chore: keep source task records task-owned
This commit is contained in:
@@ -1,76 +0,0 @@
|
||||
# Task: Implement Go migration compatibility foundation
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260812-go-migration-foundation-b74c9e21
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260812-go-migration-foundation-b74c9e21-go-migration-foundation
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-foundation-b74c9e21
|
||||
- Base commit: 7de3300034accc7a0332b56207298d1e15d91de8
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Establish executable, language-neutral compatibility contracts for the current HTTP route surface, session Cookie wire format, and PostgreSQL runtime/concurrency requirements.
|
||||
- Add a runnable Go 1.21 backend foundation with strict configuration, PostgreSQL readiness, legacy-session parsing/chunking, and health/readiness HTTP handlers.
|
||||
- Add developer verification commands without changing the current Next.js, Node Worker, Docker Compose, or ACK production routing.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Follow red-green TDD at the approved HTTP, Cookie, PostgreSQL, and Adapter seams.
|
||||
- Preserve ACK-001 as the current deployable truth; this task does not cut traffic, remove Route Handlers, start the embedded WorkerLoop, or move production Secrets.
|
||||
- Preserve the HMAC-SHA256/base64url/chunked `zhinian_session` wire contract so a future release can avoid forced logout; do not yet make the release-policy choice.
|
||||
- Keep production PostgreSQL explicit and fail-closed, verified-CA TLS explicit, and both concurrency-sensitive database functions authoritative.
|
||||
- Use deep Go Modules around configuration, identity Cookie handling, PostgreSQL access, and HTTP lifecycle rather than one shallow Interface per table.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added language-neutral compatibility contracts for the complete current route surface (47 Route Handler files and 66 method/path entries) and the full version-one `zhinian_session` lifecycle: HMAC wire format, 3000-character chunks, 20-chunk/60000-character ceiling, Cookie attributes, Secure precedence, stale-chunk cleanup, and logout cleanup.
|
||||
- Added TypeScript contract tests that detect route drift, prove the current TypeScript signer/parser matches the shared Cookie golden fixture, and freeze Cookie writing/clearing semantics. The current writer now rejects values that the 20-chunk reader cannot reconstruct.
|
||||
- Added a runnable Go 1.21 module under `backend/` with:
|
||||
- an Identity Module for legacy Cookie signing, parsing, normalization, tamper/expiry validation, bounded chunking/reassembly, Secure resolution, and transport-neutral set/clear operations;
|
||||
- a PostgreSQL Module for fail-closed backend selection, URI and numeric validation, explicit `disable` or verified-CA `verify-full` TLS, pool lifecycle, the exact readiness privilege matrix, bounded job claims through `claim_generation_jobs`, and wallet posting through `billing_post_wallet_entry`;
|
||||
- an HTTP Module for the stable `/api/health` liveness contract and three-second `/api/ready` database probe;
|
||||
- an Application composition Module and `cmd/zhinian-api` process with loopback-by-default binding and bounded graceful shutdown.
|
||||
- Added cross-platform `npm run go:{fmt,test,vet,build}` commands through a small Node runner that defaults to `CGO_ENABLED=0` without mutating the user's global Go environment.
|
||||
- Kept the current Next.js, Node Worker, Docker Compose, ACK manifests, Ingress paths, Secrets, and production traffic ownership unchanged.
|
||||
- Corrected the earlier planning count from 45/64 to the source-derived 47 Route Handler files and 66 method/path entries; the two omitted routes were `/uploads/[...path]` and `/generated-results/[...path]`.
|
||||
|
||||
## Verification
|
||||
|
||||
- TDD RED evidence was captured independently for the HTTP manifest, Identity Module, PostgreSQL configuration/database/opening slices, HTTP health/readiness Module, application composition, cross-platform Go command runner, and final Cookie lifecycle ceiling before each slice reached GREEN.
|
||||
- `npm test -- --reporter=dot`: 34 files and 126 tests passed.
|
||||
- `npm run go:test`: all five Go packages passed.
|
||||
- `npm run go:vet`: passed.
|
||||
- `npm run go:build`: produced the ignored `backend/zhinian-api` binary.
|
||||
- Local smoke run on port 18080 returned the stable health payload and successful local readiness, then exited cleanly on SIGTERM.
|
||||
- `npm run deploy:check`: all 8 current ACK manifests passed, demonstrating that the existing deployment contract was not disturbed.
