Files
jobtrackingapp/docs/work-programmes/master-work-plan.md
T
cesnimda 3143568df0
CI and Deploy / test (pull_request) Failing after 1m33s
CI and Deploy / deploy (pull_request) Has been skipped
docs(match): record term-quality evidence
2026-08-09 18:49:41 +02:00

63 KiB
Raw Blame History

JobTracker master work plan

Prepared: 2026-08-02

Authoritative sources:

  • docs/todo/work.md (UX/reliability programme, lines 1-922)
  • docs/todo/ollama.md (production local-AI programme, lines 1-825)
  • docs/audits/audit-remediation-backlog.md (validated security and reliability prerequisites)

This file is the authoritative merged implementation plan. It avoids duplicate implementations: Strategy Snapshot, CV processing, durable operations, notifications, entitlement, AI privacy, provider routing, tenant-safe workers and restart recovery are each represented once and retain references to both source programmes.

Status and completion rules

Allowed statuses are NOT STARTED, IN PROGRESS, IMPLEMENTED — NOT VERIFIED, VERIFIED LOCALLY, DEPLOYED — NOT VERIFIED, DONE, BLOCKED, and DEFERRED.

DONE requires every applicable acceptance criterion, focused and regression tests, browser/accessibility/theme/mobile checks, tenant and entitlement checks, documentation, migration/rollback evidence, and production verification. Repository-only work that still requires production is at most VERIFIED LOCALLY.

Exactly one implementation item may be IN PROGRESS. As of this revision it is CAREER-001.

Consolidated dependency order

SEC-001 -> SEC-002 -> SEC-003 -> SEC-004
    |          |          \-> SEC-005A -> SEC-005B
    |          \--------------> BG-001
    |
    +-> SEC-006 -> SEC-007 -> AI-004
    +-> SEC-008 ----------------> SEC-009

CORE-001 -> CORE-002 -> BG-001 -> OPS-001A -> OPS-001B -> OPS-001C
OPS-001A -> POL-001 -> POL-002 -> AI-001 -> AI-002
PROD-002 -> POL-002 -> AI-001
PROD-002 -> PROD-003
PROD-001 -> PROD-003 -> PROD-004
AI-001 + AI-002 -> AI-003 and AI-004

UX-001/UX-002/QA-001 may proceed after their security prerequisites.
CAREER-001 -> CAREER-002; MAIL-001, JOBS-001, JOBS-002, UX-003 and PRODUCT-001 follow foundations.
All implemented surfaces -> VER-001 -> REL-001.

Ordering differences from the suggested list:

  • SEC-001 canonical origin precedes Microsoft legacy relinking and email recovery because those links cannot prove ownership while request Host can influence their origin.
  • SEC-006/SEC-007 parser hardening precedes the CV queue migration; moving an unsafe parser into a queue does not make it safe.
  • SEC-008 attachment consistency precedes complete account deletion.
  • The synthetic workload inventory/evaluation set (PROD-002) can proceed without production access and should inform routing and benchmarks early.
  • Production inventory, benchmark and rollout remain independent blockers; repository-side queue, policy and UX work continues without them.

Requirement coverage index

Source section Covered by
Work Phase 1 baseline/plan (36-61) This master plan, the progress/handoff/decisions files, compatibility pointer under docs/plans/, VER-001
Work Phase 2 authentication (63-100) UX-001, SEC-003, SEC-004, SEC-005
Work Phase 3 theme (102-133) UX-002
Work Phase 4 job search (135-172) JOBS-001
Work Phase 5 keyword quality (174-263) QA-001, PROD-002
Work Phase 6 Career Workspace (265-307) CAREER-001
Work Phase 7 CV 504 (309-386) SEC-006, SEC-007, OPS-001A/B/C, AI-001, AI-004
Work Phase 8 CV Builder/FlowCV (388-452) CAREER-002
Work Phase 9 consolidated email (454-527) MAIL-001, POL-001, POL-002
Work Phase 10 Kanban dark mode (529-560) UX-003
Work Phase 11 application table/workspace (562-634) CORE-002, JOBS-002, AI-003, MAIL-001
Work Phases 12-13 Free/Pro (636-721) POL-001, PRODUCT-001
Work Phase 14 Strategy Snapshot (723-777) CORE-001, CORE-002, OPS-001A/B/C, POL-001, POL-002, AI-001, AI-003
Work Phase 15 action verification (779-855) VER-001
Work quality/browser/completion (857-922) Every UI package, VER-001, REL-001
Ollama Phases 1-2 inventory/safety (58-176) PROD-001
Ollama Phase 3 workloads/evaluation (177-258) PROD-002
Ollama Phases 4-6 candidate/tuning/decision (259-397) PROD-003
Ollama Phase 7 routing/privacy (398-451) POL-001, POL-002, AI-002
Ollama Phases 8-9 queue/backpressure (452-573) BG-001, OPS-001A/B/C, AI-001
Ollama Phase 10 fallback (574-608) POL-002, AI-002, PROD-004
Ollama Phase 11 frontend states (609-639) OPS-001C, AI-003, AI-004
Ollama Phases 12-14 observability/rollout/validation (640-775) PROD-004, REL-001
Ollama tests/report (776-825) Every AI package, VER-001, REL-001

Work items

SEC-001 — Canonical external origin and application Host guard

  • Source programme: shared security prerequisite; Work 17-34; Ollama 26-56; audit P0-2A/JT-002.
  • Original requirement references: work.md:17-34; ollama.md:26-56; audit-remediation-backlog.md P0-2A.
  • Related findings: JT-002.
  • Priority: P0 security prerequisite.
  • Dependencies: confirmed canonical production URL; none in code.
  • Affected components: ASP.NET startup/configuration, security-link/OAuth/billing/reminder URL builders, cookie policy, config tests, environment/deploy preflight docs.
  • Acceptance criteria: Production requires one canonical HTTPS origin; request/forwarded Host never changes an external URL; unknown production Host is rejected; local Development/Test remains explicit and working.
  • Required tests: origin parser/startup; every URL caller; hostile Host/forwarded headers; Unicode/ports/paths; secure-cookie behavior; relevant backend regression suite.
  • Required browser verification: local login/reset/verification navigation when a local email sink is available; no visual redesign.
  • Required production verification: canonical and hostile Host smoke after SEC-002; not required to claim local verification.
  • Status: VERIFIED LOCALLY.
  • Blocker: production/ingress verification depends on SEC-002; a live local Production-mode process launch was rejected by the execution policy before starting, so it is not claimed.
  • Evidence: docs/verification/sec-001-canonical-origin.md; ExternalOriginTests; focused security/controller slice 79/79; full backend 474/474; Release build; Compose config; normalized deploy-shell syntax.
  • Commit: none.
  • Remaining work: verify canonical and hostile Host behavior through the complete proxy path in SEC-002; exercise reset/verification navigation with a safe local email sink; deploy and verify before DONE.

