The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies. Co-authored-by: Cursor <cursoragent@cursor.com>
43 lines
1.5 KiB
Markdown
43 lines
1.5 KiB
Markdown
---
|
|
phase: 07-user-plugin-and-authentication
|
|
reviewed: 2026-09-22T17:26:00Z
|
|
depth: standard
|
|
files_reviewed: 4
|
|
files_reviewed_list:
|
|
- ../fonoteka.go/plugins/golem15/user/controllers/api_controller.go
|
|
- ../fonoteka.go/parity/schema_diff_test.go
|
|
- ../fonoteka.go/parity/manifest.yaml
|
|
- bouncer/phase07_coverage_test.go
|
|
findings:
|
|
critical: 0
|
|
warning: 2
|
|
info: 0
|
|
total: 2
|
|
status: issues_found
|
|
---
|
|
|
|
# Phase 7: Code Review Report
|
|
|
|
**Reviewed:** 2026-09-22T17:26:00Z
|
|
**Depth:** standard
|
|
**Files Reviewed:** 4
|
|
**Status:** issues_found
|
|
|
|
## Summary
|
|
|
|
The session, token, and lock tests match the handlers they name. Two response differences against the recorded PHP corpus are still in the Go handlers. Neither is a new crash or a secret leak. Both keep the user API routes pending.
|
|
|
|
## Warnings
|
|
|
|
### 1. Wrong activation code returns 200
|
|
|
|
`Activate` ignores the error from `VerifyActivationCode` and always writes the user payload at status 200. The isolated PHP app throws and returns the HTML error page at status 500 for `POST /_user/api/v1/activate` with `{"code":"wrong"}` and for `POST /_user/api/v1/activate-by-code` with `1!nope`. The fixtures record the HTML. The Go handler was left as-is in 07-05.
|
|
|
|
### 2. Logout blacklists a token PHP still accepts
|
|
|
|
Go logout adds the presented jti to `jwt_blacklist`, so the next fetch is 401. PHP logout returns `{"message":"Logged out"}` and a following fetch with that bearer is still 200. `TestSessionSequence` locks in the Go behavior. The recorded fixtures lock in the PHP behavior. The routes stay `pending`.
|
|
|
|
## Info
|
|
|
|
None.
|