Files
summercms/.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-VALIDATION.md
Jakub Zych 92fb6e323f docs(09-12): record the phase 9 acceptance evidence
- Security review names the test that fails if each high control is removed.
- Validation rows now point at the phase gate commands.
- Roadmap shows 12/12 plans executed.
2026-09-27 03:03:09 +02:00

5.7 KiB

phase, slug, status, nyquist_compliant, wave_0_complete, created
phase slug status nyquist_compliant wave_0_complete created
09 backend-admin-authentication-and-schema-pipeline approved true false 2026-09-24

Phase 09 — Validation Strategy

Per-phase validation contract for feedback sampling during execution.


Test Infrastructure

Property Value
Framework Go 1.27 standard testing; existing Testcontainers-backed PostgreSQL integration harness
Config file none — package-local *_test.go files and repository go.work workspaces
Quick run command go test ./bouncer ./pact ./lagoon ./party ./surf
Full suite command go test ./... && (cd ../fonoteka.go && go test ./...)
Estimated runtime Focused package checks should complete within 60 seconds; full two-repository and Testcontainers runs may take several minutes

Sampling Rate

  • After every task commit: Run the narrowest affected package tests plus go vet ./... in the modified workspace.
  • After every plan wave: Run go test ./... in both summercms.go and fonoteka.go.
  • Before $gsd-verify-work: Full suites and the assembled admin authorization matrix must be green.
  • Max feedback latency: 60 seconds for task-level checks; multi-minute integration runs are reserved for wave and phase gates.

Per-Task Verification Map

Task ID Plan Wave Requirement Threat Ref Secure Behavior Test Type Automated Command File Exists Status
09-01-T2 09-01 1 AUTH-08 T-09-01, T-09-02 Backend/frontend token crossover and permission-order denial both fail before schema/database work unit + assembled integration go test ./bouncer ./cabana -run '^TestPhase09(GuardIsolation|PermissionMatrix)$' -count=1 yes green
09-03-T1 09-03 3 ADMIN-01 T-09-05 Strict schema compilation covers every field type and rejects unknown keys/types/partials/providers unit go test ./cabana -run '^TestFormSchema(Compile|Rejects)' -count=1 yes green
09-04-T3 09-04 4 ADMIN-02 T-09-07, T-09-08 Search/sort/filter/scope selectors are compiled allowlists and adjacent pages are deterministic unit + assembled go test ./cabana -run '^TestPhase09SecurityCoverage$' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestPhase09AssembledAcceptance$' -count=1) yes green
09-10-T3 09-10 7 ADMIN-03 T-09-16, T-09-17 Relation permission and forged pivot payloads fail closed unit + PostgreSQL go test ./cabana -run '^TestPhase09SecurityCoverage$' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestCollectionsAdmin(RelationPermissions|ForgedPivot|CrossScope)$' -count=1) yes green
09-05-T3 09-05 5 ADMIN-04 T-09-09, T-09-10 Writable projection and hook rollback reject mass assignment and partial creates unit + PostgreSQL go test ./cabana -run '^TestPhase09SecurityCoverage$' -count=1 yes green
09-11-T3 09-11 8 ADMIN-05 T-09-18, T-09-19 Settings and navigation stay permission-filtered unit + PostgreSQL go test ./cabana -run '^TestPhase09PermissionMatrix$' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestAdminSettings' -count=1) yes green
09-12-T1 09-12 9 AUTH-08, ADMIN-01, ADMIN-02, ADMIN-03, ADMIN-04, ADMIN-05 T-09-01, T-09-02, T-09-03, T-09-07, T-09-09, T-09-10, T-09-13, T-09-16, T-09-19, T-09-20 Route-derived security matrix and fresh migration rollback unit + PostgreSQL go test ./bouncer ./lagoon ./cabana -run '^TestPhase09' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestPhase09Security' -count=1) yes green
09-12-T2 09-12 9 AUTH-08, ADMIN-01, ADMIN-02, ADMIN-03, ADMIN-04, ADMIN-05 T-09-20, T-09-21, T-09-SC Fail-closed route, PostgreSQL, and OpenAPI gate phase gate scripts/check-phase9.sh --self-test && scripts/check-phase9.sh --postgres && scripts/check-phase9.sh --openapi yes green
09-12-T3 09-12 9 AUTH-08, ADMIN-01, ADMIN-02, ADMIN-03, ADMIN-04, ADMIN-05 T-09-01 through T-09-21, T-09-SC Threat and Nyquist evidence phase gate scripts/check-phase9.sh --evidence yes green

Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky


Wave 0 Requirements

  • Framework schema compiler tests are assigned to 09-03 and expanded by controller plans.
  • Backend guard tests are assigned to 09-01/09-02 and swept by 09-12.
  • The assembled raw-route authorization matrix is assigned to 09-12.
  • Real-PostgreSQL bulk, relation, scoping, settings, migration, rollback, and concurrency tests are assigned to 09-05/09-10/09-11/09-12.
  • Focused test names and commands are concrete in every PLAN task; no separate pre-execution scaffold is required.

Manual-Only Verifications

All Phase 9 backend behaviors are expected to have automated verification. Phase 10 owns browser rendering and interaction UAT for the generated schemas.


Validation Sign-Off

  • All tasks have <automated> verification and an immediate observable failure direction.
  • Sampling continuity: every task has automated verification.
  • All previously missing references are assigned to owning TDD tasks and the final gate.
  • No watch-mode flags appear in validation commands.
  • Focused task-level commands target the 60-second feedback budget; multi-minute PostgreSQL/full-suite checks are phase gates.
  • nyquist_compliant: true is set after final plan/task IDs and commands are validated.

Approval: approved for execution. Plan 09-12 recorded the gate results on 2026-09-27.