diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index 115460d..01f14cb 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -30,7 +30,7 @@ Make FamilySync configurable, administrable, and maintainable for real multi-mem - [x] **Phase 9: Faster Write-Back** - Event-driven outbox drain so edits land in ~1-2s instead of ~15s, preserving every outbox durability guarantee (completed 2026-06-12) - [x] **Phase 10: Admin Role & Settings** - DB foundation (is_admin / reminder_lead / app_config) + role-gated admin UI to rotate app passwords and designate the shared calendar (completed 2026-06-13) - [x] **Phase 11: Per-Event Reminders** - Reminder selector on the event form (incl. "None") serialized as VALARM, with a variable-lead scheduler that honors each event's choice (completed 2026-06-14) -- [ ] **Phase 12: Initial Setup Wizard** - First-run validated bootstrap of env/VAPID/DB/OIDC + first app password, reusing the admin route surface +- [x] **Phase 12: Initial Setup Wizard** - First-run validated bootstrap of env/VAPID/DB/OIDC + first app password, reusing the admin route surface (completed 2026-06-16) - [x] **Phase 13: Real Lint Gate (ESLint)** - Wire ESLint flat config (typescript-eslint + React) across both apps so the Phase 8 CI lint slot actually fails on violations instead of no-op'ing (completed 2026-06-12) - [x] **Phase 14: Desktop E2E Coverage** - Add a Desktop Chrome Playwright profile + make the mobile-authored specs desktop-safe so the Phase 8 regression gate validates desktop, not just mobile (completed 2026-06-12) - [x] **Phase 15: Doc-Only CI Skip + Markdown Lint** - Aggregate-gate the slow api/harness CI jobs so doc-only PRs to main merge without running them (no branch-protection deadlock), and add markdownlint to `fast-checks` so docs get a fast format+lint gate (promoted from backlog 999.17) (completed 2026-06-12) @@ -268,8 +268,8 @@ Plans: **Wave 4 — Gap closure** *(UAT 12-UAT.md gaps 1-6; 06+07 parallel, 05 blocked on 06)* - [x] 12-06-PLAN.md — Backend: validate/vapid asserts wizard key == env VAPID_PUBLIC_KEY (gap 2) + status exposes non-secret DB name (gap 3) (SETUP-02) -- [ ] 12-07-PLAN.md — App.tsx: reverse-gate /setup post-completion (gap 5) + reconcile ['me'] so calendar banner clears after wizard (gap 6) (SETUP-01/04) -- [ ] 12-05-PLAN.md — SetupPage: drop DB-vs-env aside (gap 1) + read-only DB-name field (gap 3) + persist fields across Back (gap 4) (SETUP-01) — depends on 12-06 +- [x] 12-07-PLAN.md — App.tsx: reverse-gate /setup post-completion (gap 5) + reconcile ['me'] so calendar banner clears after wizard (gap 6) (SETUP-01/04) +- [x] 12-05-PLAN.md — SetupPage: drop DB-vs-env aside (gap 1) + read-only DB-name field (gap 3) + persist fields across Back (gap 4) (SETUP-01) — depends on 12-06 **UI hint**: yes @@ -430,7 +430,7 @@ At ≤767px (`window.matchMedia('(max-width: 767px)')` in `apps/pwa/src/App.tsx` | 9. Faster Write-Back | v1.1 | 2/2 | Complete | 2026-06-12 | | 10. Admin Role & Settings | v1.1 | 4/4 | Complete | 2026-06-13 | | 11. Per-Event Reminders | v1.1 | 5/5 | Complete | 2026-06-14 | -| 12. Initial Setup Wizard | v1.1 | 5/7 | In Progress| | +| 12. Initial Setup Wizard | v1.1 | 7/7 | Complete | 2026-06-16 | | 13. Real Lint Gate (ESLint) | v1.1 | 3/3 | Complete | 2026-06-12 | | 14. Desktop E2E Coverage | v1.1 | 1/1 | Complete | 2026-06-12 | | 15. Doc-Only CI Skip + MD Lint | v1.1 | 3/3 | Complete | 2026-06-12 | @@ -444,7 +444,7 @@ At ≤767px (`window.matchMedia('(max-width: 767px)')` in `apps/pwa/src/App.tsx` **Goal:** [Captured for future planning] Abstract the calendar backend behind a provider interface so Fastmail/CalDAV is one