Files
summercms/.planning/STATE.md

44 KiB

gsd_state_version, milestone, current_phase, current_phase_name, status, stopped_at, last_updated, last_activity, last_activity_desc, state_head, progress, milestone_name
gsd_state_version milestone current_phase current_phase_name status stopped_at last_updated last_activity last_activity_desc state_head progress milestone_name
1.0 v1.0 10 Admin Vue SPA executing Completed 10-03-PLAN.md 2026-09-27T15:02:42.446Z 2026-09-27 Phase 10 plan 03 lists, forms, filters and settings completed 1964844eb9
total_phases completed_phases total_plans completed_plans
15 8 72 70
milestone

Project State

Project Reference

See: .planning/PROJECT.md (updated 2026-09-16)

Core value: An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test. Current focus: Phase 10 — Admin Vue SPA

Current Position

Phase: 10 (Admin Vue SPA) — EXECUTING Plan: 4 of 5 Status: Ready to execute Last activity: 2026-09-27 — Phase 10 plan 03 lists, forms, filters and settings completed

Progress: [██████████] 100%

Performance Metrics

Velocity:

  • Total plans completed: 66
  • Average duration: 21 min
  • Total execution time: 104 min

By Phase:

Phase Plans Total Avg/Plan
01 4 - -
02 5 - -
03 4 - -
04 4 - -
05 6 - -
06 14 - -
7 8 - -
08 10 - -

Recent Trend:

  • Last 5 plans: 02-01 7 min, 02-02 12 min, 02-03 61 min, 02-04 9 min, 02-05 15 min
  • Trend: -

Updated after each plan completion | Phase 03 P03-01 | 17 min | 2 tasks | 52 files | | Phase 03 P03-02 | 5 min | 2 tasks | 8 files | | Phase 03 P03-03 | 8 min | 2 tasks | 17 files | | Phase 03 P03-04 | 15 min | 2 tasks | 15 files | | Phase 04 P01 | 11 min | 3 tasks | 14 files | | Phase 04 P04-02 | 10 min | 3 tasks | 11 files | | Phase 04 P04-03 | 6 min | 3 tasks | 15 files | | Phase 04 P04-04 | 8 min | 3 tasks | 9 files | | Phase 05 P01 | 16 min | 4 tasks | 37 files | | Phase 05 P02 | 27 min | 3 tasks | 32 files | | Phase 05-data-layer-full-fidelity P03 | 15 min | 3 tasks | 28 files | | Phase 05 P04 | 18 min | 3 tasks | 18 files | | Phase 05 P05 | 18 min | 3 tasks | 18 files | | Phase 05 P06 | 23 min | 3 tasks | 12 files | | Phase 06 P01 | 25 min | 3 tasks | 26 files | | Phase 06 P02 | 14 min | 3 tasks | 16 files | | Phase 06 P03 | 20 min | 3 tasks | 24 files | | Phase 06 P05 | 13 min | 3 tasks | 13 files | | Phase 06 P06 | 1h 29m | 2 tasks | 3 files | | Phase 06 P07 | 12 min | 1 tasks | 4 files | | Phase 06 P08 | 1h 20m | 1 tasks | 3 files | | Phase 06 P09 | 4 min | 1 tasks | 2 files | | Phase 06 P10 | 3h 15m | 1 tasks | 2 files | | Phase 06 P11 | 12h 30m | 1 tasks | 1 files | | Phase 07 P01 | 12 min | 3 tasks | 20 files | | Phase 07 P02 | 83m | 3 tasks | 22 files | | Phase 07 P03 | 95m | 3 tasks | 28 files | | Phase 07 P04 | 75m | 3 tasks | 16 files | | Phase 07 P05 | 45 | 3 tasks | 45 files | | Phase 07 P06 | 40 min | 3 tasks | 8 files | | Phase 07 P07 | 3h 15m | 3 tasks | 28 files | | Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files | | Phase 07-user-plugin-and-authentication P08 | 25min | 3 tasks | 6 files | | Phase 08 P01 | 25min | 2 tasks | 6 files | | Phase 08 P02 | 30min | 3 tasks | 14 files | | Phase 08 P03 | 20min | 2 tasks | 6 files | | Phase 08 P04 | 15min | 2 tasks | 5 files | | Phase 08 P05 | 55min | 3 tasks | 12 files | | Phase 08 P06 | 50min | 3 tasks | 10 files | | Phase 08 P07 | 35min | 2 tasks | 9 files | | Phase 08 P08 | 20min | 2 tasks | 4 files | | Phase 08 P09 | 55min | 3 tasks | 25 files | | Phase 08 P10 | 55min | 3 tasks | 17 files | Per-Plan Metrics:

Plan Duration Tasks Files
Phase 09 P01 26min 2 tasks 26 files
Phase 09 P02 22 min 3 tasks 14 files
Phase 09 P03 25min 3 tasks 10 files
Phase 09 P04 36min 3 tasks 13 files
Phase 09 P05 25min 3 tasks 8 files
Phase 09 P06 29min 3 tasks 15 files
Phase 09 P07 2h20m 2 tasks 9 files
Phase 09 P08 2h28m 2 tasks 4 files
Phase 09 P09 11h 48m 2 tasks 9 files
Phase 09 P10 2h 20m 3 tasks 17 files
Phase 09 P11 1h 15m 3 tasks 21 files
Phase 10 P01 31min 3 tasks 111 files
Phase 10 P02 50min 3 tasks 63 files
Phase 10 P03 23 min 3 tasks 64 files