SEC-002 — Production ingress, forwarded headers and Compose separation

  • Source programme: shared production/security prerequisite; Work 17-34; Ollama 123-176; audit P0-2B/JT-002.
  • Original requirement references: work.md:17-34; ollama.md:123-176; audit P0-2B.
  • Related findings: JT-002, JT-013, JT-020.
  • Priority: P0.
  • Dependencies: SEC-001; actual proxy network/IP supplied by operator for production verification.
  • Affected components: production/development Compose selection, nginx forwarded headers, explicit known proxy/network config, deploy script/runbook, CI deployment invocation.
  • Acceptance criteria: dev override is never auto-loaded in production; no direct production application ports; exact-host ingress contract; sanitized two-hop forwarding; rollback command documented.
  • Required tests: merged Compose assertions, production config tests, nginx/proxy integration, deploy shell checks.
  • Required browser verification: canonical public/API navigation through local proxy.
  • Required production verification: exact Traefik route, closed ports, correct HTTPS/client IP/cookies.
  • Status: VERIFIED LOCALLY.
  • Blocker: external Traefik topology, production CIDR/network inventory, firewall state and provider routes are unavailable for production verification; the pinned nginx base image was not installed locally and was not pulled without internet permission.
  • Evidence: docs/verification/sec-002-ingress-compose.md; production Compose has no published frontend/backend/Ollama ports; dev Compose publishes only 3000/5202/11434; proxy parser tests; nginx syntax/substitution checks; frontend build; backend 476/476.
  • Commit: none.
  • Remaining work: inventory/set the non-overlapping production CIDR; verify operator Traefik exact-host/header replacement and firewall; build the pinned image in approved CI; run local/prod proxy and hostile-Host smoke before DONE.

SEC-003 — Microsoft tenant and issuer trust policy

  • Source programme: Work authentication/audit prerequisite.
  • Original requirement references: work.md:91-100; audit P0-1A/JT-001.
  • Related findings: JT-001.
  • Priority: P0.
  • Dependencies: supported single/multitenant mode configured.
  • Affected components: Microsoft token validator, smart auth scheme, sign-in configuration, mocked validator tests.
  • Acceptance criteria: exact issuer/tid; (tid,oid) returned; invalid/missing/mismatched tenant rejected; unused raw bearer trust path removed or proven necessary and hardened.
  • Required tests: all tenant modes, issuer/audience/signature/lifetime, personal/organizational, same oid across tenants.
  • Required browser verification: mocked Microsoft success/failure/cancel only; real provider later if safely configured.
  • Required production verification: configured tenant mode and synthetic/provider smoke without exposing tokens.
  • Status: VERIFIED LOCALLY.
  • Blocker: none for validator implementation; real Microsoft smoke needs provider configuration.
  • Evidence: docs/verification/sec-003-microsoft-tenant.md; tenant/issuer validator matrix; raw bearer branch removed; focused 42/42 and full backend 491/491; Compose and deploy-shell config checks.
  • Commit: none.
  • Remaining work: production inventory/configuration and mocked/real safe provider smoke; SEC-004 canonical pair persistence/relinking must complete before JT-001 closes or Microsoft is enabled in production.
  • Source programme: Work authentication/audit prerequisite.
  • Original requirement references: work.md:91-100; audit P0-1B/JT-001.
  • Related findings: JT-001.
  • Priority: P0.
  • Dependencies: SEC-001, SEC-003, SEC-005A and SEC-005B recent reauthentication/email proof.
  • Affected components: ApplicationUser, EF model/migration, auth exchange/link/unlink/recovery UI and APIs.
  • Acceptance criteria: composite tenant/object key is unique owner; no email auto-link; no silent legacy backfill/merge; legitimate legacy users have explicit non-locking recovery.
  • Required tests: fresh/legacy SQLite+MariaDB migration, collisions, two tenants/same email, last-credential guard, 2FA, mocked relink.
  • Required browser verification: local mocked new sign-in and legacy relink.
  • Required production verification: anonymized legacy inventory before migration; monitored relink window.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: real Microsoft/browser/SMTP and disposable MariaDB checks are unavailable; production legacy inventory is unknown.
  • Evidence: docs/verification/sec-004-microsoft-identity.md; focused auth 34/34; backend 507/507; frontend 152/152 and build; dual-provider SQL; disposable SQLite legacy/unique-index rehearsal.
  • Commit: none.
  • Remaining work: real mocked-browser Microsoft popup/relink flow with an SMTP sink; disposable MariaDB migration; production counts-only legacy inventory, rolling-version smoke and monitored relink window before DONE.

SEC-005A — Session and recovery revocation

  • Source programme: Work auth constraints; shared recovery prerequisite.
  • Original requirement references: work.md:17-34,63-100; audit P0-4A/P0-4B, JT-007/JT-008.
  • Related findings: JT-007, JT-008.
  • Priority: P0.
  • Dependencies: SEC-001; coordinates with SEC-004.
  • Affected components: logout, password reset/change, local session validation, trusted devices, pending 2FA challenges and auth tests.
  • Acceptance criteria: logout revokes the exact copied sid; reset revokes all sessions/devices without disabling 2FA; password change rotates the current session, revokes others and preserves only the current trusted device; session validation binds sid to user; stale pending 2FA fails after a security-stamp change.
  • Required tests: valid/expired logout cookie; copied session; reset across users/devices; password rotation; trusted-device retention/removal; sid/user mismatch; pending 2FA stamp.
  • Required browser verification: logout in two tabs; password change/reset with a local email sink; 2FA recovery.
  • Required production verification: copied-cookie/reset/change smoke without logging token values.
  • Status: VERIFIED LOCALLY.
  • Blocker: browser and production checks require safe running environments.
  • Evidence: docs/verification/sec-005a-session-revocation.md; focused 48/48; full backend 497/497.
  • Commit: none.
  • Remaining work: browser/runtime and production verification before DONE; SEC-005B owns email state.

SEC-005B — Verified registration and pending-email transitions

  • Source programme: Work auth constraints; shared identity/recovery prerequisite.
  • Original requirement references: work.md:17-34,63-100; audit P0-4B, JT-007/JT-008.
  • Related findings: JT-007, JT-008.
  • Priority: P0.
  • Dependencies: SEC-001, SEC-005A; coordinates with SEC-004.
  • Affected components: registration, verification/resend, profile DTOs, pending-email request/confirm/cancel APIs, ApplicationUser, one additive EF migration/snapshot, auth/profile UI and tests.
  • Acceptance criteria: verification-required registration creates no session and returns typed 202; active email never changes before proof; latest pending request wins; confirmation uses Identity change-email semantics, conditionally updates username, clears pending state and revokes all sessions/devices.
  • Required tests: registration/no-cookie transition; verify then login; enumeration-resistant resend; duplicate/latest/mismatched/expired/replayed pending email; username preservation; passwordless/provider users; SQLite and MariaDB migration paths.
  • Required browser verification: mocked/local-sink register/resend/verify and request/cancel/confirm email at desktop/mobile with keyboard access.
  • Required production verification: safe SMTP link/origin and version-skew smoke; no real personal address.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: in-app browser localhost access was denied by its admin policy check; no safe SMTP sink, disposable MariaDB, or production environment is available.
  • Evidence: docs/verification/sec-005b-email-ownership.md; focused backend 35/35; full backend 501/501; frontend 151/151 and build; SQLite upgrade and dual-provider migration scripts; isolated API 202/no-cookie and 403/no-cookie checks.
  • Commit: none.
  • Remaining work: real-browser desktop/mobile/keyboard flows with a local email sink; expired/replayed token and custom-username integration checks; disposable MariaDB migration execution; production SMTP/origin/version-skew verification before DONE.

