chore: keep source task records task-owned

This commit is contained in:
2026-08-14 00:05:00 +08:00
parent b8db39d8b4
commit d2e71e76de
5 changed files with 0 additions and 390 deletions

View File

@@ -1,76 +0,0 @@
# Task: Implement Go migration compatibility foundation
## Identity
- Task ID: 20260812-go-migration-foundation-b74c9e21
- Mode: Feature
- Branch: codex/20260812-go-migration-foundation-b74c9e21-go-migration-foundation
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-foundation-b74c9e21
- Base commit: 7de3300034accc7a0332b56207298d1e15d91de8
- Owner: codex
- Status: Ready for Integration
## Scope
- Establish executable, language-neutral compatibility contracts for the current HTTP route surface, session Cookie wire format, and PostgreSQL runtime/concurrency requirements.
- Add a runnable Go 1.21 backend foundation with strict configuration, PostgreSQL readiness, legacy-session parsing/chunking, and health/readiness HTTP handlers.
- Add developer verification commands without changing the current Next.js, Node Worker, Docker Compose, or ACK production routing.
## Intent And Constraints
- Follow red-green TDD at the approved HTTP, Cookie, PostgreSQL, and Adapter seams.
- Preserve ACK-001 as the current deployable truth; this task does not cut traffic, remove Route Handlers, start the embedded WorkerLoop, or move production Secrets.
- Preserve the HMAC-SHA256/base64url/chunked `zhinian_session` wire contract so a future release can avoid forced logout; do not yet make the release-policy choice.
- Keep production PostgreSQL explicit and fail-closed, verified-CA TLS explicit, and both concurrency-sensitive database functions authoritative.
- Use deep Go Modules around configuration, identity Cookie handling, PostgreSQL access, and HTTP lifecycle rather than one shallow Interface per table.
## Outcome
- Added language-neutral compatibility contracts for the complete current route surface (47 Route Handler files and 66 method/path entries) and the full version-one `zhinian_session` lifecycle: HMAC wire format, 3000-character chunks, 20-chunk/60000-character ceiling, Cookie attributes, Secure precedence, stale-chunk cleanup, and logout cleanup.
- Added TypeScript contract tests that detect route drift, prove the current TypeScript signer/parser matches the shared Cookie golden fixture, and freeze Cookie writing/clearing semantics. The current writer now rejects values that the 20-chunk reader cannot reconstruct.
- Added a runnable Go 1.21 module under `backend/` with:
- an Identity Module for legacy Cookie signing, parsing, normalization, tamper/expiry validation, bounded chunking/reassembly, Secure resolution, and transport-neutral set/clear operations;
- a PostgreSQL Module for fail-closed backend selection, URI and numeric validation, explicit `disable` or verified-CA `verify-full` TLS, pool lifecycle, the exact readiness privilege matrix, bounded job claims through `claim_generation_jobs`, and wallet posting through `billing_post_wallet_entry`;
- an HTTP Module for the stable `/api/health` liveness contract and three-second `/api/ready` database probe;
- an Application composition Module and `cmd/zhinian-api` process with loopback-by-default binding and bounded graceful shutdown.
- Added cross-platform `npm run go:{fmt,test,vet,build}` commands through a small Node runner that defaults to `CGO_ENABLED=0` without mutating the user's global Go environment.
- Kept the current Next.js, Node Worker, Docker Compose, ACK manifests, Ingress paths, Secrets, and production traffic ownership unchanged.
- Corrected the earlier planning count from 45/64 to the source-derived 47 Route Handler files and 66 method/path entries; the two omitted routes were `/uploads/[...path]` and `/generated-results/[...path]`.
## Verification
- TDD RED evidence was captured independently for the HTTP manifest, Identity Module, PostgreSQL configuration/database/opening slices, HTTP health/readiness Module, application composition, cross-platform Go command runner, and final Cookie lifecycle ceiling before each slice reached GREEN.
- `npm test -- --reporter=dot`: 34 files and 126 tests passed.
- `npm run go:test`: all five Go packages passed.
- `npm run go:vet`: passed.