Accumulated Context

Roadmap Evolution

  • Phase 2 edited: edited fields: depends_on (Phase 1), goal (summer parity:* on bonfire, no longer a parallel workstream)

Decisions

Decisions are logged in PROJECT.md Key Decisions table. Recent decisions affecting current work:

  • Roadmap: gormigrate (not goose) is the migration tool, per STACK.md's more recent reasoning — ARCHITECTURE.md/PITFALLS.md text still says goose in places; treat gormigrate as authoritative when phases 3 and 5 are planned.
  • Roadmap: two repos from day one — summercms.go (framework, no app knowledge) and fonoteka.go (sibling app repo, go.work workspace of plugins). Every phase states which repo(s) it writes to.
  • Roadmap: the parity harness (Phase 2) and the first vertical slice (Phase 3) are sequenced immediately after kernel foundation, ahead of any further kernel broadening, to avoid the documented Scala-era bottom-up-kernel failure mode.
  • [Phase 02]: tide is the framework-owned parity library and does not import Fonoteka — Phase 2 CONTEXT.md discretion; summercms.go must stay app-agnostic
  • [Phase 02]: goccy/go-yaml v1.19.2 decodes fixtures with DisallowUnknownField; SaveFlow uses a dedicated encoder so nested literal bodies keep indent — goccy BytesMarshaler re-emitted |- scalars without nested indent; decode still uses the verified library
  • [Phase 02]: JSON diffs ignore object key order and fail missing keys or token-type changes at $.path; non-JSON compares bytes at offset — D-13: structural JSON compare with UseNumber, exact bytes for non-JSON
  • [Phase 02]: Proxy bind and upstream must be loopback HTTP; incoming Host/URL never selects the origin — T-02-01: pin PHP upstream, ignore client destination, cap bodies
  • [Phase 02]: Capture rules and a private 0600 --vars store drive {{name}} substitution; unclassified credential shapes fail fixture writes — D-07 D-11 and T-02-02: never commit live JWT, inv_ tokens, OAuth codes or PKCE verifiers
  • [Phase 02]: Carbon *_at values must match +00:00 before masking; Z, string ids, null vs [] and missing keys fail at $.path — D-13 D-15: assert shape before mask so parity classes stay visible
  • [Phase 02]: 154 is the app manifest validated route count, not a framework constant; --next-batch above 15 is refused — D-16 and the 15-route resume workflow; keep tide generic
  • [Phase 02]: Isolated PHP uses a parity-named SQLite file on 127.0.0.1:8423; record/reset refuse any other DB — T-02-05
  • [Phase 02]: Client OAuth replay merges /tmp/summercms-parity/pkce.vars after seed; the verifier is not in git — D-07 D-11
  • [Phase 02]: newTarget and seedHooks live in the app test package so Phase 3 can swap the synthetic handler for the real app and add a temporary genres SQL hook until POST genres is ported — D-10 D-12: framework tide stays app-agnostic; the handler/seed-hook seam is app-owned
  • [Phase 02]: Pending never equals passing: TestParityCorpus reports recorded 154/154 passing 0 pending 154 and does not replay PHP fixtures against the synthetic handler — D-16: unported PHP routes must never count as a Go pass
  • [Phase 02]: Unavailable Docker fails TestMain; testing.Short skips the container so the fast loop stays fast — QA-03 and D-12: no false green skip when Postgres cannot start
  • [Phase 02]: Fresh PHP self-replay uses disposable MariaDB fonoteka_parity_* plus process-local hex credentials, never the developer DB or caller-supplied PHP_PARITY_TARGET — T-02-01 T-02-05: check-phase2.sh --fresh-php owns the origin and rejects PHP_PARITY_TARGET
  • [Phase 02]: Client flows run on a second winter:up after dropping tables so they are not replayed after the mutating 154-route suite — D-16 and 02-03 seed-then-clients: keep route replay and Nuxt/MCP replay on disjoint schemas
  • [Phase 02]: Capture-by-reference mismatch is a two-step share:item flow with a live token change on the second /show — D-11 D-13: contract tests exercise RecordFlow/ReplayFlow public APIs, not private helpers
  • [Phase 03]: GORM and app services share one pgx-stdlib *sql.DB; the River LISTEN/NOTIFY pool is a Phase 11 seam and is not created in lagoon.Open — DATA-01: one shared pool now; dual-driver River listener deferred
  • [Phase 03]: Generated app main stays framework-generic (lagoon.RuntimeCommands + surf.ServeCommand); fonoteka.go/app.Handler is the in-process boot seam for parity tests — summer build cannot import the app package; CLI serve and tests still assemble the same surf router
  • [Phase 03]: Empty golem15.user.jwt.secret fails Boot; tests use a fixed test-only HS256 secret and do not issue tokens through a production API — D-11: missing secret must not fall back; token minting stays out of Phase 3
  • [Phase 03]: lagoon.OrderBy takes a caller allow-list so the framework never hardcodes Fonoteka table names; the handler passes PHP PolishOrder::ALLOWED_COLUMNS — summercms.go must stay app-agnostic; PolishOrder columns live at the Fonoteka call site
  • [Phase 03]: Duplicate non_empty query keys last-win, matching PHP parse_str; invalid then 1 is accepted, 1 then invalid is 422 — PHP parse_str last-wins confirmed with php -r; Go uses vals[len(vals)-1]
  • [Phase 03]: Invalid stored context is rewritten to the lowest-ID accessible kind=collection row; auto-provisioning stays out of this slice — Plan 03-02 ports only the JWT default resolve path; CollectionProvisioner is Phase 12
  • [Phase 03]: Route constraints compile regex and enum allow-lists at registration; request path text is only matched — D-15 T-03-07: PHP ->where() maps onto surf.Where/WhereIn; malformed and unknown IDs share a 404
  • [Phase 03]: A ported route with a trusted seed_hook skips the global PHP bootstrap replay — D-20: unported register/login and POST genres; the hook mints a test-only JWT
  • [Phase 03]: Corpus passing increments only after the ported subtest succeeds; pending never counts as passing — QA-04 T-03-06: 154 recorded, 1 passing, 153 pending
  • [Phase 03]: Colliding fixture IDs are derived from CanonicalGenres seed order (rock=1, electronic=2, jazz=4) — D-20: set id:token, id:wishlist-album, id:genre from PHP seed order, not user input
