mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
* docs(b3-0): record PR #1448 = d383d8c7 in the evidence block
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* docs(b3-1): inventory of what the 85 auth tests already pin, per route and property
Route x property table in the B3-1 evidence block: the existing test for
each row, or GAP and the characterization row that fills it (next commit).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* test(b3-1): auth characterization — fill the inventory gaps against today's behaviour
12 tests / 44 table rows over the mounted auth router, no mocks: read
faults via ALTER TABLE RENAME, write faults via RAISE(FAIL) triggers.
Three rows pin defects as-is with `// known:` and ledger entries
OC-0376 (register 500 after the account commit), OC-0377 (verify-totp
maps a DB error to 401), OC-0378 (challenge consumed before the session
insert); fixed in B3-9, not here. Mutation spot-check: 401->500 in
totpChallengeSecret, 500->401 in loginAuthenticate, 503->401 in
AuthMiddleware each turned the rows that name them RED.
The nine watched ledger-count claims move 56 open / 375 -> 59 / 378.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* docs(b3-1): coverage before/after, row count and pre-squash SHAs in the evidence block
auth_handler.go 78.0% -> 90.2%, totp_handler.go 78.8% -> 91.1% (statements).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* fix(b3-1): Codex P2s — guaranteed-invalid TOTP code, B3-9 scope, hp-0 breakdown
- wrongTOTPCode derives a code outside the three accepted steps instead of
assuming "000000" is invalid (1-in-333k flake in the per-user cap row)
- OC-0376/0377/0378 added to B3-9 in the step table and its section
- hp-0 open-record breakdown recomputed for the 59-open ledger
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* docs(b3-1): Codex round 2 — OC-0378 fix must keep the challenge claim atomic; coverage command syntax
- OC-0378 suggestedFix: Consume first, restore/re-issue on session failure;
issuing before Consume lets two concurrent verifies both create sessions
- evidence block: go test -coverprofile=cover.out ./api/ (flag needs a file)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
* fix(b3-1): Codex round 3 — exclude the +2 TOTP step, sequence auth B3-9 after B3-2, keep the replay claim in OC-0378's remedy
- wrongTOTPCode excludes {-1,0,+1,+2}: the verifier samples the clock after
the helper, so a step boundary in between shifts its window to {0,+1,+2}
- B3-9 "Parallel with": OC-0345/0346 any; OC-0323 with B3-8; OC-0376..0378
after B3-2 (matches the safe-parallelism rule and the section text)
- OC-0378 suggestedFix: a restored challenge must carry the accepted
verification or roll back the MarkUsed claim, or the retry is a replay
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rg9QQWVN3E5UUgBD2dydtu
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Plan index
Closes G-04. Historical plans are kept at their existing paths — links from audits and commit messages must keep resolving — so status is recorded here rather than by moving or rewriting them.
A plan's own header can drift out of date after its table is updated in place. Where that has happened it is called out below, and this index is the authority.
Active — these drive current work
| Plan | State |
|---|---|
| beta-product-requirements-2026-08-23 | Approved beta scope, frozen. 57 BPR-* requirements. |
| repo-health-roadmap-2026-08-23 | Phase order and gates, B0–B10. B0, B1 and B2 complete (HP-0, HP-1 and HP-2 all accepted); B3 is next — opens with the layout-refactor first slice. B3–B10 not started. Amended 2026-08-28: dated lines in B3–B10, a "Phase execution pattern" section, and a truthful status header. Amended 2026-08-29: B3/B7/B9 lines binding the layout-refactor supplement below; current slice updated for B2-2. |
| repo-health-issue-register-2026-08-23 | 88 planning rows. Public-safe; not a replacement for the ledger. |
| beta-requirements-traceability-2026-08-23 | Requirement → phase → evidence map. No row is release-qualified. |
| b0-baseline-2026-08-25 | Supersedes the roadmap's "current evidence snapshot." B0 measurements and dispositions. |
