Files
summercms/.planning/phases/08-oauth2-1-authorization-server/deferred-items.md
Jakub Zych 2d551c09d7 docs(08-10): record the checkpoint decision and carry the Playwright UI matrix gap forward
scripts/check-phase8.sh's final gate ran once with every stage green except
stage_ui_harness's Playwright browser matrix, a deliberate fatal() never
authored by 08-05. The user approved closing Phase 8 with this gap carried
forward; 08-VALIDATION.md flips 08-W0-07 green, marks 08-W0-08 partially
verified, and sets nyquist_compliant: false honestly. deferred-items.md
records what the follow-up spec needs to do.
2026-09-24 00:56:20 +02:00

125 lines
6.9 KiB
Markdown

# Phase 08 Deferred Items
Out-of-scope discoveries logged during plan execution, per the executor's
scope-boundary rule (fix only what the current task's changes directly
caused).
## 08-03: pre-existing full-schema rollback test failures (not caused by this plan)
**Found during:** 08-03 Task 2 full-suite verification (`go test ./...` in `fonoteka.go`).
**Failing tests:** `TestRemainingMigrationsUpDown` (`parity/remaining_models_test.go`),
`TestRollbackIsolatesFonotekaFullSchema` (`parity/rollback_isolation_full_test.go`).
**Symptom:** both tests assert the *last* fonoteka migration is
`create_fonoteka_settings` (a Phase 5 migration) and/or that a full
up/down/up cycle leaves no tables behind. Since 08-02 added
`202609230019_oauth_schema_correction.go` (the corrective OAuth
nullability/index migration, 08-02-SUMMARY.md), that migration is now the
last one in the registered slice, so the hardcoded "last migration" name
assertion is stale, and rollback of the corrected schema leaves
`golem15_fonoteka_settings` behind.
**Scope:** neither test file, nor `plugins/golem15/fonoteka/updates/`, nor
any model file is in 08-03's `files_modified` list; this plan (authorize)
touches `wristband/authorize.go`, `wristband/server.go` (Options
extension), `plugin.go`, and `routes.go` only. Confirmed pre-existing via
`git log` on the failing test files: both were last touched by Phase 5
(`6c9695f`), and 08-02's migration-correction commit (`4536b3e`) is what
shifted the "last migration" identity without updating these two tests.
**Disposition:** deferred to whichever later Phase 8 plan owns migration/
schema test maintenance (or the phase-closing unit-test plan). Not fixed
here per the executor's scope-boundary rule.
## 08-03: pre-existing flaky test in an unrelated package (summercms.go)
**Found during:** 08-03 Task 2 full-suite verification (`go test ./...` in `summercms.go`).
**Failing test:** `TestFetchTooLargeIsStreaming` (`fetchguard/fetch_test.go`),
intermittently fails with "server wrote 71680 bytes, client appears to have
buffered unbounded body" under `go test ./...` but passes reliably when run
in isolation (`go test ./fetchguard -run TestFetchTooLargeIsStreaming
-count=3`). `fetchguard` is untouched by this plan. Not fixed here.
**Resolution (orchestrator, after 08-03):** fixed in `fonoteka.go` commit
`f9b23e1` (`fix(08-03): update parity migration tests for the oauth schema
correction head`). Five parity tests (`TestMigrateSeedsCanonicalGenres`,
`TestAlbumSliceMigrationsUpDown`, `TestSecretsSliceMigrationsUpDown`,
`TestRemainingMigrationsUpDown`, `TestRollbackIsolatesFonotekaFullSchema`)
now expect `202609230019_oauth_schema_correction` as the head and walk one
extra table-less rollback step. `go test ./...` in the `fonoteka.go` root
module is green again.
## Pre-existing flake: `fetchguard.TestFetchTooLargeIsStreaming` (summercms.go)
**Found during:** post-wave test gates after 08-03.
**Symptom:** fails intermittently only under a full parallel `go test ./...`
run; passes on every isolated run (`-count=5`) and every package-level run
(`-count=3`). Last touched in Phase 6 (`e50e2dd`); no Phase 8 plan modifies
`fetchguard`. Timing-sensitive streaming assertion under load. Not a Phase 8
regression; left for a later hardening pass.