  • [Phase 03]: Phase 3 gate inlines TestParitySynthetic and CLI record/replay; PHP --fresh-php stays the Phase 2 sign-off because four wishlist album_count routes currently fail on live PHP — check-phase2.sh --fresh-php reports 150/154 on wishlist album_count expected 1 vs live 2. Phase 3 did not change PHP, tide, or those fixtures, so the Phase 3 gate must not fail on that drift.
  • [Phase 03]: testcontainers-go v0.44.0 is the STACK-named test dependency for framework lagoon isolation tests, matching the app TestMain — DATA-01 isolation tests need a real ICU pl-PL Postgres. The app already used testcontainers; the framework module now pins the same STACK versions so lagoon tests do not share the app TestMain.
  • [Phase 03]: High-severity T-03-01 through T-03-04 and T-03-06 are closed with failing-when-broken tests; token issuing remains test-only until Phase 7 — Roadmap required a security review of the JWT guard. 03-SECURITY-REVIEW.md maps each threat to a passing test; minting tokens through a production API is out of this slice.
  • [Phase 04]: registry.gen.go is regenerated by scanning Code generated by summer make files, not by rewriting plugin.go — D-12: handwritten plugin.go stays byte-identical; existing plugins get a one-time accessor hint
  • [Phase 04]: make:model table names are vendor_plugin_plural_snake with explicit gormigrate CREATE/DROP TABLE — D-13: timestamps on the model; --no-migration omits only the create-table file
  • [Phase 04]: models sibling-import check runs in build.App before go build and reports plugin ID, file, and import — D-11: limited to classes/controllers/console/jobs/middleware/updates of the same plugin module
  • [Phase 04]: go-i18n is used only to choose a CLDR category label; YAML message text never enters its template engine — D-03: PHP :name placeholders must remain literal
  • [Phase 04]: A per-locale i18n.Bundle is cached so matcher/plural rules follow the requested tag, not the English default bundle — A single English default bundle made Polish few/many look invalid
  • [Phase 04]: Fallback order is requested, parent, app.fallback_locale, then the raw key; framework defaults remain en/en — D-04 D-05: no Polish framework default and no extra core-locale step
  • [Phase 04]: Goldmark v1.8.6 is used without html.WithUnsafe; final HTML is rejected if script/iframe, event handlers, or javascript/vbscript/data schemes remain — D-07 and T-04-08: Goldmark default rejects raw HTML; a second pass keeps layout HTML trusted only as template.HTML
  • [Phase 04]: postcard.Mailer is published after Register and before Boot; each HasMailTemplates catalog is validated at that plugin Boot transition — D-20 D-21: plugin Boot can Lookup the mailer; missing files fail as party: boot with the dotted name
  • [Phase 04]: mail.smtp.tls defaults to mandatory STARTTLS; none/notls is opt-in for Mailpit and is never inferred — D-18 T-04-10: no silent production TLS downgrade; Mailpit needs explicit NoTLS
  • [Phase 04]: Mailpit image is axllent/mailpit:v1.31.1; receipt is polled from /api/v1/messages then /api/v1/message/{ID} — D-19: a successful Send claim requires observed receipt through a separate HTTP API; pin a released Mailpit tag
  • [Phase 04]: fstest.MapFS WalkDir cannot host '..' keys; malformed lang paths are extra-segment and wrong-suffix files — MapFS Open/WalkDir follows .. into an infinite directory loop; parseLangPath still rejects cleaned traversal
  • [Phase 05]: Models-leaf rule holds on keios.eu user, jz chat, and pxpx checkout; contracts/VOs/jobs/broadcasting stay inside the cast-or-hook conversion treatments
  • [Phase 05]: plugin.go Models()/Migrations() return registry All(); Boot calls classes.RegisterHooks when *gorm.DB is published — later Phase 5 plans add files, not edit plugin.go
  • [Phase 05]: lagoon.Fill matches gorm column tags against the caller allow-list and logs dropped keys once per type+key in non-production — D-05 D-06
  • [Phase 05]: Lifecycle Has* interfaces use GORM-native signatures; WithSoftDeleteCascade does not open a new transaction — DATA-03 primitive
  • [Phase 05]: Paginate coerces nil data to []; RegisterJoinTable fails loud on nil db — DATA-10 and pivot-write contract
  • [Phase 05]: DATA-09 migration count is not an acceptance number (D-01); HTTP DTO fuzz moves to Phase 12 (D-07)
  • [Phase 05]: Jsonable payload field is Data, not Value, because driver.Valuer.Value() collides under go vet — go vet rejects a field and method both named Value; type Jsonable[T] T is illegal
  • [Phase 05]: KeepMarketPriceSource is a gorm-ignored Album flag set by SaveAlbum when requested contains market_price_source — GORM has no Eloquent isDirty; the flag preserves stampMarketPrice source provenance
  • [Phase 05]: CollectionFillFields is name+description; PHP has no CollectionWriteService — D-05 service list is a subset of Fillable excluding owner_id
  • [Phase 05]: Various Artists natural key is name_key='various artists' (PHP seed), slug various-artists — seed_genre_and_various_artist_taxonomy.php uses a spaced name_key
  • [Phase 05]: go-playground/validator v10.30.4 is the STACK-named rule engine behind lagoon.Validate — STACK.md already named this library; lagoon.Validate translates Laravel rule strings onto Var()
  • [Phase 05]: Column keys are HKDF-SHA256 derived via Go 1.27 crypto/hkdf with info summercms.lagoon.encrypted.v1; no golang.org/x/crypto — D-11 stdlib-first: Go 1.24+ ships HKDF; CLAUDE.md forbids a new dependency here
  • [Phase 05]: Ciphertext is 1-byte format/key-id | 12-byte nonce | GCM seal, stored base64 in text columns — D-12 versioned ciphertext plus app.previous_keys decrypt-only fallback
  • [Phase 05]: OpenFromApp calls LoadAppKey+PublishEncryptionKeys once per boot; empty/short/undecodable app.key fails with SUMMER_APP__KEY — D-11 fail-loud, no default key; Scan/Value must not re-read config per row
  • [Phase 05]: golem15_user_organisations is owned by the user plugin; Phase 5 ships no users-table ALTER (D-03 deviation, Phase 7 AUTH-02) — User-confirmed at plan time: organisations are an FK target only this phase
