D-01 through D-06: independent Postgres cases prove active-collection scoping, nonzero and zero counts, `non_empty`, 422, and database-default Polish order.
D-07 through D-15: auth and middleware tests prove no unauthenticated or locked request reaches the handler, all seven stages are ordered, and typed/constraint params give safe 404 behavior.
D-16 through D-20: migration isolation/up/down/seed and the unchanged recorded fixture pass with honest one-of-154 corpus accounting.
The roadmap's security-load-bearing JWT guard receives a documented security review with every high-severity threat mitigated or explicitly reported.
Root and app vet/test/race checks pass; the Phase 2 parity harness regression remains green.
**As a** maintainer, **I want to** run one repeatable gate for the real genres route and its security boundaries, **so that** later endpoint work cannot silently break the first vertical slice.
Purpose: Finish the phase with dedicated meaningful unit, integration, parity, and security tests as required by CLAUDE.md.
Output: Tests for each risk, one check script, validation evidence, and security review findings.
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-03-SUMMARY.md
Plans 01–03 produce `lagoon`, `surf`, `bouncer`, a two-plugin app, a Postgres-backed genre handler, and a single ported route in `TestParityCorpus`. Phase 2's `scripts/check-phase2.sh` is the baseline harness regression command. All tests in this plan must assert externally observable behavior or security invariants, not duplicate source implementation details.
Task 1: Cover framework boundaries with adversarial unit and integration tests
lagoon/connection_test.go, lagoon/migrations_test.go, lagoon/order_test.go, surf/router_test.go, surf/middleware_test.go, surf/params_test.go, bouncer/jwt_test.go, bonfire/command_test.go, examples/hello/hello_test.go
lagoon/connection.go, lagoon/migrations.go, lagoon/order.go, surf/router.go, surf/middleware.go, surf/params.go, bouncer/jwt.go, bouncer/context.go, bonfire/command.go, examples/hello/hello_test.go, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
Add behavior-focused tests for one pgx stdlib SQL pool shared with GORM and closed on shutdown; wrong ICU provider/locale boot failure; two migration sets with separate history, ordered up/down and rollback isolation; no `AutoMigrate` schema source; allow listed ORDER BY identifiers/direction; ServeMux method/path/group and per-route middleware composition; fixed recover → CORS → locale → auth → password gate → org → rate → handler order, including preflight and panic 500 without leaked internals; missing named middleware boot failure; integer, regex and enum params with malformed and unknown ID 404; and command names `serve`, `migrate`, `migrate:status`, `migrate:rollback`. For JWT, test valid persisted subject plus missing token, malformed token, `alg:none`, wrong HMAC algorithm, bad signature, absent/expired `exp`, absent `sub`, unknown user, empty secret, and absence of token/secret text in errors. Use `httptest` and isolated Postgres where behavior requires the DB; do not create tests that merely assert a helper calls another helper. Keep root and app vet/test green before the commit.
go vet ./... && go test ./... && go test -race ./... && (cd ../fonoteka.go && go vet ./... && go test ./...)
- Every high-severity framework threat T-03-01, T-03-02, and T-03-03 has at least one failing-when-broken test.
- Both malformed and unknown typed IDs return 404, missing middleware fails boot, and an unauthenticated request cannot reach the genre handler.
- Root vet/test/race and app vet/test exit 0 at commit.
The reusable runtime's database, routing and authentication invariants are testable independently of the PHP fixture.
Task 2: Prove app isolation, recorded parity and security review in one final gate
../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/genre_security_test.go, ../fonoteka.go/parity/parity_contract_test.go, scripts/check-phase3.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/parity_test.go, ../fonoteka.go/parity/parity_contract_test.go, ../fonoteka.go/parity/fixtures/routes/get_genres_jwt.yaml, ../fonoteka.go/parity/manifest.yaml, ../fonoteka.go/parity/synthetic_test.go, scripts/check-phase2.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
Complete independent app test cases for owner, editor and foreign albums with positive counts; active-context fallback; `non_empty=0|1|invalid`; exact seeded genre order under database ICU `pl-PL`; empty `data:[]`; JWT 401 variants, locked-user 423, and CORS preflight. Add a corpus contract that checks 154 recorded, 1 real replay pass, 153 pending, 0 false passes and a deliberate mismatch failure against the unmodified fixture. Create `scripts/check-phase3.sh` to run root and app `go vet ./...`, `go test ./...`, `go test -race ./...`, the focused genres parity subtest, corpus audit, and Phase 2 harness regression; it must exit nonzero on any failure and never silently skip Docker. Perform the roadmap's security review of token verification, cross-plugin guard lookup, migration isolation, query tenant boundaries, and secret handling. Record each T-03 threat, source location, test evidence, finding and disposition in `03-SECURITY-REVIEW.md`; resolve high-severity findings before marking the gate green. Fill `03-VALIDATION.md` with actual task IDs, commands and observed results; set `nyquist_compliant: true` only after the full gate passes. Keep the PHP fixture, generic `tide` code and other 153 route statuses unchanged.
bash scripts/check-phase3.sh
- `bash scripts/check-phase3.sh` exits 0 with root and app vet/test/race green and one real ported parity pass.
- The corpus report is 154 recorded, 1 passing, 153 pending, 0 failing, 0 unrecorded; a deliberate response mutation fails a contract test.
- `03-SECURITY-REVIEW.md` maps all high-severity threats to passing tests or a resolved finding; no open high-severity JWT or cross-tenant issue remains.
- `03-VALIDATION.md` records observed evidence and only then has `nyquist_compliant: true`.
One command proves the first real Go route's parity and its security boundaries, with evidence ready for phase verification.
<threat_model>
Trust Boundaries
Boundary
Description
Test fixture and adversarial HTTP inputs → running app
Tests must exercise real routing, auth and data boundaries.
Security review → phase acceptance
Unresolved high-severity findings cannot be hidden by a green happy-path fixture.
STRIDE Threat Register
Threat ID
Category
Severity
Component
Disposition
Mitigation Plan
T-03-02
Elevation of privilege
high
named middleware
mitigate
Missing-name and unauthenticated-route tests plus source review.
T-03-03
Spoofing
high
JWT guard
mitigate
Full malformed/forged/expired/unknown-user matrix and secret handling review.
T-03-04
Information disclosure
high
aggregate query
mitigate
Cross-tenant owner/editor/foreign album tests and query review.
T-03-06
Tampering
high
parity acceptance
mitigate
Real replay, honest pass counter, deliberate mismatch test.
</threat_model>
Run the repeatable Phase 3 script from the framework root after both task commits. Inspect its output and the security review/validation artifacts before recording success.
<success_criteria>
All four Phase 3 roadmap criteria have direct passing evidence, the recorded PHP fixture is unchanged, and no high-severity security issue remains open.
</success_criteria>
Create `.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-SUMMARY.md` after completion.