- `npm run go:build`: produced the ignored `backend/zhinian-api` binary.
- Local smoke run on port 18080 returned the stable health payload and successful local readiness, then exited cleanly on SIGTERM.
- `npm run deploy:check`: all 8 current ACK manifests passed, demonstrating that the existing deployment contract was not disturbed.
- `npx tsc --noEmit --incremental false`: passed.
- `npm run build`: Next.js 15.5.18 production build completed with all 33 pages/routes; the existing multiple-lockfile workspace-root warning remains.
- `git diff --check`: passed.
- The installed `/usr/local/go` 1.21.6 internal linker produces `missing LC_UUID` test binaries on this future macOS runtime; the repository runner uses the pure-Go `CGO_ENABLED=0` path, and external linking independently executed affected tests successfully.
## Follow-ups
- Add a black-box contract runner that can execute stable health/readiness/OpenAPI assertions against either Next.js or Go by base URL.
- Resolve the observed OpenAPI drift before treating it as authoritative: reused idempotent job responses omit documented HTTP 200, `video.generate.bailian` is absent, and documentation alone advertises video `4k`.
- Implement the first identity vertical slice in Go, including PostgreSQL revalidation of account status, organization status, role constraints, and `sessionVersion`; Cookie parsing alone is not authorization.
- Expand job and wallet database return types only when their owning vertical slices migrate; this foundation intentionally exposes only the minimum needed contract.
- Keep Go unrouted and the Node Worker active until exact path-level parity, single-writer ownership, Worker drain, rollback, and production RDS/ACK checks pass.
## Promotion Candidates
- Target: `.project-docs/30-worklog/current-state.md`, `.project-docs/20-architecture/system-overview.md`, `.project-docs/20-architecture/module-map.md`, and `.project-docs/80-commitments/commitments.md`.
Proposal: record that ADR-003 implementation has started with executable route/Cookie contracts and a runnable but unrouted Go foundation; ACK-001 remains authoritative for production.
Evidence: the shared contract fixtures/tests, Go Modules and entry point, complete Node/Go/build/ACK verification, and local smoke run in this task.
Future impact: subsequent slices can use the Go configuration, PostgreSQL, Identity Cookie, health/readiness, and process lifecycle foundations instead of recreating them.
Semantic conflicts: canonical documents currently say no Go implementation has been integrated; that statement becomes stale only after this feature is merged. This work does not supersede ACK-001 or claim a cutover.
Human confirmation required: no new direction is required because ADR-003 and the user's explicit implementation request authorize this first slice; serialized Integration Gate promotion is still required.
- Target: `.project-docs/90-maintenance/stale-items.md` or corrected planning records if useful.
Proposal: correct the route inventory from 45 files / 64 handlers to 47 files / 66 method-path entries by including both file-serving Route Handlers.
Evidence: executable source-derived route manifest test.
Future impact: migration scope and progress calculations should use the complete surface.
Semantic conflicts: prior task records contain the lower count but are immutable historical evidence.
Human confirmation required: no; factual correction during Integration Gate.

View File

@@ -1,59 +0,0 @@
# Task: Implement Go password session lifecycle vertical slice
## Identity
- Task ID: 20260813-go-auth-lifecycle-3f9a6c12
- Mode: Feature
- Branch: codex/20260813-go-auth-lifecycle-3f9a6c12-go-auth-lifecycle
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-lifecycle-3f9a6c12
- Base commit: 772795e7ebd519441d98111e555288d56b75032b
- Owner: codex
- Status: Ready for Integration
## Scope
- Freeze the current platform password-login and logout HTTP/session lifecycle in language-neutral contracts consumed by TypeScript and Go tests.
- Add a deep Go Password Login Module that normalizes credentials, delegates one atomic login attempt, and creates the legacy version-one platform session.
- Add a PostgreSQL Adapter that preserves the existing per-account `FOR UPDATE` transaction, failed-attempt lockout, successful-state reset, organization checks, and scrypt password compatibility.
- Add Go HTTP Adapters for `POST /api/auth/password` and `GET|POST /api/auth/logout`, then compose them into the separately runnable Go process without moving production traffic.
