Files
jobtrackingapp/docs/work-programmes/master-work-plan.md
T
cesnimda 3b86ea2da0
CI and Deploy / test (pull_request) Successful in 4m37s
CI and Deploy / deploy (pull_request) Has been skipped
fix(cv): enforce readable render palettes
Choose a contrasting header foreground for custom accents and keep public colour and font overrides inside safe supported values.
2026-08-15 17:08:20 +02:00

809 lines
72 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# JobTracker master work plan
Prepared: 2026-08-02
Authoritative sources:
- `docs/todo/work.md` (UX/reliability programme, lines 1-922)
- `docs/todo/ollama.md` (production local-AI programme, lines 1-825)
- `docs/audits/audit-remediation-backlog.md` (validated security and reliability prerequisites)
This file is the authoritative merged implementation plan. It avoids duplicate implementations: Strategy Snapshot, CV processing, durable operations, notifications, entitlement, AI privacy, provider routing, tenant-safe workers and restart recovery are each represented once and retain references to both source programmes.
## Status and completion rules
Allowed statuses are `NOT STARTED`, `IN PROGRESS`, `IMPLEMENTED — NOT VERIFIED`, `VERIFIED LOCALLY`, `DEPLOYED — NOT VERIFIED`, `DONE`, `BLOCKED`, and `DEFERRED`.
`DONE` requires every applicable acceptance criterion, focused and regression tests, browser/accessibility/theme/mobile checks, tenant and entitlement checks, documentation, migration/rollback evidence, and production verification. Repository-only work that still requires production is at most `VERIFIED LOCALLY`.
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **JOBS-002**.
## Consolidated dependency order
```text
SEC-001 -> SEC-002 -> SEC-003 -> SEC-004
| | \-> SEC-005A -> SEC-005B
| \--------------> BG-001
|
+-> SEC-006 -> SEC-007 -> AI-004
+-> SEC-008 ----------------> SEC-009
CORE-001 -> CORE-002 -> BG-001 -> OPS-001A -> OPS-001B -> OPS-001C
OPS-001A -> POL-001 -> POL-002 -> AI-001 -> AI-002
PROD-002 -> POL-002 -> AI-001
PROD-002 -> PROD-003
PROD-001 -> PROD-003 -> PROD-004
AI-001 + AI-002 -> AI-003 and AI-004
UX-001/UX-002/QA-001 may proceed after their security prerequisites.
CAREER-001 -> CAREER-002; MAIL-001, JOBS-001, JOBS-002, UX-003 and PRODUCT-001 follow foundations.
All implemented surfaces -> VER-001 -> REL-001.
```
Ordering differences from the suggested list:
- SEC-001 canonical origin precedes Microsoft legacy relinking and email recovery because those links cannot prove ownership while request Host can influence their origin.
- SEC-006/SEC-007 parser hardening precedes the CV queue migration; moving an unsafe parser into a queue does not make it safe.
- SEC-008 attachment consistency precedes complete account deletion.
- The synthetic workload inventory/evaluation set (PROD-002) can proceed without production access and should inform routing and benchmarks early.
- Production inventory, benchmark and rollout remain independent blockers; repository-side queue, policy and UX work continues without them.
## Immediate completion queue (2026-08-15)
This queue records the highest-value work that can proceed without production credentials, provider consent or a new product decision. It reuses the work packages below rather than creating duplicate implementations.
| Order | Immediate work | Owning package(s) | Current state and finish line |
|---:|---|---|---|
| 1 | Admin-only deployed-version indicator in the application header | DEP-001, VER-001 | Implemented with authenticated API and shell tests. The badge shows the CI deployment version and exposes the commit SHA in its accessible label/tooltip only for administrators; full regression, remote CI and deployment smoke remain. |
| 2 | Lossless Career field persistence | CAREER-001 | Implemented and locally verified. Manual website/location/contact/date/language values now use a reviewed-data persistence boundary; extraction heuristics remain isolated to extraction. Full remote/production smoke remains. |
| 3 | CV contact/header/sidebar contrast correction | CAREER-002 | Implemented and locally verified. Header/custom-accent and sidebar palettes own readable foregrounds; real Chromium computed-style/overflow checks and a 17-page A4 PDF proof pass. |
| 4 | Dedicated Job Details parity and JOBS-002 closure | JOBS-002 | Next implementable package and in progress. Finish any remaining legacy follow-up/application-package parity, dirty-edit behavior, tenant authorization and 375/768/1440 theme/keyboard/history/error/long-data verification. |
| 5 | Cross-application contrast/accessibility pass | UX-002, UX-003, VER-001 | Queued after the scoped Career/CV corrections. Audit semantic alerts, secondary text, focus, loading/empty/error states and remaining hardcoded colors before documenting larger redesigns. |
| 6 | Honest Free/Pro homepage and upgrade surfaces | PRODUCT-001 | Not started. Inventory existing claims first; do not invent pricing, limits or trial terms before billing configuration is real. |
| 7 | Complete application action matrix and full regression | VER-001 | Not started. Populate incrementally, then run the complete backend/frontend/sidecar/E2E gates and accurately classify external production/provider checks. |
| 8 | Tracking and blocker reconciliation | All | Keep this plan, progress, handoff, verification log and `BLOCKERS.md` aligned after every logical increment; remove stale CI/dependency statements only when current evidence proves them obsolete. |
## Requirement coverage index
| Source section | Covered by |
|---|---|
| Work Phase 1 baseline/plan (36-61) | This master plan, the progress/handoff/decisions files, compatibility pointer under `docs/plans/`, VER-001 |
| Work Phase 2 authentication (63-100) | UX-001, SEC-003, SEC-004, SEC-005 |
| Work Phase 3 theme (102-133) | UX-002 |
| Work Phase 4 job search (135-172) | JOBS-001 |
| Work Phase 5 keyword quality (174-263) | QA-001, PROD-002 |
| Work Phase 6 Career Workspace (265-307) | CAREER-001 |
| Work Phase 7 CV 504 (309-386) | SEC-006, SEC-007, OPS-001A/B/C, AI-001, AI-004 |
| Work Phase 8 CV Builder/FlowCV (388-452) | CAREER-002 |
| Work Phase 9 consolidated email (454-527) | MAIL-001, POL-001, POL-002 |
| Work Phase 10 Kanban dark mode (529-560) | UX-003 |
| Work Phase 11 application table/workspace (562-634) | CORE-002, JOBS-002, AI-003, MAIL-001 |
| Work Phases 12-13 Free/Pro (636-721) | POL-001, PRODUCT-001 |
| Work Phase 14 Strategy Snapshot (723-777) | CORE-001, CORE-002, OPS-001A/B/C, POL-001, POL-002, AI-001, AI-003 |
| Work Phase 15 action verification (779-855) | VER-001 |
| Work quality/browser/completion (857-922) | Every UI package, VER-001, REL-001 |
| Ollama Phases 1-2 inventory/safety (58-176) | PROD-001 |
| Ollama Phase 3 workloads/evaluation (177-258) | PROD-002 |
| Ollama Phases 4-6 candidate/tuning/decision (259-397) | PROD-003 |
| Ollama Phase 7 routing/privacy (398-451) | POL-001, POL-002, AI-002 |
| Ollama Phases 8-9 queue/backpressure (452-573) | BG-001, OPS-001A/B/C, AI-001 |
| Ollama Phase 10 fallback (574-608) | POL-002, AI-002, PROD-004 |
| Ollama Phase 11 frontend states (609-639) | OPS-001C, AI-003, AI-004 |
| Ollama Phases 12-14 observability/rollout/validation (640-775) | PROD-004, REL-001 |
| Ollama tests/report (776-825) | Every AI package, VER-001, REL-001 |
## Work items
### SEC-001 — Canonical external origin and application Host guard
- **Source programme:** shared security prerequisite; Work 17-34; Ollama 26-56; audit P0-2A/JT-002.
- **Original requirement references:** `work.md:17-34`; `ollama.md:26-56`; `audit-remediation-backlog.md` P0-2A.
- **Related findings:** JT-002.
- **Priority:** P0 security prerequisite.
- **Dependencies:** confirmed canonical production URL; none in code.
- **Affected components:** ASP.NET startup/configuration, security-link/OAuth/billing/reminder URL builders, cookie policy, config tests, environment/deploy preflight docs.