|
||||
- `npx tsc --noEmit --incremental false`: passed.
|
||||
- `npm run build`: Next.js 15.5.18 production build completed with all 33 pages/routes; the existing multiple-lockfile workspace-root warning remains.
|
||||
- `git diff --check`: passed.
|
||||
- The installed `/usr/local/go` 1.21.6 internal linker produces `missing LC_UUID` test binaries on this future macOS runtime; the repository runner uses the pure-Go `CGO_ENABLED=0` path, and external linking independently executed affected tests successfully.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Add a black-box contract runner that can execute stable health/readiness/OpenAPI assertions against either Next.js or Go by base URL.
|
||||
- Resolve the observed OpenAPI drift before treating it as authoritative: reused idempotent job responses omit documented HTTP 200, `video.generate.bailian` is absent, and documentation alone advertises video `4k`.
|
||||
- Implement the first identity vertical slice in Go, including PostgreSQL revalidation of account status, organization status, role constraints, and `sessionVersion`; Cookie parsing alone is not authorization.
|
||||
- Expand job and wallet database return types only when their owning vertical slices migrate; this foundation intentionally exposes only the minimum needed contract.
|
||||
- Keep Go unrouted and the Node Worker active until exact path-level parity, single-writer ownership, Worker drain, rollback, and production RDS/ACK checks pass.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Target: `.project-docs/30-worklog/current-state.md`, `.project-docs/20-architecture/system-overview.md`, `.project-docs/20-architecture/module-map.md`, and `.project-docs/80-commitments/commitments.md`.
|
||||
Proposal: record that ADR-003 implementation has started with executable route/Cookie contracts and a runnable but unrouted Go foundation; ACK-001 remains authoritative for production.
|
||||
Evidence: the shared contract fixtures/tests, Go Modules and entry point, complete Node/Go/build/ACK verification, and local smoke run in this task.
|
||||
Future impact: subsequent slices can use the Go configuration, PostgreSQL, Identity Cookie, health/readiness, and process lifecycle foundations instead of recreating them.
|
||||
Semantic conflicts: canonical documents currently say no Go implementation has been integrated; that statement becomes stale only after this feature is merged. This work does not supersede ACK-001 or claim a cutover.
|
||||
Human confirmation required: no new direction is required because ADR-003 and the user's explicit implementation request authorize this first slice; serialized Integration Gate promotion is still required.
|
||||
|
||||
- Target: `.project-docs/90-maintenance/stale-items.md` or corrected planning records if useful.
|
||||
Proposal: correct the route inventory from 45 files / 64 handlers to 47 files / 66 method-path entries by including both file-serving Route Handlers.
|
||||
Evidence: executable source-derived route manifest test.
|
||||
Future impact: migration scope and progress calculations should use the complete surface.
|
||||
Semantic conflicts: prior task records contain the lower count but are immutable historical evidence.
|
||||
Human confirmation required: no; factual correction during Integration Gate.
|
||||
@@ -1,59 +0,0 @@
|
||||
# Task: Implement Go password session lifecycle vertical slice
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-auth-lifecycle-3f9a6c12
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-auth-lifecycle-3f9a6c12-go-auth-lifecycle
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-lifecycle-3f9a6c12
|
||||
- Base commit: 772795e7ebd519441d98111e555288d56b75032b
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Freeze the current platform password-login and logout HTTP/session lifecycle in language-neutral contracts consumed by TypeScript and Go tests.
|
||||
- Add a deep Go Password Login Module that normalizes credentials, delegates one atomic login attempt, and creates the legacy version-one platform session.
|
||||
- Add a PostgreSQL Adapter that preserves the existing per-account `FOR UPDATE` transaction, failed-attempt lockout, successful-state reset, organization checks, and scrypt password compatibility.
|
||||
- Add Go HTTP Adapters for `POST /api/auth/password` and `GET|POST /api/auth/logout`, then compose them into the separately runnable Go process without moving production traffic.
|
||||
- Keep self-service/admin password mutation, account administration, captcha/login redirect routes, Middleware replacement, local JSON authentication, and production cutover outside this slice.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Use the external HTTP Handler, the Password Login Module's single `Login` Interface, and one atomic persistence `AttemptPasswordLogin` Interface as the agreed TDD seams.