implementation among potentially many. Shipping with a single provider is fine, but the broker, sync, and event-expansion layers should be structured so additional providers (e.g. other CalDAV hosts, Google Calendar, generic ICS feeds) can be added without rework. Captures the "provider" seam as an explicit architectural concern. **Requirements:** TBD -**Plans:** 5/5 plans complete +**Plans:** 7/7 plans complete Plans: @@ -687,10 +687,12 @@ Plans: **Provenance:** Deferred from the Phase 12 discussion (2026-06-15) — see `.planning/phases/12-initial-setup-wizard/12-CONTEXT.md` §Deferred Ideas. The operator runs FamilySync this way themselves and wants no-OIDC operation as a first-class mode. **Open questions for discuss/spec:** + - Password hashing/storage choice (e.g. argon2id/bcrypt) and how it sits alongside the env-only secret kernel from Phase 12. - How local login coexists with `oidcAuthMiddleware` ordering in `apps/api/src/index.ts` (route-level auth strategy selection vs. a mode flag in `app_config`). - The OIDC-link flow: claiming an existing local user into an `oidc_iss+oidc_sub` identity without violating the D-10 "identity is OIDC, never email" rule. - Whether "local mode vs OIDC mode" is a deploy-time switch or both can be live simultaneously. Plans: + - [ ] TBD (run /gsd-plan-phase 19 to break down) diff --git a/.planning/STATE.md b/.planning/STATE.md index 337c0e5..feb8efe 100644 --- a/.planning/STATE.md +++ b/.planning/STATE.md @@ -3,14 +3,14 @@ gsd_state_version: 1.0 milestone: v1.1 milestone_name: Operability & Polish status: executing -stopped_at: Completed 12-06-PLAN.md (UAT gaps 2+3 closed) -last_updated: "2026-06-16T01:15:09.647Z" +stopped_at: Phase 12 (initial-setup-wizard) complete — UAT re-verified, all 6 gaps closed; ready to execute Phase 13 +last_updated: "2026-06-16T20:16:24.590Z" last_activity: 2026-06-16 progress: total_phases: 24 completed_phases: 10 - total_plans: 43 - completed_plans: 41 + total_plans: 44 + completed_plans: 43 percent: 42 --- @@ -18,15 +18,15 @@ progress: ## Project Reference -See: .planning/PROJECT.md (updated 2026-06-10) +See: .planning/PROJECT.md (updated 2026-06-16) **Core value:** One color-coded family calendar (shared + personal) and shared lists from a single low-friction PWA — cross-ecosystem, no app store -**Current focus:** Phase 12 — initial-setup-wizard +**Current focus:** Phase 13 — real-lint-gate-eslint ## Current Position -Phase: 12 (initial-setup-wizard) — EXECUTING -Plan: 2 of 7 +Phase: 13 +Plan: Not started Status: Ready to execute Last activity: 2026-06-16 @@ -38,7 +38,7 @@ Done 2026-06-12. Gitea branch protection on `main` now requires EXACTLY `CI / fa **Velocity:** -- Total plans completed: 48 +- Total plans completed: 55 - Average duration: - - Total execution time: 0 hours @@ -56,6 +56,7 @@ Done 2026-06-12. Gitea branch protection on `main` now requires EXACTLY `CI / fa | 16 | 6 | - | - | | 10 | 4 | - | - | | 11 | 5 | - | - | +| 12 | 7 | - | - | **Recent Trend:** diff --git a/.planning/phases/12-initial-setup-wizard/12-UAT.diagnosed.md b/.planning/phases/12-initial-setup-wizard/12-UAT.diagnosed.md index 8802a41..ec1e7a4 100644 --- a/.planning/phases/12-initial-setup-wizard/12-UAT.diagnosed.md +++ b/.planning/phases/12-initial-setup-wizard/12-UAT.diagnosed.md @@ -1,6 +1,7 @@ --- -status: diagnosed +status: superseded phase: 12-initial-setup-wizard +note: ARCHIVED historical record of the original diagnosed UAT run. All 6 gaps closed and re-verified in 12-UAT.md (status complete). Kept for traceability only — not active debt. source: [12-VERIFICATION.md] started: 2026-06-15T19:22:00Z updated: 2026-06-15T19:55:00Z