Files
summercms/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md
2026-10-04 22:53:28 +02:00

1.6 KiB

phase, plan, status, completed, commits
phase plan status completed commits
quick-261004-rou 01 complete 2026-10-04
sm-user-plugin fonoteka
0fe5b91 d1abcab

Quick 261004-rou Summary

golem15.user now owns application-wide API tokens: persistence, minting, authentication, scopes, management routes/commands, and current user-group permission grants. Raw secrets remain one-time-only and only SHA-256 hashes are persisted.

Fonoteka now uses that shared model and guard while preserving its inv_ prefix, inv_token/inv.scope:* middleware contracts, collection pins, OAuth behavior, and existing endpoints. Its transition migration preserves legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token foreign keys, and supports a lossless rollback.

BM's management API was refactored to consume user.api_token, user.scope:*, and current group permissions. Per user direction, BM and Quizzes were not committed; the tested BM changes and User submodule bump remain in the BM working tree for its dedicated dev-agent to review and commit.

Verification

  • sm-user-plugin: GOWORK=off go test ./..., GOWORK=off go vet ./...
  • Fonoteka application: go test ./..., go vet ./...
  • Fonoteka plugin: go test ./..., go vet ./...
  • BM plugin handoff: GOWORK=off go test ./..., GOWORK=off go vet ./..., git diff --check
  • Migration test covers legacy-token data, an ID collision, OAuth FK retarget, and reverse rollback.
  • BM end-to-end test proves the same shared token follows live group-permission grants and revocation.

No SummerCMS framework change was required.