test(release): complete local action matrix
CI and Deploy / test (pull_request) Successful in 5m12s
CI and Deploy / deploy (pull_request) Has been skipped

This commit is contained in:
cesnimda
2026-08-15 18:16:00 +02:00
parent a25c31b93a
commit 0d487123af
9 changed files with 189 additions and 38 deletions
+7 -6
View File
@@ -2,17 +2,17 @@
Updated: 2026-08-15
- **Overall programme status:** Active. Seven packages are locally verified; twenty-four are implemented with verification incomplete; VER-001 is in progress. The prioritized admin-only version indicator, JOBS-002 workspace, scoped accessibility pass and honest Free/Pro product surfaces are implemented on the release branch; remote and production verification remain.
- **Current work package:** `VER-001` — complete application action matrix and regression pass (`IN PROGRESS`). Reconcile the matrix against the current tree, run every local gate and classify external checks without overstating them.
- **Overall programme status:** Active. Eight packages are locally verified; twenty-four are implemented with verification incomplete; SEC-009 is in progress. The prioritized admin-only version indicator and every immediate repository/browser item are implemented on the release branch; remote and production verification remain.
- **Current work package:** `SEC-009` — complete readable export and account deletion lifecycle (`IN PROGRESS`). Proceed with owner inventory and a disabled/dark repository launch while retention/restore policy continues to block production activation.
- **Completed work packages:** None are `DONE`; all repository security/AI packages still have applicable browser, provider and/or production gates.
- **Locally verified work:** SEC-001, SEC-002, SEC-003, SEC-005A, CORE-001, PROD-002 and DEP-001 (`VERIFIED LOCALLY`).
- **Locally verified work:** SEC-001, SEC-002, SEC-003, SEC-005A, CORE-001, PROD-002, DEP-001 and VER-001 (`VERIFIED LOCALLY`).
- **Implemented, verification incomplete:** SEC-004, SEC-005B, SEC-008, CORE-002, BG-001, OPS-001A/B/C, POL-001/002, AI-001/002/003/004, UX-001/002/003, QA-001, CAREER-001/002, MAIL-001, JOBS-001/002 and PRODUCT-001 (`IMPLEMENTED — NOT VERIFIED`). Their safe repository/browser scope is implemented; production/native-device/provider gates remain where recorded.
- **Production-verified work:** None.
- **Blocked work:** SEC-006 parser upgrades remain outside the scoped frontend advisory permission; PROD-001/003/004 and REL-001 require documented production access and unfinished dependencies. Real provider, SMTP/MariaDB and production environments are unavailable; DEP-001 awaits approved merge/live verification. The in-app browser is available for local UI checks.
- **Deferred work:** None. Conditional multi-replica coordination, model deletion, realtime operation delivery and unrelated production changes remain outside current packages.
- **Immediate order:** VER-001; tracking/blocker reconciliation. Admin version (`a6cffe0`), Career lossless persistence (`f0b9b22`), CV contact contrast (`3b86ea2`), JOBS-002 (`deed948`), accessibility (`a7c2549`) and PRODUCT-001 repository/browser scope are locally complete. External-only work remains skipped, not allowed to stall this queue.
- **Status counts:** 7 `VERIFIED LOCALLY`; 24 `IMPLEMENTED — NOT VERIFIED`; 1 `IN PROGRESS`; 2 `NOT STARTED`; 5 `BLOCKED`; 0 `DONE`; 0 `DEFERRED`.
- **Test status:** backend 647/647 remains current; PRODUCT policy/billing slice 30/30; frontend 57/57 suites and 232/232 tests; optimized production build/TypeScript pass; Playwright 8/8. Chromium now also proves exactly two honest public plans, explicit light/dark at 375/768/1440, no retired commercial claims, no overflow and keyboard plan actions. The application workspace and responsive public-CV evidence remains current. CV renderer/settings 25/25, AI sidecar 22/22 and npm audit 0 evidence remain current. Historical JT-019 and Jest force-exit/open-handle behavior remain recorded.
- **Immediate order:** SEC-009 owner inventory/export first, then its disabled deletion lifecycle. The eight-item immediate queue is complete locally: admin version (`a6cffe0`), Career persistence (`f0b9b22`), CV contrast (`3b86ea2`), JOBS-002 (`deed948`), accessibility (`a7c2549`), PRODUCT-001 (`a25c31b`), VER-001 and tracking reconciliation. External-only work remains skipped, not allowed to stall repository progress.