- Keep self-service/admin password mutation, account administration, captcha/login redirect routes, Middleware replacement, local JSON authentication, and production cutover outside this slice.
## Intent And Constraints
- Use the external HTTP Handler, the Password Login Module's single `Login` Interface, and one atomic persistence `AttemptPasswordLogin` Interface as the agreed TDD seams.
- Preserve existing Cookie wire/chunk/attribute/TTL behavior and database-authoritative role/profile/sessionVersion claims; never expose hashes, salts, counters, tokens, or internal errors.
- Preserve PostgreSQL single-writer semantics: lock the account row; commit each failed-password transition; return 401 for failures one through four; on the fifth set a 15-minute lock, reset the counter to zero, commit, then return 423; successful login clears lock/fail state and updates `last_login_at` without rotating `session_version`.
- Preserve account and active-organization enforcement, while applying the already accepted rule that every non-super-admin must have a matching active organization.
- Match the existing Node scrypt format exactly (`N=16384`, `r=8`, `p=1`, key length 64; UTF-8 password and salt string; lowercase hex hash) so existing accounts can log in.
- Preserve the password route's request normalization, safe local redirect behavior, stable public response, 30-attempt per-process IP limiter, and configuration/error status mapping. Infrastructure or Cookie-writing failures remain server failures and must not masquerade as invalid credentials.
- Preserve logout's stateless 307 redirect and complete legacy Cookie clearing. No database session revocation is added.
- Keep ACK-001, Next.js Route Handlers, Docker/Compose/ACK/Ingress, Worker, Secrets, and production route ownership unchanged; do not dual-write login state in production.
## Outcome
- Added language-neutral password-login and logout HTTP/session contracts, with real TypeScript Route Handler consumers and Go black-box Handler consumers.
- Added the Go Password Login Module, which normalizes public credentials, delegates one atomic attempt, enforces exact platform role/organization rules, and creates a database-authoritative version-one session with a 24-hour lifetime.
- Added the PostgreSQL credential Adapter with an account-row `FOR UPDATE` transaction, Node-compatible scrypt verification, committed failed-attempt transitions, fifth-attempt lockout, and successful state reset.
- Added Go HTTP Adapters for password login and logout, including safe redirects, public response projection, per-IP throttling, complete signed/chunked Cookie writes, generic infrastructure failures, and all 20 legacy Cookie clears.
- Composed the two routes into the separately runnable Go process and updated its README. Next.js, Node Worker, Docker, ACK, Ingress, Secrets, and production route ownership remain unchanged.
## Verification
- `npm test`: PASS, 39 files and 148 tests.
- `npx tsc --noEmit --incremental false --pretty false`: PASS.
- `npm run go:test`: PASS across command, application, HTTP, Identity, and PostgreSQL packages.
- `npm run go:vet`: PASS.
- `npm run go:build`: PASS.
- `npm run build`: PASS; only the pre-existing multiple-lockfile workspace-root warning was emitted.
- `npm run deploy:check`: PASS for all eight ACK manifests.
- `gofmt -l backend`, `git diff --check`, and the production deployment/routing forbidden-scope diff: PASS.
## Follow-ups
- Exercise the PostgreSQL login transaction and verified-TLS path against a migrated non-production RDS instance before any path cutover.
- Decide whether organization status reads need an explicit row lock after measuring the real administration/login concurrency pattern; this slice intentionally matches the current transaction behavior.
- Migrate self-service and administrative password mutation in a later bounded slice.
## Promotion Candidates
- None recorded.

View File

@@ -1,85 +0,0 @@
# Task: Implement Go current-session HTTP adapter
## Identity
- Task ID: 20260813-go-auth-me-http-8d6f3a21
- Mode: Feature
- Branch: codex/20260813-go-auth-me-http-8d6f3a21-go-auth-me-http
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-me-8d6f3a21
- Base commit: c8490775916c46141e06e3a86ea5bb76eb8c3f1d
- Owner: codex
- Status: Ready for Integration
## Scope
- Freeze the current `GET /api/auth/me` response and transport behavior in a language-neutral contract consumed by TypeScript and Go tests.