  • [Phase 05]: DecryptLaravelPayload is cutover-import-only and is never called from Encrypted Scan/Value — D-10 live path is AES-256-GCM only; Laravel CBC is Phase 15 import
  • [Phase 05]: Blob keys are partition+disk_name (no public/protected prefix); fileblob roots at storage/app/uploads — StaticHandler reconstructs keys from PartitionDirectory+disk_name; cutover can point bucket_url at uploads/public
  • [Phase 05]: DeleteForOwner afterCommit is an in-tx key collector; DeleteKeys removes originals and thumb__ prefixes after commit — GORM has no post-commit hook; a rollback must not have already deleted bytes
  • [Phase 05]: Album/Collection MorphName returns the PHP class string and does not import attach (models stay a leaf) — models-leaf rule; interface satisfaction is implicit
  • [Phase 05]: Settings is golem15_fonoteka_settings singleton with typed search_use_typesense BOOLEAN (RESEARCH Open Question 2) — PHP SettingsModel over system_settings is not ported; dedicated typed table is the user-resolved storage
  • [Phase 05]: notifications/wishlist_subscriptions/wishlist_digest_queue have no FK on user_id/collection_id, matching PHP (Open Question 3 / T-05-18) — PHP migrations omit ->foreign() on these tables; D-02 matches actual constraints rather than fixing them
  • [Phase 05]: D-02 allow-list is settings table, users column-count (no widen_users), and the shipped extra oauth_refresh_tokens.user_id FK — Intended gaps only: Open Question 2, D-03/AUTH-02, and P3 D-17 freeze of 05-03 extra FK
  • [Phase 05]: DATA-11 fixture plugin is test-only: no process-wide Register, not in app.PluginIDs or plugins.gen.go — CONTEXT.md discretion: fixture plugin in tests is acceptable; production binary must not load it
  • [Phase 05]: Hidden-marshal registry walk lives in fonoteka.go/classes because summercms.go must not import the app — CLAUDE.md two-repo rule; plan allowed the parity/classes fallback
  • [Phase 05]: Credential fuzz excludes owner FKs from the working allow-list, matching D-05 two-layer even without a write-service file — Fillable() includes user_id/organisation_id; acceptance requires the owner FK never change
  • [Phase 05]: classes TestMain is the real-Postgres harness; parity activateAppPlugins/parityDB cannot be imported from package main — Same ICU pl-PL migrate-both-plugins shape without crossing the app/framework test boundary
  • [Phase 06]: Parameterized middleware is a surf factory (strings.Cut on first ':'), not a fixed name table (D-05)
  • [Phase 06]: TokenGuard implements CredentialGuard only; InvScope owns PHP TokenScope 401/403 bodies (D-08)
  • [Phase 06]: NewJWTGuard reuses bearerToken/Verify/write401 so Registry.Middleware(jwt) is byte-identical to bouncer.Middleware (D-10)
  • [Phase 06]: oauth is not registered this plan; only jwt and inv_token (D-09)
  • [Phase 06]: Personal-token genres fixture body matches isolated seedGenres; CORS * deferred to D-18
  • [Phase 06]: Concrete limiter is FixedWindowLimiter; surf.Limiter interface remains the unused Phase 3 seam — D-03 D-05 naming collision with pre-existing Limiter interface
  • [Phase 06]: Trusted-proxy list is a NewFixedWindowLimiter constructor argument, never a setter — Named-bucket Key closures and inline N,M must share one trusted list
  • [Phase 06]: fonoteka-* buckets live on the app plugin via surf.BucketProvider, not hardcoded in surf — summercms.go must stay Płytarium-agnostic
  • [Phase 06]: Empty PHP group builders plus test-only boot-probe routes prove middleware strings resolve without 501 shells — D-15: no 501 shells; wrap() only sees routes
  • [Phase 06]: php_parity.sh pins APP_DEBUG=false; three existing HTML exception fixtures need re-recording — T-06-09 production-shaped error bodies
  • [Phase 06]: HasHouseMiddleware is the only plugin-facing house-tag path; Assemble/BuildRouter is the sole RegisterHouseMiddleware caller (D-16)
  • [Phase 06]: Production body limits are 134217728/134217728 (128MiB), operator-confirmed 2026-09-19 from nginx client_max_body_size=128M and php.ini post_max_size=128M/upload_max_filesize=128M (D-18, T-06-13)
  • [Phase 06]: CORS path globs compile as Laravel nested * because Go path.Match would miss /api/v1/fonoteka/genres (Pitfall 10)
  • [Phase 06]: swag v1 Swagger 2 is converted by a local swagger2openapi helper to OpenAPI 3 for openapi-typescript 7; Phase 10 wires types into the admin SPA
  • [Phase 06]: Full route-table isolation uses surf.BuildRouter of the real plugins; app.Handler returns http.Handler and cannot call Routes() — app.Handler assembles an http.Handler; Routes() is on *surf.Router
  • [Phase 06]: T-06-05 remains accept as originating 06-01 (the 06-05 plan three-accepts list omitted it) — Originating plan disposition is copied verbatim into 06-SECURITY-REVIEW.md
  • [Phase 06]: PublicOnlyMode any-host-when-public is proven via skipReservedCheck httptest, not a live public IP dial — Unit tests must not require outbound network
  • [Phase 06]: Keep inv_token outermost so valid credentials populate bouncer.Credential before the limiter selects tok:. — The named bucket must retain per-token isolation for valid credentials instead of collapsing them onto the IP fallback.
  • [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
  • [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
  • [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u: isolation.
  • [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy.
  • [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6.
  • [Phase 06]: Use one unexported bufferedResponse for house and raw recovery — A shared transactional writer keeps panic-before-write and panic-after-write behavior identical while preserving raw versus house fallback bodies.
  • [Phase 06]: Keep bufferedResponse Flush as a no-op — Recovery must never unwrap, hijack, flush, or otherwise expose the destination writer before handler success.
  • [Phase 06]: Success commit replaces only route-owned header keys — Unrelated headers already placed on the destination by outer wrappers such as path-scoped CORS must survive.