SEC-006 — Compatible document-parser dependency update

  • Source programme: Work CV 504; Ollama parser prerequisite; audit P0-3A.
  • Original requirement references: work.md:309-386; ollama.md:44-56,177-258; audit JT-006.
  • Related findings: JT-006, JT-017.
  • Priority: P0.
  • Dependencies: approved package-index access during implementation; synthetic benign corpus.
  • Affected components: Python requirements/lock/hash, parser tests and image build.
  • Acceptance criteria: compatible fixed versions; no unaccepted reachable High/Critical parser advisory; clean reproducible install; benign extraction parity.
  • Required tests: dependency resolution/audit, Python suite, generated benign corpus.
  • Required browser verification: none for dependency-only package.
  • Required production verification: image digest and smoke before activation.
  • Status: BLOCKED.
  • Blocker: repository instructions prohibit internet/package resolution without explicit permission; fixed-version compatibility cannot be resolved or verified offline.
  • Evidence: audit lists reachable Pillow/pypdf/multipart/Starlette advisories and compatibility conflict.
  • Commit: none.
  • Remaining work: explicit package-index permission, compatible fixed-version resolution, lock/hash refresh, audit, benign corpus parity and image smoke; do not execute malicious files.

SEC-007 — Bounded isolated document processing

  • Source programme: Work CV 504; Ollama privacy/queue; audit P0-3B/P0-3C.
  • Original requirement references: work.md:309-386; ollama.md:177-258,452-573; audit JT-006/JT-011.
  • Related findings: JT-006, JT-011.
  • Priority: P0.
  • Dependencies: SEC-006.
  • Affected components: backend upload/fallback, FastAPI parser child, queue backpressure, container non-root/resource/tmp cleanup.
  • Acceptance criteria: bounded file/page/pixel/decompression/memory/time work; child/process group killed; no binary backend fallback; safe cleanup/errors; private tokenized service remains.
  • Required tests: generated boundary/corrupt fixtures, harmless sleeping child, cancellation/restart cleanup, outage/no-fallback, container assertions.
  • Required browser verification: synthetic CV upload status/failure; authorized private CV local-only only after safeguards.
  • Required production verification: measured memory/CPU limits and canary synthetic extraction.
  • Status: NOT STARTED.
  • Blocker: follows dependency update; production sizing requires access.
  • Evidence: audit parser call path and limits design.
  • Commit: none.
  • Remaining work: split behavioral and container commits if needed.

SEC-008 — Recoverable attachment mutations

  • Source programme: audit prerequisite for account lifecycle and workspace files.
  • Original requirement references: Work 17-34 and file/application requirements; audit P0-5/JT-010.
  • Related findings: JT-010.
  • Priority: P0 data integrity.
  • Dependencies: coordinate file-root/journal format with SEC-009.
  • Affected components: attachment controller/file helper/reconciler/tests.
  • Acceptance criteria: every DB/filesystem failure converges to committed or durable retryable state; no silent orphan/missing file; rename is metadata-only; owner/path isolation.
  • Required tests: invalid later file, cancellation, DB/move/delete failure, restart stages, traversal/symlink, two users.
  • Required browser verification: upload/rename/delete/refresh with synthetic files.
  • Required production verification: report-only orphan inventory and monitored journal counters.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: in-app browser localhost is policy-blocked; no production report-only inventory/monitoring or MariaDB environment is available. This host denied disposable symlink creation, so that branch is code-inspected only.
  • Evidence: audit JT-010 execution path; docs/verification/sec-008-attachment-consistency.md; 20/20 focused and 525/525 full backend tests; isolated User A/User B upload/download/rename/delete HTTP rehearsal.
  • Commit: none.
  • Remaining work: browser upload/rename/delete/refresh; executable symlink test on a capable host; production report-only orphan inventory and counters; MariaDB runtime; reconcile suffix markers before any rollback.

SEC-009 — Complete readable export and account deletion lifecycle

  • Source programme: Work audit constraint; Ollama private-data lifecycle; audit P0-6A/P0-6B.
  • Original requirement references: work.md:17-34; ollama.md:17-22,427-450; audit JT-009.
  • Related findings: JT-009, JT-013, JT-022.
  • Priority: P0 data lifecycle.
  • Dependencies: SEC-005 revoke-all, SEC-008, owner inventory, backup-retention/tombstone decision.
  • Affected components: domain inventory/export ZIP, owner-scoped files/caches/queues, deletion saga, provider tokens, migrations, backup restore/runbooks/UI.
  • Acceptance criteria: readable complete redacted export; idempotent live deletion across rows/files/tokens/queue/cache; no other tenant impact; backup retention truthful; restore tombstones prevent resurrection.
  • Required tests: two users/every entity, manifest/checksums/redaction, fault/restart/idempotence, provider failures, disposable restore replay.
  • Required browser verification: disposable self/admin export/delete and confirmations.
  • Required production verification: backup retention/tombstone rehearsal before self-service enablement.
  • Status: NOT STARTED.
  • Blocker: legal/operator retention and production restore decisions; repository work can proceed to disabled/dark launch.
  • Evidence: audit JT-009 inventory/design.
  • Commit: none.
  • Remaining work: owner inventory/export first, deletion second.

CORE-001 — Restore default SQLite/MariaDB behavior parity

  • Source programme: Work Strategy/Career failures; audit P1-1.
  • Original requirement references: work.md:723-777; audit JT-003.
  • Related findings: JT-003.
  • Priority: P0 broken default workflow.
  • Dependencies: none.
  • Affected components: Career/Application workspace date-order/filter queries and provider matrix tests.
  • Acceptance criteria: variants/runs/history/workspace return correct owner/empty/non-owner results on both supported providers.
  • Required tests: fresh/seeded HTTP provider matrix, date/month/timezone boundaries.
  • Required browser verification: SQLite Career/Application workspace after API tests.
  • Required production verification: MariaDB smoke after deployment.
  • Status: VERIFIED LOCALLY.
  • Blocker: production MariaDB execution and browser checks remain unavailable; direct blank-file EF-only migration is separate JT-019 schema-ownership debt while fresh application startup passes.
  • Evidence: audit runtime reproduction JT-003; docs/verification/core-001-sqlite-provider-parity.md; 3/3 real-provider tests; 509/509 backend regression; isolated fresh-SQLite owner/empty/non-owner HTTP matrix.
  • Commit: none.
  • Remaining work: browser Career/Application workspace verification and executable MariaDB smoke after safe provider/deployment access; address EF-only blank-chain drift under JT-019 rather than editing already-applied historical migrations here.