- Add a Go HTTP Identity Adapter that reassembles the legacy chunked Cookie, delegates authorization to the existing deep Identity Resolver, and returns the current public session projection.
- Compose the Adapter into the runnable Go process for local/black-box verification while leaving Next.js, Ingress, Docker, ACK manifests, and production route ownership unchanged.
- Keep login, logout, password mutation, authorization policy for other routes, Middleware replacement, and production traffic cutover outside this slice.
## Intent And Constraints
- Use the external HTTP Interface and the existing `identity.Resolver.Resolve` Interface as the two agreed TDD seams; do not test private helper structure.
- Preserve the current `/api/auth/me` anonymous behavior: invalid, absent, expired, stale, disabled, or unauthorized sessions return HTTP 200 with `authenticated: false`, not 401.
- Preserve database/configuration failures as server failures rather than disguising them as anonymous sessions.
- Reuse the exact 20-name Cookie reassembly contract and database-authoritative session refresh; do not parse raw Cookie claims in the HTTP Module.
- Preserve `authRequired` and `authConfigured` semantics and the public user projection without exposing access tokens, token type, session version, or internal rejection reasons.
- Preserve Next.js method behavior: `HEAD` executes the GET path without a response body, `OPTIONS` returns 204 with `Allow: GET, HEAD, OPTIONS`, and unsupported standard methods return an empty 405 without `Allow`.
- Preserve the pinned Next.js parser's last-value-wins behavior for duplicate protected Cookie names, and treat reassembled values above the existing 60,000-character writer ceiling as anonymous before Resolver invocation.
- Keep ACK-001 deploy truth and all production path routing unchanged; the Go route remains unrouted externally in this task.
## Outcome
- Added `contracts/auth/current-session-v1.json` as the language-neutral v1
contract for `/api/auth/me`: runtime auth configuration, method/status/header
behavior, anonymous and database-refreshed public projections, sensitive
session-field exclusion, and infrastructure-failure classification.
- Added a TypeScript contract consumer over the real auth config and App Route
`GET`, plus the pinned Next.js automatic method implementation for
`HEAD`/`OPTIONS`/unsupported methods.
- Added the Go `httpapi.NewAuthMeHandler` deep HTTP Module. It owns exact Cookie
chunk reassembly, Next-compatible duplicate-name handling, the 60,000-byte
reader guard, Identity Resolver error classification, method handling, and a
whitelist-only public response projection.
- Added an exact Go auth-config parser and application composition from
environment -> PostgreSQL Adapter -> Identity Resolver -> auth/me Handler.
Application tests prove a signed Cookie is refreshed from the persistence
snapshot and cannot preserve forged role/profile claims or leak token/session
metadata.
- Kept the Next.js route, Middleware, Docker, Compose, ACK manifests, Worker,
Secrets, and all production routing unchanged. The Go endpoint is runnable
only on the separate local process until a later path-level cutover.
## Verification
- TDD RED: the Go HTTP tests initially failed to compile because
`AuthState`, `SessionResolver`, and `NewAuthMeHandler` did not exist; the
application tests then failed before auth config and route composition were
implemented. Focused tests passed after each implementation slice.
- `npm test -- --reporter=dot`: 37 files and 141 tests passed.
- `npm run go:test`: all five Go packages passed.
- `npm run go:vet`: passed.
- `npm run go:build`: passed for `./cmd/zhinian-api`.
- `npx tsc --noEmit --incremental false --pretty false`: passed after the
concurrent `next build` process finished regenerating `.next/types`.
- `npm run build`: Next.js 15.5.18 production build passed with all 33 pages.
- `npm run deploy:check`: all 8 ACK manifest assertions passed.
- `git diff --check`, `gofmt -l backend`, project-docs validation, task doc
drift, and the forbidden production-routing diff check all passed.
## Follow-ups
- Add a local-account authorization snapshot Adapter if authenticated local-mode
Go development is required; today a configured valid Cookie on the local
backend fails with an explicit 500 rather than silently trusting claims.
- Add real PostgreSQL/RDS and verified-CA transport integration coverage before
any production auth route cutover.
