feat: add shared backend authorization seams
This commit is contained in:
1 parent
d0207fcebe
commit
48dd5d07c8
9 files changed
+1086
No files matched your search
@@ -0,0 +1,69 @@
|
||||
# Task: Complete remaining Go backend modules
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-remaining-modules-7d3a9e42
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-remaining-modules-7d3a9e42-go-remaining-modules
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-remaining-7d3a9e42
|
||||
- Base commit: d0207fcebe6ea4fb3ba80dce8c012b3c2170de40
|
||||
- Owner: codex
|
||||
- Status: Planning
|
||||
|
||||
## Scope
|
||||
|
||||
- Complete every ADR-003 Go backend module that remains after the foundation,
|
||||
database-refreshed identity, current-session HTTP, and password
|
||||
login/logout slices already present at the task base.
|
||||
- Freeze language-neutral compatibility contracts before each remaining
|
||||
vertical slice and keep the TypeScript implementation as an executable
|
||||
source-of-truth consumer until cutover.
|
||||
- Implement the remaining Identity and Administration behavior; Assets and
|
||||
storage/file serving; Billing and Usage; Jobs, providers, Webhooks, and the
|
||||
embedded WorkerLoop; and the remaining public/compatibility HTTP surface.
|
||||
- Compose all migrated routes into the separately runnable Go application and
|
||||
prove route-surface coverage without moving production traffic.
|
||||
- Keep production cutover, Next Route Handler deletion, Node Worker drain,
|
||||
Docker/ACK/Ingress ownership changes, and real RDS/OSS rollout outside this
|
||||
feature task.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Follow vertical red-green TDD at stable external HTTP Interfaces and deep
|
||||
domain/Adapter seams; do not create one shallow repository Interface per
|
||||
table.
|
||||
- Preserve current same-origin paths, method/status/JSON behavior, Cookie and
|
||||
tenant authorization, owner-scoped not-found behavior, idempotency, job
|
||||
state, wallet arithmetic, storage metadata, provider, and Webhook semantics.
|
||||
- Keep PostgreSQL as the production source of relational truth and continue
|
||||
using `claim_generation_jobs` and `billing_post_wallet_entry` for
|
||||
cross-instance concurrency. Never replace them with process-local locks.
|
||||
- Keep one owner for external side effects and every write path. The Go
|
||||
implementation remains locally runnable and contract-tested but unrouted in
|
||||
production until a later explicit cutover.
|
||||
- Keep Alibaba Cloud OSS behind an object-storage Adapter and retain an
|
||||
explicit local-development Adapter; do not claim horizontal production
|
||||
safety until real OSS and RDS/TLS checks pass.
|
||||
- Preserve the currently deployed ACK-001 Web/HTTP-polling-Worker topology and
|
||||
all production Secrets/manifests during this implementation task.
|
||||
- Work only in the owned worktree and task record; canonical project memory is
|
||||
reserved for a serialized Integration Gate.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Not completed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Not run.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Validate the complete backend against migrated non-production RDS with the
|
||||
real application role and verified-CA TLS before production cutover.
|
||||
- Validate OSS compatibility, provider credentials, external Webhooks, Worker
|
||||
drain/recovery, and rollout/rollback against production-like infrastructure.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
Reference in new issue
Block a user