1.6 KiB
phase, plan, status, completed, commits
| phase | plan | status | completed | commits | ||||
|---|---|---|---|---|---|---|---|---|
| quick-261004-rou | 01 | complete | 2026-10-04 |
|
Quick 261004-rou Summary
golem15.user now owns application-wide API tokens: persistence, minting,
authentication, scopes, management routes/commands, and current user-group
permission grants. Raw secrets remain one-time-only and only SHA-256 hashes
are persisted.
Fonoteka now uses that shared model and guard while preserving its inv_
prefix, inv_token/inv.scope:* middleware contracts, collection pins,
OAuth behavior, and existing endpoints. Its transition migration preserves
legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token
foreign keys, and supports a lossless rollback.
BM's management API was refactored to consume user.api_token, user.scope:*,
and current group permissions. Per user direction, BM and Quizzes were not
committed; the tested BM changes and User submodule bump remain in the BM
working tree for its dedicated dev-agent to review and commit.
Verification
- sm-user-plugin:
GOWORK=off go test ./...,GOWORK=off go vet ./... - Fonoteka application:
go test ./...,go vet ./... - Fonoteka plugin:
go test ./...,go vet ./... - BM plugin handoff:
GOWORK=off go test ./...,GOWORK=off go vet ./...,git diff --check - Migration test covers legacy-token data, an ID collision, OAuth FK retarget, and reverse rollback.
- BM end-to-end test proves the same shared token follows live group-permission grants and revocation.
No SummerCMS framework change was required.