Files
familysync/.planning/phases/03-event-write-back-pwa-install/.continue-here.md
T

5.4 KiB

context, phase, task, total_tasks, status, last_updated
context phase task total_tasks status last_updated
phase 03-event-write-back-pwa-install 1 3 in_progress 2026-06-06T01:47:16.059Z

<current_state> Phase 03 gap-closure execution is complete — all four gap plans (03-09, 03-12, 03-10, 03-11) executed in dependency order, merged to gsd/v1.0-milestone, with 92 API + 126 PWA tests green and both tsc --noEmit clean. Working tree is clean.

Work then shifted to an operational task: spin up the Docker stack for newt/Pangolin external exposure. This is paused mid-investigation, awaiting two decisions from the user (see Human Actions). The user installed newt into WSL2 and wants to map the stack's ports. </current_state>

<completed_work>

Gap-closure plans (all merged, all SUMMARY.md committed):

  • 03-09: Route-layer reachability — zod title/start/end contract (CR-01) + real OIDC iss/subusers.id via upsertUser (CR-06). merge 578315c.
  • 03-12: EventForm edit/a11y — WR-03 (blank/recurrence edit), WR-05 (zone-consistent dates), WR-07 (focus trap), IN-03/04. merge 1fc56f4.
  • 03-10: Outbox real VEVENT dispatch — CR-02 (buildVeventString wired), CR-03 (fail-closed creds), WR-01 (backoff index), WR-04 (all-day DTEND+1), WR-08, IN-01. merge 416e813.
  • 03-11: Outbox durability — CR-04 (create-before-delete gating), CR-05 (drain concurrency guard), WR-02 (etag re-read). merge 0e4a263.

Review-finding coverage: 16/19 closed — all 6 critical (CR) resolved. STATE.md + ROADMAP.md updated and committed (b3eff3c). </completed_work>

<remaining_work>

Phase 03:

  • 03-08 — Gate 2 live verification (real Authelia OIDC over Pangolin + iOS standalone install + end-to-end Fastmail write round-trips). Human/device checkpoint — NOT a gap plan, cannot be driven by playwright-cli. This is the only incomplete plan; phase stays "In Progress" until it passes.
  • Deferred (non-blocking, not scoped into any gap plan): WR-06 (N+1 fetchCalendars perf), IN-02 (resolveDefaultView SSR-guard nit), IN-05 (terminal outbox rows never pruned).

Operational (the paused task):

  • Bring up the Docker stack for newt exposure once the two decisions below are made. </remaining_work>

<decisions_made>

  • Executed Phase 03 with --gaps-only; 03-08 intentionally excluded (human/device Gate 2).
  • Left WR-06 / IN-02 / IN-05 open — non-critical; all critical findings closed. </decisions_made>
- Docker bring-up paused pending two user decisions (auth mode + PWA serving). - `OIDC_ISSUER` and `OIDC_CLIENT_SECRET` are **empty** in `.env` → the production/real-OIDC path cannot run yet. - No PWA build in `apps/api/public` → API serves nothing at `/` (root 404s); `/health` and `/api/*` work.

Required Reading (in order)

  1. docker-compose.yml + docker-compose.dev.yml — stack definition. Base = production target (OIDC unconditional); dev override = dev target, NODE_ENV=development, exposes mariadb:3306 + redis:6379.
  2. apps/api/src/index.ts (lines ~15-61) — devBypassActive logic (NODE_ENV!='production' && DEV_AUTH_BYPASS==='true') and the serveStatic('./public') PWA-serving + catch-all.
  3. apps/api/Dockerfile — note: production stage does NOT build the PWA into ./public; comment says PWA "built and served separately".
  4. .planning/HANDOFF.json — machine-readable mirror of this state.

Critical Anti-Patterns

None discovered through failure this session. The "Exited (255)" on api/redis was a WSL/daemon stop 12h ago, NOT a crash — the api boots cleanly on :3000 (logs show "FamilySync API running on http://localhost:3000", only a harmless serveStatic: root './public' not found warning). Do not chase it as a bug.

Infrastructure State

  • familysync-mariadb-1: Up (healthy), 0.0.0.0:3306->3306.
  • familysync-api-1: Exited (255) — stale from WSL stop, not a crash. Boots fine when restarted.
  • familysync-redis-1: Exited (255) — same; present-but-unused until Phase 4.
  • Docker 29.3.1, Compose v5.1.1.
  • newt installed in WSL2 (per user) for Pangolin tunnel; the ports it maps are unconfirmed from the repo side.

Human Actions Pending (blocking the Docker bring-up)

  1. Auth mode — dev-bypass (DEV_AUTH_BYPASS=true + dev compose, works immediately, OIDC skipped) vs real OIDC (fill OIDC_ISSUER/OIDC_CLIENT_SECRET for the actual 03-08 Gate 2 login over Pangolin).
  2. PWA serving — build PWA into apps/api/public (single port :3000 for newt) vs vite dev on :5173 (two ports) vs API-only for now.
  3. (non-blocking) Confirm which ports the Pangolin/newt config actually maps.
Mid-flow when paused: I had just run `AskUserQuestion` with the two decisions above and the user interrupted to `/gsd-pause-work` instead of answering. Nothing was started/changed for the Docker task — purely investigation. The gap-closure work is done and safe.

<next_action> Ask the user the two pending decisions (auth mode + PWA serving). Then bring up the stack:

  • Dev-bypass path: ensure DEV_AUTH_BYPASS=true in .env, then docker compose -f docker-compose.yml -f docker-compose.dev.yml up -d --build. If serving the PWA via API, first pnpm --filter @familysync/pwa build and place output in apps/api/public; otherwise run pnpm --filter @familysync/pwa dev on :5173.
  • Real-OIDC path: wait for the user to fill OIDC_ISSUER/OIDC_CLIENT_SECRET, then docker compose up -d --build (production), and build the PWA into apps/api/public so the root URL serves. </next_action>