  • [Phase 06]: Use wire.WriteJSON for both InvScope denial branches — The shared writer is the established PHP-compatible no-newline serialization path.
  • [Phase 06]: Assert exact denial bytes before JSON shape checks — Whitespace normalization would hide response-contract regressions.
  • [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
  • [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u: keys.
  • [Phase 07]: Blacklist storage expiry follows PHP jwt-auth (later of exp and iat+refreshTTL, plus one minute). — Using the raw access exp would drop a logged-out token that is still inside the refresh window.
  • [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is also the production PHP path: logout calls JWTAuth::invalidate(true) and blacklist_enabled defaults true. The earlier "PHP does not blacklist" note was a harness artifact of CACHE_DRIVER=array.
  • [Phase 07]: Fetch after logout stays 401 in Go — Re-recorded PHP with file cache still returned 200 on a reused token (show_black_list_exception default 0). That case is kept on disk but is not a ported corpus case.
  • [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
  • [Phase 07]: Both CLI serve and in-process Handler must publish *blob.Bucket; unit tests that call attach.Publish themselves cannot stand in for boot — Phase 5 shipped OpenBucket/Publish but never wired them. Phase 7 added HTTP avatar. UAT and corpus replay boot via Handler, so serve-only publish would leave the same 500.
  • [Phase 07]: Assembled Handler avatar coverage lives in parity/ next to newConfiguredTarget, not in the user plugin package — The user plugin cannot import app.Handler without a reverse import. newConfiguredTarget is the same boot as replay.
  • [Phase 08]: wristband.Options exposes only the four PHP-configurable metadata fields (service_documentation path, scopes_supported, token_endpoint_auth_methods_supported, authorization_response_iss_parameter_supported); response_types/grant_types/code_challenge_methods stay fixed protocol constants per D-06
  • [Phase 08]: Plugin.Boot always constructs wristband.Server even with an empty app.url rather than failing loud, to avoid breaking the many existing fonoteka tests that boot without app.url configured; production must set app.url
  • [Phase 08]: D-10 (oauth guard retirement) is recorded via TestOAuthMetadataRouteIsolation rather than editing Phase 6 historical docs, per 08-PATTERNS.md guidance to prefer a supersession note
  • [Phase ?]: [Phase 08 P02]: Corrective migration named 21_oauth_schema_correction.go (not 12_): Go init()-order/gormigrate slice position determines RollbackLast() target, not the migration's numeric ID, so the file must sort after 20_remaining.go
  • [Phase ?]: [Phase 08 P02]: Schema-correction rollback refuses (changes nothing) rather than deleting/coercing rows when any row depends on a nullable lifecycle column
  • [Phase ?]: [Phase 08 P02]: wristband.Tx ships the full ClientStore/AuthCodeStore/RefreshTokenStore/AccessTokenIssuer surface now so 08-03/08-04 reuse the same transaction seam without another interface change; expiry-sweep methods are deferred to 08-06
  • [Phase ?]: [Phase 08 P02]: Register strips C0/DEL control characters from client_name at DCR capture time (PHP only strips at ConnectedApp/Consent display time) per 08-CONTEXT.md discretion
  • [Phase ?]: [Phase 08 P02]: OAuth config keys live under golem15.fonoteka.oauth.* (bare plugin ID, matching compass.MergePlugin), not plugins.golem15.fonoteka.oauth.*
  • [Phase ?]: [Phase 08 P02]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md: this plan ships DCR only, not the full authorize/token/consent surface
  • [Phase 08]: [Phase 08 P03]: Options gained Resource and PendingRequestTTL (not in the plan's file list for server.go) following the 08-02 precedent of extending Options for deployment-configurable values
  • [Phase 08]: [Phase 08 P03]: authorize's allowed-scope set is a package-level authorizeAllowedScopes constant, not Options.ScopesSupported (RFC 8414 metadata field) -- conceptually distinct config surfaces matching PHP's own separation
  • [Phase 08]: [Phase 08 P03]: Client lookup and pending-row creation each open their own WithinTx call, matching PHP's lack of a wrapping transaction around authorize; only DCR and later code-exchange/refresh-rotation need single-transaction atomicity
  • [Phase 08]: [Phase 08 P03]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md, continuing 08-01/08-02's decision: this plan ships authorize only, not the full RFC surface
  • [Phase 08]: [Phase 08 P04]: Token dispatch accepts grant_type=refresh_token per PHP's exact validity check but rotateRefreshToken always returns invalid_grant in this plan's scope; full rotation/lineage-kill (T-08-REFRESH-REPLAY) is 08-06's job per ROADMAP.md Wave 6
  • [Phase 08]: [Phase 08 P04]: No routes.go/plugin.go changes -- POST /oauth/mcp/token is not mounted on the assembled app this plan; mounting happens once 08-05 wires consent and produces a real issued code
  • [Phase 08]: [Phase 08 P04]: MintablePrefix changed from const to var (D-11 groundwork) with no config wiring added yet; default stays byte-identical inv_
  • [Phase 08]: [Phase 08 P05] AuthCodeStore.MarkIssued gained scopes/collectionIDs/expiresAt params; ClientStore gained MarkConsented — PHP issueCode overwrites six columns in one UPDATE, not just code_hash/user_id; the narrower 08-02 signature could not persist consent's granted scopes or server-resolved collection pin
  • [Phase 08]: [Phase 08 P05] wristband.Options gained CodeTTL (600s default), wired from the previously-unconsumed code_ttl_seconds config key — PHP OAuthCodeManager::CODE_TTL_SECONDS is a distinct constant from PENDING_TTL_SECONDS; IssueCode needs a fresh expiry from consent time
  • [Phase 08]: [Phase 08 P05] Consent scope ordering follows auth.MintableScopes's declared read/write/ai order, not PHP array_intersect's incidental first-array order — 08-UI-SPEC.md explicitly documents canonical read -> write -> ai order as the fixed contract
