41 lines
1.6 KiB
Markdown
41 lines
1.6 KiB
Markdown
---
|
|
phase: quick-261004-rou
|
|
plan: 01
|
|
status: complete
|
|
completed: 2026-10-04
|
|
commits:
|
|
sm-user-plugin: 0fe5b91
|
|
fonoteka: d1abcab
|
|
---
|
|
|
|
# Quick 261004-rou Summary
|
|
|
|
`golem15.user` now owns application-wide API tokens: persistence, minting,
|
|
authentication, scopes, management routes/commands, and current user-group
|
|
permission grants. Raw secrets remain one-time-only and only SHA-256 hashes
|
|
are persisted.
|
|
|
|
Fonoteka now uses that shared model and guard while preserving its `inv_`
|
|
prefix, `inv_token`/`inv.scope:*` middleware contracts, collection pins,
|
|
OAuth behavior, and existing endpoints. Its transition migration preserves
|
|
legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token
|
|
foreign keys, and supports a lossless rollback.
|
|
|
|
BM's management API was refactored to consume `user.api_token`, `user.scope:*`,
|
|
and current group permissions. Per user direction, BM and Quizzes were not
|
|
committed; the tested BM changes and User submodule bump remain in the BM
|
|
working tree for its dedicated dev-agent to review and commit.
|
|
|
|
## Verification
|
|
|
|
- sm-user-plugin: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`
|
|
- Fonoteka application: `go test ./...`, `go vet ./...`
|
|
- Fonoteka plugin: `go test ./...`, `go vet ./...`
|
|
- BM plugin handoff: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`, `git diff --check`
|
|
- Migration test covers legacy-token data, an ID collision, OAuth FK retarget,
|
|
and reverse rollback.
|
|
- BM end-to-end test proves the same shared token follows live group-permission
|
|
grants and revocation.
|
|
|
|
No SummerCMS framework change was required.
|