506 lines
64 KiB
Markdown
506 lines
64 KiB
Markdown
---
|
|
gsd_state_version: "1.0"
|
|
milestone: v1.0
|
|
current_phase: 12
|
|
current_phase_name: Płytarium API — Collections and Albums
|
|
status: executing
|
|
stopped_at: Completed 12-04-PLAN.md
|
|
last_updated: "2026-10-02T12:44:01.203Z"
|
|
last_activity: 2026-10-02
|
|
last_activity_desc: Phase 12 execution started
|
|
state_head: 3cf2b38a8c84fc1251599679b9ab16f5b321566d
|
|
progress:
|
|
total_phases: 21
|
|
completed_phases: 10
|
|
total_plans: 101
|
|
completed_plans: 100
|
|
milestone_name: milestone
|
|
---
|
|
|
|
# Project State
|
|
|
|
## Project Reference
|
|
|
|
See: .planning/PROJECT.md (updated 2026-09-16)
|
|
|
|
**Core value:** An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test.
|
|
**Current focus:** Phase 12 — Płytarium API — Collections and Albums
|
|
|
|
## Current Position
|
|
|
|
Phase: 12 (Płytarium API — Collections and Albums) — EXECUTING
|
|
Plan: 5 of 5
|
|
Status: Ready to execute
|
|
Last activity: 2026-10-02 — Phase 12 execution started
|
|
|
|
Progress: [██████░░░░] 60%
|
|
|
|
## Performance Metrics
|
|
|
|
**Velocity:**
|
|
|
|
- Total plans completed: 62
|
|
- Average duration: 21 min
|
|
- Total execution time: 104 min
|
|
|
|
**By Phase:**
|
|
|
|
| Phase | Plans | Total | Avg/Plan |
|
|
|-------|-------|-------|----------|
|
|
| 01 | 4 | - | - |
|
|
| 02 | 5 | - | - |
|
|
| 03 | 4 | - | - |
|
|
| 04 | 4 | - | - |
|
|
| 05 | 6 | - | - |
|
|
| 06 | 14 | - | - |
|
|
| 7 | 8 | - | - |
|
|
| 08 | 10 | - | - |
|
|
| 10 | 5 | - | - |
|
|
| 10.2 | 2 | - | - |
|
|
|
|
**Recent Trend:**
|
|
|
|
- Last 5 plans: 02-01 7 min, 02-02 12 min, 02-03 61 min, 02-04 9 min, 02-05 15 min
|
|
- Trend: -
|
|
|
|
*Updated after each plan completion*
|
|
| Phase 03 P03-01 | 17 min | 2 tasks | 52 files |
|
|
| Phase 03 P03-02 | 5 min | 2 tasks | 8 files |
|
|
| Phase 03 P03-03 | 8 min | 2 tasks | 17 files |
|
|
| Phase 03 P03-04 | 15 min | 2 tasks | 15 files |
|
|
| Phase 04 P01 | 11 min | 3 tasks | 14 files |
|
|
| Phase 04 P04-02 | 10 min | 3 tasks | 11 files |
|
|
| Phase 04 P04-03 | 6 min | 3 tasks | 15 files |
|
|
| Phase 04 P04-04 | 8 min | 3 tasks | 9 files |
|
|
| Phase 05 P01 | 16 min | 4 tasks | 37 files |
|
|
| Phase 05 P02 | 27 min | 3 tasks | 32 files |
|
|
| Phase 05-data-layer-full-fidelity P03 | 15 min | 3 tasks | 28 files |
|
|
| Phase 05 P04 | 18 min | 3 tasks | 18 files |
|
|
| Phase 05 P05 | 18 min | 3 tasks | 18 files |
|
|
| Phase 05 P06 | 23 min | 3 tasks | 12 files |
|
|
| Phase 06 P01 | 25 min | 3 tasks | 26 files |
|
|
| Phase 06 P02 | 14 min | 3 tasks | 16 files |
|
|
| Phase 06 P03 | 20 min | 3 tasks | 24 files |
|
|
| Phase 06 P05 | 13 min | 3 tasks | 13 files |
|
|
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
|
|
| Phase 06 P07 | 12 min | 1 tasks | 4 files |
|
|
| Phase 06 P08 | 1h 20m | 1 tasks | 3 files |
|
|
| Phase 06 P09 | 4 min | 1 tasks | 2 files |
|
|
| Phase 06 P10 | 3h 15m | 1 tasks | 2 files |
|
|
| Phase 06 P11 | 12h 30m | 1 tasks | 1 files |
|
|
| Phase 07 P01 | 12 min | 3 tasks | 20 files |
|
|
| Phase 07 P02 | 83m | 3 tasks | 22 files |
|
|
| Phase 07 P03 | 95m | 3 tasks | 28 files |
|
|
| Phase 07 P04 | 75m | 3 tasks | 16 files |
|
|
| Phase 07 P05 | 45 | 3 tasks | 45 files |
|
|
| Phase 07 P06 | 40 min | 3 tasks | 8 files |
|
|
| Phase 07 P07 | 3h 15m | 3 tasks | 28 files |
|
|
| Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files |
|
|
| Phase 07-user-plugin-and-authentication P08 | 25min | 3 tasks | 6 files |
|
|
| Phase 08 P01 | 25min | 2 tasks | 6 files |
|
|
| Phase 08 P02 | 30min | 3 tasks | 14 files |
|
|
| Phase 08 P03 | 20min | 2 tasks | 6 files |
|
|
| Phase 08 P04 | 15min | 2 tasks | 5 files |
|
|
| Phase 08 P05 | 55min | 3 tasks | 12 files |
|
|
| Phase 08 P06 | 50min | 3 tasks | 10 files |
|
|
| Phase 08 P07 | 35min | 2 tasks | 9 files |
|
|
| Phase 08 P08 | 20min | 2 tasks | 4 files |
|
|
| Phase 08 P09 | 55min | 3 tasks | 25 files |
|
|
| Phase 08 P10 | 55min | 3 tasks | 17 files |
|
|
**Per-Plan Metrics:**
|
|
|
|
| Plan | Duration | Tasks | Files |
|
|
|------|----------|-------|-------|
|
|
| Phase 09 P01 | 26min | 2 tasks | 26 files |
|
|
| Phase 09 P02 | 22 min | 3 tasks | 14 files |
|
|
| Phase 09 P03 | 25min | 3 tasks | 10 files |
|
|
| Phase 09 P04 | 36min | 3 tasks | 13 files |
|
|
| Phase 09 P05 | 25min | 3 tasks | 8 files |
|
|
| Phase 09 P06 | 29min | 3 tasks | 15 files |
|
|
| Phase 09 P07 | 2h20m | 2 tasks | 9 files |
|
|
| Phase 09 P08 | 2h28m | 2 tasks | 4 files |
|
|
| Phase 09 P09 | 11h 48m | 2 tasks | 9 files |
|
|
| Phase 09 P10 | 2h 20m | 3 tasks | 17 files |
|
|
| Phase 09 P11 | 1h 15m | 3 tasks | 21 files |
|
|
| Phase 10 P01 | 31min | 3 tasks | 111 files |
|
|
| Phase 10 P02 | 50min | 3 tasks | 63 files |
|
|
| Phase 10 P03 | 23 min | 3 tasks | 64 files |
|
|
| Phase 10 P04 | 21min | 2 tasks | 42 files |
|
|
| Phase 10 P05 | 53 min | 3 tasks | 76 files |
|
|
| Phase 10.2 P01 | 10h56m | 3 tasks | 404 files |
|
|
| Phase 10.2 P02 | 14m | 3 tasks | 20 files |
|
|
| Phase 10.1 P01 | 25min | 3 tasks | 33 files |
|
|
| Phase 10.1 P02 | 17 min | 3 tasks | 29 files |
|
|
| Phase 10.1 P03 | 11min | 3 tasks | 16 files |
|
|
| Phase 10.1 P04 | 42min | 3 tasks | 32 files |
|
|
| Phase 11 P01 | 37 min | 3 tasks | 50 files |
|
|
| Phase 11 P02 | 385 min | 2 tasks | 21 files |
|
|
| Phase 11 P03 | 12h 45m | 3 tasks | 31 files |
|
|
| Phase 11 P05 | 24 min | 2 tasks | 14 files |
|
|
| Phase 11 P06 | 23 min | 3 tasks | 39 files |
|
|
| Phase 11 P04 | 17 min | 2 tasks | 19 files |
|
|
| Phase 11 P07 | 59min | 3 tasks | 40 files |
|
|
| Phase 11 P08 | unknown (manual close-out) | 3 tasks | 13 files |
|
|
| Phase 11.1 P01 | 15min | 3 tasks | 18 files |
|
|
| Phase 11.1 P02 | 30min | 3 tasks | 53 files |
|
|
| Phase 11.1 P03 | 15min | 3 tasks | 28 files |
|
|
| Phase 11.1 P04 | 47min | 3 tasks | 68 files |
|
|
| Phase 11.1 P05 | 18min | 3 tasks | 37 files |
|
|
| Phase 11.1 P06 | 29min | 3 tasks | 168 files |
|
|
| Phase 11.1 P07 | 33 min | 5 tasks | 64 files |
|
|
| Phase 11.2 P01 | 12 min | 3 tasks | 35 files |
|
|
| Phase 11.2 P02 | 22min | 5 tasks | 36 files |
|
|
| Phase 11.2 P03 | 13 min | 3 tasks | 11 files |
|
|
| Phase 12 P01 | 39 min | 4 tasks | 57 files |
|
|
| Phase 12 P02 | 46 min | 3 tasks | 119 files |
|
|
| Phase 12 P03 | 36 min | 3 tasks | 72 files |
|
|
| Phase 12 P04 | 82 min | 3 tasks | 226 files |
|
|
|
|
## Accumulated Context
|
|
|
|
### Roadmap Evolution
|
|
|
|
- Phase 2 edited: edited fields: depends_on (Phase 1), goal (summer parity:* on bonfire, no longer a parallel workstream)
|
|
- Phase 10.1 inserted after Phase 10: Runtime admin extension point (URGENT)
|
|
- Phase 10.2 inserted after Phase 10: Nest framework packages under modules and write run docs (URGENT)
|
|
- Phase 11.1 inserted after Phase 11: SummerCMS documentation for humans and AI agents, modelled on wintercms.com/docs; after core framework, before Płytarium API port
|
|
- Phase 11.2 inserted after Phase 11.1: Ready to share: summercms.io website (sm-summercmsio-app + vue-summercmsio-app), sm-newsletter-plugin stub with double opt-in, 11.1 docs at /docs
|
|
- Phase 11.2 edited: edited fields: title, goal, repos, design source, success_criteria — reshaped into the Alpha 0.1 landing page (Nuxt 4 on SummerCMS, nginx + supervisor deploy); newsletter moved to 11.3