  • [Phase 08]: [Phase 08 P05] POST /oauth/mcp/token mounted in this plan, closing 08-04's deliberate D-09 deferral — Only once consent produces a real issued code does an end-to-end /token call through the real route have anything to exchange
  • [Phase 08]: [Phase 08 P05] AUTH-05/06/07 remain Pending in REQUIREMENTS.md — Refresh rotation (08-06) and connected-apps list/revoke are still outstanding pieces of those requirements; this plan ships consent plus the token mount only
  • [Phase 08 P06]: rotateRefreshToken commits lineage-kill revocation inside WithinTx and returns nil (success) on replay, mapping a captured replayed flag to invalid_grant outside the transaction -- mirrors PHP rotateRefresh's own commit-then-throw shape
  • [Phase 08 P06]: RevokeLineage walks forward only through RotatedToID; sufficient for both replay-kill and connected-app-revoke because every normal rotation already revokes its own predecessor's access token and connected-app revoke always starts from the terminal row
  • [Phase 08 P06]: Fixed RevokeLineage (GORM adapter and in-memory test double) to also revoke each visited row's linked access token -- the 08-02-era method only stamped the refresh row itself, leaving a replayed lineage's live access token usable
  • [Phase 08 P06]: AUTH-05/06/07 remain Pending in REQUIREMENTS.md: refresh-rotation and connected-apps pieces are done, but AUTH-05/07's unchanged-fonoteka-mcp clause needs 08-08/08-09, and AUTH-06's CSRF/rate-limit/cache-header claims are reconciled by 08-10's security review
  • [Phase ?]: [Phase 08 P07]: bonfire.Flag.Repeatable / Input.Flags(name) is the new shape for PHP-parity =* console options (Cobra StringSlice), with no change to existing scalar/bare Flag callers
  • [Phase ?]: [Phase 08 P07]: fonoteka:oauth-client create reuses wristband.Tx.CreateWithCap(ctx, rec, math.MaxInt32) instead of adding an uncapped Create method -- operator-issued clients are never subject to DCR's 200-client cap
  • [Phase ?]: [Phase 08 P07]: list/update operate directly on models.OAuthClient via *gorm.DB rather than extending wristband.ClientStore -- only client issuance needs the shared wristband hash/validation path (T-08-SECRET-TIMING)
  • [Phase ?]: [Phase 08 P07]: Fixed clientRecordToModel to persist ScopeCeiling, a mapping gap silent since 08-02 because DCR never sets a ceiling
  • [Phase ?]: [Phase 08 P07]: AUTH-05/AUTH-07 remain Pending in REQUIREMENTS.md -- both requirements' full text still needs 08-08/08-09's unchanged fonoteka-mcp install/auth flow proof
  • [Phase ?]: [Phase 08 P08]: me_token_controller.go was created in the Task 1 RED commit as a compiling 501 stub (Rule 3), following the 08-04/08-06/08-07 precedent -- controllers/api must compile with its new test file while the route stays unmounted
  • [Phase ?]: [Phase 08 P08]: scopes/collection_ids on GET /api/v1/fonoteka/me always serialize via wire.Slice (nil -> []), a deliberate divergence from PHP's collection_ids null-means-unrestricted semantics, accepted because fonoteka-mcp's TS MeResponse type never reads collection_ids
  • [Phase ?]: [Phase 08 P08]: AUTH-07 stays Pending in REQUIREMENTS.md -- this plan ships the /me prerequisite but the requirement's 'fonoteka-mcp completes its install and auth flow unchanged' clause needs 08-09's real MCP gate
  • [Phase ?]: [Phase 08 P09]: Lifecycle fixture recorded via a one-time Go program calling tide.RecordFlow directly against isolated PHP (deleted after use), not via Playwright/capture_clients.mjs -- login and consent are plain JWT API calls with no browser dependency
  • [Phase ?]: [Phase 08 P09]: wristband's explicit no-store Cache-Control becomes no-store, private and unheadered JSON errors default to no-cache, private -- confirmed by live PHP recording, superseding the earlier 08-CONTEXT.md assumption of bare no-store
  • [Phase ?]: [Phase 08 P09]: wristband redirects now emit Symfony's exact HTML redirect body (wristband/redirect_html.go) with PHP htmlspecialchars(ENT_QUOTES) escaping -- Go's bare 302 never matched real PHP
  • [Phase ?]: [Phase 08 P09]: {request_id} route constraint is now upper-bound only ([A-Za-z0-9_-]{1,128}) -- PHP applies no router-level shape constraint and the 16-char lower bound was rejecting a valid recorded 404 test case at the router
  • [Phase ?]: [Phase 08 P09]: OAuthConsentController's basic-validation failure now writes Winter's generic production 500 HTML page (not a clean 422) -- PHP's bare $request->validate() on this route is never caught by a JSON exception renderer, confirmed live with APP_DEBUG=false
  • [Phase ?]: [Phase 08 P09]: All nine OAuth manifest routes are status: ported with seed_hook: genres; scripts/check-phase8.sh's stage bodies are fully implemented but never executed by this plan -- 08-10 Task 3 is the sole execution site
  • [Phase ?]: [Phase 08 P09]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md -- this plan proves byte parity and builds the real-MCP gate machinery, but only 08-10's actual gate execution can prove the unchanged-fonoteka-mcp clause
  • [Phase 08]: Security review self-performed by the 08-10 executor (no Task/Agent spawner available), disclosed in 08-SECURITY-REVIEW.md's frontmatter and Reviewer Note — Per 08-CONTEXT.md D-04's documented fallback; every cited file:TestName was individually re-run, not inherited unverified
  • [Phase 08]: Checkpoint decision: approved closing Phase 8 with the Playwright UI matrix gap (check-phase8-ui.mjs:458) carried forward as a named follow-up — Every other scripts/check-phase8.sh stage ran green in the sole full gate execution; the Playwright matrix was a deliberate, never-authored fatal() left by 08-05 as 08-10's seam
  • [Phase 08]: AUTH-05, AUTH-06 and AUTH-07 marked complete in REQUIREMENTS.md — Each requirement's exact text is satisfied by the delivered backend/gate evidence; none mandates a Playwright-verified browser regression suite, so the carried-forward UI gap does not block completion
  • [Phase 09]: Frontend verification accepts PHP tokens that omit aud and rejects any other explicit audience
