinite directory loop; parseLangPath still rejects cleaned traversal
- [Phase 05]: Models-leaf rule holds on keios.eu user, jz chat, and pxpx checkout; contracts/VOs/jobs/broadcasting stay inside the cast-or-hook conversion treatments
- [Phase 05]: plugin.go Models()/Migrations() return registry All(); Boot calls classes.RegisterHooks when *gorm.DB is published — later Phase 5 plans add files, not edit plugin.go
- [Phase 05]: lagoon.Fill matches gorm column tags against the caller allow-list and logs dropped keys once per type+key in non-production — D-05 D-06
- [Phase 05]: Lifecycle Has* interfaces use GORM-native signatures; WithSoftDeleteCascade does not open a new transaction — DATA-03 primitive
- [Phase 05]: Paginate coerces nil data to []; RegisterJoinTable fails loud on nil db — DATA-10 and pivot-write contract
- [Phase 05]: DATA-09 migration count is not an acceptance number (D-01); HTTP DTO fuzz moves to Phase 12 (D-07)
- [Phase 05]: Jsonable payload field is Data, not Value, because driver.Valuer.Value() collides under go vet — go vet rejects a field and method both named Value; type Jsonable[T] T is illegal
- [Phase 05]: KeepMarketPriceSource is a gorm-ignored Album flag set by SaveAlbum when requested contains market_price_source — GORM has no Eloquent isDirty; the flag preserves stampMarketPrice source provenance
- [Phase 05]: CollectionFillFields is name+description; PHP has no CollectionWriteService — D-05 service list is a subset of Fillable excluding owner_id
- [Phase 05]: Various Artists natural key is name_key='various artists' (PHP seed), slug various-artists — seed_genre_and_various_artist_taxonomy.php uses a spaced name_key
- [Phase 05]: go-playground/validator v10.30.4 is the STACK-named rule engine behind lagoon.Validate — STACK.md already named this library; lagoon.Validate translates Laravel rule strings onto Var()
- [Phase 05]: Column keys are HKDF-SHA256 derived via Go 1.27 crypto/hkdf with info summercms.lagoon.encrypted.v1; no golang.org/x/crypto — D-11 stdlib-first: Go 1.24+ ships HKDF; CLAUDE.md forbids a new dependency here
- [Phase 05]: Ciphertext is 1-byte format/key-id | 12-byte nonce | GCM seal, stored base64 in text columns — D-12 versioned ciphertext plus app.previous_keys decrypt-only fallback
- [Phase 05]: OpenFromApp calls LoadAppKey+PublishEncryptionKeys once per boot; empty/short/undecodable app.key fails with SUMMER_APP__KEY — D-11 fail-loud, no default key; Scan/Value must not re-read config per row
- [Phase 05]: golem15_user_organisations is owned by the user plugin; Phase 5 ships no users-table ALTER (D-03 deviation, Phase 7 AUTH-02) — User-confirmed at plan time: organisations are an FK target only this phase
- [Phase 05]: DecryptLaravelPayload is cutover-import-only and is never called from Encrypted Scan/Value — D-10 live path is AES-256-GCM only; Laravel CBC is Phase 15 import
- [Phase 05]: Blob keys are partition+disk_name (no public/protected prefix); fileblob roots at storage/app/uploads — StaticHandler reconstructs keys from PartitionDirectory+disk_name; cutover can point bucket_url at uploads/public
- [Phase 05]: DeleteForOwner afterCommit is an in-tx key collector; DeleteKeys removes originals and thumb__ prefixes after commit — GORM has no post-commit hook; a rollback must not have already deleted bytes
- [Phase 05]: Album/Collection MorphName returns the PHP class string and does not import attach (models stay a leaf) — models-leaf rule; interface satisfaction is implicit
- [Phase 05]: Settings is golem15_fonoteka_settings singleton with typed search_use_typesense BOOLEAN (RESEARCH Open Question 2) — PHP SettingsModel over system_settings is not ported; dedicated typed table is the user-resolved storage
- [Phase 05]: notifications/wishlist_subscriptions/wishlist_digest_queue have no FK on user_id/collection_id, matching PHP (Open Question 3 / T-05-18) — PHP migrations omit ->foreign() on these tables; D-02 matches actual constraints rather than fixing them
- [Phase 05]: D-02 allow-list is settings table, users column-count (no widen_users), and the shipped extra oauth_refresh_tokens.user_id FK — Intended gaps only: Open Question 2, D-03/AUTH-02, and P3 D-17 freeze of 05-03 extra FK
- [Phase 05]: DATA-11 fixture plugin is test-only: no process-wide Register, not in app.PluginIDs or plugins.gen.go — CONTEXT.md discretion: fixture plugin in tests is acceptable; production binary must not load it
- [Phase 05]: Hidden-marshal registry walk lives in fonoteka.go/classes because summercms.go must not import the app — CLAUDE.md two-repo rule; plan allowed the parity/classes fallback
- [Phase 05]: Credential fuzz excludes owner FKs from the working allow-list, matching D-05 two-layer even without a write-service file — Fillable() includes user_id/organisation_id; acceptance requires the owner FK never change
