Files
summercms/.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-PLAN.md
2026-09-17 18:40:13 +02:00

139 lines
11 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
phase: 03-first-vertical-slice-genres-end-to-end
plan: 04
type: execute
wave: 4
depends_on: ["03-03"]
files_modified:
- lagoon/connection_test.go
- lagoon/migrations_test.go
- lagoon/order_test.go
- surf/router_test.go
- surf/middleware_test.go
- surf/params_test.go
- bouncer/jwt_test.go
- bonfire/command_test.go
- examples/hello/hello_test.go
- ../fonoteka.go/parity/genre_integration_test.go
- ../fonoteka.go/parity/genre_security_test.go
- ../fonoteka.go/parity/parity_contract_test.go
- scripts/check-phase3.sh
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
- .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
autonomous: true
requirements: [DATA-01, DATA-02, HTTP-01, HTTP-02, QA-04]
must_haves:
truths:
- "D-01 through D-06: independent Postgres cases prove active-collection scoping, nonzero and zero counts, `non_empty`, 422, and database-default Polish order."
- "D-07 through D-15: auth and middleware tests prove no unauthenticated or locked request reaches the handler, all seven stages are ordered, and typed/constraint params give safe 404 behavior."
- "D-16 through D-20: migration isolation/up/down/seed and the unchanged recorded fixture pass with honest one-of-154 corpus accounting."
- "The roadmap's security-load-bearing JWT guard receives a documented security review with every high-severity threat mitigated or explicitly reported."
- "Root and app vet/test/race checks pass; the Phase 2 parity harness regression remains green."
artifacts:
- path: bouncer/jwt_test.go
provides: Adversarial token verification coverage
- path: surf/middleware_test.go
provides: Pipeline and missing guard boot coverage
- path: ../fonoteka.go/parity/genre_security_test.go
provides: Cross-plugin auth and tenant isolation coverage
- path: scripts/check-phase3.sh
provides: Repeatable full gate for both repositories
- path: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
provides: Security review evidence and findings
key_links:
- from: scripts/check-phase3.sh
to: ../fonoteka.go/parity/parity_test.go
via: focused ported-route and full corpus Go test
- from: .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md
to: bouncer/jwt_test.go
via: threat-to-test evidence
---
<objective>
**As a** maintainer, **I want to** run one repeatable gate for the real genres route and its security boundaries, **so that** later endpoint work cannot silently break the first vertical slice.
Purpose: Finish the phase with dedicated meaningful unit, integration, parity, and security tests as required by CLAUDE.md.
Output: Tests for each risk, one check script, validation evidence, and security review findings.
</objective>
<execution_context>
@/home/jin/.codex/get-shit-done/workflows/execute-plan.md
@/home/jin/.codex/get-shit-done/templates/summary.md
</execution_context>
<context>
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-01-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-02-SUMMARY.md
@.planning/phases/03-first-vertical-slice-genres-end-to-end/03-03-SUMMARY.md
<interfaces>
Plans 01–03 produce `lagoon`, `surf`, `bouncer`, a two-plugin app, a Postgres-backed genre handler, and a single ported route in `TestParityCorpus`. Phase 2's `scripts/check-phase2.sh` is the baseline harness regression command. All tests in this plan must assert externally observable behavior or security invariants, not duplicate source implementation details.
</interfaces>
</context>
<tasks>
<task type="auto">
<name>Task 1: Cover framework boundaries with adversarial unit and integration tests</name>
<files>lagoon/connection_test.go, lagoon/migrations_test.go, lagoon/order_test.go, surf/router_test.go, surf/middleware_test.go, surf/params_test.go, bouncer/jwt_test.go, bonfire/command_test.go, examples/hello/hello_test.go</files>
<read_first>lagoon/connection.go, lagoon/migrations.go, lagoon/order.go, surf/router.go, surf/middleware.go, surf/params.go, bouncer/jwt.go, bouncer/context.go, bonfire/command.go, examples/hello/hello_test.go, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-RESEARCH.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md</read_first>
<action>Add behavior-focused tests for one pgx stdlib SQL pool shared with GORM and closed on shutdown; wrong ICU provider/locale boot failure; two migration sets with separate history, ordered up/down and rollback isolation; no `AutoMigrate` schema source; allow listed ORDER BY identifiers/direction; ServeMux method/path/group and per-route middleware composition; fixed recover → CORS → locale → auth → password gate → org → rate → handler order, including preflight and panic 500 without leaked internals; missing named middleware boot failure; integer, regex and enum params with malformed and unknown ID 404; and command names `serve`, `migrate`, `migrate:status`, `migrate:rollback`. For JWT, test valid persisted subject plus missing token, malformed token, `alg:none`, wrong HMAC algorithm, bad signature, absent/expired `exp`, absent `sub`, unknown user, empty secret, and absence of token/secret text in errors. Use `httptest` and isolated Postgres where behavior requires the DB; do not create tests that merely assert a helper calls another helper. Keep root and app vet/test green before the commit.</action>
<verify><automated>go vet ./... &amp;&amp; go test ./... &amp;&amp; go test -race ./... &amp;&amp; (cd ../fonoteka.go &amp;&amp; go vet ./... &amp;&amp; go test ./...)</automated></verify>
<acceptance_criteria>
- Every high-severity framework threat T-03-01, T-03-02, and T-03-03 has at least one failing-when-broken test.