- **Acceptance criteria:** Production requires one canonical HTTPS origin; request/forwarded Host never changes an external URL; unknown production Host is rejected; local Development/Test remains explicit and working.
- **Required tests:** origin parser/startup; every URL caller; hostile Host/forwarded headers; Unicode/ports/paths; secure-cookie behavior; relevant backend regression suite.
- **Required browser verification:** local login/reset/verification navigation when a local email sink is available; no visual redesign.
- **Required production verification:** canonical and hostile Host smoke after SEC-002; not required to claim local verification.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** production/ingress verification depends on SEC-002; a live local Production-mode process launch was rejected by the execution policy before starting, so it is not claimed.
- **Evidence:** `docs/verification/sec-001-canonical-origin.md`; `ExternalOriginTests`; focused security/controller slice 79/79; full backend 474/474; Release build; Compose config; normalized deploy-shell syntax.
- **Commit:** none.
- **Remaining work:** verify canonical and hostile Host behavior through the complete proxy path in SEC-002; exercise reset/verification navigation with a safe local email sink; deploy and verify before `DONE`.
### SEC-002 — Production ingress, forwarded headers and Compose separation
- **Source programme:** shared production/security prerequisite; Work 17-34; Ollama 123-176; audit P0-2B/JT-002.
- **Original requirement references:** `work.md:17-34`; `ollama.md:123-176`; audit P0-2B.
- **Related findings:** JT-002, JT-013, JT-020.
- **Priority:** P0.
- **Dependencies:** SEC-001; actual proxy network/IP supplied by operator for production verification.
- **Affected components:** production/development Compose selection, nginx forwarded headers, explicit known proxy/network config, deploy script/runbook, CI deployment invocation.
- **Acceptance criteria:** dev override is never auto-loaded in production; no direct production application ports; exact-host ingress contract; sanitized two-hop forwarding; rollback command documented.
- **Required tests:** merged Compose assertions, production config tests, nginx/proxy integration, deploy shell checks.
- **Required browser verification:** canonical public/API navigation through local proxy.
- **Required production verification:** exact Traefik route, closed ports, correct HTTPS/client IP/cookies.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** external Traefik topology, production CIDR/network inventory, firewall state and provider routes are unavailable for production verification; the pinned nginx base image was not installed locally and was not pulled without internet permission.
- **Evidence:** `docs/verification/sec-002-ingress-compose.md`; production Compose has no published frontend/backend/Ollama ports; dev Compose publishes only 3000/5202/11434; proxy parser tests; nginx syntax/substitution checks; frontend build; backend 476/476.
- **Commit:** none.
- **Remaining work:** inventory/set the non-overlapping production CIDR; verify operator Traefik exact-host/header replacement and firewall; build the pinned image in approved CI; run local/prod proxy and hostile-Host smoke before `DONE`.
### SEC-003 — Microsoft tenant and issuer trust policy
- **Source programme:** Work authentication/audit prerequisite.
- **Original requirement references:** `work.md:91-100`; audit P0-1A/JT-001.
- **Related findings:** JT-001.
- **Priority:** P0.
- **Dependencies:** supported single/multitenant mode configured.
- **Affected components:** Microsoft token validator, smart auth scheme, sign-in configuration, mocked validator tests.
- **Acceptance criteria:** exact issuer/`tid`; (`tid`,`oid`) returned; invalid/missing/mismatched tenant rejected; unused raw bearer trust path removed or proven necessary and hardened.
- **Required tests:** all tenant modes, issuer/audience/signature/lifetime, personal/organizational, same `oid` across tenants.
- **Required browser verification:** mocked Microsoft success/failure/cancel only; real provider later if safely configured.
- **Required production verification:** configured tenant mode and synthetic/provider smoke without exposing tokens.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** none for validator implementation; real Microsoft smoke needs provider configuration.
- **Evidence:** `docs/verification/sec-003-microsoft-tenant.md`; tenant/issuer validator matrix; raw bearer branch removed; focused 42/42 and full backend 491/491; Compose and deploy-shell config checks.
- **Commit:** none.
- **Remaining work:** production inventory/configuration and mocked/real safe provider smoke; SEC-004 canonical pair persistence/relinking must complete before JT-001 closes or Microsoft is enabled in production.
### SEC-004 — Canonical Microsoft links and safe legacy relinking
- **Source programme:** Work authentication/audit prerequisite.
- **Original requirement references:** `work.md:91-100`; audit P0-1B/JT-001.
- **Related findings:** JT-001.
- **Priority:** P0.
- **Dependencies:** SEC-001, SEC-003, SEC-005A and SEC-005B recent reauthentication/email proof.
- **Affected components:** `ApplicationUser`, EF model/migration, auth exchange/link/unlink/recovery UI and APIs.
- **Acceptance criteria:** composite tenant/object key is unique owner; no email auto-link; no silent legacy backfill/merge; legitimate legacy users have explicit non-locking recovery.
- **Required tests:** fresh/legacy SQLite+MariaDB migration, collisions, two tenants/same email, last-credential guard, 2FA, mocked relink.
- **Required browser verification:** local mocked new sign-in and legacy relink.
- **Required production verification:** anonymized legacy inventory before migration; monitored relink window.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** real Microsoft/browser/SMTP and disposable MariaDB checks are unavailable; production legacy inventory is unknown.
- **Evidence:** `docs/verification/sec-004-microsoft-identity.md`; focused auth 34/34; backend 507/507; frontend 152/152 and build; dual-provider SQL; disposable SQLite legacy/unique-index rehearsal.
- **Commit:** none.
- **Remaining work:** real mocked-browser Microsoft popup/relink flow with an SMTP sink; disposable MariaDB migration; production counts-only legacy inventory, rolling-version smoke and monitored relink window before `DONE`.
### SEC-005A — Session and recovery revocation
- **Source programme:** Work auth constraints; shared recovery prerequisite.
- **Original requirement references:** `work.md:17-34,63-100`; audit P0-4A/P0-4B, JT-007/JT-008.
- **Related findings:** JT-007, JT-008.
- **Priority:** P0.
- **Dependencies:** SEC-001; coordinates with SEC-004.
- **Affected components:** logout, password reset/change, local session validation, trusted devices, pending 2FA challenges and auth tests.
- **Acceptance criteria:** logout revokes the exact copied `sid`; reset revokes all sessions/devices without disabling 2FA; password change rotates the current session, revokes others and preserves only the current trusted device; session validation binds `sid` to user; stale pending 2FA fails after a security-stamp change.
- **Required tests:** valid/expired logout cookie; copied session; reset across users/devices; password rotation; trusted-device retention/removal; `sid`/user mismatch; pending 2FA stamp.
- **Required browser verification:** logout in two tabs; password change/reset with a local email sink; 2FA recovery.
- **Required production verification:** copied-cookie/reset/change smoke without logging token values.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** browser and production checks require safe running environments.
- **Evidence:** `docs/verification/sec-005a-session-revocation.md`; focused 48/48; full backend 497/497.
- **Commit:** none.
- **Remaining work:** browser/runtime and production verification before `DONE`; SEC-005B owns email state.
### SEC-005B — Verified registration and pending-email transitions
- **Source programme:** Work auth constraints; shared identity/recovery prerequisite.
- **Original requirement references:** `work.md:17-34,63-100`; audit P0-4B, JT-007/JT-008.
- **Related findings:** JT-007, JT-008.
- **Priority:** P0.
- **Dependencies:** SEC-001, SEC-005A; coordinates with SEC-004.
- **Affected components:** registration, verification/resend, profile DTOs, pending-email request/confirm/cancel APIs, `ApplicationUser`, one additive EF migration/snapshot, auth/profile UI and tests.
- **Acceptance criteria:** verification-required registration creates no session and returns typed 202; active email never changes before proof; latest pending request wins; confirmation uses Identity change-email semantics, conditionally updates username, clears pending state and revokes all sessions/devices.
- **Required tests:** registration/no-cookie transition; verify then login; enumeration-resistant resend; duplicate/latest/mismatched/expired/replayed pending email; username preservation; passwordless/provider users; SQLite and MariaDB migration paths.
- **Required browser verification:** mocked/local-sink register/resend/verify and request/cancel/confirm email at desktop/mobile with keyboard access.