|
||||
- Preserve existing Cookie wire/chunk/attribute/TTL behavior and database-authoritative role/profile/sessionVersion claims; never expose hashes, salts, counters, tokens, or internal errors.
|
||||
- Preserve PostgreSQL single-writer semantics: lock the account row; commit each failed-password transition; return 401 for failures one through four; on the fifth set a 15-minute lock, reset the counter to zero, commit, then return 423; successful login clears lock/fail state and updates `last_login_at` without rotating `session_version`.
|
||||
- Preserve account and active-organization enforcement, while applying the already accepted rule that every non-super-admin must have a matching active organization.
|
||||
- Match the existing Node scrypt format exactly (`N=16384`, `r=8`, `p=1`, key length 64; UTF-8 password and salt string; lowercase hex hash) so existing accounts can log in.
|
||||
- Preserve the password route's request normalization, safe local redirect behavior, stable public response, 30-attempt per-process IP limiter, and configuration/error status mapping. Infrastructure or Cookie-writing failures remain server failures and must not masquerade as invalid credentials.
|
||||
- Preserve logout's stateless 307 redirect and complete legacy Cookie clearing. No database session revocation is added.
|
||||
- Keep ACK-001, Next.js Route Handlers, Docker/Compose/ACK/Ingress, Worker, Secrets, and production route ownership unchanged; do not dual-write login state in production.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added language-neutral password-login and logout HTTP/session contracts, with real TypeScript Route Handler consumers and Go black-box Handler consumers.
|
||||
- Added the Go Password Login Module, which normalizes public credentials, delegates one atomic attempt, enforces exact platform role/organization rules, and creates a database-authoritative version-one session with a 24-hour lifetime.
|
||||
- Added the PostgreSQL credential Adapter with an account-row `FOR UPDATE` transaction, Node-compatible scrypt verification, committed failed-attempt transitions, fifth-attempt lockout, and successful state reset.
|
||||
- Added Go HTTP Adapters for password login and logout, including safe redirects, public response projection, per-IP throttling, complete signed/chunked Cookie writes, generic infrastructure failures, and all 20 legacy Cookie clears.
|
||||
- Composed the two routes into the separately runnable Go process and updated its README. Next.js, Node Worker, Docker, ACK, Ingress, Secrets, and production route ownership remain unchanged.
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm test`: PASS, 39 files and 148 tests.
|
||||
- `npx tsc --noEmit --incremental false --pretty false`: PASS.
|
||||
- `npm run go:test`: PASS across command, application, HTTP, Identity, and PostgreSQL packages.
|
||||
- `npm run go:vet`: PASS.
|
||||
- `npm run go:build`: PASS.
|
||||
- `npm run build`: PASS; only the pre-existing multiple-lockfile workspace-root warning was emitted.
|
||||
- `npm run deploy:check`: PASS for all eight ACK manifests.
|
||||
- `gofmt -l backend`, `git diff --check`, and the production deployment/routing forbidden-scope diff: PASS.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Exercise the PostgreSQL login transaction and verified-TLS path against a migrated non-production RDS instance before any path cutover.
|
||||
- Decide whether organization status reads need an explicit row lock after measuring the real administration/login concurrency pattern; this slice intentionally matches the current transaction behavior.
|
||||
- Migrate self-service and administrative password mutation in a later bounded slice.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
@@ -1,85 +0,0 @@
|
||||
# Task: Implement Go current-session HTTP adapter
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-auth-me-http-8d6f3a21
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-auth-me-http-8d6f3a21-go-auth-me-http
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-me-8d6f3a21
|
||||
- Base commit: c8490775916c46141e06e3a86ea5bb76eb8c3f1d
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Freeze the current `GET /api/auth/me` response and transport behavior in a language-neutral contract consumed by TypeScript and Go tests.
|
||||
- Add a Go HTTP Identity Adapter that reassembles the legacy chunked Cookie, delegates authorization to the existing deep Identity Resolver, and returns the current public session projection.
|
||||
- Compose the Adapter into the runnable Go process for local/black-box verification while leaving Next.js, Ingress, Docker, ACK manifests, and production route ownership unchanged.
|
||||
- Keep login, logout, password mutation, authorization policy for other routes, Middleware replacement, and production traffic cutover outside this slice.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Use the external HTTP Interface and the existing `identity.Resolver.Resolve` Interface as the two agreed TDD seams; do not test private helper structure.