|
|
- Phase 11.3 inserted after Phase 11.2: Newsletter plugin and signup on summercms.io (split out of the original 11.2)
|
|
- Phase 11.3 deferred to the backlog as Phase 999.1 (2026-10-02): the Journal plugin and delivering Płytarium take priority
|
|
- Phase 12.1 inserted after Phase 12: User plugin admin screens (sm-user-plugin): Users, User Groups, Organisations admin, before Phase 15 cutover
|
|
- Phase 12.2 inserted after Phase 12: Admin form fields: date picker, file upload and relation-manager create/update/delete with Winter-like deferred binding (RelationController parity); framework only, ships as tag v0.1.1; blocks a downstream project on v0.1 (URGENT)
|
|
|
|
### Decisions
|
|
|
|
Decisions are logged in PROJECT.md Key Decisions table.
|
|
Recent decisions affecting current work:
|
|
|
|
- Roadmap: gormigrate (not goose) is the migration tool, per STACK.md's more recent reasoning — ARCHITECTURE.md/PITFALLS.md text still says goose in places; treat gormigrate as authoritative when phases 3 and 5 are planned.
|
|
- Roadmap: two repos from day one — `summercms.go` (framework, no app knowledge) and `fonoteka.go` (sibling app repo, go.work workspace of plugins). Every phase states which repo(s) it writes to.
|
|
- Roadmap: the parity harness (Phase 2) and the first vertical slice (Phase 3) are sequenced immediately after kernel foundation, ahead of any further kernel broadening, to avoid the documented Scala-era bottom-up-kernel failure mode.
|
|
- [Phase 02]: tide is the framework-owned parity library and does not import Fonoteka — Phase 2 CONTEXT.md discretion; summercms.go must stay app-agnostic
|
|
- [Phase 02]: goccy/go-yaml v1.19.2 decodes fixtures with DisallowUnknownField; SaveFlow uses a dedicated encoder so nested literal bodies keep indent — goccy BytesMarshaler re-emitted |- scalars without nested indent; decode still uses the verified library
|
|
- [Phase 02]: JSON diffs ignore object key order and fail missing keys or token-type changes at $.path; non-JSON compares bytes at offset — D-13: structural JSON compare with UseNumber, exact bytes for non-JSON
|
|
- [Phase 02]: Proxy bind and upstream must be loopback HTTP; incoming Host/URL never selects the origin — T-02-01: pin PHP upstream, ignore client destination, cap bodies
|
|
- [Phase 02]: Capture rules and a private 0600 --vars store drive {{name}} substitution; unclassified credential shapes fail fixture writes — D-07 D-11 and T-02-02: never commit live JWT, inv_ tokens, OAuth codes or PKCE verifiers
|
|
- [Phase 02]: Carbon *_at values must match +00:00 before masking; Z, string ids, null vs [] and missing keys fail at $.path — D-13 D-15: assert shape before mask so parity classes stay visible
|
|
- [Phase 02]: 154 is the app manifest validated route count, not a framework constant; --next-batch above 15 is refused — D-16 and the 15-route resume workflow; keep tide generic
|
|
- [Phase 02]: Isolated PHP uses a parity-named SQLite file on 127.0.0.1:8423; record/reset refuse any other DB — T-02-05
|
|
- [Phase 02]: Client OAuth replay merges `/tmp/summercms-parity/pkce.vars` after seed; the verifier is not in git — D-07 D-11
|
|
- [Phase 02]: newTarget and seedHooks live in the app test package so Phase 3 can swap the synthetic handler for the real app and add a temporary genres SQL hook until POST genres is ported — D-10 D-12: framework tide stays app-agnostic; the handler/seed-hook seam is app-owned
|
|
- [Phase 02]: Pending never equals passing: TestParityCorpus reports recorded 154/154 passing 0 pending 154 and does not replay PHP fixtures against the synthetic handler — D-16: unported PHP routes must never count as a Go pass
|
|
- [Phase 02]: Unavailable Docker fails TestMain; testing.Short skips the container so the fast loop stays fast — QA-03 and D-12: no false green skip when Postgres cannot start
|
|
- [Phase 02]: Fresh PHP self-replay uses disposable MariaDB fonoteka_parity_* plus process-local hex credentials, never the developer DB or caller-supplied PHP_PARITY_TARGET — T-02-01 T-02-05: check-phase2.sh --fresh-php owns the origin and rejects PHP_PARITY_TARGET
|
|
- [Phase 02]: Client flows run on a second winter:up after dropping tables so they are not replayed after the mutating 154-route suite — D-16 and 02-03 seed-then-clients: keep route replay and Nuxt/MCP replay on disjoint schemas
|
|
- [Phase 02]: Capture-by-reference mismatch is a two-step share:item flow with a live token change on the second /show — D-11 D-13: contract tests exercise RecordFlow/ReplayFlow public APIs, not private helpers
|
|
- [Phase 03]: GORM and app services share one pgx-stdlib *sql.DB; the River LISTEN/NOTIFY pool is a Phase 11 seam and is not created in lagoon.Open — DATA-01: one shared pool now; dual-driver River listener deferred
|
|
- [Phase 03]: Generated app main stays framework-generic (lagoon.RuntimeCommands + surf.ServeCommand); fonoteka.go/app.Handler is the in-process boot seam for parity tests — summer build cannot import the app package; CLI serve and tests still assemble the same surf router
|
|
- [Phase 03]: Empty golem15.user.jwt.secret fails Boot; tests use a fixed test-only HS256 secret and do not issue tokens through a production API — D-11: missing secret must not fall back; token minting stays out of Phase 3
|
|
- [Phase 03]: lagoon.OrderBy takes a caller allow-list so the framework never hardcodes Fonoteka table names; the handler passes PHP PolishOrder::ALLOWED_COLUMNS — summercms.go must stay app-agnostic; PolishOrder columns live at the Fonoteka call site
|
|
- [Phase 03]: Duplicate non_empty query keys last-win, matching PHP parse_str; invalid then 1 is accepted, 1 then invalid is 422 — PHP parse_str last-wins confirmed with php -r; Go uses vals[len(vals)-1]
|
|
- [Phase 03]: Invalid stored context is rewritten to the lowest-ID accessible kind=collection row; auto-provisioning stays out of this slice — Plan 03-02 ports only the JWT default resolve path; CollectionProvisioner is Phase 12
|
|
- [Phase 03]: Route constraints compile regex and enum allow-lists at registration; request path text is only matched — D-15 T-03-07: PHP ->where() maps onto surf.Where/WhereIn; malformed and unknown IDs share a 404
|
|
- [Phase 03]: A ported route with a trusted seed_hook skips the global PHP bootstrap replay — D-20: unported register/login and POST genres; the hook mints a test-only JWT
|
|
- [Phase 03]: Corpus passing increments only after the ported subtest succeeds; pending never counts as passing — QA-04 T-03-06: 154 recorded, 1 passing, 153 pending
|
|
- [Phase 03]: Colliding fixture IDs are derived from CanonicalGenres seed order (rock=1, electronic=2, jazz=4) — D-20: set id:token, id:wishlist-album, id:genre from PHP seed order, not user input
|
|
- [Phase 03]: Phase 3 gate inlines TestParitySynthetic and CLI record/replay; PHP --fresh-php stays the Phase 2 sign-off because four wishlist album_count routes currently fail on live PHP — check-phase2.sh --fresh-php reports 150/154 on wishlist album_count expected 1 vs live 2. Phase 3 did not change PHP, tide, or those fixtures, so the Phase 3 gate must not fail on that drift.