- Migrate login, logout, password mutation, Middleware enforcement, and other
protected routes in later independently contract-tested slices.
## Promotion Candidates
- Promote `contracts/auth/current-session-v1.json` as the current-session HTTP
compatibility truth when the task is integrated.
- Record that the Go application can serve `/api/auth/me` locally while ACK-001
and all production route ownership remain with Next.js.

View File

@@ -1,73 +0,0 @@
# Task: Implement Go identity authorization vertical slice
## Identity
- Task ID: 20260813-go-identity-vertical-c4e91a72
- Mode: Feature
- Branch: codex/20260813-go-identity-vertical-c4e91a72-go-identity-vertical
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-identity-c4e91a72
- Base commit: 716a8031b1f0b322470e180e45dea2fe12fdead3
- Owner: codex
- Status: Ready for Integration
## Scope
- Add a language-neutral platform-session authorization matrix that fixes the per-request account, organization, role, client, and `sessionVersion` contract shared by TypeScript and Go.
- Add a deep Go Identity Module whose external seam resolves a signed legacy Cookie into a database-refreshed current session or a typed unauthenticated rejection.
- Add a PostgreSQL Adapter that loads the complete authorization snapshot in one parameterized account/organization query.
- Keep login, password changes, HTTP identity routes, middleware replacement, Docker/ACK manifests, and production traffic ownership outside this slice.
## Intent And Constraints
- Follow vertical red-green TDD at the existing signed-session/Identity seam and PostgreSQL Adapter seam.
- Treat Cookie data only as authenticated input; database account role, profile, status, organization state, and session version are authoritative for every resolved request.
- Preserve current legacy compatibility where an absent or zero `sessionVersion` is accepted, while any nonzero mismatch is rejected; the refreshed result always carries the current database version.
- Require every non-super-admin account to belong to an active existing organization; allow an unbound super-admin as the current billing/administration model requires.
- Collapse authentication denials for callers while retaining typed internal rejection reasons for tests and diagnostics; propagate database failures separately.
- Do not expose or route a Go identity endpoint and do not change ACK-001 production behavior in this task.
## Outcome
- Added `contracts/auth/platform-session-authorization-v1.json`, a language-neutral 14-case matrix covering database-authoritative claim refresh, platform-client enforcement, active/disabled accounts, exact platform roles, legacy missing/zero `sessionVersion`, nonzero version mismatch, rejection precedence, organization requirements, and super-admin organization compatibility.
- Added the Go Identity `Resolver` as one deep external seam from a signed legacy Cookie to a database-refreshed `Session`. Authentication denials collapse through `ErrUnauthenticated` while retaining stable internal rejection reasons; persistence failures remain distinct and propagate to the caller.
- Added a Go PostgreSQL authorization-snapshot Adapter that implements the Resolver's single persistence Interface with one explicit-column, parameterized `LEFT JOIN` over `public.platform_users` and `public.platform_organizations`. It deliberately returns disabled/missing organization state to the Identity Module instead of hiding policy in SQL.
- Added the equivalent TypeScript authorization seam and PostgreSQL snapshot store, then changed `getOptionalAuthSession` to use them. PostgreSQL request revalidation now uses one joined query rather than separate account and organization reads; the local development path projects the same narrow snapshot without exposing password storage fields.
- Closed the existing authorization gap that accepted non-super-admin accounts with no organization. All non-super-admin accounts now require a matching, active organization; an unbound super-admin remains valid.
- Kept login, password changes, Middleware, Go identity HTTP routes, Docker/ACK manifests, Ingress paths, and production traffic ownership unchanged. The Go Resolver is implemented and tested but remains intentionally unrouted.
## Verification
- Vertical TDD RED evidence was captured independently before the Go Resolver, Go PostgreSQL Adapter, TypeScript authorization seam, and TypeScript snapshot store implementations existed. Intermediate RED assertions also exposed missing organization-admin claim reconstruction and local snapshot leakage before those paths reached GREEN.
