Files
summercms/.planning/phases/07-user-plugin-and-authentication/07-REVIEW.md
Jakub Zych d4e9c17816 docs(07): record the phase goal verification
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:27:27 +02:00

1.5 KiB

phase, reviewed, depth, files_reviewed, files_reviewed_list, findings, status
phase reviewed depth files_reviewed files_reviewed_list findings status
07-user-plugin-and-authentication 2026-09-22T17:26:00Z standard 4
../fonoteka.go/plugins/golem15/user/controllers/api_controller.go
../fonoteka.go/parity/schema_diff_test.go
../fonoteka.go/parity/manifest.yaml
bouncer/phase07_coverage_test.go
critical warning info total
0 2 0 2
issues_found

Phase 7: Code Review Report

Reviewed: 2026-09-22T17:26:00Z Depth: standard Files Reviewed: 4 Status: issues_found

Summary

The session, token, and lock tests match the handlers they name. Two response differences against the recorded PHP corpus are still in the Go handlers. Neither is a new crash or a secret leak. Both keep the user API routes pending.

Warnings

1. Wrong activation code returns 200

Activate ignores the error from VerifyActivationCode and always writes the user payload at status 200. The isolated PHP app throws and returns the HTML error page at status 500 for POST /_user/api/v1/activate with {"code":"wrong"} and for POST /_user/api/v1/activate-by-code with 1!nope. The fixtures record the HTML. The Go handler was left as-is in 07-05.

2. Logout blacklists a token PHP still accepts

Go logout adds the presented jti to jwt_blacklist, so the next fetch is 401. PHP logout returns {"message":"Logged out"} and a following fetch with that bearer is still 200. TestSessionSequence locks in the Go behavior. The recorded fixtures lock in the PHP behavior. The routes stay pending.

Info

None.