|
|
- [Phase 03]: testcontainers-go v0.44.0 is the STACK-named test dependency for framework lagoon isolation tests, matching the app TestMain — DATA-01 isolation tests need a real ICU pl-PL Postgres. The app already used testcontainers; the framework module now pins the same STACK versions so lagoon tests do not share the app TestMain.
|
|
- [Phase 03]: High-severity T-03-01 through T-03-04 and T-03-06 are closed with failing-when-broken tests; token issuing remains test-only until Phase 7 — Roadmap required a security review of the JWT guard. 03-SECURITY-REVIEW.md maps each threat to a passing test; minting tokens through a production API is out of this slice.
|
|
- [Phase 04]: registry.gen.go is regenerated by scanning Code generated by summer make files, not by rewriting plugin.go — D-12: handwritten plugin.go stays byte-identical; existing plugins get a one-time accessor hint
|
|
- [Phase 04]: make:model table names are vendor_plugin_plural_snake with explicit gormigrate CREATE/DROP TABLE — D-13: timestamps on the model; --no-migration omits only the create-table file
|
|
- [Phase 04]: models sibling-import check runs in build.App before go build and reports plugin ID, file, and import — D-11: limited to classes/controllers/console/jobs/middleware/updates of the same plugin module
|
|
- [Phase 04]: go-i18n is used only to choose a CLDR category label; YAML message text never enters its template engine — D-03: PHP :name placeholders must remain literal
|
|
- [Phase 04]: A per-locale i18n.Bundle is cached so matcher/plural rules follow the requested tag, not the English default bundle — A single English default bundle made Polish few/many look invalid
|
|
- [Phase 04]: Fallback order is requested, parent, app.fallback_locale, then the raw key; framework defaults remain en/en — D-04 D-05: no Polish framework default and no extra core-locale step
|
|
- [Phase 04]: Goldmark v1.8.6 is used without html.WithUnsafe; final HTML is rejected if script/iframe, event handlers, or javascript/vbscript/data schemes remain — D-07 and T-04-08: Goldmark default rejects raw HTML; a second pass keeps layout HTML trusted only as template.HTML
|
|
- [Phase 04]: postcard.Mailer is published after Register and before Boot; each HasMailTemplates catalog is validated at that plugin Boot transition — D-20 D-21: plugin Boot can Lookup the mailer; missing files fail as party: boot <plugin ID> with the dotted name
|
|
- [Phase 04]: mail.smtp.tls defaults to mandatory STARTTLS; none/notls is opt-in for Mailpit and is never inferred — D-18 T-04-10: no silent production TLS downgrade; Mailpit needs explicit NoTLS
|
|
- [Phase 04]: Mailpit image is axllent/mailpit:v1.31.1; receipt is polled from /api/v1/messages then /api/v1/message/{ID} — D-19: a successful Send claim requires observed receipt through a separate HTTP API; pin a released Mailpit tag
|
|
- [Phase 04]: fstest.MapFS WalkDir cannot host '..' keys; malformed lang paths are extra-segment and wrong-suffix files — MapFS Open/WalkDir follows .. into an infinite directory loop; parseLangPath still rejects cleaned traversal
|
|
- [Phase 05]: Models-leaf rule holds on keios.eu user, jz chat, and pxpx checkout; contracts/VOs/jobs/broadcasting stay inside the cast-or-hook conversion treatments
|
|
- [Phase 05]: plugin.go Models()/Migrations() return registry All(); Boot calls classes.RegisterHooks when *gorm.DB is published — later Phase 5 plans add files, not edit plugin.go
|
|
- [Phase 05]: lagoon.Fill matches gorm column tags against the caller allow-list and logs dropped keys once per type+key in non-production — D-05 D-06
|
|
- [Phase 05]: Lifecycle Has* interfaces use GORM-native signatures; WithSoftDeleteCascade does not open a new transaction — DATA-03 primitive
|
|
- [Phase 05]: Paginate coerces nil data to []; RegisterJoinTable fails loud on nil db — DATA-10 and pivot-write contract
|
|
- [Phase 05]: DATA-09 migration count is not an acceptance number (D-01); HTTP DTO fuzz moves to Phase 12 (D-07)
|
|
- [Phase 05]: Jsonable payload field is Data, not Value, because driver.Valuer.Value() collides under go vet — go vet rejects a field and method both named Value; type Jsonable[T] T is illegal
|
|
- [Phase 05]: KeepMarketPriceSource is a gorm-ignored Album flag set by SaveAlbum when requested contains market_price_source — GORM has no Eloquent isDirty; the flag preserves stampMarketPrice source provenance
|
|
- [Phase 05]: CollectionFillFields is name+description; PHP has no CollectionWriteService — D-05 service list is a subset of Fillable excluding owner_id
|
|
- [Phase 05]: Various Artists natural key is name_key='various artists' (PHP seed), slug various-artists — seed_genre_and_various_artist_taxonomy.php uses a spaced name_key
|
|
- [Phase 05]: go-playground/validator v10.30.4 is the STACK-named rule engine behind lagoon.Validate — STACK.md already named this library; lagoon.Validate translates Laravel rule strings onto Var()
|
|
- [Phase 05]: Column keys are HKDF-SHA256 derived via Go 1.27 crypto/hkdf with info summercms.lagoon.encrypted.v1; no golang.org/x/crypto — D-11 stdlib-first: Go 1.24+ ships HKDF; CLAUDE.md forbids a new dependency here
|
|
- [Phase 05]: Ciphertext is 1-byte format/key-id | 12-byte nonce | GCM seal, stored base64 in text columns — D-12 versioned ciphertext plus app.previous_keys decrypt-only fallback
|
|
- [Phase 05]: OpenFromApp calls LoadAppKey+PublishEncryptionKeys once per boot; empty/short/undecodable app.key fails with SUMMER_APP__KEY — D-11 fail-loud, no default key; Scan/Value must not re-read config per row
|
|
- [Phase 05]: golem15_user_organisations is owned by the user plugin; Phase 5 ships no users-table ALTER (D-03 deviation, Phase 7 AUTH-02) — User-confirmed at plan time: organisations are an FK target only this phase
|
|
- [Phase 05]: DecryptLaravelPayload is cutover-import-only and is never called from Encrypted Scan/Value — D-10 live path is AES-256-GCM only; Laravel CBC is Phase 15 import
|
|
- [Phase 05]: Blob keys are partition+disk_name (no public/protected prefix); fileblob roots at storage/app/uploads — StaticHandler reconstructs keys from PartitionDirectory+disk_name; cutover can point bucket_url at uploads/public
|
|
- [Phase 05]: DeleteForOwner afterCommit is an in-tx key collector; DeleteKeys removes originals and thumb_<id>_ prefixes after commit — GORM has no post-commit hook; a rollback must not have already deleted bytes
|
|
- [Phase 05]: Album/Collection MorphName returns the PHP class string and does not import attach (models stay a leaf) — models-leaf rule; interface satisfaction is implicit
|
|
- [Phase 05]: Settings is golem15_fonoteka_settings singleton with typed search_use_typesense BOOLEAN (RESEARCH Open Question 2) — PHP SettingsModel over system_settings is not ported; dedicated typed table is the user-resolved storage
|
|
- [Phase 05]: notifications/wishlist_subscriptions/wishlist_digest_queue have no FK on user_id/collection_id, matching PHP (Open Question 3 / T-05-18) — PHP migrations omit ->foreign() on these tables; D-02 matches actual constraints rather than fixing them
|
|
- [Phase 05]: D-02 allow-list is settings table, users column-count (no widen_users), and the shipped extra oauth_refresh_tokens.user_id FK — Intended gaps only: Open Question 2, D-03/AUTH-02, and P3 D-17 freeze of 05-03 extra FK
|
|
- [Phase 05]: DATA-11 fixture plugin is test-only: no process-wide Register, not in app.PluginIDs or plugins.gen.go — CONTEXT.md discretion: fixture plugin in tests is acceptable; production binary must not load it
|
|
- [Phase 05]: Hidden-marshal registry walk lives in fonoteka.go/classes because summercms.go must not import the app — CLAUDE.md two-repo rule; plan allowed the parity/classes fallback
|
|
- [Phase 05]: Credential fuzz excludes owner FKs from the working allow-list, matching D-05 two-layer even without a write-service file — Fillable() includes user_id/organisation_id; acceptance requires the owner FK never change
|
|
- [Phase 05]: classes TestMain is the real-Postgres harness; parity activateAppPlugins/parityDB cannot be imported from package main — Same ICU pl-PL migrate-both-plugins shape without crossing the app/framework test boundary
|
|
- [Phase 06]: Parameterized middleware is a surf factory (strings.Cut on first ':'), not a fixed name table (D-05)
|
|