**Resolution (orchestrator, after 08-05):** the flake tripped the post-wave
gate on two of three full runs, so it was fixed in `summercms.go` commit
`test(fetchguard): widen streaming-cap ceiling to stop flake under parallel
runs`. The ceiling moved from 64 KiB to 1 MiB; the assertion still proves the
client does not buffer an unbounded body (the handler would reach 8 MiB).
## Follow-up: Playwright UI matrix for scripts/check-phase8-ui.mjs --final-gate
**Found during:** 08-10 Task 3, the sole real execution of
`scripts/check-phase8.sh` (2026-09-24).
**What is missing:** `scripts/check-phase8-ui.mjs`'s `--final-gate` mode
(`runFinalGate()`, `scripts/check-phase8-ui.mjs:436-459`) runs
`verify:oauth-return-path` and `verify:oauth-i18n` for real, then reaches a
deliberate `fatal('--final-gate Playwright matrix wiring is 08-10's
responsibility; not implemented in 08-05.')` at line 458. The 32-scenario
`SCENARIOS` catalog (08-UI-SPEC.md's complete state/accessibility/
responsive/i18n matrix) is fully authored and self-tested for completeness
by `--contract-self-test`, but no Playwright spec file consumes it and no
Playwright config exists to run one. Specifically still needed:
- A Playwright config and spec file living outside the `vue-fonoteka-app`
Nuxt checkout (08-UI-SPEC.md's Non-Redesign Rule: this harness must never
write inside the Nuxt checkout or add a registry component there), that
imports/consumes the versioned `SCENARIOS` catalog already in
`check-phase8-ui.mjs` so the spec and the scenario data cannot drift apart.
- `NUXT_DEV_BACKEND_ORIGIN` (or an equivalent env var) wired from the spec's
Playwright config to the ephemeral Go app `scripts/check-phase8.sh` boots
for the gate run, so the real Nuxt dev/preview server the Playwright
browser drives talks to the disposable gate backend instead of a
developer's local backend.
- A real login through the assembled Go backend (not a mocked network
response) for every scenario that is not explicitly declared
network-intercepted in the `SCENARIOS` catalog (see the catalog's own
`no-request` / `redirect-to-login-with-return` scenarios, which assert the
*absence* of a network call and must stay mocked).
- DOM assertions against `app/pages/connect.vue`,
`app/components/fonoteka/ConsentScopePicker.vue`, and
`app/components/fonoteka/ConnectedAppsManager.vue` (the three guarded Nuxt
source files `check-phase8-ui.mjs` hashes at
`scripts/check-phase8-ui.mjs:57-59`), selected via their existing
`data-testid` attributes, matching each scenario's expected state.
**Failing identifier:** `scripts/check-phase8-ui.mjs --final-gate` ->
stage `stage_ui_harness` (`scripts/check-phase8.sh:426-431`) -> fatal message
`--final-gate Playwright matrix wiring is 08-10's responsibility; not
implemented in 08-05.` (`scripts/check-phase8-ui.mjs:458`).
**Disposition:** the user approved closing Phase 8 on 2026-09-24 with this
gap carried forward as a named follow-up ("Approve, carry gap forward" —
08-10 Task 3 checkpoint decision). Every other `scripts/check-phase8.sh`
stage ran green in that same gate execution: docker preflight, Postgres,
app boot, the real unchanged `fonoteka-mcp` lifecycle (discovery, DCR, PKCE
authorize, JWT consent, token, tool call, refresh, replay, revoke), both
repositories' vet/test/race, the 169/169 parity corpus, the secret scan, the
6/6 OAuth return-path checks, the 74-key i18n check, the unchanged-client
diff, and the security review (11/11 threats closed, 0 open). The gate script
must keep failing closed on `stage_ui_harness` until the Playwright spec
above exists -- do not weaken, skip, or stub that stage to close this gap.
Whichever future plan authors the spec should also flip 08-VALIDATION.md's
08-W0-08 row and `nyquist_compliant` back to fully green.