- Both malformed and unknown typed IDs return 404, missing middleware fails boot, and an unauthenticated request cannot reach the genre handler.
- Root vet/test/race and app vet/test exit 0 at commit.
</acceptance_criteria>
<done>The reusable runtime's database, routing and authentication invariants are testable independently of the PHP fixture.</done>
</task>
<task type="auto">
<name>Task 2: Prove app isolation, recorded parity and security review in one final gate</name>
<files>../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/genre_security_test.go, ../fonoteka.go/parity/parity_contract_test.go, scripts/check-phase3.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-SECURITY-REVIEW.md</files>
<read_first>../fonoteka.go/parity/genre_integration_test.go, ../fonoteka.go/parity/parity_test.go, ../fonoteka.go/parity/parity_contract_test.go, ../fonoteka.go/parity/fixtures/routes/get_genres_jwt.yaml, ../fonoteka.go/parity/manifest.yaml, ../fonoteka.go/parity/synthetic_test.go, scripts/check-phase2.sh, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-VALIDATION.md, .planning/phases/03-first-vertical-slice-genres-end-to-end/03-CONTEXT.md</read_first>
<action>Complete independent app test cases for owner, editor and foreign albums with positive counts; active-context fallback; `non_empty=0|1|invalid`; exact seeded genre order under database ICU `pl-PL`; empty `data:[]`; JWT 401 variants, locked-user 423, and CORS preflight. Add a corpus contract that checks 154 recorded, 1 real replay pass, 153 pending, 0 false passes and a deliberate mismatch failure against the unmodified fixture. Create `scripts/check-phase3.sh` to run root and app `go vet ./...`, `go test ./...`, `go test -race ./...`, the focused genres parity subtest, corpus audit, and Phase 2 harness regression; it must exit nonzero on any failure and never silently skip Docker. Perform the roadmap's security review of token verification, cross-plugin guard lookup, migration isolation, query tenant boundaries, and secret handling. Record each T-03 threat, source location, test evidence, finding and disposition in `03-SECURITY-REVIEW.md`; resolve high-severity findings before marking the gate green. Fill `03-VALIDATION.md` with actual task IDs, commands and observed results; set `nyquist_compliant: true` only after the full gate passes. Keep the PHP fixture, generic `tide` code and other 153 route statuses unchanged.</action>
<verify><automated>bash scripts/check-phase3.sh</automated></verify>
<acceptance_criteria>
- `bash scripts/check-phase3.sh` exits 0 with root and app vet/test/race green and one real ported parity pass.
- The corpus report is 154 recorded, 1 passing, 153 pending, 0 failing, 0 unrecorded; a deliberate response mutation fails a contract test.
- `03-SECURITY-REVIEW.md` maps all high-severity threats to passing tests or a resolved finding; no open high-severity JWT or cross-tenant issue remains.
- `03-VALIDATION.md` records observed evidence and only then has `nyquist_compliant: true`.
</acceptance_criteria>
<done>One command proves the first real Go route's parity and its security boundaries, with evidence ready for phase verification.</done>
</task>
</tasks>
<threat_model>
## Trust Boundaries
| Boundary | Description |
|---|---|
| Test fixture and adversarial HTTP inputs → running app | Tests must exercise real routing, auth and data boundaries. |
| Security review → phase acceptance | Unresolved high-severity findings cannot be hidden by a green happy-path fixture. |
## STRIDE Threat Register
| Threat ID | Category | Severity | Component | Disposition | Mitigation Plan |
|---|---|---|---|---|---|
| T-03-02 | Elevation of privilege | high | named middleware | mitigate | Missing-name and unauthenticated-route tests plus source review. |
| T-03-03 | Spoofing | high | JWT guard | mitigate | Full malformed/forged/expired/unknown-user matrix and secret handling review. |
| T-03-04 | Information disclosure | high | aggregate query | mitigate | Cross-tenant owner/editor/foreign album tests and query review. |
| T-03-06 | Tampering | high | parity acceptance | mitigate | Real replay, honest pass counter, deliberate mismatch test. |
</threat_model>
<verification>
Run the repeatable Phase 3 script from the framework root after both task commits. Inspect its output and the security review/validation artifacts before recording success.
</verification>
<success_criteria>
All four Phase 3 roadmap criteria have direct passing evidence, the recorded PHP fixture is unchanged, and no high-severity security issue remains open.
</success_criteria>
<output>
Create `.planning/phases/03-first-vertical-slice-genres-end-to-end/03-04-SUMMARY.md` after completion.
</output>