Files
mygo/docs/server/roadmap.md
T
ld a18f96912d feat(repository): refactor query/mutation ports with capability-safe
interfaces

- refactor: split UserRepository into AuthUserRepository and
  AdminUserRepository capabilities
- refactor: split SessionRepository into AuthSessionRepository and
  repository-owned CLI/admin methods
- refactor: replace generic Repository Update/Delete with
  operation-specific params and ownership predicates
- refactor: replace CredentialRepository generic CRUD with
  passkey-specific methods
- refactor: replace FileRepository generic Create/Update/Delete with
  UploadedFileParams, DirectoryParams, and owned soft-delete
- refactor: remove repository fields from WebApp struct; repositories
  are now composition-time wiring only
- feat: add domain error kinds ErrParentNotFound, ErrParentNotDir,
  ErrDirectoryNotEmpty, ErrInvalidMove
- feat: add CredentialTypeAppPasskey constant
- feat: add testutil.SetUserAdmin for test fixture setup that bypasses
  production service ports
- test: add architecture test banning GORM Save in repository package
- test: add capability interface contract tests ensuring each service
  receives the minimal interface
- test: add blockingStorage helper for concurrent promotion tests
- test: add preserved DSN parameter test for sqliteImmediateDSN
- docs: update architecture decisions with repository write rules and
  capability separation
- docs: update roadmap to clarify atomic single-use refresh sessions
- docs: add -race test target to development docs
2026-07-16 12:24:36 +08:00

2.1 KiB

Roadmap

v0

Feature Status Notes
CLI config management Viper YAML + env + flags, typed Duration config
JWT authentication access + refresh tokens, atomic single-use refresh sessions, app passkey support
Web API foundation WebApp composition, Gin router, graceful shutdown, GET /api/v1/version
File upload/download/manage APIs 🛠 WIP REST API via Gin
Admin endpoints 🛠 WIP user service boundary in place for superusers
WebDAV 🛠 WIP future v0 or v1

Implementation Tasks

Package-level implementation order (each task includes unit tests):

  1. internal/config — Viper loader, config struct
  2. internal/app — runtime dependency container
  3. internal/model — domain types, error codes
  4. internal/api — protocol-neutral error kind to REST response mapping
  5. internal/auth — JWT utils
  6. internal/storage — backend interface + local fs with staged upload promotion
  7. internal/repository — command-scoped mutation capabilities + GORM/SQLite transaction protocol
  8. internal/service — auth, file, admin services
  9. internal/middleware — logger, cors, auth (auth done; principal boundary enforced)
  10. internal/handler — auth, account, file, admin handlers 🛠 (HTTP DTO mapping in place)
  11. internal/server — Gin router, route registration, graceful shutdown
  12. cmd/serve.go, cmd/config.go, cmd/status.go (serve done)
  13. Integration tests 🛠 (authenticated register → login → upload → list → download route flow covered with a small file; authentication bypass, invalid token, concealed cross-user resources, strict delete, atomic refresh consumption, and file hierarchy race boundaries covered)
  14. Architecture boundary tests

Future

Feature Status Notes
Image server plan thumbnail generation
Pastebin & code snippets plan in sharing context
S3 storage backend plan new storage impl
Nextcloud-compatible API plan new handler layer on existing services