Fills in every scripts/check-phase8.sh stage skeleton with real logic: disposable Postgres (docker run + pg_isready), the assembled Go app built and served against it with a throwaway onboarding-seeded gate account, the real unchanged fonoteka-mcp process started with all three required environment variables, and the full scripted SDK lifecycle -- discovery (MCP's own RFC 9728 401 hint, verified separately from authorization server metadata), DCR, PKCE authorize, JWT login/consent, token, an MCP tool call, refresh, replay of the spent refresh token, revoke, and a post-revoke refresh failure -- delegated to the new scripts/check-phase8-mcp-client.mjs driver, which resolves the MCP SDK's auth helpers from fonoteka-mcp's own node_modules (no new dependency, same pattern as parity/capture_clients.mjs). Both repositories' vet/test/race, the full parity/corpus/secret-scan gate, the existing check-phase8-ui.mjs --final-gate UI harness, an unchanged-client git-diff check for both MCP_ROOT and NUXT_ROOT, and a 08-SECURITY-REVIEW.md status:verified gate close out the stage list. --contract-self-test validates structure only (stage names/order, cleanup trap, loopback-only binding, the three MCP env vars, the redaction helper, no pre-final full-run flag, read-only unchanged-client references) in well under 30 seconds -- it boots no services. The --red-contract self-test from Task 1 is preserved unchanged. run_full_gate (the no-flag invocation) is 08-10 Task 3's sole execution site; 08-09 never invokes it.
SummerCMS (Go)
A Go rewrite of the WinterCMS/OctoberCMS content management framework, built for the Golem15 stack.
SummerCMS keeps what makes WinterCMS productive — plugins that extend each other, YAML-driven admin forms, models/controllers/components, scaffolding commands — and drops the parts that do not survive a compiled language.
Status
Pre-alpha. Planning and research. Nothing runs yet.
Why Go
The first SummerCMS attempt was Scala 3. Three infrastructure modules were built (config, i18n, console) before the effort stalled on ecosystem depth: proven, reusable libraries for things like an OAuth2/OIDC server did not exist, and building them from scratch was out of budget. Go's ecosystem covers every concern in the Illuminate module map with maintained, widely used libraries. See .planning/notes/why-go-not-scala.md and .planning/research/go-ecosystem.md.
v1 target
Port Płytarium (the fonoteka project): a headless WinterCMS backend with a Nuxt 4 frontend, 160 API routes, its own OAuth2 provider, Discogs and AI integrations, queued jobs, realtime notifications, and organization-scoped collections.
Definition of done for v1: vue-fonoteka-app runs unchanged against the Go backend.
See .planning/notes/v1-target-plytarium.md.
Architecture decisions so far
- Compiled plugins, Caddy/xcaddy style: a
plugins/workspace of Go modules, a generated import list, scaffold and rebuild commands, watch-rebuild in dev. - A sandboxed WASM extension API for untrusted third-party extensions comes later, behind a stable core plugin API.
- Headless first. Admin is a schema-driven SPA. Server-rendered themes come with the second port target (keios.eu).
Layout
.planning/ GSD planning artifacts (notes, research, seeds, roadmap)
Everything else will be created by the GSD roadmap phases.