- [Phase 05]: classes TestMain is the real-Postgres harness; parity activateAppPlugins/parityDB cannot be imported from package main — Same ICU pl-PL migrate-both-plugins shape without crossing the app/framework test boundary
- [Phase 06]: Parameterized middleware is a surf factory (strings.Cut on first ':'), not a fixed name table (D-05)
- [Phase 06]: TokenGuard implements CredentialGuard only; InvScope owns PHP TokenScope 401/403 bodies (D-08)
- [Phase 06]: NewJWTGuard reuses bearerToken/Verify/write401 so Registry.Middleware(jwt) is byte-identical to bouncer.Middleware (D-10)
- [Phase 06]: oauth is not registered this plan; only jwt and inv_token (D-09)
- [Phase 06]: Personal-token genres fixture body matches isolated seedGenres; CORS * deferred to D-18
- [Phase 06]: Concrete limiter is FixedWindowLimiter; surf.Limiter interface remains the unused Phase 3 seam — D-03 D-05 naming collision with pre-existing Limiter interface
- [Phase 06]: Trusted-proxy list is a NewFixedWindowLimiter constructor argument, never a setter — Named-bucket Key closures and inline N,M must share one trusted list
- [Phase 06]: fonoteka-* buckets live on the app plugin via surf.BucketProvider, not hardcoded in surf — summercms.go must stay Płytarium-agnostic
- [Phase 06]: Empty PHP group builders plus test-only boot-probe routes prove middleware strings resolve without 501 shells — D-15: no 501 shells; wrap() only sees routes
- [Phase 06]: php_parity.sh pins APP_DEBUG=false; three existing HTML exception fixtures need re-recording — T-06-09 production-shaped error bodies
- [Phase 06]: HasHouseMiddleware is the only plugin-facing house-tag path; Assemble/BuildRouter is the sole RegisterHouseMiddleware caller (D-16)
- [Phase 06]: Production body limits are 134217728/134217728 (128MiB), operator-confirmed 2026-09-19 from nginx client_max_body_size=128M and php.ini post_max_size=128M/upload_max_filesize=128M (D-18, T-06-13)
- [Phase 06]: CORS path globs compile as Laravel nested * because Go path.Match would miss /api/v1/fonoteka/genres (Pitfall 10)
- [Phase 06]: swag v1 Swagger 2 is converted by a local swagger2openapi helper to OpenAPI 3 for openapi-typescript 7; Phase 10 wires types into the admin SPA
- [Phase 06]: Full route-table isolation uses surf.BuildRouter of the real plugins; app.Handler returns http.Handler and cannot call Routes() — app.Handler assembles an http.Handler; Routes() is on *surf.Router
- [Phase 06]: T-06-05 remains accept as originating 06-01 (the 06-05 plan three-accepts list omitted it) — Originating plan disposition is copied verbatim into 06-SECURITY-REVIEW.md
- [Phase 06]: PublicOnlyMode any-host-when-public is proven via skipReservedCheck httptest, not a live public IP dial — Unit tests must not require outbound network
- [Phase 06]: Keep inv_token outermost so valid credentials populate bouncer.Credential before the limiter selects tok:. — The named bucket must retain per-token isolation for valid credentials instead of collapsing them onto the IP fallback.
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
- [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u: isolation.
- [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy.
- [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6.
- [Phase 06]: Use one unexported bufferedResponse for house and raw recovery — A shared transactional writer keeps panic-before-write and panic-after-write behavior identical while preserving raw versus house fallback bodies.
- [Phase 06]: Keep bufferedResponse Flush as a no-op — Recovery must never unwrap, hijack, flush, or otherwise expose the destination writer before handler success.
- [Phase 06]: Success commit replaces only route-owned header keys — Unrelated headers already placed on the destination by outer wrappers such as path-scoped CORS must survive.
- [Phase 06]: Use wire.WriteJSON for both InvScope denial branches — The shared writer is the established PHP-compatible no-newline serialization path.
- [Phase 06]: Assert exact denial bytes before JSON shape checks — Whitespace normalization would hide response-contract regressions.
- [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
- [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u: keys.
Pending Todos
None yet.
Blockers/Concerns
- Phase 8 (OAuth2.1) needs a pre-planning check of
wavepath.org/plugins/golem15/oauthserverto resolve whetherClientCredentialsStorage/TokenExchangeStorageare needed — flagged in research/SUMMARY.md Gaps, unresolved. - Phase 9 (admin schema pipeline / relation manager) is the least-precedented design surface in the research — plan with
--research-phase. - Phase 11 (River dual-driver split) is documented but unverified against a real build — plan with
--research-phaseand budget a timed-latency test.
Deferred Items
Items acknowledged and carried forward from previous milestone close:
| Category | Item | Status | Deferred At |
|---|---|---|---|
| (none — first milestone) |
Session Continuity
Last session: 2026-09-21T11:04:05.263Z Stopped at: Completed 06-11-PLAN.md Resume file: None