- [Phase 06]: TokenGuard implements CredentialGuard only; InvScope owns PHP TokenScope 401/403 bodies (D-08)
|
|
- [Phase 06]: NewJWTGuard reuses bearerToken/Verify/write401 so Registry.Middleware(jwt) is byte-identical to bouncer.Middleware (D-10)
|
|
- [Phase 06]: oauth is not registered this plan; only jwt and inv_token (D-09)
|
|
- [Phase 06]: Personal-token genres fixture body matches isolated seedGenres; CORS * deferred to D-18
|
|
- [Phase 06]: Concrete limiter is FixedWindowLimiter; surf.Limiter interface remains the unused Phase 3 seam — D-03 D-05 naming collision with pre-existing Limiter interface
|
|
- [Phase 06]: Trusted-proxy list is a NewFixedWindowLimiter constructor argument, never a setter — Named-bucket Key closures and inline N,M must share one trusted list
|
|
- [Phase 06]: fonoteka-* buckets live on the app plugin via surf.BucketProvider, not hardcoded in surf — summercms.go must stay Płytarium-agnostic
|
|
- [Phase 06]: Empty PHP group builders plus test-only boot-probe routes prove middleware strings resolve without 501 shells — D-15: no 501 shells; wrap() only sees routes
|
|
- [Phase 06]: php_parity.sh pins APP_DEBUG=false; three existing HTML exception fixtures need re-recording — T-06-09 production-shaped error bodies
|
|
- [Phase 06]: HasHouseMiddleware is the only plugin-facing house-tag path; Assemble/BuildRouter is the sole RegisterHouseMiddleware caller (D-16)
|
|
- [Phase 06]: Production body limits are 134217728/134217728 (128MiB), operator-confirmed 2026-09-19 from nginx client_max_body_size=128M and php.ini post_max_size=128M/upload_max_filesize=128M (D-18, T-06-13)
|
|
- [Phase 06]: CORS path globs compile as Laravel nested * because Go path.Match would miss /api/v1/fonoteka/genres (Pitfall 10)
|
|
- [Phase 06]: swag v1 Swagger 2 is converted by a local swagger2openapi helper to OpenAPI 3 for openapi-typescript 7; Phase 10 wires types into the admin SPA
|
|
- [Phase 06]: Full route-table isolation uses surf.BuildRouter of the real plugins; app.Handler returns http.Handler and cannot call Routes() — app.Handler assembles an http.Handler; Routes() is on *surf.Router
|
|
- [Phase 06]: T-06-05 remains accept as originating 06-01 (the 06-05 plan three-accepts list omitted it) — Originating plan disposition is copied verbatim into 06-SECURITY-REVIEW.md
|
|
- [Phase 06]: PublicOnlyMode any-host-when-public is proven via skipReservedCheck httptest, not a live public IP dial — Unit tests must not require outbound network
|
|
- [Phase 06]: Keep inv_token outermost so valid credentials populate bouncer.Credential before the limiter selects tok:<id>. — The named bucket must retain per-token isolation for valid credentials instead of collapsing them onto the IP fallback.
|
|
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
|
|
- [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
|
|
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation.
|
|
- [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy.
|
|
- [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6.
|
|
- [Phase 06]: Use one unexported bufferedResponse for house and raw recovery — A shared transactional writer keeps panic-before-write and panic-after-write behavior identical while preserving raw versus house fallback bodies.
|
|
- [Phase 06]: Keep bufferedResponse Flush as a no-op — Recovery must never unwrap, hijack, flush, or otherwise expose the destination writer before handler success.
|
|
- [Phase 06]: Success commit replaces only route-owned header keys — Unrelated headers already placed on the destination by outer wrappers such as path-scoped CORS must survive.
|
|
- [Phase 06]: Use wire.WriteJSON for both InvScope denial branches — The shared writer is the established PHP-compatible no-newline serialization path.
|
|
- [Phase 06]: Assert exact denial bytes before JSON shape checks — Whitespace normalization would hide response-contract regressions.
|
|
- [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
|
|
- [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|<ClientIP>, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u:<id> keys.
|
|
- [Phase 07]: Blacklist storage expiry follows PHP jwt-auth (later of exp and iat+refreshTTL, plus one minute). — Using the raw access exp would drop a logged-out token that is still inside the refresh window.
|
|
- [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is also the production PHP path: logout calls JWTAuth::invalidate(true) and blacklist_enabled defaults true. The earlier "PHP does not blacklist" note was a harness artifact of CACHE_DRIVER=array.
|
|
- [Phase 07]: Fetch after logout stays 401 in Go — Re-recorded PHP with file cache still returned 200 on a reused token (show_black_list_exception default 0). That case is kept on disk but is not a ported corpus case.
|
|
- [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
|
|
- [Phase 07]: Both CLI serve and in-process Handler must publish *blob.Bucket; unit tests that call attach.Publish themselves cannot stand in for boot — Phase 5 shipped OpenBucket/Publish but never wired them. Phase 7 added HTTP avatar. UAT and corpus replay boot via Handler, so serve-only publish would leave the same 500.
|
|
- [Phase 07]: Assembled Handler avatar coverage lives in parity/ next to newConfiguredTarget, not in the user plugin package — The user plugin cannot import app.Handler without a reverse import. newConfiguredTarget is the same boot as replay.
|
|
- [Phase 08]: wristband.Options exposes only the four PHP-configurable metadata fields (service_documentation path, scopes_supported, token_endpoint_auth_methods_supported, authorization_response_iss_parameter_supported); response_types/grant_types/code_challenge_methods stay fixed protocol constants per D-06
|
|
- [Phase 08]: Plugin.Boot always constructs wristband.Server even with an empty app.url rather than failing loud, to avoid breaking the many existing fonoteka tests that boot without app.url configured; production must set app.url
|
|
- [Phase 08]: D-10 (oauth guard retirement) is recorded via TestOAuthMetadataRouteIsolation rather than editing Phase 6 historical docs, per 08-PATTERNS.md guidance to prefer a supersession note
|
|
- [Phase ?]: [Phase 08 P02]: Corrective migration named 21_oauth_schema_correction.go (not 12_): Go init()-order/gormigrate slice position determines RollbackLast() target, not the migration's numeric ID, so the file must sort after 20_remaining.go
|
|
- [Phase ?]: [Phase 08 P02]: Schema-correction rollback refuses (changes nothing) rather than deleting/coercing rows when any row depends on a nullable lifecycle column
|
|
- [Phase ?]: [Phase 08 P02]: wristband.Tx ships the full ClientStore/AuthCodeStore/RefreshTokenStore/AccessTokenIssuer surface now so 08-03/08-04 reuse the same transaction seam without another interface change; expiry-sweep methods are deferred to 08-06
|
|
- [Phase ?]: [Phase 08 P02]: Register strips C0/DEL control characters from client_name at DCR capture time (PHP only strips at ConnectedApp/Consent display time) per 08-CONTEXT.md discretion
|
|
- [Phase ?]: [Phase 08 P02]: OAuth config keys live under golem15.fonoteka.oauth.* (bare plugin ID, matching compass.MergePlugin), not plugins.golem15.fonoteka.oauth.*
|
|
- [Phase ?]: [Phase 08 P02]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md: this plan ships DCR only, not the full authorize/token/consent surface
|
|
- [Phase 08]: [Phase 08 P03]: Options gained Resource and PendingRequestTTL (not in the plan's file list for server.go) following the 08-02 precedent of extending Options for deployment-configurable values
|
|
- [Phase 08]: [Phase 08 P03]: authorize's allowed-scope set is a package-level authorizeAllowedScopes constant, not Options.ScopesSupported (RFC 8414 metadata field) -- conceptually distinct config surfaces matching PHP's own separation
|
|
- [Phase 08]: [Phase 08 P03]: Client lookup and pending-row creation each open their own WithinTx call, matching PHP's lack of a wrapping transaction around authorize; only DCR and later code-exchange/refresh-rotation need single-transaction atomicity
|
|
- [Phase 08]: [Phase 08 P03]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md, continuing 08-01/08-02's decision: this plan ships authorize only, not the full RFC surface
|
|
