Files
summercms/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md
2026-10-04 22:53:28 +02:00

41 lines
1.6 KiB
Markdown

---
phase: quick-261004-rou
plan: 01
status: complete
completed: 2026-10-04
commits:
sm-user-plugin: 0fe5b91
fonoteka: d1abcab
---
# Quick 261004-rou Summary
`golem15.user` now owns application-wide API tokens: persistence, minting,
authentication, scopes, management routes/commands, and current user-group
permission grants. Raw secrets remain one-time-only and only SHA-256 hashes
are persisted.
Fonoteka now uses that shared model and guard while preserving its `inv_`
prefix, `inv_token`/`inv.scope:*` middleware contracts, collection pins,
OAuth behavior, and existing endpoints. Its transition migration preserves
legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token
foreign keys, and supports a lossless rollback.
BM's management API was refactored to consume `user.api_token`, `user.scope:*`,
and current group permissions. Per user direction, BM and Quizzes were not
committed; the tested BM changes and User submodule bump remain in the BM
working tree for its dedicated dev-agent to review and commit.
## Verification
- sm-user-plugin: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`
- Fonoteka application: `go test ./...`, `go vet ./...`
- Fonoteka plugin: `go test ./...`, `go vet ./...`
- BM plugin handoff: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`, `git diff --check`
- Migration test covers legacy-token data, an ID collision, OAuth FK retarget,
and reverse rollback.
- BM end-to-end test proves the same shared token follows live group-permission
grants and revocation.
No SummerCMS framework change was required.