CORE-002 — Remove ambiguous application-workspace routes

  • Source programme: Work Strategy and embedded workspace; audit P1-2.
  • Original requirement references: work.md:562-634,723-777; audit JT-004.
  • Related findings: JT-004.
  • Priority: P0 broken core route.
  • Dependencies: CORE-001; inventory frontend/API consumers.
  • Affected components: workspace/timeline/interview controllers, API clients/tests/docs.
  • Acceptance criteria: one action per verb/path; owner 200, non-owner 404, anonymous 401; UI panels load.
  • Required tests: route-table uniqueness, HTTP ownership, frontend panel tests.
  • Required browser verification: direct/deep-link workspace panels and Back/Forward.
  • Required production verification: authenticated workspace smoke.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: in-app browser localhost is policy-blocked; no production/MariaDB HTTP environment is available.
  • Evidence: audit runtime ambiguous route reproduction; docs/verification/core-002-route-uniqueness.md; reflection route regression; 31/31 focused and 511/511 full backend; 153/153 frontend and build; owner 200/non-owner 404/anonymous 401 HTTP matrix.
  • Commit: none.
  • Remaining work: browser direct/deep-link, Back/Forward and rendered-panel verification; production authenticated smoke before DONE.

BG-001 — Tenant-safe hosted-worker foundation

  • Source programme: both; shared prerequisite.
  • Original requirement references: work.md:17-34,723-777; ollama.md:44-56,452-529; audit JT-005.
  • Related findings: JT-005, JT-012, JT-022.
  • Priority: P0/P1.
  • Dependencies: CORE-001/CORE-002; do not activate workers before OPS-001B, POL-001 and POL-002.
  • Affected components: rules/reminders/export/enrichment/CV/AI hosted services, owner context, worker kill switches and tests.
  • Acceptance criteria: explicit owner selection, deny-on-null avoided safely, idempotent results, structured failures, no cross-owner work, disabled workers remain off.
  • Required tests: two-owner/no-HttpContext, enable/disable, restart/retry/clock, fake email/AI.
  • Required browser verification: notification/result surfaces only after OPS-001C.
  • Required production verification: one-worker canary and owner-safe metrics.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: activation blocked until policy/notification prerequisites; foundation code is not blocked.
  • Evidence: audit JT-005 service inspection; docs/verification/bg-001-tenant-workers.md; real-SQLite two-owner worker suite with fake email/AI; full backend 532/532; Compose validation; isolated default-off startup/health/no-export check.
  • Commit: none.
  • Remaining work: OPS-001B persistent notification/idempotency before reminders/rules; POL-001/002 and durable AI queue before enrichment; restart/clock tests; browser result surfaces; monitored single-worker production canary. Keep all four switches false.

OPS-001A — Durable operation record and lease state machine

  • Source programme: both; shared CV/Strategy/AI operation foundation.
  • Original requirement references: work.md:360-386,761-777; ollama.md:452-529.
  • Related findings: JT-005, JT-013, JT-014, JT-022.
  • Priority: P1 foundation.
  • Dependencies: BG-001; explicit schema ownership.
  • Affected components: UserOperation entity, owner/idempotency/claim indexes, state/lease store, provider-aware EF migration and tests.
  • Acceptance criteria: stable owner-scoped ID; atomic idempotent create/claim; bounded states/retries/leases/deadlines/cancellation; restart recovery; no raw private payload field.
  • Required tests: concurrent create/claim, two tenants, transition guards, lease expiry/final attempt, cancellation, retry delay, deadlines, migration up/down/provider SQL.
  • Required browser verification: not applicable until OPS-001C exposes owner APIs.
  • Required production verification: executable MariaDB upgrade/down rehearsal and monitored schema rollout.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: no disposable MariaDB or production environment; application consumers deliberately not migrated yet.
  • Evidence: docs/verification/ops-001a-durable-operations.md; 7/7 focused and 539/539 full backend tests; SQLite upgrade/down/up and fresh startup; dual-provider scripts.
  • Commit: none.
  • Remaining work: MariaDB execution/production rollout; task-specific producers must validate references/policies and use OPS-001B/C rather than storing private payloads.

OPS-001B — Persistent operation notifications and terminal outbox

  • Source programme: both; shared completion/failure visibility and reminder safety.
  • Original requirement references: work.md:360-386,761-777; ollama.md:512-529,609-639.
  • Related findings: JT-005, JT-012, JT-014, JT-022.
  • Priority: P1 foundation.
  • Dependencies: OPS-001A; keep real SMTP/AI workers disabled.
  • Affected components: owner notification entity/store, operation terminal transactions, unread/dismiss state, provider-safe schema and tests.
  • Acceptance criteria: success/failure/cancellation notification is committed atomically with terminal state; owner isolation; idempotent single notification; no private content; retained across restart.
  • Required tests: every terminal state, duplicate completion, DB failure rollback, two owners, unread/read/dismiss, migration provider scripts.
  • Required browser verification: deferred to OPS-001C.
  • Required production verification: schema rollout and synthetic notification canary only.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: MariaDB execution unavailable; repository implementation can continue.
  • Evidence: docs/verification/ops-001b-notifications.md; 9/9 focused and 541/541 full backend tests; forced transaction rollback; SQLite upgrade/down/up; current model snapshot; generated SQLite/MariaDB up/down SQL.
  • Commit: none.
  • Remaining work: execute the migration on MariaDB; expose owner APIs/UI in OPS-001C; complete browser and production canaries. No email delivery is part of this package.

OPS-001C — Owner operation/notification APIs and frontend queue client

  • Source programme: both; shared queued-operation UX.
  • Original requirement references: work.md:360-386,761-777; ollama.md:499-510,609-639.
  • Related findings: JT-014, JT-015, JT-022.
  • Priority: P1 foundation.
  • Dependencies: OPS-001A/B; POL-001 locked-state admission precedes AI producers.
  • Affected components: status/list/cancel/retry APIs, notification read/dismiss APIs, frontend polling/status/notification client and shell badge.
  • Acceptance criteria: stable status URL, owner-only list/detail/cancel/retry; refresh/navigation recovery; honest states/errors; completion badge/read/dismiss; no duplicate submission or private diagnostics.
  • Required tests: two-user API, refresh/poll/retry/cancel, invalid/expired IDs, component/keyboard/accessibility states.
  • Required browser verification: queued/refresh/navigate/retry/cancel/completion notification with synthetic handler at 375/768/1440 and light/dark.
  • Required production verification: authenticated synthetic polling/notification smoke.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser localhost remains policy-blocked, but repository/API/component work can continue.
  • Evidence: docs/verification/ops-001c-operation-ui.md; 12/12 focused backend, 544/544 backend, 3/3 focused UI, 156/156 frontend and production build; isolated two-user HTTP owner/cross-owner matrix.
  • Commit: none.
  • Remaining work: real browser responsive/theme/keyboard/refresh checks, MariaDB/production smoke and feature-specific producers in AI-003/004. No generic create API is exposed.