- [Phase 08]: [Phase 08 P04]: Token dispatch accepts grant_type=refresh_token per PHP's exact validity check but rotateRefreshToken always returns invalid_grant in this plan's scope; full rotation/lineage-kill (T-08-REFRESH-REPLAY) is 08-06's job per ROADMAP.md Wave 6
|
|
- [Phase 08]: [Phase 08 P04]: No routes.go/plugin.go changes -- POST /oauth/mcp/token is not mounted on the assembled app this plan; mounting happens once 08-05 wires consent and produces a real issued code
|
|
- [Phase 08]: [Phase 08 P04]: MintablePrefix changed from const to var (D-11 groundwork) with no config wiring added yet; default stays byte-identical inv_
|
|
- [Phase 08]: [Phase 08 P05] AuthCodeStore.MarkIssued gained scopes/collectionIDs/expiresAt params; ClientStore gained MarkConsented — PHP issueCode overwrites six columns in one UPDATE, not just code_hash/user_id; the narrower 08-02 signature could not persist consent's granted scopes or server-resolved collection pin
|
|
- [Phase 08]: [Phase 08 P05] wristband.Options gained CodeTTL (600s default), wired from the previously-unconsumed code_ttl_seconds config key — PHP OAuthCodeManager::CODE_TTL_SECONDS is a distinct constant from PENDING_TTL_SECONDS; IssueCode needs a fresh expiry from consent time
|
|
- [Phase 08]: [Phase 08 P05] Consent scope ordering follows auth.MintableScopes's declared read/write/ai order, not PHP array_intersect's incidental first-array order — 08-UI-SPEC.md explicitly documents canonical read -> write -> ai order as the fixed contract
|
|
- [Phase 08]: [Phase 08 P05] POST /oauth/mcp/token mounted in this plan, closing 08-04's deliberate D-09 deferral — Only once consent produces a real issued code does an end-to-end /token call through the real route have anything to exchange
|
|
- [Phase 08]: [Phase 08 P05] AUTH-05/06/07 remain Pending in REQUIREMENTS.md — Refresh rotation (08-06) and connected-apps list/revoke are still outstanding pieces of those requirements; this plan ships consent plus the token mount only
|
|
- [Phase 08 P06]: rotateRefreshToken commits lineage-kill revocation inside WithinTx and returns nil (success) on replay, mapping a captured replayed flag to invalid_grant outside the transaction -- mirrors PHP rotateRefresh's own commit-then-throw shape
|
|
- [Phase 08 P06]: RevokeLineage walks forward only through RotatedToID; sufficient for both replay-kill and connected-app-revoke because every normal rotation already revokes its own predecessor's access token and connected-app revoke always starts from the terminal row
|
|
- [Phase 08 P06]: Fixed RevokeLineage (GORM adapter and in-memory test double) to also revoke each visited row's linked access token -- the 08-02-era method only stamped the refresh row itself, leaving a replayed lineage's live access token usable
|
|
- [Phase 08 P06]: AUTH-05/06/07 remain Pending in REQUIREMENTS.md: refresh-rotation and connected-apps pieces are done, but AUTH-05/07's unchanged-fonoteka-mcp clause needs 08-08/08-09, and AUTH-06's CSRF/rate-limit/cache-header claims are reconciled by 08-10's security review
|
|
- [Phase ?]: [Phase 08 P07]: bonfire.Flag.Repeatable / Input.Flags(name) is the new shape for PHP-parity =* console options (Cobra StringSlice), with no change to existing scalar/bare Flag callers
|
|
- [Phase ?]: [Phase 08 P07]: fonoteka:oauth-client create reuses wristband.Tx.CreateWithCap(ctx, rec, math.MaxInt32) instead of adding an uncapped Create method -- operator-issued clients are never subject to DCR's 200-client cap
|
|
- [Phase ?]: [Phase 08 P07]: list/update operate directly on models.OAuthClient via *gorm.DB rather than extending wristband.ClientStore -- only client issuance needs the shared wristband hash/validation path (T-08-SECRET-TIMING)
|
|
- [Phase ?]: [Phase 08 P07]: Fixed clientRecordToModel to persist ScopeCeiling, a mapping gap silent since 08-02 because DCR never sets a ceiling
|
|
- [Phase ?]: [Phase 08 P07]: AUTH-05/AUTH-07 remain Pending in REQUIREMENTS.md -- both requirements' full text still needs 08-08/08-09's unchanged fonoteka-mcp install/auth flow proof
|
|
- [Phase ?]: [Phase 08 P08]: me_token_controller.go was created in the Task 1 RED commit as a compiling 501 stub (Rule 3), following the 08-04/08-06/08-07 precedent -- controllers/api must compile with its new test file while the route stays unmounted
|
|
- [Phase ?]: [Phase 08 P08]: scopes/collection_ids on GET /api/v1/fonoteka/me always serialize via wire.Slice (nil -> []), a deliberate divergence from PHP's collection_ids null-means-unrestricted semantics, accepted because fonoteka-mcp's TS MeResponse type never reads collection_ids
|
|
- [Phase ?]: [Phase 08 P08]: AUTH-07 stays Pending in REQUIREMENTS.md -- this plan ships the /me prerequisite but the requirement's 'fonoteka-mcp completes its install and auth flow unchanged' clause needs 08-09's real MCP gate
|
|
- [Phase ?]: [Phase 08 P09]: Lifecycle fixture recorded via a one-time Go program calling tide.RecordFlow directly against isolated PHP (deleted after use), not via Playwright/capture_clients.mjs -- login and consent are plain JWT API calls with no browser dependency
|
|
- [Phase ?]: [Phase 08 P09]: wristband's explicit no-store Cache-Control becomes no-store, private and unheadered JSON errors default to no-cache, private -- confirmed by live PHP recording, superseding the earlier 08-CONTEXT.md assumption of bare no-store
|
|
- [Phase ?]: [Phase 08 P09]: wristband redirects now emit Symfony's exact HTML redirect body (wristband/redirect_html.go) with PHP htmlspecialchars(ENT_QUOTES) escaping -- Go's bare 302 never matched real PHP
|
|
- [Phase ?]: [Phase 08 P09]: {request_id} route constraint is now upper-bound only ([A-Za-z0-9_-]{1,128}) -- PHP applies no router-level shape constraint and the 16-char lower bound was rejecting a valid recorded 404 test case at the router
|
|
- [Phase ?]: [Phase 08 P09]: OAuthConsentController's basic-validation failure now writes Winter's generic production 500 HTML page (not a clean 422) -- PHP's bare $request->validate() on this route is never caught by a JSON exception renderer, confirmed live with APP_DEBUG=false
|
|
- [Phase ?]: [Phase 08 P09]: All nine OAuth manifest routes are status: ported with seed_hook: genres; scripts/check-phase8.sh's stage bodies are fully implemented but never executed by this plan -- 08-10 Task 3 is the sole execution site
|
|
- [Phase ?]: [Phase 08 P09]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md -- this plan proves byte parity and builds the real-MCP gate machinery, but only 08-10's actual gate execution can prove the unchanged-fonoteka-mcp clause
|
|
- [Phase 08]: Security review self-performed by the 08-10 executor (no Task/Agent spawner available), disclosed in 08-SECURITY-REVIEW.md's frontmatter and Reviewer Note — Per 08-CONTEXT.md D-04's documented fallback; every cited file:TestName was individually re-run, not inherited unverified
|
|
- [Phase 08]: Checkpoint decision: approved closing Phase 8 with the Playwright UI matrix gap (check-phase8-ui.mjs:458) carried forward as a named follow-up — Every other scripts/check-phase8.sh stage ran green in the sole full gate execution; the Playwright matrix was a deliberate, never-authored fatal() left by 08-05 as 08-10's seam
|
|
- [Phase 08]: AUTH-05, AUTH-06 and AUTH-07 marked complete in REQUIREMENTS.md — Each requirement's exact text is satisfied by the delivered backend/gate evidence; none mandates a Playwright-verified browser regression suite, so the carried-forward UI gap does not block completion
|
|
- [Phase 09]: Frontend verification accepts PHP tokens that omit aud and rejects any other explicit audience
|
|
- [Phase 09]: Backend JWTs require aud=backend, use admin.jwt.secret, and omit the PHP user prv hash
|
|
- [Phase 09]: Cabana mounts from BuildRouter only when a plugin registers admin controllers; an empty admin.jwt.secret fails that assembly
|
|
- [Phase 09]: Admin jti rows live in backend_jwt_blacklist and cabana does not republish the frontend BlacklistStore — Refresh and logout must not revoke frontend tokens or be revoked by them.
|
|
- [Phase 09]: backend_user_roles.code is indexed and not unique so Winter rows can repeat a code — admin:create rejects zero or many matches instead of a unique constraint the cutover table does not have.
|
|
- [Phase 09]: tokens_valid_after is a nullable additive column used to revoke admin JWTs on password reset — The guard already honors Principal.TokensValidAfter and Winter's required columns stay unchanged.