- **Required production verification:** safe SMTP link/origin and version-skew smoke; no real personal address.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** in-app browser localhost access was denied by its admin policy check; no safe SMTP sink, disposable MariaDB, or production environment is available.
- **Evidence:** `docs/verification/sec-005b-email-ownership.md`; focused backend 35/35; full backend 501/501; frontend 151/151 and build; SQLite upgrade and dual-provider migration scripts; isolated API 202/no-cookie and 403/no-cookie checks.
- **Commit:** none.
- **Remaining work:** real-browser desktop/mobile/keyboard flows with a local email sink; expired/replayed token and custom-username integration checks; disposable MariaDB migration execution; production SMTP/origin/version-skew verification before `DONE`.
### SEC-006 — Compatible document-parser dependency update
- **Source programme:** Work CV 504; Ollama parser prerequisite; audit P0-3A.
- **Original requirement references:** `work.md:309-386`; `ollama.md:44-56,177-258`; audit JT-006.
- **Related findings:** JT-006, JT-017.
- **Priority:** P0.
- **Dependencies:** approved package-index access during implementation; synthetic benign corpus.
- **Affected components:** Python requirements/lock/hash, parser tests and image build.
- **Acceptance criteria:** compatible fixed versions; no unaccepted reachable High/Critical parser advisory; clean reproducible install; benign extraction parity.
- **Required tests:** dependency resolution/audit, Python suite, generated benign corpus.
- **Required browser verification:** none for dependency-only package.
- **Required production verification:** image digest and smoke before activation.
- **Status:** `BLOCKED`.
- **Blocker:** repository instructions prohibit internet/package resolution without explicit permission; fixed-version compatibility cannot be resolved or verified offline.
- **Evidence:** audit lists reachable Pillow/pypdf/multipart/Starlette advisories and compatibility conflict.
- **Commit:** none.
- **Remaining work:** explicit package-index permission, compatible fixed-version resolution, lock/hash refresh, audit, benign corpus parity and image smoke; do not execute malicious files.
### SEC-007 — Bounded isolated document processing
- **Source programme:** Work CV 504; Ollama privacy/queue; audit P0-3B/P0-3C.
- **Original requirement references:** `work.md:309-386`; `ollama.md:177-258,452-573`; audit JT-006/JT-011.
- **Related findings:** JT-006, JT-011.
- **Priority:** P0.
- **Dependencies:** SEC-006.
- **Affected components:** backend upload/fallback, FastAPI parser child, queue backpressure, container non-root/resource/tmp cleanup.
- **Acceptance criteria:** bounded file/page/pixel/decompression/memory/time work; child/process group killed; no binary backend fallback; safe cleanup/errors; private tokenized service remains.
- **Required tests:** generated boundary/corrupt fixtures, harmless sleeping child, cancellation/restart cleanup, outage/no-fallback, container assertions.
- **Required browser verification:** synthetic CV upload status/failure; authorized private CV local-only only after safeguards.
- **Required production verification:** measured memory/CPU limits and canary synthetic extraction.
- **Status:** `NOT STARTED`.
- **Blocker:** follows dependency update; production sizing requires access.
- **Evidence:** audit parser call path and limits design.
- **Commit:** none.
- **Remaining work:** split behavioral and container commits if needed.
### SEC-008 — Recoverable attachment mutations
- **Source programme:** audit prerequisite for account lifecycle and workspace files.
- **Original requirement references:** Work 17-34 and file/application requirements; audit P0-5/JT-010.
- **Related findings:** JT-010.
- **Priority:** P0 data integrity.
- **Dependencies:** coordinate file-root/journal format with SEC-009.
- **Affected components:** attachment controller/file helper/reconciler/tests.
- **Acceptance criteria:** every DB/filesystem failure converges to committed or durable retryable state; no silent orphan/missing file; rename is metadata-only; owner/path isolation.
- **Required tests:** invalid later file, cancellation, DB/move/delete failure, restart stages, traversal/symlink, two users.
- **Required browser verification:** upload/rename/delete/refresh with synthetic files.
- **Required production verification:** report-only orphan inventory and monitored journal counters.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** in-app browser localhost is policy-blocked; no production report-only inventory/monitoring or MariaDB environment is available. This host denied disposable symlink creation, so that branch is code-inspected only.
- **Evidence:** audit JT-010 execution path; `docs/verification/sec-008-attachment-consistency.md`; 20/20 focused and 525/525 full backend tests; isolated User A/User B upload/download/rename/delete HTTP rehearsal.
- **Commit:** none.
- **Remaining work:** browser upload/rename/delete/refresh; executable symlink test on a capable host; production report-only orphan inventory and counters; MariaDB runtime; reconcile suffix markers before any rollback.
### SEC-009 — Complete readable export and account deletion lifecycle
- **Source programme:** Work audit constraint; Ollama private-data lifecycle; audit P0-6A/P0-6B.
- **Original requirement references:** `work.md:17-34`; `ollama.md:17-22,427-450`; audit JT-009.
- **Related findings:** JT-009, JT-013, JT-022.
- **Priority:** P0 data lifecycle.
- **Dependencies:** SEC-005 revoke-all, SEC-008, owner inventory, backup-retention/tombstone decision.
- **Affected components:** domain inventory/export ZIP, owner-scoped files/caches/queues, deletion saga, provider tokens, migrations, backup restore/runbooks/UI.
- **Acceptance criteria:** readable complete redacted export; idempotent live deletion across rows/files/tokens/queue/cache; no other tenant impact; backup retention truthful; restore tombstones prevent resurrection.
- **Required tests:** two users/every entity, manifest/checksums/redaction, fault/restart/idempotence, provider failures, disposable restore replay.
- **Required browser verification:** disposable self/admin export/delete and confirmations.
- **Required production verification:** backup retention/tombstone rehearsal before self-service enablement.
- **Status:** `NOT STARTED`.
- **Blocker:** legal/operator retention and production restore decisions; repository work can proceed to disabled/dark launch.
- **Evidence:** audit JT-009 inventory/design.
- **Commit:** none.
- **Remaining work:** owner inventory/export first, deletion second.
### CORE-001 — Restore default SQLite/MariaDB behavior parity
- **Source programme:** Work Strategy/Career failures; audit P1-1.
- **Original requirement references:** `work.md:723-777`; audit JT-003.
- **Related findings:** JT-003.
- **Priority:** P0 broken default workflow.
- **Dependencies:** none.
- **Affected components:** Career/Application workspace date-order/filter queries and provider matrix tests.
- **Acceptance criteria:** variants/runs/history/workspace return correct owner/empty/non-owner results on both supported providers.
- **Required tests:** fresh/seeded HTTP provider matrix, date/month/timezone boundaries.
- **Required browser verification:** SQLite Career/Application workspace after API tests.
- **Required production verification:** MariaDB smoke after deployment.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** production MariaDB execution and browser checks remain unavailable; direct blank-file EF-only migration is separate JT-019 schema-ownership debt while fresh application startup passes.
- **Evidence:** audit runtime reproduction JT-003; `docs/verification/core-001-sqlite-provider-parity.md`; 3/3 real-provider tests; 509/509 backend regression; isolated fresh-SQLite owner/empty/non-owner HTTP matrix.
- **Commit:** none.
- **Remaining work:** browser Career/Application workspace verification and executable MariaDB smoke after safe provider/deployment access; address EF-only blank-chain drift under JT-019 rather than editing already-applied historical migrations here.
### CORE-002 — Remove ambiguous application-workspace routes
- **Source programme:** Work Strategy and embedded workspace; audit P1-2.
- **Original requirement references:** `work.md:562-634,723-777`; audit JT-004.
- **Related findings:** JT-004.
- **Priority:** P0 broken core route.
- **Dependencies:** CORE-001; inventory frontend/API consumers.
- **Affected components:** workspace/timeline/interview controllers, API clients/tests/docs.
- **Acceptance criteria:** one action per verb/path; owner 200, non-owner 404, anonymous 401; UI panels load.
- **Required tests:** route-table uniqueness, HTTP ownership, frontend panel tests.
- **Required browser verification:** direct/deep-link workspace panels and Back/Forward.
- **Required production verification:** authenticated workspace smoke.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** in-app browser localhost is policy-blocked; no production/MariaDB HTTP environment is available.