  • [Phase 09]: Backend JWTs require aud=backend, use admin.jwt.secret, and omit the PHP user prv hash
  • [Phase 09]: Cabana mounts from BuildRouter only when a plugin registers admin controllers; an empty admin.jwt.secret fails that assembly
  • [Phase 09]: Admin jti rows live in backend_jwt_blacklist and cabana does not republish the frontend BlacklistStore — Refresh and logout must not revoke frontend tokens or be revoked by them.
  • [Phase 09]: backend_user_roles.code is indexed and not unique so Winter rows can repeat a code — admin:create rejects zero or many matches instead of a unique constraint the cutover table does not have.
  • [Phase 09]: tokens_valid_after is a nullable additive column used to revoke admin JWTs on password reset — The guard already honors Principal.TokensValidAfter and Winter's required columns stay unchanged.
  • [Phase 09]: Cached form schemas keep source phrase keys; each response localizes a copy and records meta.locale
  • [Phase 09]: Absent config_form.yaml does not fail activation, so the 09-01 Genre list controller still boots
  • [Phase 09]: YAML option keys keep their JSON scalar type; method options call DropdownOptions with the exact field name
  • [Phase 09]: make:admin-controller writes controllers/name config_form and config_list pointing at models/name fields and columns
  • [Phase 09]: Omitted sortable defaults to true, except relation columns, which stay unsortable unless columns.yaml sets sortable
  • [Phase 09]: perPageOptions keep YAML order and must include recordsPerPage
  • [Phase 09]: list_toolbar, recordUrl, and showCheckboxes compile to create, update, and delete
  • [Phase 09]: A conditions key is a boot error; a model scope must be listed by FilterScopes()
  • [Phase 09]: Admin list meta uses D-11 page, while lagoon.Paginate still computes last_page
  • [Phase 09]: Writable admin fields are bound to gorm columns at activation; id, timestamps, scope, and system flags are never fillable
  • [Phase 09]: Show and update use one not-found body for missing and out-of-scope rows; delete of an absent row is deleted 0 and does not run hooks
  • [Phase 09]: A bulk selection that matches no scoped row is a no-op; a mixed present and absent selection is a 409 and rolls back
  • [Phase 09]: Controller hook failures return an opaque lifecycle error and do not echo the hook text
  • [Phase 09]: Album admin D-14 stores collection_id of the one active frontend user matched by normalized backend email; no album user_id column was added
  • [Phase 09]: Winter relation keys match exported Go fields case-insensitively and the served JSON keeps the YAML spelling
  • [Phase 09]: Required relation fields stay on the admin form schema and are not save-time column rules
  • [Phase 09]: Genre and style admin option values are decimal strings because pact.Option.Value is a string
  • [Phase 09]: Artists uses only the shared cabana list and CRUD engines; the controller contains identity, asset paths, model factory, and permission declaration only
  • [Phase 09]: Artist name_key and slug remain model-owned lifecycle fields and are not exposed by the admin writable projection
  • [Phase 09]: The Phase 9 Genre tracer remains the one production controller; form capability was added without a parallel route or identity
  • [Phase 09]: The tracer list and columns were already byte-equivalent to the tracked Winter source, so Task 2 added behavioral proof rather than rewriting them
  • [Phase 09]: The tracked Style source declares no dropdown provider or filter, so production YAML stays exact while isolated compiler fixtures prove typed scalars and provider rejection
  • [Phase 09]: Style slug retains the tracked update-only readonly schema and is generated on create by the model lifecycle
  • [Phase 09]: Style equal-value list ordering is explicitly stabilized by the shared primary-key tie-breaker
  • [Phase 09]: Collection-specific pivot identifiers and stamps remain plugin-owned behind a typed relation contract. — Cabana can validate and execute relations generically without hardcoding Fonoteka tables, columns, roles, or payload behavior.
  • [Phase 10]: Admin prefix is backend.uri (default /backend); admin API at {prefix}/api/v1, embedded SPA at {prefix}; fonoteka uses /plytadmin
  • [Phase 10]: Admin SPA uses the HttpOnly summer_admin cookie selected by X-Requested-With; cookie-only POST/PUT/DELETE without the header get 403 forbidden; Bearer bodies unchanged
  • [Phase 10]: Framework owns admin/openapi/admin.json (swag -> swagger2openapi -> openapi-typescript); fonoteka docs/openapi.json no longer lists admin paths
  • [Phase 10]: npm package gate approved: 17 exact pins in admin/package.json; any new package or version needs a checkpoint
  • [Phase 10]: 10-02: Relation lists, field options and filter options share one mounted six-segment GET pattern dispatched by nestedGet (ServeMux cannot register them side by side); documented paths unchanged
  • [Phase 10]: 10-02: Record responses carry relation values in data and labels in meta.labels; a belongsTo on a protected fill key is read-only (Collections owner)
  • [Phase 10]: 10-02: Message key validation checks declared keys and framework defaults only; defaults derived from Winter prompt, noRecordsMessage or form name may be literal text
  • [Phase 10]: 10-02: Filter options path {scope} is the filter name; the model's FilterOptions receives the scope method name
  • [Phase 10]: 10-02: Tailwind excludes generated schema.d.ts and openapi/ from the class scan so API changes do not churn boardwalk/dist
  • [Phase 10]: Admin OpenAPI declares write bodies (AdminRecord, AdminIDsRequest) and the list filter query as a deepObject so the SPA sends typed payloads
  • [Phase 10]: A form field without span fills the whole row (Winter default); auto and row take the next free slot
  • [Phase 10]: The save body skips read-only fields and unregistered types (relation-manager, unknown); Winter attributes pass through an allowlist
  • [Phase 10]: aria-sort reflects only the explicit URL sort; defaultSort is applied server-side without a header indicator