|
|
- [Phase 09]: Cached form schemas keep source phrase keys; each response localizes a copy and records meta.locale
|
|
- [Phase 09]: Absent config_form.yaml does not fail activation, so the 09-01 Genre list controller still boots
|
|
- [Phase 09]: YAML option keys keep their JSON scalar type; method options call DropdownOptions with the exact field name
|
|
- [Phase 09]: make:admin-controller writes controllers/name config_form and config_list pointing at models/name fields and columns
|
|
- [Phase 09]: Omitted sortable defaults to true, except relation columns, which stay unsortable unless columns.yaml sets sortable
|
|
- [Phase 09]: perPageOptions keep YAML order and must include recordsPerPage
|
|
- [Phase 09]: list_toolbar, recordUrl, and showCheckboxes compile to create, update, and delete
|
|
- [Phase 09]: A conditions key is a boot error; a model scope must be listed by FilterScopes()
|
|
- [Phase 09]: Admin list meta uses D-11 page, while lagoon.Paginate still computes last_page
|
|
- [Phase 09]: Writable admin fields are bound to gorm columns at activation; id, timestamps, scope, and system flags are never fillable
|
|
- [Phase 09]: Show and update use one not-found body for missing and out-of-scope rows; delete of an absent row is deleted 0 and does not run hooks
|
|
- [Phase 09]: A bulk selection that matches no scoped row is a no-op; a mixed present and absent selection is a 409 and rolls back
|
|
- [Phase 09]: Controller hook failures return an opaque lifecycle error and do not echo the hook text
|
|
- [Phase 09]: Album admin D-14 stores collection_id of the one active frontend user matched by normalized backend email; no album user_id column was added
|
|
- [Phase 09]: Winter relation keys match exported Go fields case-insensitively and the served JSON keeps the YAML spelling
|
|
- [Phase 09]: Required relation fields stay on the admin form schema and are not save-time column rules
|
|
- [Phase 09]: Genre and style admin option values are decimal strings because pact.Option.Value is a string
|
|
- [Phase 09]: Artists uses only the shared cabana list and CRUD engines; the controller contains identity, asset paths, model factory, and permission declaration only
|
|
- [Phase 09]: Artist name_key and slug remain model-owned lifecycle fields and are not exposed by the admin writable projection
|
|
- [Phase 09]: The Phase 9 Genre tracer remains the one production controller; form capability was added without a parallel route or identity
|
|
- [Phase 09]: The tracer list and columns were already byte-equivalent to the tracked Winter source, so Task 2 added behavioral proof rather than rewriting them
|
|
- [Phase 09]: The tracked Style source declares no dropdown provider or filter, so production YAML stays exact while isolated compiler fixtures prove typed scalars and provider rejection
|
|
- [Phase 09]: Style slug retains the tracked update-only readonly schema and is generated on create by the model lifecycle
|
|
- [Phase 09]: Style equal-value list ordering is explicitly stabilized by the shared primary-key tie-breaker
|
|
- [Phase 09]: Collection-specific pivot identifiers and stamps remain plugin-owned behind a typed relation contract. — Cabana can validate and execute relations generically without hardcoding Fonoteka tables, columns, roles, or payload behavior.
|
|
- [Phase 10]: Admin prefix is backend.uri (default /backend); admin API at {prefix}/api/v1, embedded SPA at {prefix}; fonoteka uses /plytadmin
|
|
- [Phase 10]: Admin SPA uses the HttpOnly summer_admin cookie selected by X-Requested-With; cookie-only POST/PUT/DELETE without the header get 403 forbidden; Bearer bodies unchanged
|
|
- [Phase 10]: Framework owns admin/openapi/admin.json (swag -> swagger2openapi -> openapi-typescript); fonoteka docs/openapi.json no longer lists admin paths
|
|
- [Phase 10]: npm package gate approved: 17 exact pins in admin/package.json; any new package or version needs a checkpoint
|
|
- [Phase 10]: 10-02: Relation lists, field options and filter options share one mounted six-segment GET pattern dispatched by nestedGet (ServeMux cannot register them side by side); documented paths unchanged
|
|
- [Phase 10]: 10-02: Record responses carry relation values in data and labels in meta.labels; a belongsTo on a protected fill key is read-only (Collections owner)
|
|
- [Phase 10]: 10-02: Message key validation checks declared keys and framework defaults only; defaults derived from Winter prompt, noRecordsMessage or form name may be literal text
|
|
- [Phase 10]: 10-02: Filter options path {scope} is the filter name; the model's FilterOptions receives the scope method name
|
|
- [Phase 10]: 10-02: Tailwind excludes generated schema.d.ts and openapi/ from the class scan so API changes do not churn boardwalk/dist
|
|
- [Phase 10]: Admin OpenAPI declares write bodies (AdminRecord, AdminIDsRequest) and the list filter query as a deepObject so the SPA sends typed payloads
|
|
- [Phase 10]: A form field without span fills the whole row (Winter default); auto and row take the next free slot
|
|
- [Phase 10]: The save body skips read-only fields and unregistered types (relation-manager, unknown); Winter attributes pass through an allowlist
|
|
- [Phase 10]: aria-sort reflects only the explicit URL sort; defaultSort is applied server-side without a header indicator
|
|
- [Phase 10]: relation-manager is record-bound: dropped on create even without context: update and never sent in the save body
|
|
- [Phase 10]: Admin OpenAPI declares search, sort, dir, page and per_page on the linked and candidate relation routes
|
|
- [Phase 10]: Collapsed rail: Enter or ArrowDown opens the SectionFlyout and moves focus into it; click still navigates; expand button only for a manual collapse
|
|
- [Phase 10]: logout(router) always clears user, navigation and settings and ends on the login route, even when POST /auth/logout fails
|
|
- [Phase 10]: Phase 10 gate allow-lists exactly the two pre-existing fonoteka parity failures by package and test name and refuses once either passes
|
|
- [Phase 10]: Field controls import components/form/control.ts; registry.ts re-exports it (breaks a registry/control import cycle)
|
|
- [Phase 10]: Tailwind skips admin/tests so test code never changes boardwalk/dist
|
|
- [Phase 10]: Framework tests use neutral acme names; the hygiene stage refuses application names in summercms.go admin, boardwalk, cabana and phrasebook
|
|
- [Phase 10.2]: Kept framework onboarding in the root README and application setup in fonoteka.go, preserving the two-repository boundary.
|
|
- [Phase 10.2]: Made the gate scan tracked Go, template, and shell files in both repositories while excluding itself and planning artifacts.