- **Evidence:** audit runtime ambiguous route reproduction; `docs/verification/core-002-route-uniqueness.md`; reflection route regression; 31/31 focused and 511/511 full backend; 153/153 frontend and build; owner 200/non-owner 404/anonymous 401 HTTP matrix.
- **Commit:** none.
- **Remaining work:** browser direct/deep-link, Back/Forward and rendered-panel verification; production authenticated smoke before `DONE`.
### BG-001 — Tenant-safe hosted-worker foundation
- **Source programme:** both; shared prerequisite.
- **Original requirement references:** `work.md:17-34,723-777`; `ollama.md:44-56,452-529`; audit JT-005.
- **Related findings:** JT-005, JT-012, JT-022.
- **Priority:** P0/P1.
- **Dependencies:** CORE-001/CORE-002; do not activate workers before OPS-001B, POL-001 and POL-002.
- **Affected components:** rules/reminders/export/enrichment/CV/AI hosted services, owner context, worker kill switches and tests.
- **Acceptance criteria:** explicit owner selection, deny-on-null avoided safely, idempotent results, structured failures, no cross-owner work, disabled workers remain off.
- **Required tests:** two-owner/no-HttpContext, enable/disable, restart/retry/clock, fake email/AI.
- **Required browser verification:** notification/result surfaces only after OPS-001C.
- **Required production verification:** one-worker canary and owner-safe metrics.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** activation blocked until policy/notification prerequisites; foundation code is not blocked.
- **Evidence:** audit JT-005 service inspection; `docs/verification/bg-001-tenant-workers.md`; real-SQLite two-owner worker suite with fake email/AI; full backend 532/532; Compose validation; isolated default-off startup/health/no-export check.
- **Commit:** none.
- **Remaining work:** OPS-001B persistent notification/idempotency before reminders/rules; POL-001/002 and durable AI queue before enrichment; restart/clock tests; browser result surfaces; monitored single-worker production canary. Keep all four switches false.
### OPS-001A — Durable operation record and lease state machine
- **Source programme:** both; shared CV/Strategy/AI operation foundation.
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:452-529`.
- **Related findings:** JT-005, JT-013, JT-014, JT-022.
- **Priority:** P1 foundation.
- **Dependencies:** BG-001; explicit schema ownership.
- **Affected components:** `UserOperation` entity, owner/idempotency/claim indexes, state/lease store, provider-aware EF migration and tests.
- **Acceptance criteria:** stable owner-scoped ID; atomic idempotent create/claim; bounded states/retries/leases/deadlines/cancellation; restart recovery; no raw private payload field.
- **Required tests:** concurrent create/claim, two tenants, transition guards, lease expiry/final attempt, cancellation, retry delay, deadlines, migration up/down/provider SQL.
- **Required browser verification:** not applicable until OPS-001C exposes owner APIs.
- **Required production verification:** executable MariaDB upgrade/down rehearsal and monitored schema rollout.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** no disposable MariaDB or production environment; application consumers deliberately not migrated yet.
- **Evidence:** `docs/verification/ops-001a-durable-operations.md`; 7/7 focused and 539/539 full backend tests; SQLite upgrade/down/up and fresh startup; dual-provider scripts.
- **Commit:** none.
- **Remaining work:** MariaDB execution/production rollout; task-specific producers must validate references/policies and use OPS-001B/C rather than storing private payloads.
### OPS-001B — Persistent operation notifications and terminal outbox
- **Source programme:** both; shared completion/failure visibility and reminder safety.
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:512-529,609-639`.
- **Related findings:** JT-005, JT-012, JT-014, JT-022.
- **Priority:** P1 foundation.
- **Dependencies:** OPS-001A; keep real SMTP/AI workers disabled.
- **Affected components:** owner notification entity/store, operation terminal transactions, unread/dismiss state, provider-safe schema and tests.
- **Acceptance criteria:** success/failure/cancellation notification is committed atomically with terminal state; owner isolation; idempotent single notification; no private content; retained across restart.
- **Required tests:** every terminal state, duplicate completion, DB failure rollback, two owners, unread/read/dismiss, migration provider scripts.
- **Required browser verification:** deferred to OPS-001C.
- **Required production verification:** schema rollout and synthetic notification canary only.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** MariaDB execution unavailable; repository implementation can continue.
- **Evidence:** `docs/verification/ops-001b-notifications.md`; 9/9 focused and 541/541 full backend tests; forced transaction rollback; SQLite upgrade/down/up; current model snapshot; generated SQLite/MariaDB up/down SQL.
- **Commit:** none.
- **Remaining work:** execute the migration on MariaDB; expose owner APIs/UI in OPS-001C; complete browser and production canaries. No email delivery is part of this package.
### OPS-001C — Owner operation/notification APIs and frontend queue client
- **Source programme:** both; shared queued-operation UX.
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:499-510,609-639`.
- **Related findings:** JT-014, JT-015, JT-022.
- **Priority:** P1 foundation.
- **Dependencies:** OPS-001A/B; POL-001 locked-state admission precedes AI producers.
- **Affected components:** status/list/cancel/retry APIs, notification read/dismiss APIs, frontend polling/status/notification client and shell badge.
- **Acceptance criteria:** stable status URL, owner-only list/detail/cancel/retry; refresh/navigation recovery; honest states/errors; completion badge/read/dismiss; no duplicate submission or private diagnostics.
- **Required tests:** two-user API, refresh/poll/retry/cancel, invalid/expired IDs, component/keyboard/accessibility states.
- **Required browser verification:** queued/refresh/navigate/retry/cancel/completion notification with synthetic handler at 375/768/1440 and light/dark.
- **Required production verification:** authenticated synthetic polling/notification smoke.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser localhost remains policy-blocked, but repository/API/component work can continue.
- **Evidence:** `docs/verification/ops-001c-operation-ui.md`; 12/12 focused backend, 544/544 backend, 3/3 focused UI, 156/156 frontend and production build; isolated two-user HTTP owner/cross-owner matrix.
- **Commit:** none.
- **Remaining work:** real browser responsive/theme/keyboard/refresh checks, MariaDB/production smoke and feature-specific producers in AI-003/004. No generic create API is exposed.
### POL-001 — Canonical Free/Pro entitlement policy
- **Source programme:** Work Free/Pro and Ollama entitlement enforcement.
- **Original requirement references:** `work.md:636-721`; `ollama.md:17-22,412-449,501-529,638`.
- **Related findings:** JT-012, JT-022.
- **Priority:** P1 security/business policy.
- **Dependencies:** OPS-001A operation admission contract.
- **Affected components:** role/subscription capability service, API authorization, worker admission/recheck, usage accounting, auth DTO, frontend locked states.
- **Acceptance criteria:** exactly Free and Pro externally; Free has no AI; server rejects direct/batch/background bypass; Pro/expired/downgraded/admin behavior consistent; non-AI data remains accessible.
- **Required tests:** endpoint inventory for Free/Pro/expired/downgraded/admin, worker recheck, usage, direct requests and two tenants.
- **Required browser verification:** locked state/upgrade action/dismissal and Pro execution; mobile/theme/accessibility.
- **Required production verification:** configured Stripe/role mapping only when operator activation is approved.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser localhost is denied; Stripe/MariaDB/production are unavailable. Usage accounting is complete only for AI Workspace, so provider rollout remains blocked until durable execution centralizes it.
- **Evidence:** `docs/verification/pol-001-free-pro-entitlements.md`; focused backend 74/74; full backend 568/568; focused frontend 22/22; full frontend 47 suites/157 tests; production build.
- **Commit:** none.
- **Remaining work:** browser locked/Pro state checks; mocked Stripe expiry/downgrade lifecycle; central all-task usage accounting through AI-003/004 producers; production role/config smoke. PRODUCT-001 separately removes the known landing-page price/third-tier/unlimited claims.
### POL-002 — AI privacy, consent and external-fallback policy
- **Source programme:** both.
- **Original requirement references:** `work.md:17-34,495-505,723-777`; `ollama.md:398-451,574-608`.
- **Related findings:** JT-012, JT-022, JT-025.
- **Priority:** P1 privacy/security.
- **Dependencies:** POL-001, PROD-002 task/privacy classification.
- **Affected components:** persistent settings, operation policy snapshot, payload minimization, admin diagnostics, fallback audit, UI privacy explanation.