Pending Todos

None yet.

Blockers/Concerns

  • Phase 8 (OAuth2.1) pre-planning check of the PHP OAuth server for ClientCredentialsStorage/TokenExchangeStorage — resolved 2026-09-23 during Phase 8 discussion/research: the PHP server is hand-rolled and supports only authorization_code/refresh_token, so neither interface is needed (see 08-CONTEXT.md, 08-RESEARCH.md).
  • Phase 9 (admin schema pipeline / relation manager) is the least-precedented design surface in the research — plan with --research-phase.
  • Phase 11 (River dual-driver split) is documented but unverified against a real build — plan with --research-phase and budget a timed-latency test.
  • Phase 8 UI gate: scripts/check-phase8-ui.mjs --final-gate's real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented (deliberate fatal() at check-phase8-ui.mjs:458, never authored by 08-05); stage_ui_harness must keep failing closed until a Playwright spec is authored. User approved Phase 8 closure on 2026-09-24 with this gap carried forward -- see 08-10-SUMMARY.md and .planning/phases/08-oauth2-1-authorization-server/deferred-items.md.

Deferred Items

Items acknowledged and carried forward from previous milestone close:

Category Item Status Deferred At
Phase 8 UI gate scripts/check-phase8-ui.mjs --final-gate's real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented -- deliberate fatal() at scripts/check-phase8-ui.mjs:458, never authored by 08-05. stage_ui_harness must keep failing closed until a Playwright config/spec outside the Nuxt checkout is authored (see .planning/phases/08-oauth2-1-authorization-server/deferred-items.md). Every other Phase 8 gate stage (real unchanged fonoteka-mcp lifecycle, both repos' vet/test/race, 169/169 parity corpus, secret scan, security review 11/11 closed, return-path 6/6, i18n 74 keys) is green. Open — carried forward, user-approved 08-10, 2026-09-24

Session Continuity

Last session: 2026-09-27T15:02:42.136Z Stopped at: Completed 10-03-PLAN.md Resume file: None