|
||||
- Preserve the current `/api/auth/me` anonymous behavior: invalid, absent, expired, stale, disabled, or unauthorized sessions return HTTP 200 with `authenticated: false`, not 401.
|
||||
- Preserve database/configuration failures as server failures rather than disguising them as anonymous sessions.
|
||||
- Reuse the exact 20-name Cookie reassembly contract and database-authoritative session refresh; do not parse raw Cookie claims in the HTTP Module.
|
||||
- Preserve `authRequired` and `authConfigured` semantics and the public user projection without exposing access tokens, token type, session version, or internal rejection reasons.
|
||||
- Preserve Next.js method behavior: `HEAD` executes the GET path without a response body, `OPTIONS` returns 204 with `Allow: GET, HEAD, OPTIONS`, and unsupported standard methods return an empty 405 without `Allow`.
|
||||
- Preserve the pinned Next.js parser's last-value-wins behavior for duplicate protected Cookie names, and treat reassembled values above the existing 60,000-character writer ceiling as anonymous before Resolver invocation.
|
||||
- Keep ACK-001 deploy truth and all production path routing unchanged; the Go route remains unrouted externally in this task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added `contracts/auth/current-session-v1.json` as the language-neutral v1
|
||||
contract for `/api/auth/me`: runtime auth configuration, method/status/header
|
||||
behavior, anonymous and database-refreshed public projections, sensitive
|
||||
session-field exclusion, and infrastructure-failure classification.
|
||||
- Added a TypeScript contract consumer over the real auth config and App Route
|
||||
`GET`, plus the pinned Next.js automatic method implementation for
|
||||
`HEAD`/`OPTIONS`/unsupported methods.
|
||||
- Added the Go `httpapi.NewAuthMeHandler` deep HTTP Module. It owns exact Cookie
|
||||
chunk reassembly, Next-compatible duplicate-name handling, the 60,000-byte
|
||||
reader guard, Identity Resolver error classification, method handling, and a
|
||||
whitelist-only public response projection.
|
||||
- Added an exact Go auth-config parser and application composition from
|
||||
environment -> PostgreSQL Adapter -> Identity Resolver -> auth/me Handler.
|
||||
Application tests prove a signed Cookie is refreshed from the persistence
|
||||
snapshot and cannot preserve forged role/profile claims or leak token/session
|
||||
metadata.
|
||||
- Kept the Next.js route, Middleware, Docker, Compose, ACK manifests, Worker,
|
||||
Secrets, and all production routing unchanged. The Go endpoint is runnable
|
||||
only on the separate local process until a later path-level cutover.
|
||||
|
||||
## Verification
|
||||
|
||||
- TDD RED: the Go HTTP tests initially failed to compile because
|
||||
`AuthState`, `SessionResolver`, and `NewAuthMeHandler` did not exist; the
|
||||
application tests then failed before auth config and route composition were
|
||||
implemented. Focused tests passed after each implementation slice.
|
||||
- `npm test -- --reporter=dot`: 37 files and 141 tests passed.
|
||||
- `npm run go:test`: all five Go packages passed.
|
||||
- `npm run go:vet`: passed.
|
||||
- `npm run go:build`: passed for `./cmd/zhinian-api`.
|
||||
- `npx tsc --noEmit --incremental false --pretty false`: passed after the
|
||||
concurrent `next build` process finished regenerating `.next/types`.
|
||||
- `npm run build`: Next.js 15.5.18 production build passed with all 33 pages.
|
||||
- `npm run deploy:check`: all 8 ACK manifest assertions passed.
|
||||
- `git diff --check`, `gofmt -l backend`, project-docs validation, task doc
|
||||
drift, and the forbidden production-routing diff check all passed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Add a local-account authorization snapshot Adapter if authenticated local-mode
|
||||
Go development is required; today a configured valid Cookie on the local
|
||||
backend fails with an explicit 500 rather than silently trusting claims.
|
||||
- Add real PostgreSQL/RDS and verified-CA transport integration coverage before
|
||||
any production auth route cutover.
|
||||
- Migrate login, logout, password mutation, Middleware enforcement, and other
|
||||
protected routes in later independently contract-tested slices.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Promote `contracts/auth/current-session-v1.json` as the current-session HTTP
|
||||
compatibility truth when the task is integrated.