- **Acceptance criteria:** local-only/default/fallback policy enforced server-side; private categories never leave without permission; minimum payload; provider/reason recorded; opt-out never overridden; no browser secrets.
- **Required tests:** task/privacy matrix, consent changes, payload capture/redaction, fallback allowed/prohibited, entitlement, two tenants.
- **Required browser verification:** user/admin controls and disclosure/locked/failure states.
- **Required production verification:** external egress capture with synthetic data only; no real private CV/email.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser localhost is denied; MariaDB/production/external-provider verification is unavailable. Task-specific payload minimization/accounting depend on AI-003/004.
- **Evidence:** `docs/verification/pol-002-ai-privacy.md`; focused backend 72/72 and final policy 28/28; sidecar 18/18; focused frontend 8/8; full backend 576/576; full frontend 47 suites/158 tests; production build; config and migration script checks.
- **Commit:** none.
- **Remaining work:** browser user/admin disclosure checks; MariaDB and production synthetic egress proof; AI-003/004 task-specific payload minimization, accounting and real producer verification. AI-001/002 now carry rechecked policy/task context and record bounded local-first provenance.
### AI-001 — Durable AI queue, backpressure and operation APIs
- **Source programme:** both.
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:452-573,609-639`.
- **Related findings:** JT-005, JT-011, JT-013, JT-014.
- **Priority:** P1.
- **Dependencies:** BG-001, OPS-001A/B/C, POL-001, POL-002.
- **Affected components:** AI operation handlers/worker, priority/concurrency/capacity/deadline/circuit, API polling/retry/cancel, frontend shared queue UI.
- **Acceptance criteria:** HTTP returns 202/stable URL; bounded priority queue protects Ollama; exact state transitions; no duplicate billing/output; refresh/restart recovery; scheduled jobs cannot starve interactive work.
- **Required tests:** queue capacity/priority, atomic claim, circuit, timeout/retry/jitter, duplicate click/idempotency, cancellation, shutdown/restart, tenant and policy recheck.
- **Required browser verification:** synthetic operation status across refresh/nav/double-click/offline/retry/cancel.
- **Required production verification:** queue depth/age, one-worker canary, Ollama offline/restart and app/worker restart.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** real 202 producers/browser verification depend on AI-003/004; MariaDB/production are unavailable and the worker remains off.
- **Evidence:** `docs/verification/ai-001-durable-ai-queue.md`; focused queue/state/API tests 17/17; full backend 581/581; Compose config and diff checks.
- **Commit:** none.
- **Remaining work:** AI-003/004 task handlers and 202 endpoints; browser refresh/double-click/cancel/retry; MariaDB and monitored single-worker production canary. AI-002 supplies local-first circuit/provenance. Do not create a second CV- or Strategy-specific queue.
### AI-002 — Ollama adapter and local-first provider routing
- **Source programme:** Ollama local-first; Work privacy/Pro constraints.
- **Original requirement references:** `ollama.md:398-451,574-608`; `work.md:17-34,723-777`.
- **Related findings:** JT-012, JT-017, JT-022.
- **Priority:** P1.
- **Dependencies:** PROD-002, POL-001, POL-002, AI-001.
- **Affected components:** central task routing policy, Ollama/external adapters, sidecar/backend provider boundary, circuit/health, provider diagnostics/config.
- **Acceptance criteria:** deterministic then primary local then optional local then permitted external then clear failure; one policy considers task/privacy/entitlement/health/deadline/cost; no simultaneous duplicate completion.
- **Required tests:** routing matrix, Ollama adapter, schema failure, local circuit, fallback allowed/prohibited/unavailable, cost limits and deduplication.
- **Required browser verification:** provider-agnostic queued states and appropriate fallback disclosure.
- **Required production verification:** actual selected local model and controlled synthetic fallback.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser and production checks, actual local-model selection and controlled provider fallback depend on administrator browser policy plus PROD-001/003 access/benchmarks. Repository behavior is not blocked.
- **Evidence:** `docs/verification/ai-002-provider-routing.md`; V-098V-100; focused backend 26/26, full backend 588/588, sidecar fake-transport 22/22, Compose/diff checks pass.
- **Commit:** none.
- **Remaining work:** AI-003/004 must register typed producers/handlers and explicit external task allowlists; complete monthly cross-feature accounting; browser/MariaDB/selected-model/controlled-provider/production verification. Old provider/model configuration remains available for rollback.
### PROD-001 — Read-only production AI inventory and rollout safety
- **Source programme:** Ollama Phases 1-2.
- **Original requirement references:** `ollama.md:58-176`.
- **Related findings:** JT-013, JT-017, JT-020, JT-021.
- **Priority:** P1 production gate.
- **Dependencies:** documented/configured production access; none for repository report templates.
- **Affected components:** production hardware assessment, current Ollama/app/network/config inventory, backup and rollout/rollback report.
- **Acceptance criteria:** sanitized measured OS/CPU/RAM/GPU/storage/Ollama/deployment inventory; no public Ollama; config/backup/restart/interruption/rollback recorded before mutation.
- **Required tests:** read-only commands only; backup mechanism evidence; no secrets/content in reports.
- **Required browser verification:** none.
- **Required production verification:** this item is itself production read-only verification.
- **Status:** `BLOCKED`.
- **Blocker:** repository docs state the local environment has no production route and CI SSH secrets are unavailable; no documented callable host/credential is present.
- **Evidence:** `docs/deployment/backup-restore.md` and `docs/operations/production-backup-verification.md` explicitly record the access gap.
- **Commit:** none.
- **Remaining work:** create sanitized report template locally; operator/documented access required for measured completion.
### PROD-002 — AI workload inventory and synthetic evaluation set
- **Source programme:** Ollama Phase 3; Work keyword/AI/CV/email features.
- **Original requirement references:** `ollama.md:177-258`; `work.md:174-263,309-386,454-527,723-777`.
- **Related findings:** JT-012, JT-022.
- **Priority:** P1.
- **Dependencies:** code inventory; no production access.
- **Affected components:** workload catalog, synthetic/redacted fixtures, deterministic-versus-AI and privacy/latency/output classifications.
- **Acceptance criteria:** every AI task has input/size/output/language/latency/quality/privacy/fallback/interactive/entitlement/current-provider classification; evaluation set covers every listed English/Norwegian/noisy/adversarial/long/invalid case without real data.
- **Required tests:** fixture validity, deterministic expected signals, strict JSON schemas, prompt-injection containment inputs.
- **Required browser verification:** none; fixtures later drive UI packages.
- **Required production verification:** none until benchmark.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** none; authorized private CV is optional local-only and never committed/external.
- **Evidence:** `docs/verification/prod-002-ai-evaluation.md`; `docs/ai/workload-inventory.md`; fixture validation 1/1; full backend 569/569; frontend 47 suites/157 tests and build.
- **Commit:** none.
- **Remaining work:** PROD-003 later executes model benchmarks and sets measured thresholds. Revise classifications if POL-002 route tracing finds an omitted payload; no production/provider work is required for this package.
### PROD-003 — Production model benchmarks and model decision
- **Source programme:** Ollama Phases 4-6.
- **Original requirement references:** `ollama.md:259-397`.
- **Related findings:** JT-021.
- **Priority:** P1 production gate.
- **Dependencies:** PROD-001 measured hardware, PROD-002 evaluation set.
- **Affected components:** benchmark harness/evidence and `ollama-model-benchmark.md`.
- **Acceptance criteria:** exact candidate tags/license/version/quantization/resources/latency/throughput/quality/JSON/Norwegian/injection/failure/repeat results; measured context/tuning; primary/optional/deterministic/external decision.
- **Required tests:** repeated synthetic benchmark at 4K/8K and 16K only if safe; one inference initially; no very large/cloud model.
- **Required browser verification:** none.
- **Required production verification:** measured on actual machine; local workstation results are labeled separately.
- **Status:** `BLOCKED`.
- **Blocker:** PROD-001 production access/hardware inventory.
- **Evidence:** none yet.
- **Commit:** none.
- **Remaining work:** repository harness can be prepared after PROD-002.
### PROD-004 — Local-model rollout, fallback, observability and operations
- **Source programme:** Ollama Phases 9-14.
- **Original requirement references:** `ollama.md:531-775`.
- **Related findings:** JT-005, JT-013, JT-017, JT-021, JT-022.
- **Priority:** P1 production deployment.