- **Status counts:** 8 `VERIFIED LOCALLY`; 24 `IMPLEMENTED — NOT VERIFIED`; 1 `IN PROGRESS`; 1 `NOT STARTED`; 5 `BLOCKED`; 0 `DONE`; 0 `DEFERRED`.
- **Test status:** backend 647/647; frontend 57/57 suites and 232/232 tests; AI sidecar 22/22; optimized production build/TypeScript; Docker Compose config; safe-failure deployment preflight; and Playwright 9/9 pass. Chromium covers the admin deployment badge/normal-user absence, notification popover, honest Free behavior, explicit light/dark at 375/768/1440, application workspace, Career/CV, discovery, Kanban and public CV/PDF. npm audit 0 evidence remains current because the lockfile did not change. Historical JT-019 and Jest force-exit/open-handle behavior remain recorded.
- **Deployment status:** Gitea pull-request run 609 passed the complete CI job in 4m20s. Deploy was intentionally skipped because the workflow deploys only a `push` to `main`; live remains unchanged. No merge/deployment was performed directly, no production migrations were run and the AI operation worker remains disabled by default.
- **Production status:** Unchanged and unverified. No provider/model call, model pull, external request or paid API occurred.
- **Known regressions:** None found by automated/local browser checks. Jest still needs `--forceExit` and reports its existing open-handle notice. Email-provider/send tests are fake/local only; real delivery is not claimed. Current MAIL browser evidence is 1280×720 only because the browser surface could not resize or perform native Tab traversal. Interrupted attempts are aged after 15 minutes and notified without retry; the five-minute scan is unmeasured on a large ledger. Direct clean EF-only SQLite migration still hits the pre-existing historical blank-chain defect before later migrations; normal startup owns reconciliation. Cross-feature monthly AI usage accounting remains a rollout gap.
@@ -50,5 +50,6 @@ Updated: 2026-08-15
- `docs/verification/jobs-001-job-discovery.md`
- `docs/verification/ux-003-kanban-theme.md`
- `docs/verification/product-001-honest-plans.md`
- `docs/verification/ver-001-complete-regression.md`
- `docs/verification/prod-002-ai-evaluation.md`
- `docs/work-programmes/master-work-plan.md`
+10 -10
View File
@@ -16,7 +16,7 @@ Allowed statuses are `NOT STARTED`, `IN PROGRESS`, `IMPLEMENTED — NOT VERIFIED
`DONE` requires every applicable acceptance criterion, focused and regression tests, browser/accessibility/theme/mobile checks, tenant and entitlement checks, documentation, migration/rollback evidence, and production verification. Repository-only work that still requires production is at most `VERIFIED LOCALLY`.
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **VER-001**.
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **SEC-009**.
## Consolidated dependency order
@@ -60,8 +60,8 @@ This queue records the highest-value work that can proceed without production cr
| 4 | Dedicated Job Details parity and JOBS-002 closure | JOBS-002 | Locally complete. Application answers/recruiter drafts now live on the dedicated page, note markers are encapsulated, edits are lossless, dirty navigation is guarded, focus returns to the row, tenant regressions pass, and Chromium covers 375/768/1440 light/dark/history/error/long data. Production smoke remains. |
| 5 | Cross-application contrast/accessibility pass | UX-002, UX-003, VER-001 | Locally complete. All icon controls own programmatic names; CV cards are keyboard links; the A4 public CV scales without inner/outer mobile overflow; dark Alert contrast is measured in Chromium at WCAG AA; full frontend/build/Playwright pass. Native assistive-technology and a general CI crawler remain external/future gates. |
| 6 | Honest Free/Pro homepage and upgrade surfaces | PRODUCT-001 | Locally complete. One catalogue drives exactly Free/Pro; retired tier/price/Free-AI/unlimited claims are gone; configured billing state controls the real upgrade action; contextual notices are reusable/dismissible. Frontend 232/232, policy/billing 30/30, build and Chromium 8/8 pass. |
| 7 | Complete application action matrix and full regression | VER-001 | In progress. Reconcile the rolling matrix, run the complete backend/frontend/sidecar/E2E/configuration gates and accurately classify external production/provider checks. |
| 8 | Tracking and blocker reconciliation | All | Keep this plan, progress, handoff, verification log and `BLOCKERS.md` aligned after every logical increment; remove stale CI/dependency statements only when current evidence proves them obsolete. |
| 7 | Complete application action matrix and full regression | VER-001 | Locally complete. Backend 647/647, frontend 232/232, sidecar 22/22, build, Compose configuration, safe-failure preflight and Chromium 9/9 pass; external provider/native-AT/production cells remain explicitly unverified. |
| 8 | Tracking and blocker reconciliation | All | Complete for this checkpoint. The plan, progress, handoff, verification log, action matrix and `BLOCKERS.md` distinguish repository work from external gates; continue updating them with each later package. |
## Requirement coverage index
@@ -268,8 +268,8 @@ This queue records the highest-value work that can proceed without production cr
- **Required tests:** two users/every entity, manifest/checksums/redaction, fault/restart/idempotence, provider failures, disposable restore replay.
