67 lines
2.9 KiB
Markdown
67 lines
2.9 KiB
Markdown
# Phase 12: Płytarium API — Collections and Albums - Discussion Log
|
|
|
|
> **Audit trail only.** Do not use as input to planning, research, or execution agents.
|
|
> Decisions are captured in CONTEXT.md — this log preserves the alternatives considered.
|
|
|
|
**Date:** 2026-09-28
|
|
**Phase:** 12-p-ytarium-api-collections-and-albums
|
|
**Areas discussed:** Route boundary, Parity evidence, Invitations & mail, Search & security test
|
|
|
|
---
|
|
|
|
## Todo cross-reference
|
|
|
|
| Option | Description | Selected |
|
|
|--------|-------------|----------|
|
|
| Fold only if Discogs lands here | Decide with the route boundary | ✓ |
|
|
| Leave for Phase 14 | Keep pending | |
|
|
|
|
**Outcome:** Discogs cover-price deferred → todo not folded.
|
|
|
|
## Route boundary
|
|
|
|
| Question | Options | Selected |
|
|
|----------|---------|----------|
|
|
| Reservations (wishlist-only in PHP) | Move to Phase 13 / Keep in 12 | Move to Phase 13 |
|
|
| Discogs cover-price | Pull minimal Discogs in / Defer to 14 | Defer to 14 |
|
|
| sync/stats/value/missing/bulk | All five / Only what Nuxt calls | All five |
|
|
| match/apply-release/recognize/import | Phase 14 / Phase 12 | Phase 14 |
|
|
| cover_urls on create | Seam wired in 14 / Port CoverImporter now | Port CoverImporter now |
|
|
| Public share surface | Collection side in 12 / All public routes in 13 | All public routes in 13 |
|
|
|
|
**Notes:** API-01 and success criterion 1 need rewording; CoverImporter uses the existing fetchguard GET.
|
|
|
|
## Parity evidence
|
|
|
|
| Question | Options | Selected |
|
|
|----------|---------|----------|
|
|
| New recordings | Nuxt flows + error cases / Flows only / Existing only | Nuxt flows + error cases |
|
|
| Centrifugo publications | Record for album flows / Reuse P11 | Record for album flows |
|
|
| Token-group twins | Same handler, own fixtures / Route-table only | Same handler, own fixtures |
|
|
| Uploads | Replay + blob assertions / Go tests only | Replay + blob assertions |
|
|
|
|
## Invitations & mail
|
|
|
|
| Question | Options | Selected |
|
|
|----------|---------|----------|
|
|
| Mail sending | River job in transaction / Inline after commit | River job |
|
|
| Accept notification | Port write now / Seam until 13 | Port write now |
|
|
| No-account invitations | Existing-account path only / Full path now | Existing-account path only |
|
|
|
|
## Search & security test
|
|
|
|
| Question | Options | Selected |
|
|
|----------|---------|----------|
|
|
| Re-gate shape | Mirror Scout exactly / Candidates then SQL paginate | Mirror Scout exactly |
|
|
| SQL LIKE on Postgres | ILIKE escaped / Research decides | ILIKE escaped |
|
|
| Leak test cases (multi) | Stale doc; Mis-scoped doc; Deleted/revoked; Token frozen | All four |
|
|
| Typesense in tests | Fake engine driver / Real container | Fake engine driver |
|
|
|
|
## Claude's Discretion
|
|
|
|
Handler layout, DTO structs and fuzz enumeration, job kind names, fake engine shape, record-vs-Go-test for impractical error cases, plan count and split.
|
|
|
|
## Deferred Ideas
|
|
|
|
Reservations and public routes → Phase 13; Discogs/AI routes → Phase 14; register-via-invitation → Phase 13; notifications API → Phase 13.
|