- **Dependencies:** AI-001, AI-002, PROD-001/003, verified backup/rollback.
- **Affected components:** Ollama limits/model install, app config/migrations/worker, telemetry/health/runbook, validation matrix.
- **Acceptance criteria:** selected digest installed without deleting old model; bounded Ollama/app queues; local-first default; safe fallback; privacy-safe metrics/health; drain/restart/rollback; full production validation matrix.
- **Required tests:** offline/timeout/restart/congestion/concurrent/fallback/free/pro/two-tenant/notification matrix.
- **Required browser verification:** queued AI journeys in production using synthetic data.
- **Required production verification:** mandatory; no `DONE` without actual deploy, resource observation and restart recovery.
- **Status:** `BLOCKED`.
- **Blocker:** production access plus all dependencies.
- **Evidence:** none yet.
- **Commit:** none.
- **Remaining work:** repository runbooks/config only after measured values; no guessed limits/model.
### AI-003 — Strategy Snapshot durable-operation migration
- **Source programme:** both; one consolidated implementation.
- **Original requirement references:** `work.md:723-777`; `ollama.md:609-639,730-765`.
- **Related findings:** JT-003, JT-004, JT-005, JT-012, JT-014, JT-022.
- **Priority:** P1 broken user workflow.
- **Dependencies:** CORE-001/002, AI-001/002, POL-001/002.
- **Affected components:** Strategy button/API/operation handler/result persistence/UI status/notification.
- **Acceptance criteria:** root timeout reproduced; enqueue returns 202; stable result; success/failure/timeout/cancel/retry/idempotent double-click/refresh/restart; no duplicate usage/output.
- **Required tests:** endpoint/handler/provider fakes, all required states, entitlement/privacy/tenant checks, E2E.
- **Required browser verification:** complete queue/status/error/retry/cancel/refresh/back-forward/mobile/theme flow.
- **Required production verification:** local model success, timeout and restart recovery.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser localhost policy, selected local model, MariaDB, restart canary and production access remain unavailable; worker stays default-off.
- **Evidence:** `docs/verification/ai-003-strategy-snapshot-queue.md`; verification-log V-101V-103; `docs/audits/evidence/ai-003/README.md`.
- **Commit:** `a621226` (`feat(ai): queue strategy snapshots`).
- **Remaining work:** real browser/mobile/theme/refresh/back-forward checks; selected-model timeout/quality test; MariaDB and production single-worker restart/canary/rollback; complete cross-feature usage accounting. No Strategy-specific queue was created.
### AI-004 — CV-processing 504 and durable-operation migration
- **Source programme:** both; one consolidated implementation.
- **Original requirement references:** `work.md:309-386`; `ollama.md:609-639,730-765`.
- **Related findings:** JT-006, JT-011, JT-014.
- **Priority:** P1 broken user workflow/security.
- **Dependencies:** SEC-006/007, OPS-001A/B/C, AI-001; authorized private file optional only after safe fixture reproduction.
- **Affected components:** browser upload/API/proxy/artifact/parser/normalization/result polling/recovery/UI queue states.
- **Acceptance criteria:** 504 origin established; enqueue/persist/progress/result; bounded processing/retry/cancel/cleanup; restart recovery; no timeout inflation; review gate preserved.
- **Required tests:** safe synthetic PDFs/DOCX/images, proxy/backend/parser/provider failure, duplicate/refresh/restart, E2E.
- **Required browser verification:** synthetic CV first; authorized private file via temporary local copy only, never logged/committed/external.
- **Required production verification:** synthetic/local-only canary, no external payload, restart recovery.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** SEC-006 dependency upgrades need internet permission; browser/private-file/MariaDB/production reproduction remains unavailable. Synthetic repository work can continue.
- **Evidence:** `docs/verification/ai-004-cv-processing-queue.md`; V-104V-107; real SQLite synthetic integration proves 202/active deduplication/owner-scoped handler/retry provenance/notification/review gate; backend 594/594; frontend 161/161 and build.
- **Commit:** `c3c5af8` (`feat(cv)!: queue durable processing`).
- **Remaining work:** SEC-006/007 parser dependency/isolation and complete parser cancellation; browser synthetic upload/refresh/retry/cancel/review at required widths/themes/keyboard; selected-model and worker-restart canary; MariaDB/production rollout. Reconcile dormant extraction-row status immediately when an operation is cancelled before claim. Do not use the private CV before safeguards.
### UX-001 — Unified authentication page
- **Source programme:** Work Phase 2.
- **Original requirement references:** `work.md:63-100`.
- **Related findings:** JT-001, JT-007, JT-008, JT-015.
- **Priority:** P2 after auth safety.
- **Dependencies:** SEC-003/004/005 behavior contracts.
- **Affected components:** login/register UI, Microsoft/Google buttons, error/cancel/return handling, translations/tests.
- **Acceptance criteria:** one username/password card, `or`, normal Google/Microsoft alternatives, recovery/register links; prohibited provider-status clutter removed; no linking implication.
- **Required tests:** invalid credentials/provider failure/cancel/return, focus/order/labels.
- **Required browser verification:** 375/768/1440, light/dark, keyboard/focus, logged-out/provider mocks.
- **Required production verification:** real provider smoke only with authorized accounts.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** light/System-theme browser, configured/real-provider and production checks require the UX-002 preference work plus authorized provider/deployment environments.
- **Evidence:** `docs/verification/ux-001-unified-authentication.md`; V-108V-110; focused 13/13, full frontend 47/47 suites and 166/166 tests, production build, responsive dark-theme browser captures at 375/768/1440.
- **Commit:** `93b8692` (`feat(auth): unify sign-in options`).
- **Remaining work:** light/System theme browser; configured-provider browser; real authorized Google/Microsoft cancel/return; production smoke. Keep identity migration separate.
### UX-002 — Deterministic theme state
- **Source programme:** Work Phase 3.
- **Original requirement references:** `work.md:102-133`.
- **Related findings:** JT-015.
- **Priority:** P2.
- **Dependencies:** inspect all theme sources.
- **Affected components:** theme provider/bootstrap/local/profile/cross-tab state and tests.
- **Acceptance criteria:** saved user > anonymous local > system only in System > default; no unexpected route/nav changes or startup flash; loop-free tab sync.
- **Required tests:** Light/Dark/System, login/logout/refresh/navigation/storage/preference listeners/tabs.
- **Required browser verification:** 375/768/1440, light/dark/system, refresh/navigation/two tabs/reduced motion.
- **Required production verification:** normal browser smoke after deploy.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** production and live authenticated multi-user browser environments are unavailable; repository/browser work is complete.
- **Evidence:** `docs/verification/ux-002-deterministic-theme-state.md`; V-111V-113; focused 6/6, full frontend 48/48 suites and 172/172 tests, build, Light/Dark/System/navigation/refresh/two-tab browser checks and 375/768/1440 captures.
- **Commit:** `11734ee` (`fix(theme): make preference state deterministic`).
- **Remaining work:** live User A/User B preference switching and production browser smoke; retain existing preference keys during rollout.
### QA-001 — Job-analysis and keyword quality
- **Source programme:** Work Phase 5; Ollama deterministic workload rule.
- **Original requirement references:** `work.md:174-263`; `ollama.md:177-223`.
- **Related findings:** JT-021 (measurement), AI quality.
- **Priority:** P2.
- **Dependencies:** PROD-002 fixtures; current pipeline/caching version inventory.
- **Affected components:** import cleanup/language/token/stop words/phrases/skills/scoring/prompt/postprocess/storage/UI label.
- **Acceptance criteria:** function/filler/chrome suppressed generically; technologies/punctuation/multiword phrases preserved; contextual generic terms; honest label; versioned regeneration behavior.
- **Required tests:** seven specified Norwegian/English/mixed/short/noisy/tech/filler fixtures.
- **Required browser verification:** result presentation/empty/error/long Norwegian text at three widths/themes.
- **Required production verification:** synthetic analysis comparison; no silent historical rewrite.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser presentation and production comparison remain; deterministic repository work is complete.
- **Evidence:** `docs/verification/qa-001-job-term-quality.md`; V-114V-116; seven required fixtures, focused matcher 15/15, affected backend 54/54, full backend 601/601, focused UI 13/13, full frontend 172/172 and build.
- **Commit:** `da1aa8b` (`fix(match): prioritize meaningful job terms`).
