Jakub Zych 6cc07a42e2 fix(08-09): match wristband OAuth byte contract to live-recorded PHP
Recording the full mcp-lifecycle fixture against real isolated PHP
(08-09-PLAN.md Task 2) uncovered three byte-level gaps between wristband's
assumed contract and actual production PHP behavior:

- Every explicit "Cache-Control: no-store" PHP sets is actually delivered
  as "no-store, private" (Laravel's session-cookie default merges "private"
  onto any explicit value); wristband's own default for unheadered JSON
  error responses is "no-cache, private" (matching the house convention
  already used elsewhere), not empty.
- PHP's redirect responses (authorize success and every error redirect)
  render Symfony's default HTML redirect body with Content-Type
  "text/html; charset=utf-8"; Go's bare 302 with no body never matched.
  wristband/redirect_html.go ports that exact byte template, including
  PHP's htmlspecialchars(ENT_QUOTES) escaping (Go's html.EscapeString uses
  different quote entities).

tide/normalize.go: isIDKey now also masks "_ids" plural array fields
(e.g. collection_ids), a latent parity-corpus gap no prior fixture had
exercised with a literal, non-empty, non-placeholder array value.
2026-09-23 23:12:02 +02:00
2026-09-16 09:36:57 +02:00

SummerCMS (Go)

A Go rewrite of the WinterCMS/OctoberCMS content management framework, built for the Golem15 stack.

SummerCMS keeps what makes WinterCMS productive — plugins that extend each other, YAML-driven admin forms, models/controllers/components, scaffolding commands — and drops the parts that do not survive a compiled language.

Status

Pre-alpha. Planning and research. Nothing runs yet.

Why Go

The first SummerCMS attempt was Scala 3. Three infrastructure modules were built (config, i18n, console) before the effort stalled on ecosystem depth: proven, reusable libraries for things like an OAuth2/OIDC server did not exist, and building them from scratch was out of budget. Go's ecosystem covers every concern in the Illuminate module map with maintained, widely used libraries. See .planning/notes/why-go-not-scala.md and .planning/research/go-ecosystem.md.

v1 target

Port Płytarium (the fonoteka project): a headless WinterCMS backend with a Nuxt 4 frontend, 160 API routes, its own OAuth2 provider, Discogs and AI integrations, queued jobs, realtime notifications, and organization-scoped collections.

Definition of done for v1: vue-fonoteka-app runs unchanged against the Go backend.

See .planning/notes/v1-target-plytarium.md.

Architecture decisions so far

  • Compiled plugins, Caddy/xcaddy style: a plugins/ workspace of Go modules, a generated import list, scaffold and rebuild commands, watch-rebuild in dev.
  • A sandboxed WASM extension API for untrusted third-party extensions comes later, behind a stable core plugin API.
  • Headless first. Admin is a schema-driven SPA. Server-rendered themes come with the second port target (keios.eu).

Layout

.planning/   GSD planning artifacts (notes, research, seeds, roadmap)

Everything else will be created by the GSD roadmap phases.

Description
Content management framework for Go,
https://summercms.io
Readme 9.6 MiB
Languages
Go 73.5%
TypeScript 11.3%
Vue 5.7%
Shell 4.3%
JavaScript 2.6%
Other 2.6%