Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout. Co-authored-by: Cursor <cursoragent@cursor.com>
5.9 KiB
phase, plan, subsystem, tags, requires, provides, affects, tech-stack, key-files, key-decisions, patterns-established, requirements-completed, duration, completed
| phase | plan | subsystem | tags | requires | provides | affects | tech-stack | key-files | key-decisions | patterns-established | requirements-completed | duration | completed | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 07-user-plugin-and-authentication | 05 | auth |
|
|
|
|
|
|
|
|
45min | 2026-09-22 |
Phase 7 Plan 05: User API parity capture Summary
The 15 /_user/api/v1 routes are recorded from the isolated PHP app. They stay pending because several PHP bodies differ from the current Go handlers.
Performance
- Duration: 45 min
- Started: 2026-09-22T16:11:00Z
- Completed: 2026-09-22T16:45:00Z
- Tasks: 3
- Files modified: 45
Accomplishments
- Recorded login, logout, fetch, refresh, register, forgot-password, reset-password, activate, activate-by-code, update, change-password, avatar, avatar/remove, marketing-consent, and oauth-providers, including validation and auth failures.
db_capturereadsreset_password_codeandactivation_codethrough the isolated artisan tinker and stores{id}!{code}.nuxt-auth.yamlwalks register, fetch, update, change-password, refresh, logout, and a following fetch.nuxt-auth-lock.yamlrecords 423 on genres, 200 on me/locale, then a successful change-password.- The corpus audit prints
recorded 169/169. Ported routes stay at 7. The new routes are pending.
Task Commits
- Task 1–3: Record and verify the user API corpus —
30984b6infonoteka.go - Scrubber allow-list for the second test password —
7d5d865insummercms.go
Files Created/Modified
parity/manifest.yaml— 15auth_group: user-apientriesparity/capture-rules.yaml— register, refresh, and activate-by-code token captureparity/db_capture.go— PHP tinker and Postgres code readersparity/fixtures/nuxt/nuxt-auth.yaml— D-14 session flowparity/fixtures/nuxt/nuxt-auth-lock.yaml— locked-user 423 then me/localetide/variables.go—parity-alice-nextis an allow-listed test password
Decisions Made
A2 is settled from the recording. Six rapid failed logins for a2@parity.test are all 401 {"error":true,"message":"Nieprawidłowy email lub hasło"}. The 6th body equals the 1st. This login path does not suspend the account.
Register with allow_registration=false and register after the per-IP limit both record {"error":"Internal server error"} at status 500 under APP_DEBUG=false.
Every recorded login, fetch, register, and update success user payload contains feedback_widget_hidden: false.
Deviations from Plan
Auto-fixed Issues
1. [Rule 1 - Bug] Authenticated activate with a wrong code is an HTML 500
- Found during: Task 2
- Issue: The plan expected 200
{"user":...}withis_activatedunchanged. PHPattemptActivationthrows outside the JSON catch, and the isolated app returns the generic HTML page titled "Błąd strony" at status 500.POST activate-by-codewith1!nopedoes the same. - Fix: The fixtures keep the recorded HTML. The Go handler's 200 is a gap for a later closure, not a fixture edit.
- Files modified:
parity/fixtures/routes/POST___user_api_v1_activate_user-api.yaml,parity/fixtures/routes/POST___user_api_v1_activate-by-code_user-api__invalid.yaml - Committed in:
30984b6
2. [Rule 1 - Bug] Fetch after logout is still 200
- Found during: Task 2
- Issue: The plan expected the logged-out bearer to be refused. PHP logout returns
{"message":"Logged out"}and a followingGET /fetchwith that bearer is still 200. The Go handler blacklists the token. - Fix:
GET___user_api_v1_fetch_user-api__reused.yamland the last step ofnuxt-auth.yamlrecord the 200. The routes staypending. - Files modified:
parity/fixtures/routes/GET___user_api_v1_fetch_user-api__reused.yaml,parity/fixtures/nuxt/nuxt-auth.yaml - Committed in:
30984b6
Total deviations: 2 recorded, not patched in Go Impact on plan: The corpus matches PHP. Closing the activate and logout gaps is follow-up work, not a silent fixture rewrite.
Issues Encountered
None
User Setup Required
None - no external service configuration required.
Next Phase Readiness
Ready for 07-06 unit coverage. AUTH-01, AUTH-02, AUTH-03, AUTH-04, and I18N-02 stay unchecked until phase sign-off. The user-api routes stay pending until Go matches the recorded bodies.
Self-Check: PASSED
- Secret grep over the new fixtures found no live JWT or
inv_token. /tmp/summercms-parity/vars.yamlis mode 0600 and outside the repo.go run ./parity/check_corpus.go --require-recorded --require-clients --check-secretsprintedrecorded 169/169.go test ./parity/ -run 'TestParityCorpus|TestDBCapture'passed with 7 ported and 162 pending.- Commits
30984b6and7d5d865are on master.