POL-001 — Canonical Free/Pro entitlement policy

  • Source programme: Work Free/Pro and Ollama entitlement enforcement.
  • Original requirement references: work.md:636-721; ollama.md:17-22,412-449,501-529,638.
  • Related findings: JT-012, JT-022.
  • Priority: P1 security/business policy.
  • Dependencies: OPS-001A operation admission contract.
  • Affected components: role/subscription capability service, API authorization, worker admission/recheck, usage accounting, auth DTO, frontend locked states.
  • Acceptance criteria: exactly Free and Pro externally; Free has no AI; server rejects direct/batch/background bypass; Pro/expired/downgraded/admin behavior consistent; non-AI data remains accessible.
  • Required tests: endpoint inventory for Free/Pro/expired/downgraded/admin, worker recheck, usage, direct requests and two tenants.
  • Required browser verification: locked state/upgrade action/dismissal and Pro execution; mobile/theme/accessibility.
  • Required production verification: configured Stripe/role mapping only when operator activation is approved.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser localhost is denied; Stripe/MariaDB/production are unavailable. Usage accounting is complete only for AI Workspace, so provider rollout remains blocked until durable execution centralizes it.
  • Evidence: docs/verification/pol-001-free-pro-entitlements.md; focused backend 74/74; full backend 568/568; focused frontend 22/22; full frontend 47 suites/157 tests; production build.
  • Commit: none.
  • Remaining work: browser locked/Pro state checks; mocked Stripe expiry/downgrade lifecycle; central all-task usage accounting through AI-003/004 producers; production role/config smoke. PRODUCT-001 separately removes the known landing-page price/third-tier/unlimited claims.
  • Source programme: both.
  • Original requirement references: work.md:17-34,495-505,723-777; ollama.md:398-451,574-608.
  • Related findings: JT-012, JT-022, JT-025.
  • Priority: P1 privacy/security.
  • Dependencies: POL-001, PROD-002 task/privacy classification.
  • Affected components: persistent settings, operation policy snapshot, payload minimization, admin diagnostics, fallback audit, UI privacy explanation.
  • Acceptance criteria: local-only/default/fallback policy enforced server-side; private categories never leave without permission; minimum payload; provider/reason recorded; opt-out never overridden; no browser secrets.
  • Required tests: task/privacy matrix, consent changes, payload capture/redaction, fallback allowed/prohibited, entitlement, two tenants.
  • Required browser verification: user/admin controls and disclosure/locked/failure states.
  • Required production verification: external egress capture with synthetic data only; no real private CV/email.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser localhost is denied; MariaDB/production/external-provider verification is unavailable. Task-specific payload minimization/accounting depend on AI-003/004.
  • Evidence: docs/verification/pol-002-ai-privacy.md; focused backend 72/72 and final policy 28/28; sidecar 18/18; focused frontend 8/8; full backend 576/576; full frontend 47 suites/158 tests; production build; config and migration script checks.
  • Commit: none.
  • Remaining work: browser user/admin disclosure checks; MariaDB and production synthetic egress proof; AI-003/004 task-specific payload minimization, accounting and real producer verification. AI-001/002 now carry rechecked policy/task context and record bounded local-first provenance.

AI-001 — Durable AI queue, backpressure and operation APIs

  • Source programme: both.
  • Original requirement references: work.md:360-386,761-777; ollama.md:452-573,609-639.
  • Related findings: JT-005, JT-011, JT-013, JT-014.
  • Priority: P1.
  • Dependencies: BG-001, OPS-001A/B/C, POL-001, POL-002.
  • Affected components: AI operation handlers/worker, priority/concurrency/capacity/deadline/circuit, API polling/retry/cancel, frontend shared queue UI.
  • Acceptance criteria: HTTP returns 202/stable URL; bounded priority queue protects Ollama; exact state transitions; no duplicate billing/output; refresh/restart recovery; scheduled jobs cannot starve interactive work.
  • Required tests: queue capacity/priority, atomic claim, circuit, timeout/retry/jitter, duplicate click/idempotency, cancellation, shutdown/restart, tenant and policy recheck.
  • Required browser verification: synthetic operation status across refresh/nav/double-click/offline/retry/cancel.
  • Required production verification: queue depth/age, one-worker canary, Ollama offline/restart and app/worker restart.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: real 202 producers/browser verification depend on AI-003/004; MariaDB/production are unavailable and the worker remains off.
  • Evidence: docs/verification/ai-001-durable-ai-queue.md; focused queue/state/API tests 17/17; full backend 581/581; Compose config and diff checks.
  • Commit: none.
  • Remaining work: AI-003/004 task handlers and 202 endpoints; browser refresh/double-click/cancel/retry; MariaDB and monitored single-worker production canary. AI-002 supplies local-first circuit/provenance. Do not create a second CV- or Strategy-specific queue.

AI-002 — Ollama adapter and local-first provider routing

  • Source programme: Ollama local-first; Work privacy/Pro constraints.
  • Original requirement references: ollama.md:398-451,574-608; work.md:17-34,723-777.
  • Related findings: JT-012, JT-017, JT-022.
  • Priority: P1.
  • Dependencies: PROD-002, POL-001, POL-002, AI-001.
  • Affected components: central task routing policy, Ollama/external adapters, sidecar/backend provider boundary, circuit/health, provider diagnostics/config.
  • Acceptance criteria: deterministic then primary local then optional local then permitted external then clear failure; one policy considers task/privacy/entitlement/health/deadline/cost; no simultaneous duplicate completion.
  • Required tests: routing matrix, Ollama adapter, schema failure, local circuit, fallback allowed/prohibited/unavailable, cost limits and deduplication.
  • Required browser verification: provider-agnostic queued states and appropriate fallback disclosure.
  • Required production verification: actual selected local model and controlled synthetic fallback.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser and production checks, actual local-model selection and controlled provider fallback depend on administrator browser policy plus PROD-001/003 access/benchmarks. Repository behavior is not blocked.
  • Evidence: docs/verification/ai-002-provider-routing.md; V-098V-100; focused backend 26/26, full backend 588/588, sidecar fake-transport 22/22, Compose/diff checks pass.
  • Commit: none.
  • Remaining work: AI-003/004 must register typed producers/handlers and explicit external task allowlists; complete monthly cross-feature accounting; browser/MariaDB/selected-model/controlled-provider/production verification. Old provider/model configuration remains available for rollback.

PROD-001 — Read-only production AI inventory and rollout safety

  • Source programme: Ollama Phases 1-2.
  • Original requirement references: ollama.md:58-176.
  • Related findings: JT-013, JT-017, JT-020, JT-021.
  • Priority: P1 production gate.
  • Dependencies: documented/configured production access; none for repository report templates.
  • Affected components: production hardware assessment, current Ollama/app/network/config inventory, backup and rollout/rollback report.
  • Acceptance criteria: sanitized measured OS/CPU/RAM/GPU/storage/Ollama/deployment inventory; no public Ollama; config/backup/restart/interruption/rollback recorded before mutation.
  • Required tests: read-only commands only; backup mechanism evidence; no secrets/content in reports.
  • Required browser verification: none.
  • Required production verification: this item is itself production read-only verification.
  • Status: BLOCKED.
  • Blocker: repository docs state the local environment has no production route and CI SSH secrets are unavailable; no documented callable host/credential is present.
  • Evidence: docs/deployment/backup-restore.md and docs/operations/production-backup-verification.md explicitly record the access gap.
  • Commit: none.
  • Remaining work: create sanitized report template locally; operator/documented access required for measured completion.