|
||||
- Record that the Go application can serve `/api/auth/me` locally while ACK-001
|
||||
and all production route ownership remain with Next.js.
|
||||
@@ -1,73 +0,0 @@
|
||||
# Task: Implement Go identity authorization vertical slice
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-identity-vertical-c4e91a72
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-identity-vertical-c4e91a72-go-identity-vertical
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-identity-c4e91a72
|
||||
- Base commit: 716a8031b1f0b322470e180e45dea2fe12fdead3
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Add a language-neutral platform-session authorization matrix that fixes the per-request account, organization, role, client, and `sessionVersion` contract shared by TypeScript and Go.
|
||||
- Add a deep Go Identity Module whose external seam resolves a signed legacy Cookie into a database-refreshed current session or a typed unauthenticated rejection.
|
||||
- Add a PostgreSQL Adapter that loads the complete authorization snapshot in one parameterized account/organization query.
|
||||
- Keep login, password changes, HTTP identity routes, middleware replacement, Docker/ACK manifests, and production traffic ownership outside this slice.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Follow vertical red-green TDD at the existing signed-session/Identity seam and PostgreSQL Adapter seam.
|
||||
- Treat Cookie data only as authenticated input; database account role, profile, status, organization state, and session version are authoritative for every resolved request.
|
||||
- Preserve current legacy compatibility where an absent or zero `sessionVersion` is accepted, while any nonzero mismatch is rejected; the refreshed result always carries the current database version.
|
||||
- Require every non-super-admin account to belong to an active existing organization; allow an unbound super-admin as the current billing/administration model requires.
|
||||
- Collapse authentication denials for callers while retaining typed internal rejection reasons for tests and diagnostics; propagate database failures separately.
|
||||
- Do not expose or route a Go identity endpoint and do not change ACK-001 production behavior in this task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added `contracts/auth/platform-session-authorization-v1.json`, a language-neutral 14-case matrix covering database-authoritative claim refresh, platform-client enforcement, active/disabled accounts, exact platform roles, legacy missing/zero `sessionVersion`, nonzero version mismatch, rejection precedence, organization requirements, and super-admin organization compatibility.
|
||||
- Added the Go Identity `Resolver` as one deep external seam from a signed legacy Cookie to a database-refreshed `Session`. Authentication denials collapse through `ErrUnauthenticated` while retaining stable internal rejection reasons; persistence failures remain distinct and propagate to the caller.
|
||||
- Added a Go PostgreSQL authorization-snapshot Adapter that implements the Resolver's single persistence Interface with one explicit-column, parameterized `LEFT JOIN` over `public.platform_users` and `public.platform_organizations`. It deliberately returns disabled/missing organization state to the Identity Module instead of hiding policy in SQL.
|
||||
- Added the equivalent TypeScript authorization seam and PostgreSQL snapshot store, then changed `getOptionalAuthSession` to use them. PostgreSQL request revalidation now uses one joined query rather than separate account and organization reads; the local development path projects the same narrow snapshot without exposing password storage fields.
|
||||
- Closed the existing authorization gap that accepted non-super-admin accounts with no organization. All non-super-admin accounts now require a matching, active organization; an unbound super-admin remains valid.
|
||||
- Kept login, password changes, Middleware, Go identity HTTP routes, Docker/ACK manifests, Ingress paths, and production traffic ownership unchanged. The Go Resolver is implemented and tested but remains intentionally unrouted.
|
||||
|
||||
## Verification
|
||||
|
||||
- Vertical TDD RED evidence was captured independently before the Go Resolver, Go PostgreSQL Adapter, TypeScript authorization seam, and TypeScript snapshot store implementations existed. Intermediate RED assertions also exposed missing organization-admin claim reconstruction and local snapshot leakage before those paths reached GREEN.
|
||||
- `npm test -- --reporter=dot`: 36 test files and 135 tests passed, including both consumers of the shared authorization matrix and the PostgreSQL/local snapshot-store contract.
|
||||
- `npx tsc --noEmit --incremental false`: passed.
|
||||
- `npm run build`: Next.js 15.5.18 production build completed for all current routes; the pre-existing multiple-lockfile workspace-root warning remains.
|
||||
- `npm run go:test`: all five Go packages passed.
|
||||
- `npm run go:vet`: passed.