- `npm test -- --reporter=dot`: 36 test files and 135 tests passed, including both consumers of the shared authorization matrix and the PostgreSQL/local snapshot-store contract.
- `npx tsc --noEmit --incremental false`: passed.
- `npm run build`: Next.js 15.5.18 production build completed for all current routes; the pre-existing multiple-lockfile workspace-root warning remains.
- `npm run go:test`: all five Go packages passed.
- `npm run go:vet`: passed.
- `npm run go:build`: built `cmd/zhinian-api` successfully through the repository's cross-platform runner.
- `npm run deploy:check`: all 8 ACK manifest assertions passed, confirming that production routing and workload ownership were not changed.
- `git diff --check` and `gofmt -d` over all changed Go files: passed with no output.
- The independent Sol review found one cross-language composite-failure ordering mismatch. A fixture case was strengthened to combine an unknown database role with a nonzero version mismatch, producing the expected TypeScript RED (`invalid_role` versus `session_version_mismatch`); TypeScript was then aligned with Go so version mismatch has stable precedence. A second review caught that this temporarily removed standalone `invalid_role` coverage, so a redundant standalone version-mismatch case was converted to preserve both reasons while retaining all organization cases and the 14-case total. Both focused contracts and all verification above passed again.
## Follow-ups
- Add the first Go current-user/authentication HTTP Adapter only after its response, 401/403/500 mapping, Cookie transport, and black-box parity contracts are frozen; this task does not claim `/api/auth/me` or another identity path.
- Move or duplicate database-refreshed authorization at the routing boundary before any protected route cutover. The current Next.js Middleware still performs signed-Cookie-only gating, while server Route Handlers perform the authoritative database refresh.
- Add a Go local-development authorization snapshot Adapter before expecting the unrouted Go process to serve identity flows with `ZHINIAN_DATA_BACKEND=local`.
- Exercise the joined identity query against the production-like RDS role, verified-CA TLS, schema privileges, disabled accounts, deleted organizations, and concurrent account mutations before cutover.
- Migrate login/logout/password and lockout mutation flows as separate vertical slices so session-version invalidation and single-writer ownership can be reviewed independently.
## Promotion Candidates
- Target: `.project-docs/30-worklog/current-state.md`, `.project-docs/20-architecture/module-map.md`, and `.project-docs/20-architecture/data-flow.md`.
Proposal: after integration, record the implemented but unrouted Go Identity Resolver, its single PostgreSQL authorization-snapshot seam, and the shared TypeScript/Go authorization contract.
Evidence: the 14-case shared fixture, both language implementations, exact joined-query tests, and complete Node/Go/build/ACK verification in this task.
Future impact: later HTTP slices can consume one current-session result instead of reimplementing Cookie parsing, account/organization lookup order, or role/session-version rules.
Semantic conflicts: canonical documents still describe the Go backend as a foundation with no identity authorization slice; they should change only when this feature is integrated. ACK-001 and Next.js route ownership remain unchanged.
Human confirmation required: no new architecture direction is required; promotion still belongs to the serialized Integration Gate.
- Target: `.project-docs/40-domain/business-rules.md`.
Proposal: record that every active non-super-admin platform account must reference the same active organization returned by the authorization snapshot, while a super-admin may be unbound; missing/zero legacy session versions are temporarily accepted and refreshed, while nonzero mismatches revoke the session.
Evidence: the shared authorization matrix and both TypeScript/Go Resolver contract suites.
Future impact: account deletion, organization archival, role changes, session invalidation, and future authorization Adapters must preserve this rule.
Semantic conflicts: this deliberately closes a prior TypeScript conditional gap and aligns runtime authorization with the existing account mutation/domain constraints.
Human confirmation required: no; the task scope explicitly selected this security rule and no production route ownership changed.

View File

@@ -1,97 +0,0 @@
# Task: Complete remaining Go backend modules
## Identity
- Task ID: 20260813-go-remaining-modules-7d3a9e42
- Mode: Feature
- Branch: codex/20260813-go-remaining-modules-7d3a9e42-go-remaining-modules
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-remaining-7d3a9e42
- Base commit: d0207fcebe6ea4fb3ba80dce8c012b3c2170de40
- Owner: codex
- Status: Ready for Integration
## Scope
- Complete every ADR-003 Go backend module that remains after the foundation,
database-refreshed identity, current-session HTTP, and password
login/logout slices already present at the task base.