PROD-002 — AI workload inventory and synthetic evaluation set

  • Source programme: Ollama Phase 3; Work keyword/AI/CV/email features.
  • Original requirement references: ollama.md:177-258; work.md:174-263,309-386,454-527,723-777.
  • Related findings: JT-012, JT-022.
  • Priority: P1.
  • Dependencies: code inventory; no production access.
  • Affected components: workload catalog, synthetic/redacted fixtures, deterministic-versus-AI and privacy/latency/output classifications.
  • Acceptance criteria: every AI task has input/size/output/language/latency/quality/privacy/fallback/interactive/entitlement/current-provider classification; evaluation set covers every listed English/Norwegian/noisy/adversarial/long/invalid case without real data.
  • Required tests: fixture validity, deterministic expected signals, strict JSON schemas, prompt-injection containment inputs.
  • Required browser verification: none; fixtures later drive UI packages.
  • Required production verification: none until benchmark.
  • Status: VERIFIED LOCALLY.
  • Blocker: none; authorized private CV is optional local-only and never committed/external.
  • Evidence: docs/verification/prod-002-ai-evaluation.md; docs/ai/workload-inventory.md; fixture validation 1/1; full backend 569/569; frontend 47 suites/157 tests and build.
  • Commit: none.
  • Remaining work: PROD-003 later executes model benchmarks and sets measured thresholds. Revise classifications if POL-002 route tracing finds an omitted payload; no production/provider work is required for this package.

PROD-003 — Production model benchmarks and model decision

  • Source programme: Ollama Phases 4-6.
  • Original requirement references: ollama.md:259-397.
  • Related findings: JT-021.
  • Priority: P1 production gate.
  • Dependencies: PROD-001 measured hardware, PROD-002 evaluation set.
  • Affected components: benchmark harness/evidence and ollama-model-benchmark.md.
  • Acceptance criteria: exact candidate tags/license/version/quantization/resources/latency/throughput/quality/JSON/Norwegian/injection/failure/repeat results; measured context/tuning; primary/optional/deterministic/external decision.
  • Required tests: repeated synthetic benchmark at 4K/8K and 16K only if safe; one inference initially; no very large/cloud model.
  • Required browser verification: none.
  • Required production verification: measured on actual machine; local workstation results are labeled separately.
  • Status: BLOCKED.
  • Blocker: PROD-001 production access/hardware inventory.
  • Evidence: none yet.
  • Commit: none.
  • Remaining work: repository harness can be prepared after PROD-002.

PROD-004 — Local-model rollout, fallback, observability and operations

  • Source programme: Ollama Phases 9-14.
  • Original requirement references: ollama.md:531-775.
  • Related findings: JT-005, JT-013, JT-017, JT-021, JT-022.
  • Priority: P1 production deployment.
  • Dependencies: AI-001, AI-002, PROD-001/003, verified backup/rollback.
  • Affected components: Ollama limits/model install, app config/migrations/worker, telemetry/health/runbook, validation matrix.
  • Acceptance criteria: selected digest installed without deleting old model; bounded Ollama/app queues; local-first default; safe fallback; privacy-safe metrics/health; drain/restart/rollback; full production validation matrix.
  • Required tests: offline/timeout/restart/congestion/concurrent/fallback/free/pro/two-tenant/notification matrix.
  • Required browser verification: queued AI journeys in production using synthetic data.
  • Required production verification: mandatory; no DONE without actual deploy, resource observation and restart recovery.
  • Status: BLOCKED.
  • Blocker: production access plus all dependencies.
  • Evidence: none yet.
  • Commit: none.
  • Remaining work: repository runbooks/config only after measured values; no guessed limits/model.

AI-003 — Strategy Snapshot durable-operation migration

  • Source programme: both; one consolidated implementation.
  • Original requirement references: work.md:723-777; ollama.md:609-639,730-765.
  • Related findings: JT-003, JT-004, JT-005, JT-012, JT-014, JT-022.
  • Priority: P1 broken user workflow.
  • Dependencies: CORE-001/002, AI-001/002, POL-001/002.
  • Affected components: Strategy button/API/operation handler/result persistence/UI status/notification.
  • Acceptance criteria: root timeout reproduced; enqueue returns 202; stable result; success/failure/timeout/cancel/retry/idempotent double-click/refresh/restart; no duplicate usage/output.
  • Required tests: endpoint/handler/provider fakes, all required states, entitlement/privacy/tenant checks, E2E.
  • Required browser verification: complete queue/status/error/retry/cancel/refresh/back-forward/mobile/theme flow.
  • Required production verification: local model success, timeout and restart recovery.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser localhost policy, selected local model, MariaDB, restart canary and production access remain unavailable; worker stays default-off.
  • Evidence: docs/verification/ai-003-strategy-snapshot-queue.md; verification-log V-101V-103; docs/audits/evidence/ai-003/README.md.
  • Commit: a621226 (feat(ai): queue strategy snapshots).
  • Remaining work: real browser/mobile/theme/refresh/back-forward checks; selected-model timeout/quality test; MariaDB and production single-worker restart/canary/rollback; complete cross-feature usage accounting. No Strategy-specific queue was created.

AI-004 — CV-processing 504 and durable-operation migration

  • Source programme: both; one consolidated implementation.
  • Original requirement references: work.md:309-386; ollama.md:609-639,730-765.
  • Related findings: JT-006, JT-011, JT-014.
  • Priority: P1 broken user workflow/security.
  • Dependencies: SEC-006/007, OPS-001A/B/C, AI-001; authorized private file optional only after safe fixture reproduction.
  • Affected components: browser upload/API/proxy/artifact/parser/normalization/result polling/recovery/UI queue states.
  • Acceptance criteria: 504 origin established; enqueue/persist/progress/result; bounded processing/retry/cancel/cleanup; restart recovery; no timeout inflation; review gate preserved.
  • Required tests: safe synthetic PDFs/DOCX/images, proxy/backend/parser/provider failure, duplicate/refresh/restart, E2E.
  • Required browser verification: synthetic CV first; authorized private file via temporary local copy only, never logged/committed/external.
  • Required production verification: synthetic/local-only canary, no external payload, restart recovery.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: SEC-006 dependency upgrades need internet permission; browser/private-file/MariaDB/production reproduction remains unavailable. Synthetic repository work can continue.
  • Evidence: docs/verification/ai-004-cv-processing-queue.md; V-104V-107; real SQLite synthetic integration proves 202/active deduplication/owner-scoped handler/retry provenance/notification/review gate; backend 594/594; frontend 161/161 and build.
  • Commit: c3c5af8 (feat(cv)!: queue durable processing).
  • Remaining work: SEC-006/007 parser dependency/isolation and complete parser cancellation; browser synthetic upload/refresh/retry/cancel/review at required widths/themes/keyboard; selected-model and worker-restart canary; MariaDB/production rollout. Reconcile dormant extraction-row status immediately when an operation is cancelled before claim. Do not use the private CV before safeguards.

UX-001 — Unified authentication page

  • Source programme: Work Phase 2.
  • Original requirement references: work.md:63-100.
  • Related findings: JT-001, JT-007, JT-008, JT-015.
  • Priority: P2 after auth safety.
  • Dependencies: SEC-003/004/005 behavior contracts.
  • Affected components: login/register UI, Microsoft/Google buttons, error/cancel/return handling, translations/tests.
  • Acceptance criteria: one username/password card, or, normal Google/Microsoft alternatives, recovery/register links; prohibited provider-status clutter removed; no linking implication.
  • Required tests: invalid credentials/provider failure/cancel/return, focus/order/labels.
  • Required browser verification: 375/768/1440, light/dark, keyboard/focus, logged-out/provider mocks.
  • Required production verification: real provider smoke only with authorized accounts.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: light/System-theme browser, configured/real-provider and production checks require the UX-002 preference work plus authorized provider/deployment environments.
  • Evidence: docs/verification/ux-001-unified-authentication.md; V-108V-110; focused 13/13, full frontend 47/47 suites and 166/166 tests, production build, responsive dark-theme browser captures at 375/768/1440.
  • Commit: 93b8692 (feat(auth): unify sign-in options).
  • Remaining work: light/System theme browser; configured-provider browser; real authorized Google/Microsoft cancel/return; production smoke. Keep identity migration separate.