- **Remaining work:** browser empty/error/long Norwegian/three-width/theme presentation; synthetic production comparison. No stored analysis migration exists.
### CAREER-001 — Career Workspace action-oriented redesign
- **Source programme:** Work Phase 6.
- **Original requirement references:** `work.md:265-307`.
- **Related findings:** JT-003, JT-015.
- **Priority:** P2.
- **Dependencies:** CORE-001 and AI-004 status contract.
- **Affected components:** Career Workspace hierarchy/empty/onboarding/import review/completeness/recent docs/status UI.
- **Acceptance criteria:** concise actions for profile/import/review/resume/builder/general/job CV/recent/completeness/errors; long paragraph removed; approval gate preserved.
- **Required tests:** first/returning/incomplete/processing/failure state and navigation.
- **Required browser verification:** three widths, light/dark, keyboard/focus/loading/empty/error/Norwegian.
- **Required production verification:** synthetic account smoke.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** browser session was already finalized; three-width/theme/keyboard/Norwegian checks and production synthetic-account smoke remain.
- **Evidence:** `docs/verification/career-001-career-workspace.md`; V-117V-119, V-164 and V-167; focused Career/Profile UI 17/17, affected backend 112/112, full backend 642/642, extraction backend 8/8, sidecar 22/22 and production build. State-aware actions/recent CVs are implemented, extraction polling no longer overwrites unsaved form state, reviewed values round-trip without extraction reinterpretation, and the Apply/Discard gate is unchanged.
- **Commit:** `268b3a0` (`feat(career): clarify workspace actions`) plus the V-164 polling and V-167 persistence checkpoints.
- **Remaining work:** browser and production gates. Live model-quality benchmarking and deeper builder interaction belong to CAREER-002.
### CAREER-002 — CV Builder interaction redesign and external research
- **Source programme:** Work Phase 8.
- **Original requirement references:** `work.md:388-452`.
- **Related findings:** JT-003, JT-015, JT-025.
- **Priority:** P2.
- **Dependencies:** CAREER-001, AI-004; inspect existing advanced builder before changing it.
- **Affected components:** builder list/editor/sections/entries/reorder/visibility/autosave/validation/preview/responsive/accessibility.
- **Acceptance criteria:** all specified section/edit/add/delete/reorder/hide/validation/save/nav/preview behaviors while preserving data/templates/render/export/version/import/profile separation.
- **Required tests:** editing/collapse/add/delete/reorder/save/failure/persistence/preview.
- **Required browser verification:** authorized FlowCV research if accessible, never bypass auth; original JobTracker design at three widths/themes/keyboard/focus.
- **Required production verification:** existing variants/edit/export/public render smoke.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** authenticated JobTracker three-width/theme/keyboard checks and production synthetic-variant smoke require their runtime environments.
- **Evidence:** `docs/verification/career-002-cv-builder.md`; V-120V-125, V-165 and V-168. Builder/public UI 22/22 and renderer/templates 25/25 pass. Real Chromium confirms contrast ownership and zero overflow for default/light custom/sidebar palettes; a harder pathological fixture produces a readable 17-page A4 PDF with final-page text and no text shrinking.
- **Commit:** `b58cc19`, `a5b74e0`, `2043349` plus the V-165 checkpoint.
- **Remaining work:** complete authenticated application-browser/production gates and the honest deployed DOCX capability check. Public competitor-pattern research is complete; no authenticated competitor session is claimed.
### MAIL-001 — Consolidated job-email hub and explicit sending
- **Source programme:** Work Phase 9.
- **Original requirement references:** `work.md:454-527`.
- **Related findings:** JT-005, JT-012, JT-015, JT-022, JT-025.
- **Priority:** P2.
- **Dependencies:** BG-001, OPS-001B/C notifications, POL-001/002, provider tenant safety.
- **Affected components:** Gmail Review/Correspondence routes, shared domain/components, Gmail/Graph/IMAP, detection/linking, drafts/send audit/application embedding.
- **Acceptance criteria:** one hub plus shared application view; linked/suggested messages; provider identity/search/filter/states; editable draft and explicit confirmed idempotent send; no autonomous AI/send; weak signals never auto-link.
- **Required tests:** link/unlink/dismiss/draft/send duplicate/uncertain/provider failure/reauth/two tenants/free/pro/application embed.
- **Required browser verification:** all states at three widths/themes/keyboard; mocked providers only unless safe configured account.
- **Required production verification:** provider read/draft/send requires explicit authorized synthetic account; never real unsolicited email.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** real provider/re-consent, full SEC-009 deletion, MariaDB, production and required 375/768/1440/theme/keyboard browser gates are unavailable or require new authority.
- **Evidence:** `docs/verification/mail-001-job-email-hub.md`; V-126V-153. Draft/new-message UI 13/13, API/idempotency/rotation 10/10, persistence 1/1 with dual-provider reversible SQL and readable export 4/4; Free send policy 7/7; provider states 9/9; hub unlink 8/8 UI and 2/2 API; shared application context focused 10/10; prior send export/cascade focused 16/16; recovery/send focused 10/10; legacy follow-up/worker 10/10; delivery/capability 18/18; provider/correspondence 5/5; hub detail 5/5; backend 630/630; frontend 50/50 suites and 198/198 tests plus build/audit; local empty/disconnected and compatibility-route browser smoke at 1280×720.
- **Commit:** `6008b4a` (hub), `536d403` (neutral reads), `a20775c` (safe detail), `653f011` (ledger), `e9937ac` (Gmail/Graph delivery adapters and consent), `123fc55` (explicit-confirmed send API), `449faeb` (confirmed reply composer), `ee5ef7e` (interrupted-send recovery), `8fe3903` (legacy SMTP retirement), `aff34cc` (content-free export and cascade evidence), `ff547df` (shared application context), `1dabbeb` (confirmed hub unlink), `f9e641c` (honest provider states), `7f41cb2` (Free email policy regression), `14b396a` (inert tenant draft persistence), `2fa4e38` (owner-isolated readable draft export), `a9bb22e` (tenant-safe revisioned draft API), `80b5532` (persisted draft send identity), `d3d2b67` (saved reply recovery/conflicts), `29de263` (definitive-failure identity rotation), `b735963` (new-message job/provider drafting).
- **Remaining work:** full account deletion remains SEC-009; provider mailbox category capabilities require separately authorized scopes/re-consent and remain absent; searchable selection beyond the 100 recent jobs; browser/production verification. Existing connections need explicit re-consent; IMAP remains read-only. No real email; uncertain sends need manual reconciliation. JT-019 blocks a clean full-chain SQLite rehearsal before the new draft migration.
### JOBS-001 — Job-search source and assessment redesign
- **Source programme:** Work Phase 4.
- **Original requirement references:** `work.md:135-172`.
- **Related findings:** JT-015, JT-021, JT-024.
- **Priority:** P2.
- **Dependencies:** source provenance inventory; CORE fixes.
- **Affected components:** discovery DTO/storage/source labels/filter/sort/cards/import flow.
- **Acceptance criteria:** every listing shows honest source/type/original link/retrieval/deadline; derived sources labeled; source preserved on import; scan/search/filter/location/work-mode/errors/duplicates/mobile improved.
- **Required tests:** provenance mapping/filter/import preservation/empty/loading/error/duplicates.
- **Required browser verification:** three widths/themes/keyboard/long text/Norwegian/import.
- **Required production verification:** official NAV/safe provider smoke; unavailable providers labeled.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** live official NAV compatibility and production smoke remain external; browser data/import was mocked.
- **Evidence:** `docs/verification/jobs-001-job-discovery.md`; V-154V-156. Verified source/acquisition/retrieval/deadline/import, honest result states/retry/sorts/missing-data disclosure, feed duplicate withdrawal and mocked browser journey at 375/768/1440 with light/dark, keyboard, long Norwegian content and reviewed import; backend 631/631, frontend 201/201, Playwright 5/5 and production build pass.
- **Commit:** `511a9f6` (honest provenance/import), `3f74b23` (result states/sort), `82f4526` (duplicate/browser/contrast regression and evidence).
- **Remaining work:** live NAV compatibility, native mobile assistive-technology and production smoke. Add source filtering only when more than one real source is available.
### JOBS-002 — Applications table and dedicated workspace
- **Source programme:** Work Phase 11.
