a18f96912d
interfaces - refactor: split UserRepository into AuthUserRepository and AdminUserRepository capabilities - refactor: split SessionRepository into AuthSessionRepository and repository-owned CLI/admin methods - refactor: replace generic Repository Update/Delete with operation-specific params and ownership predicates - refactor: replace CredentialRepository generic CRUD with passkey-specific methods - refactor: replace FileRepository generic Create/Update/Delete with UploadedFileParams, DirectoryParams, and owned soft-delete - refactor: remove repository fields from WebApp struct; repositories are now composition-time wiring only - feat: add domain error kinds ErrParentNotFound, ErrParentNotDir, ErrDirectoryNotEmpty, ErrInvalidMove - feat: add CredentialTypeAppPasskey constant - feat: add testutil.SetUserAdmin for test fixture setup that bypasses production service ports - test: add architecture test banning GORM Save in repository package - test: add capability interface contract tests ensuring each service receives the minimal interface - test: add blockingStorage helper for concurrent promotion tests - test: add preserved DSN parameter test for sqliteImmediateDSN - docs: update architecture decisions with repository write rules and capability separation - docs: update roadmap to clarify atomic single-use refresh sessions - docs: add -race test target to development docs
2.1 KiB
2.1 KiB
Roadmap
v0
| Feature | Status | Notes |
|---|---|---|
| CLI config management | ✅ | Viper YAML + env + flags, typed Duration config |
| JWT authentication | ✅ | access + refresh tokens, atomic single-use refresh sessions, app passkey support |
| Web API foundation | ✅ | WebApp composition, Gin router, graceful shutdown, GET /api/v1/version |
| File upload/download/manage APIs | 🛠 WIP | REST API via Gin |
| Admin endpoints | 🛠 WIP | user service boundary in place for superusers |
| WebDAV | 🛠 WIP | future v0 or v1 |
Implementation Tasks
Package-level implementation order (each task includes unit tests):
internal/config— Viper loader, config struct ✅internal/app— runtime dependency container ✅internal/model— domain types, error codes ✅internal/api— protocol-neutral error kind to REST response mapping ✅internal/auth— JWT utils ✅internal/storage— backend interface + local fs with staged upload promotioninternal/repository— command-scoped mutation capabilities + GORM/SQLite transaction protocol ✅internal/service— auth, file, admin services ✅internal/middleware— logger, cors, auth ✅ (auth done; principal boundary enforced)internal/handler— auth, account, file, admin handlers 🛠 (HTTP DTO mapping in place)internal/server— Gin router, route registration, graceful shutdown ✅cmd/serve.go,cmd/config.go,cmd/status.go✅ (serve done)- Integration tests 🛠 (authenticated register → login → upload → list → download route flow covered with a small file; authentication bypass, invalid token, concealed cross-user resources, strict delete, atomic refresh consumption, and file hierarchy race boundaries covered)
- Architecture boundary tests ✅
Future
| Feature | Status | Notes |
|---|---|---|
| Image server | ⬜ plan | thumbnail generation |
| Pastebin & code snippets | ⬜ plan | in sharing context |
| S3 storage backend | ⬜ plan | new storage impl |
| Nextcloud-compatible API | ⬜ plan | new handler layer on existing services |