UX-002 — Deterministic theme state

  • Source programme: Work Phase 3.
  • Original requirement references: work.md:102-133.
  • Related findings: JT-015.
  • Priority: P2.
  • Dependencies: inspect all theme sources.
  • Affected components: theme provider/bootstrap/local/profile/cross-tab state and tests.
  • Acceptance criteria: saved user > anonymous local > system only in System > default; no unexpected route/nav changes or startup flash; loop-free tab sync.
  • Required tests: Light/Dark/System, login/logout/refresh/navigation/storage/preference listeners/tabs.
  • Required browser verification: 375/768/1440, light/dark/system, refresh/navigation/two tabs/reduced motion.
  • Required production verification: normal browser smoke after deploy.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: production and live authenticated multi-user browser environments are unavailable; repository/browser work is complete.
  • Evidence: docs/verification/ux-002-deterministic-theme-state.md; V-111V-113; focused 6/6, full frontend 48/48 suites and 172/172 tests, build, Light/Dark/System/navigation/refresh/two-tab browser checks and 375/768/1440 captures.
  • Commit: 11734ee (fix(theme): make preference state deterministic).
  • Remaining work: live User A/User B preference switching and production browser smoke; retain existing preference keys during rollout.

QA-001 — Job-analysis and keyword quality

  • Source programme: Work Phase 5; Ollama deterministic workload rule.
  • Original requirement references: work.md:174-263; ollama.md:177-223.
  • Related findings: JT-021 (measurement), AI quality.
  • Priority: P2.
  • Dependencies: PROD-002 fixtures; current pipeline/caching version inventory.
  • Affected components: import cleanup/language/token/stop words/phrases/skills/scoring/prompt/postprocess/storage/UI label.
  • Acceptance criteria: function/filler/chrome suppressed generically; technologies/punctuation/multiword phrases preserved; contextual generic terms; honest label; versioned regeneration behavior.
  • Required tests: seven specified Norwegian/English/mixed/short/noisy/tech/filler fixtures.
  • Required browser verification: result presentation/empty/error/long Norwegian text at three widths/themes.
  • Required production verification: synthetic analysis comparison; no silent historical rewrite.
  • Status: IMPLEMENTED — NOT VERIFIED.
  • Blocker: browser presentation and production comparison remain; deterministic repository work is complete.
  • Evidence: docs/verification/qa-001-job-term-quality.md; V-114V-116; seven required fixtures, focused matcher 15/15, affected backend 54/54, full backend 601/601, focused UI 13/13, full frontend 172/172 and build.
  • Commit: da1aa8b (fix(match): prioritize meaningful job terms).
  • Remaining work: browser empty/error/long Norwegian/three-width/theme presentation; synthetic production comparison. No stored analysis migration exists.

CAREER-001 — Career Workspace action-oriented redesign

  • Source programme: Work Phase 6.
  • Original requirement references: work.md:265-307.
  • Related findings: JT-003, JT-015.
  • Priority: P2.
  • Dependencies: CORE-001 and AI-004 status contract.
  • Affected components: Career Workspace hierarchy/empty/onboarding/import review/completeness/recent docs/status UI.
  • Acceptance criteria: concise actions for profile/import/review/resume/builder/general/job CV/recent/completeness/errors; long paragraph removed; approval gate preserved.
  • Required tests: first/returning/incomplete/processing/failure state and navigation.
  • Required browser verification: three widths, light/dark, keyboard/focus/loading/empty/error/Norwegian.
  • Required production verification: synthetic account smoke.
  • Status: IN PROGRESS.
  • Blocker: browser tooling must be available for completion.
  • Evidence: source requirements and current Career Workspace state hierarchy are next for complete trace; CORE-001 and AI-004 contracts are available.
  • Commit: none.
  • Remaining work: no master-profile overwrite.

CAREER-002 — CV Builder interaction redesign and external research

  • Source programme: Work Phase 8.
  • Original requirement references: work.md:388-452.
  • Related findings: JT-003, JT-015, JT-025.
  • Priority: P2.
  • Dependencies: CAREER-001, AI-004; inspect existing advanced builder before changing it.
  • Affected components: builder list/editor/sections/entries/reorder/visibility/autosave/validation/preview/responsive/accessibility.
  • Acceptance criteria: all specified section/edit/add/delete/reorder/hide/validation/save/nav/preview behaviors while preserving data/templates/render/export/version/import/profile separation.
  • Required tests: editing/collapse/add/delete/reorder/save/failure/persistence/preview.
  • Required browser verification: authorized FlowCV research if accessible, never bypass auth; original JobTracker design at three widths/themes/keyboard/focus.
  • Required production verification: existing variants/edit/export/public render smoke.
  • Status: NOT STARTED.
  • Blocker: FlowCV may require manual authenticated session; implementation can proceed from local evidence if research is labeled blocked.
  • Evidence: existing builder is more complete than the programme's premise; redesign must begin with a real gap analysis.
  • Commit: none.
  • Remaining work: avoid rewriting already-working features.

MAIL-001 — Consolidated job-email hub and explicit sending

  • Source programme: Work Phase 9.
  • Original requirement references: work.md:454-527.
  • Related findings: JT-005, JT-012, JT-015, JT-022, JT-025.
  • Priority: P2.
  • Dependencies: BG-001, OPS-001B/C notifications, POL-001/002, provider tenant safety.
  • Affected components: Gmail Review/Correspondence routes, shared domain/components, Gmail/Graph/IMAP, detection/linking, drafts/send audit/application embedding.
  • Acceptance criteria: one hub plus shared application view; linked/suggested messages; provider identity/search/filter/states; editable draft and explicit confirmed idempotent send; no autonomous AI/send; weak signals never auto-link.
  • Required tests: link/unlink/dismiss/draft/send duplicate/uncertain/provider failure/reauth/two tenants/free/pro/application embed.
  • Required browser verification: all states at three widths/themes/keyboard; mocked providers only unless safe configured account.
  • Required production verification: provider read/draft/send requires explicit authorized synthetic account; never real unsolicited email.
  • Status: NOT STARTED.
  • Blocker: real provider verification external; mocked/local implementation not blocked after dependencies.
  • Evidence: final product decisions in source programme.
  • Commit: none.
  • Remaining work: route compatibility and one data model, no copies.