- Freeze language-neutral compatibility contracts before each remaining
vertical slice and keep the TypeScript implementation as an executable
source-of-truth consumer until cutover.
- Implement the remaining Identity and Administration behavior; Assets and
storage/file serving; Billing and Usage; Jobs, providers, Webhooks, and the
embedded WorkerLoop; and the remaining public/compatibility HTTP surface.
- Compose all migrated routes into the separately runnable Go application and
prove route-surface coverage without moving production traffic.
- Keep production cutover, Next Route Handler deletion, Node Worker drain,
Docker/ACK/Ingress ownership changes, and real RDS/OSS rollout outside this
feature task.
## Intent And Constraints
- Follow vertical red-green TDD at stable external HTTP Interfaces and deep
domain/Adapter seams; do not create one shallow repository Interface per
table.
- Preserve current same-origin paths, method/status/JSON behavior, Cookie and
tenant authorization, owner-scoped not-found behavior, idempotency, job
state, wallet arithmetic, storage metadata, provider, and Webhook semantics.
- Keep PostgreSQL as the production source of relational truth and continue
using `claim_generation_jobs` and `billing_post_wallet_entry` for
cross-instance concurrency. Never replace them with process-local locks.
- Keep one owner for external side effects and every write path. The Go
implementation remains locally runnable and contract-tested but unrouted in
production until a later explicit cutover.
- Keep Alibaba Cloud OSS behind an object-storage Adapter and retain an
explicit local-development Adapter; do not claim horizontal production
safety until real OSS and RDS/TLS checks pass.
- Preserve the currently deployed ACK-001 Web/HTTP-polling-Worker topology and
all production Secrets/manifests during this implementation task.
- Work only in the owned worktree and task record; canonical project memory is
reserved for a serialized Integration Gate.
## Outcome
- Completed in the feature worktree. Implemented and composed the remaining Go
modules: administration and organization lifecycle, assets and hardened
storage/remote fetch, billing ledger/catalog/settlement, usage reporting,
jobs/providers/webhooks/worker loop, templates/prompt, settings/logging,
public and compatibility HTTP routes, localstore adapters, PostgreSQL
adapters, and lifecycle fencing migration 0002. Added language-neutral
contracts and executable TypeScript/Go consumers while preserving the
existing Next production ownership and deployment topology.
- Added final lifecycle hardening for streamed HTTP event logging, unique
worker lease tokens and CAS fencing, commit-outcome reconciliation, retry
recovery handles, readiness checks for lifecycle columns, mock output
registration, usage filter options, public webhook/priority validation, and
a single settings/billing-account source.
## Verification
- `CGO_ENABLED=0 go test -count=1 ./...` — PASS
- `CGO_ENABLED=0 go test -race -count=1 ./internal/...` (all migrated
packages) — PASS
- `npm run go:vet` — PASS
- `npm run go:build` — PASS
- `npm test -- --run` — 57 files / 172 tests PASS
- `npx tsc --noEmit --incremental false` — PASS
- `npm run build` — PASS (Next build)
- `node scripts/check-ack-manifests.mjs` and `npm run deploy:check` — PASS
- `git diff --check`, `gofmt` cleanliness, and production boundary diff
checks — PASS
- Independent `sol_reviewer` final review — PASS; no blocking findings.
## Follow-ups
- Validate the complete backend against migrated non-production RDS with the
real application role and verified-CA TLS before production cutover.
- Validate OSS compatibility, provider credentials, external Webhooks, Worker
drain/recovery, and rollout/rollback against production-like infrastructure.
- Keep Go unrouted until the explicit production cutover review; do not delete
the Next handlers or change Docker/ACK/Ingress ownership in this task.
## Promotion Candidates
- Preserve the new Go module map and contract fixtures as candidates for the
next serialized Integration Gate to promote into canonical architecture
memory. This feature task does not modify shared canonical documents.