Files
summercms/.planning/phases/08-oauth2-1-authorization-server/deferred-items.md
Jakub Zych 2d551c09d7 docs(08-10): record the checkpoint decision and carry the Playwright UI matrix gap forward
scripts/check-phase8.sh's final gate ran once with every stage green except
stage_ui_harness's Playwright browser matrix, a deliberate fatal() never
authored by 08-05. The user approved closing Phase 8 with this gap carried
forward; 08-VALIDATION.md flips 08-W0-07 green, marks 08-W0-08 partially
verified, and sets nyquist_compliant: false honestly. deferred-items.md
records what the follow-up spec needs to do.
2026-09-24 00:56:20 +02:00

6.9 KiB

Phase 08 Deferred Items

Out-of-scope discoveries logged during plan execution, per the executor's scope-boundary rule (fix only what the current task's changes directly caused).

08-03: pre-existing full-schema rollback test failures (not caused by this plan)

Found during: 08-03 Task 2 full-suite verification (go test ./... in fonoteka.go).

Failing tests: TestRemainingMigrationsUpDown (parity/remaining_models_test.go), TestRollbackIsolatesFonotekaFullSchema (parity/rollback_isolation_full_test.go).

Symptom: both tests assert the last fonoteka migration is create_fonoteka_settings (a Phase 5 migration) and/or that a full up/down/up cycle leaves no tables behind. Since 08-02 added 202609230019_oauth_schema_correction.go (the corrective OAuth nullability/index migration, 08-02-SUMMARY.md), that migration is now the last one in the registered slice, so the hardcoded "last migration" name assertion is stale, and rollback of the corrected schema leaves golem15_fonoteka_settings behind.

Scope: neither test file, nor plugins/golem15/fonoteka/updates/, nor any model file is in 08-03's files_modified list; this plan (authorize) touches wristband/authorize.go, wristband/server.go (Options extension), plugin.go, and routes.go only. Confirmed pre-existing via git log on the failing test files: both were last touched by Phase 5 (6c9695f), and 08-02's migration-correction commit (4536b3e) is what shifted the "last migration" identity without updating these two tests.

Disposition: deferred to whichever later Phase 8 plan owns migration/ schema test maintenance (or the phase-closing unit-test plan). Not fixed here per the executor's scope-boundary rule.

08-03: pre-existing flaky test in an unrelated package (summercms.go)

Found during: 08-03 Task 2 full-suite verification (go test ./... in summercms.go).

Failing test: TestFetchTooLargeIsStreaming (fetchguard/fetch_test.go), intermittently fails with "server wrote 71680 bytes, client appears to have buffered unbounded body" under go test ./... but passes reliably when run in isolation (go test ./fetchguard -run TestFetchTooLargeIsStreaming -count=3). fetchguard is untouched by this plan. Not fixed here.

Resolution (orchestrator, after 08-03): fixed in fonoteka.go commit f9b23e1 (fix(08-03): update parity migration tests for the oauth schema correction head). Five parity tests (TestMigrateSeedsCanonicalGenres, TestAlbumSliceMigrationsUpDown, TestSecretsSliceMigrationsUpDown, TestRemainingMigrationsUpDown, TestRollbackIsolatesFonotekaFullSchema) now expect 202609230019_oauth_schema_correction as the head and walk one extra table-less rollback step. go test ./... in the fonoteka.go root module is green again.

Pre-existing flake: fetchguard.TestFetchTooLargeIsStreaming (summercms.go)

Found during: post-wave test gates after 08-03.

Symptom: fails intermittently only under a full parallel go test ./... run; passes on every isolated run (-count=5) and every package-level run (-count=3). Last touched in Phase 6 (e50e2dd); no Phase 8 plan modifies fetchguard. Timing-sensitive streaming assertion under load. Not a Phase 8 regression; left for a later hardening pass.

Resolution (orchestrator, after 08-05): the flake tripped the post-wave gate on two of three full runs, so it was fixed in summercms.go commit test(fetchguard): widen streaming-cap ceiling to stop flake under parallel runs. The ceiling moved from 64 KiB to 1 MiB; the assertion still proves the client does not buffer an unbounded body (the handler would reach 8 MiB).

Follow-up: Playwright UI matrix for scripts/check-phase8-ui.mjs --final-gate

Found during: 08-10 Task 3, the sole real execution of scripts/check-phase8.sh (2026-09-24).

What is missing: scripts/check-phase8-ui.mjs's --final-gate mode (runFinalGate(), scripts/check-phase8-ui.mjs:436-459) runs verify:oauth-return-path and verify:oauth-i18n for real, then reaches a deliberate fatal('--final-gate Playwright matrix wiring is 08-10's responsibility; not implemented in 08-05.') at line 458. The 32-scenario SCENARIOS catalog (08-UI-SPEC.md's complete state/accessibility/ responsive/i18n matrix) is fully authored and self-tested for completeness by --contract-self-test, but no Playwright spec file consumes it and no Playwright config exists to run one. Specifically still needed:

  • A Playwright config and spec file living outside the vue-fonoteka-app Nuxt checkout (08-UI-SPEC.md's Non-Redesign Rule: this harness must never write inside the Nuxt checkout or add a registry component there), that imports/consumes the versioned SCENARIOS catalog already in check-phase8-ui.mjs so the spec and the scenario data cannot drift apart.
  • NUXT_DEV_BACKEND_ORIGIN (or an equivalent env var) wired from the spec's Playwright config to the ephemeral Go app scripts/check-phase8.sh boots for the gate run, so the real Nuxt dev/preview server the Playwright browser drives talks to the disposable gate backend instead of a developer's local backend.
  • A real login through the assembled Go backend (not a mocked network response) for every scenario that is not explicitly declared network-intercepted in the SCENARIOS catalog (see the catalog's own no-request / redirect-to-login-with-return scenarios, which assert the absence of a network call and must stay mocked).
  • DOM assertions against app/pages/connect.vue, app/components/fonoteka/ConsentScopePicker.vue, and app/components/fonoteka/ConnectedAppsManager.vue (the three guarded Nuxt source files check-phase8-ui.mjs hashes at scripts/check-phase8-ui.mjs:57-59), selected via their existing data-testid attributes, matching each scenario's expected state.

Failing identifier: scripts/check-phase8-ui.mjs --final-gate -> stage stage_ui_harness (scripts/check-phase8.sh:426-431) -> fatal message --final-gate Playwright matrix wiring is 08-10's responsibility; not implemented in 08-05. (scripts/check-phase8-ui.mjs:458).

Disposition: the user approved closing Phase 8 on 2026-09-24 with this gap carried forward as a named follow-up ("Approve, carry gap forward" — 08-10 Task 3 checkpoint decision). Every other scripts/check-phase8.sh stage ran green in that same gate execution: docker preflight, Postgres, app boot, the real unchanged fonoteka-mcp lifecycle (discovery, DCR, PKCE authorize, JWT consent, token, tool call, refresh, replay, revoke), both repositories' vet/test/race, the 169/169 parity corpus, the secret scan, the 6/6 OAuth return-path checks, the 74-key i18n check, the unchanged-client diff, and the security review (11/11 threats closed, 0 open). The gate script must keep failing closed on stage_ui_harness until the Playwright spec above exists -- do not weaken, skip, or stub that stage to close this gap. Whichever future plan authors the spec should also flip 08-VALIDATION.md's 08-W0-08 row and nyquist_compliant back to fully green.