Files
summercms/.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-12-SUMMARY.md
Jakub Zych 92fb6e323f docs(09-12): record the phase 9 acceptance evidence
- Security review names the test that fails if each high control is removed.
- Validation rows now point at the phase gate commands.
- Roadmap shows 12/12 plans executed.
2026-09-27 03:03:09 +02:00

7.6 KiB

phase, plan, subsystem, tags, requires, provides, affects, actuals, tech-stack, key-files, key-decisions, patterns-established, requirements-completed, coverage, duration, completed, status
phase plan subsystem tags requires provides affects actuals tech-stack key-files key-decisions patterns-established requirements-completed coverage duration completed status
09-backend-admin-authentication-and-schema-pipeline 12 admin
security
postgres
openapi
authorization
acceptance
phase provides
09-backend-admin-authentication-and-schema-pipeline Backend guard, controllers, schemas, CRUD, relations, permissions, and settings
Route-derived Phase 9 security matrix across guard, cabana, and the assembled app
Fresh PostgreSQL admin migration rollback that preserves other histories
Fail-closed phase gate and committed admin OpenAPI contract
phase-10-spa
admin-api
tokens tasks commits
18000 3 4
added patterns
The mounted admin route table is the permission matrix; a new handler without the backend guard fails the gate
OpenAPI admin paths are generated from cabana annotations and checked against that same route list
PostgreSQL stages fail when a TestPhase09 test is skipped or matches nothing
created modified
bouncer/backend_guard_test.go
cabana/security_coverage_test.go
cabana/admin_openapi.go
cabana/phase09_contract_test.go
scripts/check-phase9.sh
../fonoteka.go/plugins/golem15/fonoteka/admin_phase09_security_test.go
../fonoteka.go/plugins/golem15/fonoteka/admin_phase09_e2e_test.go
.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-SECURITY-REVIEW.md
lagoon/backend_admin_migrations_test.go
../fonoteka.go/scripts/check-openapi.sh
../fonoteka.go/docs/openapi.json
../fonoteka.go/plugins/golem15/fonoteka/controllers/genre_controller.go
.planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-VALIDATION.md
Admin OpenAPI annotations live in cabana/admin_openapi.go so swag can see them; TestPhase09PermissionMatrix keeps that list equal to service.mount
Migration rollback is proven on a dedicated database. The shared assembled test database is not rolled back
scripts/check-phase9.sh is the only phase acceptance command
AUTH-08
ADMIN-01
ADMIN-02
ADMIN-03
ADMIN-04
ADMIN-05
id description requirement verification human_judgment
D1 Frontend and backend tokens cannot cross guards, secrets, refresh, blacklist, or password-reset cutoff. AUTH-08
kind ref status
unit bouncer/backend_guard_test.go#TestPhase09GuardIsolation pass
false
id description requirement verification human_judgment
D2 Every mounted admin route is inventoried, protected routes carry the backend guard, and denial happens before handler work. ADMIN-02
kind ref status
unit cabana/security_coverage_test.go#TestPhase09PermissionMatrix pass
kind ref status
integration plugins/golem15/fonoteka/admin_phase09_security_test.go#TestPhase09SecurityRoutes pass
false
id description requirement verification human_judgment
D3 Mass assignment, identifier injection, pivot forgery, auth-log redaction, and hook rollback fail closed. ADMIN-04
kind ref status
integration cabana/security_coverage_test.go#TestPhase09SecurityCoverage pass
false
id description requirement verification human_judgment
D4 Fresh PostgreSQL migration, rollback, and re-migrate keep framework and plugin histories independent and reseed roles. AUTH-08
kind ref status
integration lagoon/backend_admin_migrations_test.go#TestPhase09MigrationsFreshRollback pass
false
id description requirement verification human_judgment
D5 Assembled acceptance covers login replay, five controllers, settings, relations, locale, empty/single/adjacent pages, and concurrent reads. ADMIN-01
kind ref status
e2e plugins/golem15/fonoteka/admin_phase09_e2e_test.go#TestPhase09AssembledAcceptance pass
false
id description requirement verification human_judgment
D6 Committed OpenAPI lists every D-09 route with 401 responses and BackendBearer on protected operations. ADMIN-05
kind ref status
unit cabana/phase09_contract_test.go#TestPhase09ContractInventory pass
false
3h 2026-09-27 complete

Phase 9 Plan 12: Security, PostgreSQL, OpenAPI, and Acceptance Summary

The admin surface now has one fail-closed gate for guard isolation, route permissions, real PostgreSQL, and the committed OpenAPI contract.

Performance

  • Duration: 3h
  • Started: 2026-09-27T00:30:00+02:00
  • Completed: 2026-09-27T03:05:00+02:00
  • Tasks: 3
  • Files modified: 14

Accomplishments

  • Added TestPhase09GuardIsolation, TestPhase09PermissionMatrix, and TestPhase09SecurityCoverage.
  • Added assembled route and denial tests plus a PostgreSQL journey across the five admin controllers, settings, and the editors relation.
  • Added scripts/check-phase9.sh with self-test, security, postgres, openapi, and evidence stages.
  • Regenerated fonoteka.go/docs/openapi.json from the public genre route and the cabana admin annotations.
  • Recorded threat evidence in 09-SECURITY-REVIEW.md and replaced the pending validation rows.

Task Commits

  1. Task 1: Build a non-bypassable Phase 9 security matrix - 30bfd2d (summercms.go), 336a90b (fonoteka.go)
  2. Task 2: Gate all routes, PostgreSQL behavior, and committed OpenAPI - 4392550 (summercms.go), feaca6b (fonoteka.go)
  3. Task 3: Record independent threat evidence and finalize Nyquist mappings - docs commit on summercms.go

Files Created/Modified

  • bouncer/backend_guard_test.go - cross-guard token matrix
  • cabana/security_coverage_test.go - mounted route inventory and adversarial fixtures
  • cabana/admin_openapi.go - swag annotations for every D-09 route
  • cabana/phase09_contract_test.go - committed OpenAPI inventory
  • scripts/check-phase9.sh - fail-closed phase gate
  • lagoon/backend_admin_migrations_test.go - fresh migrate/rollback/reseed
  • fonoteka.go admin_phase09_security_test.go, admin_phase09_e2e_test.go, docs/openapi.json, scripts/check-openapi.sh

Decisions Made

  • Swag documents exported functions in cabana/admin_openapi.go. The mount test fails if that list and service.mount disagree.
  • Rollback uses a dedicated database so the shared assembled test database stays intact for the rest of the package.

Deviations from Plan

[Rule 3 - Blocking] TDD tests passed on the first run

Found during: Task 1 Issue: The guard, permission order, projection, and migration behavior already existed from plans 09-01 through 09-11. A new assertion written against that behavior passed immediately, so there was no honest RED commit. Fix: Committed the new tests as test(09-12) once they passed. The gate still fails if a later change removes the control. Files modified: bouncer/backend_guard_test.go, cabana/security_coverage_test.go, lagoon/backend_admin_migrations_test.go Verification: scripts/check-phase9.sh --evidence Commit: 30bfd2d

Total deviations: 1 Impact: No production control was weakened. The new tests are the regression net the plan asked for.

Issues Encountered

None.

User Setup Required

None.

Next Phase Readiness

Plan 09-12 is executed. Phase 9 still needs its verification report before the roadmap phase checkbox can close.

Self-Check: PASSED

  • bouncer/backend_guard_test.go exists
  • scripts/check-phase9.sh exists
  • 09-SECURITY-REVIEW.md exists
  • Commits 30bfd2d, 336a90b, 4392550, and feaca6b are present