- **Required browser verification:** disposable self/admin export/delete and confirmations.
- **Required production verification:** backup retention/tombstone rehearsal before self-service enablement.
- **Status:** `NOT STARTED`.
- **Blocker:** legal/operator retention and production restore decisions; repository work can proceed to disabled/dark launch.
- **Status:** `IN PROGRESS`.
- **Blocker:** legal/operator retention and production restore decisions block activation, not the repository-side disabled/dark launch.
- **Evidence:** audit JT-009 inventory/design.
- **Commit:** none.
- **Remaining work:** owner inventory/export first, deletion second.
@@ -754,11 +754,11 @@ This queue records the highest-value work that can proceed without production cr
- **Required tests:** full backend/frontend/Python/E2E plus regressions for confirmed defects.
- **Required browser verification:** running app, synthetic users/data, 375/768/1440, themes/keyboard/focus/refresh/back/tabs/slow/error; no real email/paid provider/destructive production action.
- **Required production verification:** applicable smoke actions only after deployment; local and production classifications remain distinct.
- **Status:** `IN PROGRESS`.
- **Blocker:** browser tooling/access and external providers may block individual rows, not the matrix.
- **Evidence:** audit user-journey/action gaps.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** remote CI, external providers, native assistive technology and production access block individual external cells, not the completed local matrix.
- **Evidence:** `docs/verification/ver-001-complete-regression.md`; V-172. Backend 647/647, frontend 57 suites/232 tests, sidecar 22/22, production build, Compose config, preflight negative tests and Chromium 9/9 pass.
- **Commit:** none.
- **Remaining work:** create early and update per package; final sweep last.
- **Remaining work:** keep the rolling matrix current; execute only its provider/native-AT/production cells when those environments and approvals exist.
### DEP-001 — Frontend advisory deployment gate
@@ -801,7 +801,7 @@ This queue records the highest-value work that can proceed without production cr
Full decisions are in `docs/work-programmes/decisions.md`.
1. **AI provider architecture:** ADR-004/current roadmap say one deployment provider; the newer Ollama programme explicitly requires local-first plus controlled fallback. The new programme is the target, implemented centrally and compatibly; old config/models remain for rollback.
2. **Free AI:** current code gives Free users limited AI; the new programme says Free has no AI. POL-001 must change behavior server-side without deleting existing user data or renaming persisted roles prematurely.
2. **Free AI:** resolved by POL-001/PRODUCT-001. Free has no AI admission at the server boundary, manual/existing data remains accessible, and public copy now matches that behavior without renaming persisted roles.
3. **Production authority:** Work says no production deploy unless instructed; Ollama programme and the current request authorize only scoped local-AI production work after inventory/backup/rollback. No other production mutation is authorized.
4. **Schema ownership:** OPS-001A chose one EF-owned, provider-conditional migration for `UserOperations` and deliberately omitted reconciler DDL. MariaDB script generation passes; executable server verification remains.
5. **Compose documentation:** docs claim a separate dev override, but the filename is auto-loaded by production deploy. SEC-002 corrects actual behavior.
+8 -8
View File
@@ -2,17 +2,17 @@
Updated: 2026-08-15
- **Exact current task:** commit/push PRODUCT-001, then execute VER-001 full action-matrix and regression reconciliation.