|
||||
- `npm run go:build`: built `cmd/zhinian-api` successfully through the repository's cross-platform runner.
|
||||
- `npm run deploy:check`: all 8 ACK manifest assertions passed, confirming that production routing and workload ownership were not changed.
|
||||
- `git diff --check` and `gofmt -d` over all changed Go files: passed with no output.
|
||||
- The independent Sol review found one cross-language composite-failure ordering mismatch. A fixture case was strengthened to combine an unknown database role with a nonzero version mismatch, producing the expected TypeScript RED (`invalid_role` versus `session_version_mismatch`); TypeScript was then aligned with Go so version mismatch has stable precedence. A second review caught that this temporarily removed standalone `invalid_role` coverage, so a redundant standalone version-mismatch case was converted to preserve both reasons while retaining all organization cases and the 14-case total. Both focused contracts and all verification above passed again.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Add the first Go current-user/authentication HTTP Adapter only after its response, 401/403/500 mapping, Cookie transport, and black-box parity contracts are frozen; this task does not claim `/api/auth/me` or another identity path.
|
||||
- Move or duplicate database-refreshed authorization at the routing boundary before any protected route cutover. The current Next.js Middleware still performs signed-Cookie-only gating, while server Route Handlers perform the authoritative database refresh.
|
||||
- Add a Go local-development authorization snapshot Adapter before expecting the unrouted Go process to serve identity flows with `ZHINIAN_DATA_BACKEND=local`.
|
||||
- Exercise the joined identity query against the production-like RDS role, verified-CA TLS, schema privileges, disabled accounts, deleted organizations, and concurrent account mutations before cutover.
|
||||
- Migrate login/logout/password and lockout mutation flows as separate vertical slices so session-version invalidation and single-writer ownership can be reviewed independently.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Target: `.project-docs/30-worklog/current-state.md`, `.project-docs/20-architecture/module-map.md`, and `.project-docs/20-architecture/data-flow.md`.
|
||||
Proposal: after integration, record the implemented but unrouted Go Identity Resolver, its single PostgreSQL authorization-snapshot seam, and the shared TypeScript/Go authorization contract.
|
||||
Evidence: the 14-case shared fixture, both language implementations, exact joined-query tests, and complete Node/Go/build/ACK verification in this task.
|
||||
Future impact: later HTTP slices can consume one current-session result instead of reimplementing Cookie parsing, account/organization lookup order, or role/session-version rules.
|
||||
Semantic conflicts: canonical documents still describe the Go backend as a foundation with no identity authorization slice; they should change only when this feature is integrated. ACK-001 and Next.js route ownership remain unchanged.
|
||||
Human confirmation required: no new architecture direction is required; promotion still belongs to the serialized Integration Gate.
|
||||
|
||||
- Target: `.project-docs/40-domain/business-rules.md`.
|
||||
Proposal: record that every active non-super-admin platform account must reference the same active organization returned by the authorization snapshot, while a super-admin may be unbound; missing/zero legacy session versions are temporarily accepted and refreshed, while nonzero mismatches revoke the session.
|
||||
Evidence: the shared authorization matrix and both TypeScript/Go Resolver contract suites.
|
||||
Future impact: account deletion, organization archival, role changes, session invalidation, and future authorization Adapters must preserve this rule.
|
||||
Semantic conflicts: this deliberately closes a prior TypeScript conditional gap and aligns runtime authorization with the existing account mutation/domain constraints.
|
||||
Human confirmation required: no; the task scope explicitly selected this security rule and no production route ownership changed.
|
||||
@@ -1,97 +0,0 @@
|
||||
# Task: Complete remaining Go backend modules
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-remaining-modules-7d3a9e42
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-remaining-modules-7d3a9e42-go-remaining-modules
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-remaining-7d3a9e42
|
||||
- Base commit: d0207fcebe6ea4fb3ba80dce8c012b3c2170de40
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Complete every ADR-003 Go backend module that remains after the foundation,
|
||||
database-refreshed identity, current-session HTTP, and password
|
||||
login/logout slices already present at the task base.
|
||||
- Freeze language-neutral compatibility contracts before each remaining
|
||||
vertical slice and keep the TypeScript implementation as an executable
|
||||
source-of-truth consumer until cutover.