| b1-repository-foundation-2026-08-25 | B1-0 through B1-8 all done. B1 execution plan. Re-verifies every RL-* claim against HEAD; several are refuted. |
| hp-0-scorecard-2026-08-25 | HP-0 accepted 2026-08-25. The single baseline-acceptance artifact. Part-closes R-08. |
| hp-1-scorecard-2026-08-27 | HP-1 accepted 2026-08-27. Structural-diff proofs for the flatten and module rename, plus the B1 exit gate. |
| b2-protocol-trust-compat-2026-08-28 | B2 complete — HP-2 accepted 2026-08-29. B2-0, B2-1, B2-8 done 2026-08-28; B2-2 (B2-3/B2-4 folded in), B2-5, B2-6, B2-7, B2-9 done 2026-08-29. Scorecard below. |
| hp-2-scorecard-2026-08-29 | HP-2 accepted 2026-08-29. Seven questions answered with commands; B2 exit gate, nine conditions met (1 at the slim epoch scope, 4 with one E2EE gap disclaimed). Owner follow-ups that do not gate B3: BPR-051 reader line, SEC-01/SEC-04 advisory IDs. |
| b3-server-architecture-guardrails-2026-08-29 | B3 in progress from 2026-08-29. Execution plan: B3-0 inventory → B3-1/B3-2 auth slice → HP-3 → lifecycle, hub options, ws split, families; guardrails and the alpha dataset beside the slice. B3-0 (inventory + db-import-boundary rule) in review 2026-08-29. |
| audit-2026-08-19-remediation | Phases 1–6 done 2026-08-20; phase 7 pending. Its header still reads "in progress 2026-08-19" — stale; the phase table is correct. |
Partially implemented
| Plan | State |
|---|---|
| bug-detection-improvements | Tier 1a (make fuzz) and Tier 2 (five ESLint rules) shipped 2026-08-08. Remaining tiers open. |
Design only — not implemented
| Plan | State |
|---|---|
| developer-experience-layout-refactor-2026-08-29 | Draft, not started. Implementation supplement bound into the roadmap 2026-08-29: B3 workstream 17 (Phases 1–3, auth slice → HP-3), B7 workstream 16 (Phases 4–6), B9 workstream 11 (CSS split). Nothing starts before HP-2. |
| slash-commands | Design only. No implementation; not in beta scope. |
Shipped — kept for history, do not use as current status
| Plan | Shipped |
|---|---|
| audit-2026-07-19-decisions | Decisions recorded; greenlit items implemented through 2026-07-23. |
| channel-visibility-unification | 2026-07-20 (D9), re-verified 2026-08-04. |
| v2-dispatch-migration | 2026-07-20 (D10), re-verified 2026-08-04. |
| tauri-capability-narrowing | 2026-07-20, re-verified 2026-08-04. |
| http-tofu-proxy | 2026-07-19, re-verified 2026-08-04. |
| permission-middleware-consolidation | 2026-07-23 (D13), re-verified 2026-08-04. |
| security-hardening-remediation | 2026-07-23, re-confirmed 2026-08-04. |
| security-scan-2026-07-22-remediation | All 8 findings F1–F8 closed, verified 2026-08-04. |
| sqlc-adoption | Shipped, verified 2026-08-04. |
| discord-parity | Phases 1–6 complete, verified 2026-08-04. Phase 1's table reads as a gap list but every row shipped. |
| infrastructure-roadmap | 2026-08-15, with two recorded leftovers (TOTP persister seam; published capacity numbers). |
Where status actually lives
Planning documents are not trackers. Do not read a defect count out of one.
| Concern | Source of truth |
|---|---|
| Defect status | .superpowers/findings-ledger.json (FINDINGS.md is rendered from it) |
| Security-sensitive defects | Private GitHub Security Advisories |
| Product scope | beta-product-requirements-2026-08-23 |
| Phase order and gates | repo-health-roadmap-2026-08-23 |
| Current measured baseline | b0-baseline-2026-08-25 |
Ledger at 2026-08-29: 315 fixed / 59 open / 3 declined / 1 duplicate = 378.
All 38 open records still resolved to a live file:line at
5cc0888964e26276d1aca145e83270a2c1b9febd when that sweep was run — it was a
manual pass, not something a command reproduces. What the tooling does check:
node .superpowers/render-ledger.mjs --check # the ledger's schema is valid
node scripts/check-doc-counts.mjs # documents agree with it, and
# FINDINGS.md is not stale
Adding a plan
- Give it a
**Status:**line with a date, and update that line — not only the phase table — when it changes. - Add a row here. A plan absent from this index has no recorded status.
- Mark a superseded plan here; leave it at its path so existing links resolve.