|
|
- [Phase 10.1]: 10.1-01: create and delete are reserved names in the single controller action namespace shared by toolbar.buttons and widget action: keys
|
|
- [Phase 10.1]: 10.1-01: toolbar action body must be exactly {}; record_id or values is a 422
|
|
- [Phase 10.1]: 10.1-01: partial view-model guard also refuses html/template trusted content types; href/src with whitespace or control characters are dropped
|
|
- [Phase 10.1]: 10.1-02: a widget posts only its fill keys' current values; loadControllerAssets resolves with failed script URLs so a widget fails fast instead of waiting 5000 ms
|
|
- [Phase 10.1]: 10.1-02: plugin stylesheet links are keyed by controller and URL and toggled on every list and form open
|
|
- [Phase 10.1]: 10.1-02: the client partial allowlist drops the server's removed tags with their subtree and unwraps other unknown tags
|
|
- [Phase 10.1]: 10.1-03: lagoon.Fill converts json.Number into integer, unsigned and float fields; a fraction or overflow into an integer field is an error
|
|
- [Phase 10.1]: 10.1-03: Discogs lookup and sync admin actions are D-02 stubs reusing golem15.fonoteka.access_albums; Phase 14 replaces them
|
|
- [Phase 11]: 11-01: conga job registration closes only while a worker client runs; the insert-only client has no Workers bundle
|
|
- [Phase 11]: 11-01: a conga worker's lifetime is Worker.Stop, not the start ctx (River Start on context.WithoutCancel), so SIGTERM stops serve and queue:work gracefully
|
|
- [Phase 11]: 11-01: an app with no jobs gets an internal summercms_conga_idle worker because River refuses to start without workers
|
|
- [Phase 11]: 11-01: lagoon.OnDatabase treats a published *gorm.DB as ready and derives the pool; fonoteka GORM hooks now register under serve
|
|
- [Phase 11]: 11-01: River v7 tables are river_job, river_leader, river_migration, river_notification, river_queue (fonoteka schema allow-list)
|
|
- [Phase 11]: 11-03: broadcast job args carry the payload as a JSON string because River's JSONB args column reorders object keys
|
|
- [Phase 11]: 11-03: no broadcast job is enqueued (and Emit is a no-op) for the null driver or a driver whose Enabled() is false (Centrifugo without an API key)
|
|
- [Phase 11]: 11-03: the fonoteka test harness boots realtime.driver centrifugo so assembled route tables always carry the realtime routes
|
|
- [Phase 11]: 11-03: Phase 12 album store/update/bulk must use WithoutBroadcasting[models.Album] plus Service.Emit (the in-tx automatic payload can carry stale artists)
|
|
- [Phase 11]: 11-05: beachcomber sync callbacks are pinned After(gorm:after_*) and Before(gorm:commit_or_rollback_transaction); GORM appends After-only callbacks past the commit and past lagoon:after_commit
|
|
- [Phase 11]: 11-05: code on a GORM callback's handle builds a clean session (Session NewDB+Context, Clauses(), Session NewDB); Session with a Context clones the write statement and a later WithContext queries through the written model
|
|
- [Phase 11]: 11-05: search index name is search.prefix + SearchableAs(); SearchIDs returns candidates only and Phase 12 must re-gate in SQL
|
|
- [Phase 11]: 11-05: sync is inline after commit on context.WithoutCancel, bounded by the Typesense timeout; errors are typesense.StatusError without bodies and are logged, never returned to the write
|
|
- [Phase 11]: flare VAPID driver never follows redirects and sends only to https hosts on push.allowed_hosts (checked before dialing)
|
|
- [Phase 11]: compass Persist now merges runtime values over the existing overrides.yaml so websockets:generate-vapid-keys --update cannot wipe other persisted overrides
|
|
- [Phase 11]: websockets:health probes the Centrifugo info API (PHP only read local config); an error body fails the check
|
|
- [Phase 11]: Phase 11 removal checks are scripted: check-phase11.sh --removal applies anchor-exact mutations, requires the named test to fail on an assertion and restores the file byte for byte (cmp); kept out of --all because it edits tracked source
|
|
- [Phase 11]: Savepoint helpers (beachcomber, lighthouse) roll back when RELEASE fails, because a swallowed read error still aborts the Postgres transaction
|
|
- [Phase 11]: lagoon after-commit callbacks always receive a clean statement on the write's connection; side-effect GORM callbacks declare Before(gorm:commit_or_rollback_transaction)
|
|
- [Phase 11]: Phase gates accept a pending skip only by exact test name and pending text (TestBroadcastGoldens/created and /updated until Phase 12), in check-phase11.sh and check-phase10.1.sh
|
|
- [Phase 11]: Phase 11-08: lagoon.AfterCommit inside a foreign plain GORM transaction warns and skips the callback instead of running it immediately; Cabana writes and SaveAlbum run in lagoon.Transaction — Lagoon cannot observe a foreign commit; running early sent uncommitted, pre-pivot or rolled-back Album state to Typesense (CR-01)
|
|
- [Phase 11]: Phase 11-08: a nested lagoon.Transaction given a root handle returns an error (WR-03) — Treating it as a savepoint would commit independently while its callbacks waited on the parent buffer
|
|
- [Phase 11.1]: 11.1-02: The identifier index resolves promoted members itself; go doc does not resolve embedding and stays only as the fallback
|
|
- [Phase 11.1]: 11.1-02: docsCommands() collects app command names from the real constructors on backpack.New(&compass.Config{}); TestDocsCommandsMirrorGeneratedMain keeps it in step with internal/build
|
|
- [Phase 11.1]: 11.1-02: chroma/v2 v2.27.0 is the only new direct dependency (D-15); tokens map onto tok-* classes without chroma's HTML formatter
|
|
- [Phase 11.1]: 11.1-03: the Plugin.php-in-Go section shows modules/party/example_plugin_test.go as a whole-file src= fence because Go methods cannot live in an Example body
|
|
- [Phase 11.1]: 11.1-03: docs pages never carry hand-written Go fences; where no runnable Example fits, the page uses prose
|
|
- [Phase 11.1]: 11.1-03: bonfire has no duplicate command name check; documented as is and logged as todo bonfire-duplicate-command-names
|
|
- [Phase 11.1]: 11.1-04: The transactions page follows lagoon at HEAD: nested lagoon.Transaction needs the outer tx, AfterCommit in a plain GORM transaction warns and skips
|
|
- [Phase 11.1]: 11.1-04: Docs examples never register global drivers or engines; toy engines use test-only hooks and driver examples live in the driver package
|
|
- [Phase 11.1]: 11.1-04: Database-bound docs snippets run as TestDocs* regions on each module's Postgres harness through export_docs_test.go wrappers
|
|
- [Phase 11.1]: 11.1-05: acme.blog walkthrough lives in the root module (docs/examples/blog) and is pinned to make:* output by TestScaffoldLayout
|
|
- [Phase 11.1]: 11.1-05: console.PublishCommand takes a withDB parameter because generated zero-argument commands cannot reach the app; Plugin.Commands appends it
|
|
- [Phase 11.1]: 11.1-05: walkthrough form omits published_at (cabana has no date field type); blog:publish sets it and the list shows it
|
|
- [Phase 11.1]: 11.1-06: violation cases are overlays on testdata/clean with a want.txt naming the one problem each plant must produce
|
|
- [Phase 11.1]: 11.1-06: check-phase11.1.sh --named requires every named test to PASS; module TestDocs* and output Examples are derived from source
|
|
- [Phase 11.1]: 11.1-06: CRLF and BOM docs pages stay refused, with a message naming the encoding
|
|
- [Phase 11.1]: A src= fence that is not a top-level block of a docs page is refused and docs:sync does not rewrite it.
|
|
- [Phase 11.1]: Module README src= fences are refused and never captioned; Go fences without src= in a README stay legal.
|
|
- [Phase 11.1]: The identifier fallback runs go doc -c, so a span must match the declaration's case.
|
|
- [Phase 11.1]: Shell command words follow cobra stripFlags and include env prefixes, go run ./cmd/summer and bin/{app}.
|
|
- [Phase 11.2]: 11.2-01: Header at phone widths hides the empty links wrapper at <=720px and tightens gap/padding at <=420px; the handoff spacing overflowed 375px
|
|
- [Phase 11.2]: 11.2-01: Page title 'SummerCMS: A new dawn in content management' with titleTemplate %s; header sun is the unmasked original scaled 1.12, hero sun 136px
|
|
- [Phase 11.2]: 11.2-01: Copy button falls back to a hidden textarea + execCommand when the Clipboard API is missing; a failed copy leaves the label unchanged
|
|
- [Phase 11.2]: 11.2-02: D-42 resolved as defer-tag; no v0.1.0 tag in summercms.go, release path proven on a scratch clone with a local tag, and creating + pushing v0.1.0 and pushing master is a DEPLOY.md launch step
|
|
- [Phase 11.2]: 11.2-02: the terminal check's clone override clones into the page's directory (git clone <override> summercms) so the page's cd summercms works with a local path
|
|
- [Phase 11.2]: 11.2-03: the gate's --built stage builds in release mode only when the framework checkout build.sh uses has v0.1.0, else a dev build
|
|
- [Phase 11.2]: 11.2-03: plugin route coexistence is tested with the plugin's real patterns from surf.BuildRouter(...).Routes() beside cabana's admin patterns on one ServeMux
|
|
- [Phase 12]: 12-01: lagoon.ValidateRequest follows Laravel exactly, including that a wildcard rule with nothing to expand adds no attribute; Go expectations are cross-checked against the real Winter validator from the PHP vendor tree
|
|
- [Phase 12]: 12-01: lagoon.ErrorKeys(errs, rules) rebuilds the PHP message-bag key order from the rule table, since a Go map carries none