|
||||
- Implement the remaining Identity and Administration behavior; Assets and
|
||||
storage/file serving; Billing and Usage; Jobs, providers, Webhooks, and the
|
||||
embedded WorkerLoop; and the remaining public/compatibility HTTP surface.
|
||||
- Compose all migrated routes into the separately runnable Go application and
|
||||
prove route-surface coverage without moving production traffic.
|
||||
- Keep production cutover, Next Route Handler deletion, Node Worker drain,
|
||||
Docker/ACK/Ingress ownership changes, and real RDS/OSS rollout outside this
|
||||
feature task.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Follow vertical red-green TDD at stable external HTTP Interfaces and deep
|
||||
domain/Adapter seams; do not create one shallow repository Interface per
|
||||
table.
|
||||
- Preserve current same-origin paths, method/status/JSON behavior, Cookie and
|
||||
tenant authorization, owner-scoped not-found behavior, idempotency, job
|
||||
state, wallet arithmetic, storage metadata, provider, and Webhook semantics.
|
||||
- Keep PostgreSQL as the production source of relational truth and continue
|
||||
using `claim_generation_jobs` and `billing_post_wallet_entry` for
|
||||
cross-instance concurrency. Never replace them with process-local locks.
|
||||
- Keep one owner for external side effects and every write path. The Go
|
||||
implementation remains locally runnable and contract-tested but unrouted in
|
||||
production until a later explicit cutover.
|
||||
- Keep Alibaba Cloud OSS behind an object-storage Adapter and retain an
|
||||
explicit local-development Adapter; do not claim horizontal production
|
||||
safety until real OSS and RDS/TLS checks pass.
|
||||
- Preserve the currently deployed ACK-001 Web/HTTP-polling-Worker topology and
|
||||
all production Secrets/manifests during this implementation task.
|
||||
- Work only in the owned worktree and task record; canonical project memory is
|
||||
reserved for a serialized Integration Gate.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Completed in the feature worktree. Implemented and composed the remaining Go
|
||||
modules: administration and organization lifecycle, assets and hardened
|
||||
storage/remote fetch, billing ledger/catalog/settlement, usage reporting,
|
||||
jobs/providers/webhooks/worker loop, templates/prompt, settings/logging,
|
||||
public and compatibility HTTP routes, localstore adapters, PostgreSQL
|
||||
adapters, and lifecycle fencing migration 0002. Added language-neutral
|
||||
contracts and executable TypeScript/Go consumers while preserving the
|
||||
existing Next production ownership and deployment topology.
|
||||
|
||||
- Added final lifecycle hardening for streamed HTTP event logging, unique
|
||||
worker lease tokens and CAS fencing, commit-outcome reconciliation, retry
|
||||
recovery handles, readiness checks for lifecycle columns, mock output
|
||||
registration, usage filter options, public webhook/priority validation, and
|
||||
a single settings/billing-account source.
|
||||
|
||||
## Verification
|
||||
|
||||
- `CGO_ENABLED=0 go test -count=1 ./...` — PASS
|
||||
- `CGO_ENABLED=0 go test -race -count=1 ./internal/...` (all migrated
|
||||
packages) — PASS
|
||||
- `npm run go:vet` — PASS
|
||||
- `npm run go:build` — PASS
|
||||
- `npm test -- --run` — 57 files / 172 tests PASS
|
||||
- `npx tsc --noEmit --incremental false` — PASS
|
||||
- `npm run build` — PASS (Next build)
|
||||
- `node scripts/check-ack-manifests.mjs` and `npm run deploy:check` — PASS
|
||||
- `git diff --check`, `gofmt` cleanliness, and production boundary diff
|
||||
checks — PASS
|
||||
- Independent `sol_reviewer` final review — PASS; no blocking findings.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Validate the complete backend against migrated non-production RDS with the
|
||||
real application role and verified-CA TLS before production cutover.
|
||||
- Validate OSS compatibility, provider credentials, external Webhooks, Worker
|
||||
drain/recovery, and rollout/rollback against production-like infrastructure.
|
||||
- Keep Go unrouted until the explicit production cutover review; do not delete
|
||||
the Next handlers or change Docker/ACK/Ingress ownership in this task.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Preserve the new Go module map and contract fixtures as candidates for the
|
||||
next serialized Integration Gate to promote into canonical architecture
|
||||
memory. This feature task does not modify shared canonical documents.
|
||||
Reference in New Issue
Block a user