- **Last completed step:** replaced contradictory three-tier/fixed-price/Free-AI/unlimited claims with exactly Free/Pro, centralized public capability copy and reused dismissible contextual upgrade notices.
- **Files currently modified:** plan catalogue, homepage, active AI notices, billing-state explanation, focused tests, product documentation and programme evidence.
- **Commands already run:** PRODUCT frontend 30/30; policy/billing backend 30/30; full frontend 57 suites/232 tests; optimized build; full Playwright 8/8; claim searches and diff review.
- **Test results:** all listed tests pass. Chromium covers exactly two plans, retired-claim absence, explicit light/dark, 375/768/1440 no-overflow and keyboard actions. Jest retains the documented force-exit/open-handle notice.
- **Exact current task:** begin SEC-009 with the owner inventory/readable export, then implement the deletion lifecycle behind a disabled production gate.
- **Last completed step:** reconciled VER-001 and completed the safe local release matrix, including the prioritized admin deployment identity and all immediate repository/browser work.
- **Files currently modified:** expanded Playwright configuration/journeys plus VER-001 action-matrix and programme evidence.
- **Commands already run:** backend 647/647; frontend 57 suites/232 tests; sidecar 22/22; optimized build; Compose config; preflight negative cases; full Playwright 9/9; diff hygiene.
- **Test results:** all listed local gates pass. Provider/native-AT/production cells remain explicitly partial, not run or blocked. Jest retains the documented force-exit/open-handle notice.
- **Services currently running:** none on task-owned ports 3000/5202. Playwright stopped its disposable API/Next servers. Pre-existing Docker services were not changed.
- **Temporary files or processes:** no task-owned process is running and the failed disposable migration database was removed. Existing synthetic browser evidence/account and startup-created local backup remain documented. No provider account, real email, private content, paid service or production service was accessed.
- **Production changes currently active:** none. No deployment, migration, provider connection/sync/send or production payload occurred.
- **Rollback status:** downgrade `20260810080858_AddEmailDraftClientRequestId`, then `20260810075206_AddEmailDrafts`, before reverting draft commits; then follow the existing MAIL rollback order (`ee5ef7e`, `449faeb`, `123fc55`/`e9937ac`, ledger downgrade before `653f011`). No production migration/deploy/provider grant occurred.
- **Uncommitted changes:** V-171 PRODUCT-001 presentation/documentation increment; no backend/dependency/schema/config/migration change. V-166 through V-170 are pushed as `a6cffe0`, `f0b9b22`, `3b86ea2`, `deed948` and `a7c2549`.
- **Uncommitted changes:** V-172 test/evidence increment only; no application dependency, schema or production configuration change. V-166 through V-171 are pushed as `a6cffe0`, `f0b9b22`, `3b86ea2`, `deed948`, `a7c2549` and `a25c31b`.
- **Known failures:** live deployment is not verified because PR deploy is intentionally skipped and the active branch is not approved for merge. Draft export/API/UI, full thread/category actions and non-Gmail review remain; existing accounts need re-consent and IMAP stays read-only. A clean full-chain SQLite apply fails in the pre-existing JT-019 migration before the new draft migration. Browser/provider/MariaDB/production unavailable or unverified; recovery scan performance is unmeasured at large ledger scale; Jest open handles; SEC-006 parser dependency work is still separately gated; parser isolation remains SEC-007.
- **Exact next action:** commit/push V-171, reconcile `application-action-matrix.md` against the current repository and run the complete local VER-001 gate set.
- **Work that can continue independently:** VER-001 and tracking reconciliation. UX/JOBS/PRODUCT production, MAIL provider mutations, SEC-006/007 and PROD packages retain their recorded external gates.
- **Exact next action:** commit/push V-172, then inventory every user-owned row/file/token/cache/queue boundary for SEC-009 before implementing export.
- **Work that can continue independently:** SEC-009 repository-side owner inventory/export and disabled deletion lifecycle. UX/JOBS/PRODUCT production, MAIL provider mutations, SEC-006/007 and PROD packages retain their recorded external gates.
- **Decisions still required from the user:** none for synthetic/code-inspected repository work. Any provider connection or send test, internet/package upgrades, private data, external/paid providers and production actions retain explicit approval/safety gates; SEC-009 retention/legal policy remains unresolved.