|
|
- [Phase 12]: 12-01: exists:table,column compares CAST(column AS TEXT) with the PHP string form of the value, so bad input is a 422, never a Postgres error
|
|
- [Phase 12]: 12-01: beachcomber.PageSearcher is optional and SearchPage falls back to SearchIDs, so Engine and existing fakes stay unchanged; Typesense pages are capped at 250
|
|
- [Phase 12]: 12-01: sm-user-plugin user groups are additive (migration 202610020001_create_user_groups, User.Groups never serialized); commits are local because the orchestrator forbade pushing
|
|
- [Phase 12]: 12-02: Collection strings are trimmed on save (Collection.BeforeSave) because Winter models trim every string attribute; recordings store ' New Shelf ' as 'New Shelf'
|
|
- [Phase 12]: 12-02: ProvisionCollection and the resolve fallback have no kind filter, as PHP; a lower-id wishlist can become the active context
|
|
- [Phase 12]: 12-02: Parity cases that mutate state are recorded from a fresh PHP tinker reset (parity/fonoteka_reset.php) and replayed from a fresh fonoteka seed per case; id sequences lifted to 8 digits
|
|
- [Phase 12]: 12-02: The backend admin album binding keeps a non-provisioning resolver; only API callers provision
|
|
- [Phase 12]: 12-02: Winter HttpException pages are embedded as winter_<status>.html with only the app.url stylesheet origin templated
|
|
- [Phase 12]: Invitation ValidationExceptions (store required|email, normalizeEmail) answer Winter's 500 error page, as recorded PHP does; the store runs a Laravel RFCValidation email port before normalizeEmail
|
|
- [Phase 12]: Invitation mail is a conga Enqueue River job on the invite transaction with the token as lagoon.Encrypted ciphertext; the worker skips superseded or non-pending invitations
|
|
- [Phase 12]: Every resolver caller maps errors through writeResolveError (404 page, 409 pending-invitation page, else opaque 500)
|
|
- [Phase 12]: Route parity cases needing an invitation token seed it on both sides as secret:invite; flows read a PHP-minted token from the log mailer (php_parity.sh serve-mail, invite-token)
|
|
- [Phase 12]: 12-04: slugs and artist name keys port Laravel Str::slug/Str::ascii (czeslaw-niemen, rb), non-Latin scripts dropped
|
|
- [Phase 12]: 12-04: album search engine ids are re-gated by access and active collection only, as Scout's query callback; filters stay engine-side
|
|
- [Phase 12]: 12-04: sync versions compare at whole seconds so PHP's base64 cursor round-trips; albums/value prints exact sums like sprintf('%.2f')
|
|
- [Phase 12]: 12-04: GORM callback handles are used through a NewDB session (cleanSession); WithContext keeps the write's bind variables
|
|
- [Phase 12]: 12-04: parity album state uses fixed ids/timestamps on both sides; recorded query strings are restored from the spec
|
|
|
|
### Pending Todos
|
|
|
|
- [2026-10-01] [docs] Benchmark Płytarium on WinterCMS vs SummerCMS and publish a measured table — [todo file](.planning/todos/pending/2026-10-01-benchmark-the-application-on-wintercms-vs-summercms.md)
|
|
- [unknown] [summercms.go admin auth] Backend admin personal API tokens (deferred Apparatus PersonalApiToken) — [todo file](.planning/todos/pending/backend-admin-api-tokens.md)
|
|
- [unknown] [summercms.go bonfire] Reject duplicate console command names in bonfire.NewRoot — [todo file](.planning/todos/pending/bonfire-duplicate-command-names.md)
|
|
- [unknown] [summercms.go/fetchguard] Extend fetchguard into a guarded outbound http.Client (replaces Apparatus RequestSender) — [todo file](.planning/todos/pending/fetchguard-guarded-http-client.md)
|
|
- [unknown] [summercms.go lagoon] lagoon README registers an after-commit GORM callback that can sort after the flush — [todo file](.planning/todos/pending/lagoon-readme-after-commit-callback-order.md)
|
|
- [unknown] [summercms.go lagoon] lagoon.Validate reports every numeric range failure with the max message — [todo file](.planning/todos/pending/lagoon-validate-min-message.md)
|
|
- [unknown] [summercms.go] Nest framework packages under modules/ — same beach names — [todo file](.planning/todos/pending/nest-framework-packages-under-modules.md)
|
|
- [unknown] [summercms.go/modules] Short README.md per modules/* after the nest — [todo file](.planning/todos/pending/per-module-readmes-after-nest.md)
|
|
- [unknown] [summercms.go/modules/*/README.md, internal/docsite] Convert module README Go code blocks to compiled src= references — [todo file](.planning/todos/pending/readme-go-fences-src.md)
|
|
- [unknown] [summercms.go logging] Framework slog handler that redacts credentials (port RedactCredentialsTap) — [todo file](.planning/todos/pending/redacting-slog-handler.md)
|
|
- [unknown] [../fonoteka.go/README.md] Refresh fonoteka.go README — short status plus migrate/serve/login — [todo file](.planning/todos/pending/refresh-fonoteka-readme.md)
|
|
- [unknown] [summercms.go/README.md] Rewrite summercms.go README — onboard, recreate login, honest cutover — [todo file](.planning/todos/pending/rewrite-summercms-readme.md)
|
|
- [unknown] [summercms.go internal/build] make:admin-controller output does not boot and names the model after the controller — [todo file](.planning/todos/pending/scaffold-admin-controller-incomplete.md)
|
|
- [unknown] [summercms.go internal/build] Scaffolded files carry a DO NOT EDIT header, and make:command cannot reach the application — [todo file](.planning/todos/pending/scaffold-generated-header-and-command-deps.md)
|
|
- [unknown] [summercms.go internal/build] make:model and make:migration in the same second produce migrations that run out of order — [todo file](.planning/todos/pending/scaffold-same-second-migration-order.md)
|
|
- [unknown] [summercms.go wristband] Neutral default resource URL in wristband.DefaultOptions — [todo file](.planning/todos/pending/wristband-neutral-resource-default.md)
|
|
|
|
### Blockers/Concerns
|
|
|
|
- ~~Phase 8 (OAuth2.1) pre-planning check of the PHP OAuth server for `ClientCredentialsStorage`/`TokenExchangeStorage`~~ — resolved 2026-09-23 during Phase 8 discussion/research: the PHP server is hand-rolled and supports only `authorization_code`/`refresh_token`, so neither interface is needed (see 08-CONTEXT.md, 08-RESEARCH.md).
|
|
- Phase 9 (admin schema pipeline / relation manager) is the least-precedented design surface in the research — plan with `--research-phase`.
|
|
- Phase 11 (River dual-driver split) is documented but unverified against a real build — plan with `--research-phase` and budget a timed-latency test.
|
|
- Phase 8 UI gate: scripts/check-phase8-ui.mjs --final-gate's real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented (deliberate fatal() at check-phase8-ui.mjs:458, never authored by 08-05); stage_ui_harness must keep failing closed until a Playwright spec is authored. User approved Phase 8 closure on 2026-09-24 with this gap carried forward -- see 08-10-SUMMARY.md and .planning/phases/08-oauth2-1-authorization-server/deferred-items.md.
|
|
|
|
### Quick Tasks Completed
|
|
|
|
| # | Description | Date | Commit | Directory |
|
|
|---|-------------|------|--------|-----------|
|
|
| 260927-q23 | fix CR-01: /auth/refresh must enforce tokens_valid_after and is_activated | 2026-09-27 | be4a923 | [260927-q23-fix-cr-01-auth-refresh-must-enforce-toke](./quick/260927-q23-fix-cr-01-auth-refresh-must-enforce-toke/) |
|
|
| 261001-qoa | Add a docs page on performance and scaling compared to PHP/WinterCMS | 2026-10-01 | 4103d95 | [261001-qoa-add-a-docs-page-on-performance-and-scali](./quick/261001-qoa-add-a-docs-page-on-performance-and-scali/) |
|
|
| 261002-esz | Extract golem15.user into its own repo sm-user-plugin, mounted back as a submodule | 2026-10-02 | 18576db | [261002-esz-extract-golem15-user-plugin-from-fonotek](./quick/261002-esz-extract-golem15-user-plugin-from-fonotek/) |
|
|
| 2 | make admin SPA edit/create and settings forms full width | 2026-09-27 | 2585671 | — |
|
|
| 260928-lf2 | Rewrite module READMEs and root README as professional app-agnostic docs | 2026-09-28 | fafb12f | [260928-lf2-rewrite-module-readmes-and-root-readme-a](./quick/260928-lf2-rewrite-module-readmes-and-root-readme-a/) |
|
|
| 261001-ddh | Replace lagoon hardcoded ICU pl-PL database locale with per-query COLLATE option | 2026-10-01 | 037dc53 | [261001-ddh-replace-lagoon-hardcoded-icu-pl-pl-datab](./quick/261001-ddh-replace-lagoon-hardcoded-icu-pl-pl-datab/) |
|
|
|
|
## Deferred Items
|
|
|
|
Items acknowledged and carried forward from previous milestone close:
|
|
|
|
| Category | Item | Status | Deferred At |
|
|
|----------|------|--------|-------------|
|
|
| Phase 8 UI gate | `scripts/check-phase8-ui.mjs --final-gate`'s real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented -- deliberate `fatal()` at `scripts/check-phase8-ui.mjs:458`, never authored by 08-05. `stage_ui_harness` must keep failing closed until a Playwright config/spec outside the Nuxt checkout is authored (see .planning/phases/08-oauth2-1-authorization-server/deferred-items.md). Every other Phase 8 gate stage (real unchanged fonoteka-mcp lifecycle, both repos' vet/test/race, 169/169 parity corpus, secret scan, security review 11/11 closed, return-path 6/6, i18n 74 keys) is green. | Open — carried forward, user-approved | 08-10, 2026-09-24 |
|
|
|
|
## Session Continuity
|
|
|
|
Last session: 2026-10-02T12:44:00.552Z
|
|
Stopped at: Completed 12-04-PLAN.md
|
|
Resume file: None
|