JOBS-001 — Job-search source and assessment redesign

  • Source programme: Work Phase 4.
  • Original requirement references: work.md:135-172.
  • Related findings: JT-015, JT-021, JT-024.
  • Priority: P2.
  • Dependencies: source provenance inventory; CORE fixes.
  • Affected components: discovery DTO/storage/source labels/filter/sort/cards/import flow.
  • Acceptance criteria: every listing shows honest source/type/original link/retrieval/deadline; derived sources labeled; source preserved on import; scan/search/filter/location/work-mode/errors/duplicates/mobile improved.
  • Required tests: provenance mapping/filter/import preservation/empty/loading/error/duplicates.
  • Required browser verification: three widths/themes/keyboard/long text/Norwegian/import.
  • Required production verification: official NAV/safe provider smoke; unavailable providers labeled.
  • Status: NOT STARTED.
  • Blocker: live provider checks may be external; synthetic fixtures suffice locally.
  • Evidence: source requirement.
  • Commit: none.
  • Remaining work: no scraping or inferred-as-verified source.

JOBS-002 — Applications table and embedded workspace

  • Source programme: Work Phase 11.
  • Original requirement references: work.md:562-634.
  • Related findings: JT-003, JT-004, JT-015, JT-021.
  • Priority: P2.
  • Dependencies: CORE-001/002, MAIL-001 embedding contract, AI-003 status.
  • Affected components: applications table, filters/search/sort, route-backed drawer/modal/full-page fallback, workspace sections/focus/unsaved state.
  • Acceptance criteria: scan-friendly priority columns; list context preserved; deep-link/back-forward/direct URL; accessible focus/close; mobile full-screen; no nested modal; full-page fallback.
  • Required tests: route/history/filter persistence/focus/unsaved/direct link/mobile, tenant authorization.
  • Required browser verification: three widths/themes/keyboard/back-forward/refresh/error/long data.
  • Required production verification: existing application/workspace smoke.
  • Status: NOT STARTED.
  • Blocker: none after dependencies.
  • Evidence: source requirement and existing workspace architecture.
  • Commit: none.
  • Remaining work: do not place every field in table or duplicate workspace data.

UX-003 — Kanban theme-state correction

  • Source programme: Work Phase 10.
  • Original requirement references: work.md:529-560.
  • Related findings: JT-015.
  • Priority: P2.
  • Dependencies: UX-002 shared theme tokens preferably first.
  • Affected components: Kanban column/card/drag/focus/loading/error styles and tests.
  • Acceptance criteria: no white dark-mode targets; all listed drag/empty/card/hover/keyboard/error states have shared-token contrast and light/mobile quality.
  • Required tests: component/visual state coverage.
  • Required browser verification: three widths, light/dark, pointer and keyboard drag, focus/contrast.
  • Required production verification: board smoke.
  • Status: NOT STARTED.
  • Blocker: browser verification required for completion.
  • Evidence: reported visual defect not yet reproduced.
  • Commit: none.
  • Remaining work: smallest token-level root fix.

PRODUCT-001 — Homepage plans and respectful Pro promotion

  • Source programme: Work Phases 12-13.
  • Original requirement references: work.md:636-721.
  • Related findings: JT-012, JT-015, JT-022.
  • Priority: P2.
  • Dependencies: POL-001 canonical policy.
  • Affected components: homepage/pricing/registration/settings/nav/metadata/upgrade prompts/locked states/translations/tests.
  • Acceptance criteria: exactly Free (no AI/core tracking) and Pro (defined AI capabilities); no invented price/trial/limit; central capability data; concise dismissible non-dark-pattern promotion.
  • Required tests: copy/capability consistency, Free/Pro/expired/downgraded locked states, dismissal/no false generation.
  • Required browser verification: homepage and contextual prompts at three widths/themes/keyboard/accessibility.
  • Required production verification: configured price text only if actual billing product exists; otherwise no invented values.
  • Status: NOT STARTED.
  • Blocker: public plan behavior depends on POL-001 compatibility decision; real billing activation is external.
  • Evidence: source requirement.
  • Commit: none.
  • Remaining work: inventory all current contradictory plan claims.

VER-001 — Complete application action matrix and regression pass

  • Source programme: Work Phase 15; Ollama validation/tests.
  • Original requirement references: work.md:779-903; ollama.md:730-798.
  • Related findings: all relevant audit findings, especially JT-014/JT-015/JT-016.
  • Priority: P1 verification gate.
  • Dependencies: all implemented work packages; matrix may be populated incrementally earlier.
  • Affected components: docs/verification/application-action-matrix.md, browser evidence, regression tests.
  • Acceptance criteria: every meaningful safe control/action has route/role/plan/result/path/loading/success/failure/auth/tenant/tests/manual/automated/finding classification; failures fixed or accurately blocked.
  • Required tests: full backend/frontend/Python/E2E plus regressions for confirmed defects.
  • Required browser verification: running app, synthetic users/data, 375/768/1440, themes/keyboard/focus/refresh/back/tabs/slow/error; no real email/paid provider/destructive production action.
  • Required production verification: applicable smoke actions only after deployment; local and production classifications remain distinct.
  • Status: NOT STARTED.
  • Blocker: browser tooling/access and external providers may block individual rows, not the matrix.
  • Evidence: audit user-journey/action gaps.
  • Commit: none.
  • Remaining work: create early and update per package; final sweep last.

REL-001 — Production validation and remaining audit closure

  • Source programme: both final reports and production validation.
  • Original requirement references: work.md:905-922; ollama.md:640-825; audit backlog remaining phases.
  • Related findings: all open findings.
  • Priority: P1 release gate.
  • Dependencies: VER-001, PROD-004, completed repository packages, backup/rollback/access.
  • Affected components: docs/production/production-ai-validation.md, operations runbook, deployment evidence, audit verification logs, final reports.
  • Acceptance criteria: truthful production/local/mocked/blocked matrix; queue/model/routing/restart/tenant/Free-Pro/privacy verified; remaining findings explicitly open/deferred; rollback proven.
  • Required tests: full release command matrix and production synthetic smoke.
  • Required browser verification: production journeys requiring real deployment, no private data in evidence.
  • Required production verification: mandatory for DONE where source programme requires rollout.
  • Status: BLOCKED.
  • Blocker: production access plus unfinished dependencies.
  • Evidence: current production documents explicitly say production data/access not verified.
  • Commit: none.
  • Remaining work: continue safe local packages; do not claim production completion.

Conflict register summary

Full decisions are in docs/work-programmes/decisions.md.

  1. AI provider architecture: ADR-004/current roadmap say one deployment provider; the newer Ollama programme explicitly requires local-first plus controlled fallback. The new programme is the target, implemented centrally and compatibly; old config/models remain for rollback.
  2. Free AI: current code gives Free users limited AI; the new programme says Free has no AI. POL-001 must change behavior server-side without deleting existing user data or renaming persisted roles prematurely.
  3. Production authority: Work says no production deploy unless instructed; Ollama programme and the current request authorize only scoped local-AI production work after inventory/backup/rollback. No other production mutation is authorized.
  4. Schema ownership: OPS-001A chose one EF-owned, provider-conditional migration for UserOperations and deliberately omitted reconciler DDL. MariaDB script generation passes; executable server verification remains.
  5. Compose documentation: docs claim a separate dev override, but the filename is auto-loaded by production deploy. SEC-002 corrects actual behavior.
  6. CV Builder premise: programme asks for capabilities already present. CAREER-002 begins with a browser/code gap analysis and changes only evidenced gaps.