- **Original requirement references:** `work.md:562-634`.
- **Related findings:** JT-003, JT-004, JT-015, JT-021.
- **Priority:** P2.
- **Dependencies:** CORE-001/002, MAIL-001 embedding contract, AI-003 status.
- **Affected components:** applications table, filters/search/sort, canonical dedicated route, workspace sections/focus/unsaved state.
- **Acceptance criteria:** scan-friendly priority columns; list context preserved; deep-link/back-forward/direct URL; accessible focus/return; responsive dedicated page; no job-details popup.
- **Required tests:** route/history/filter persistence/focus/unsaved/direct link/mobile, tenant authorization.
- **Required browser verification:** three widths/themes/keyboard/back-forward/refresh/error/long data.
- **Required production verification:** existing application/workspace smoke.
- **Status:** `IN PROGRESS`.
- **Blocker:** none after dependencies.
- **Evidence:** V-158V-162; `docs/verification/jobs-002-application-workspace.md`.
- **Commit:** `bd5362c` (URL-owned list state), `109745e` (canonical dedicated page/table/sidebar integration).
- **Remaining work:** canonical `/jobs/:id`, row/card navigation, compact priority columns, richer job details, contextual links, sidebar cleanup and notification popover are implemented. Still required: confirm section dirty-edit behavior; browser widths/themes/keyboard/history/error/long-data checks; authorization regression and production smoke. Do not place every field in the table or duplicate workspace data.
### UX-003 — Kanban theme-state correction
- **Source programme:** Work Phase 10.
- **Original requirement references:** `work.md:529-560`.
- **Related findings:** JT-015.
- **Priority:** P2.
- **Dependencies:** UX-002 shared theme tokens preferably first.
- **Affected components:** Kanban column/card/drag/focus/loading/error styles and tests.
- **Acceptance criteria:** no white dark-mode targets; all listed drag/empty/card/hover/keyboard/error states have shared-token contrast and light/mobile quality.
- **Required tests:** component/visual state coverage.
- **Required browser verification:** three widths, light/dark, pointer and keyboard drag, focus/contrast.
- **Required production verification:** board smoke.
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
- **Blocker:** production board smoke and native assistive-device testing remain external.
- **Evidence:** `docs/verification/ux-003-kanban-theme.md`; V-157. Confirmed white dark-mode columns, then verified shared theme surfaces, pointer/keyboard/invalid/failure/loading states, 1440/768/375 behavior and dark/light contrast; component 7/7, frontend 204/204, Playwright 6/6 and build pass.
- **Commit:** `fb6f17e` (theme/state/keyboard/mobile root fix and evidence), `4e5ce0c` (required-width and real browser hover/drag verification).
- **Remaining work:** production board smoke and native assistive-device validation only.
### PRODUCT-001 — Homepage plans and respectful Pro promotion
- **Source programme:** Work Phases 12-13.
- **Original requirement references:** `work.md:636-721`.
- **Related findings:** JT-012, JT-015, JT-022.
- **Priority:** P2.
- **Dependencies:** POL-001 canonical policy.
- **Affected components:** homepage/pricing/registration/settings/nav/metadata/upgrade prompts/locked states/translations/tests.
- **Acceptance criteria:** exactly Free (no AI/core tracking) and Pro (defined AI capabilities); no invented price/trial/limit; central capability data; concise dismissible non-dark-pattern promotion.
- **Required tests:** copy/capability consistency, Free/Pro/expired/downgraded locked states, dismissal/no false generation.
- **Required browser verification:** homepage and contextual prompts at three widths/themes/keyboard/accessibility.
- **Required production verification:** configured price text only if actual billing product exists; otherwise no invented values.
- **Status:** `NOT STARTED`.
- **Blocker:** public plan behavior depends on POL-001 compatibility decision; real billing activation is external.
- **Evidence:** source requirement.
- **Commit:** none.
- **Remaining work:** inventory all current contradictory plan claims.
### VER-001 — Complete application action matrix and regression pass
- **Source programme:** Work Phase 15; Ollama validation/tests.
- **Original requirement references:** `work.md:779-903`; `ollama.md:730-798`.
- **Related findings:** all relevant audit findings, especially JT-014/JT-015/JT-016.
- **Priority:** P1 verification gate.
- **Dependencies:** all implemented work packages; matrix may be populated incrementally earlier.
- **Affected components:** `docs/verification/application-action-matrix.md`, browser evidence, regression tests.
- **Acceptance criteria:** every meaningful safe control/action has route/role/plan/result/path/loading/success/failure/auth/tenant/tests/manual/automated/finding classification; failures fixed or accurately blocked.
- **Required tests:** full backend/frontend/Python/E2E plus regressions for confirmed defects.
- **Required browser verification:** running app, synthetic users/data, 375/768/1440, themes/keyboard/focus/refresh/back/tabs/slow/error; no real email/paid provider/destructive production action.
- **Required production verification:** applicable smoke actions only after deployment; local and production classifications remain distinct.
- **Status:** `NOT STARTED`.
- **Blocker:** browser tooling/access and external providers may block individual rows, not the matrix.
- **Evidence:** audit user-journey/action gaps.
- **Commit:** none.
- **Remaining work:** create early and update per package; final sweep last.
### DEP-001 — Frontend advisory deployment gate
- **Source programme:** live deployment blocker reported 2026-08-10; audit supply-chain finding.
- **Original requirement references:** user deployment failure report; JT-017.
- **Related findings:** JT-017.
- **Priority:** P0 release blocker.
- **Dependencies:** none for repository remediation; CI/live access for final verification.
- **Affected components:** `job-tracker-ui/package.json`, lockfile, RouterProvider compatibility and Jest jsdom setup.
- **Acceptance criteria:** npm audit is clean without suppressing advisories; production build and route regressions pass; CI consumes the fixed lockfile; live deployment proceeds.
- **Required tests:** resolved dependency tree, `npm audit`, focused router tests, full frontend tests and production build.
- **Required browser verification:** route/navigation smoke after deployment; existing automated route coverage is required before push.
- **Required production verification:** CI audit and live deployment from the fixed commit.
- **Status:** `VERIFIED LOCALLY`.
- **Blocker:** final deployment verification depends on the remote CI/live environment.
- **Evidence:** `docs/verification/dep-001-frontend-advisories.md`; V-137/V-141; audit 0 vulnerabilities, focused 24/24, full 190/190 and production build pass; Gitea run 609 passed complete pull-request CI in 4m20s after the stale browser assertion correction.
- **Commit:** `b55a592` (pushed).
- **Remaining work:** the admin-only header version indicator is implemented on the release branch; run full/remote gates, merge/deploy from `main`, confirm the visible badge matches the CI run version and production commit, run route smoke, and update to `DONE` only after production verification.
### REL-001 — Production validation and remaining audit closure
- **Source programme:** both final reports and production validation.
- **Original requirement references:** `work.md:905-922`; `ollama.md:640-825`; audit backlog remaining phases.
- **Related findings:** all open findings.
- **Priority:** P1 release gate.
- **Dependencies:** VER-001, PROD-004, completed repository packages, backup/rollback/access.
- **Affected components:** `docs/production/production-ai-validation.md`, operations runbook, deployment evidence, audit verification logs, final reports.
- **Acceptance criteria:** truthful production/local/mocked/blocked matrix; queue/model/routing/restart/tenant/Free-Pro/privacy verified; remaining findings explicitly open/deferred; rollback proven.
- **Required tests:** full release command matrix and production synthetic smoke.
- **Required browser verification:** production journeys requiring real deployment, no private data in evidence.
- **Required production verification:** mandatory for `DONE` where source programme requires rollout.
- **Status:** `BLOCKED`.
- **Blocker:** production access plus unfinished dependencies.
- **Evidence:** current production documents explicitly say production data/access not verified.
- **Commit:** none.
- **Remaining work:** continue safe local packages; do not claim production completion.
## Conflict register summary
Full decisions are in `docs/work-programmes/decisions.md`.
1. **AI provider architecture:** ADR-004/current roadmap say one deployment provider; the newer Ollama programme explicitly requires local-first plus controlled fallback. The new programme is the target, implemented centrally and compatibly; old config/models remain for rollback.
2. **Free AI:** current code gives Free users limited AI; the new programme says Free has no AI. POL-001 must change behavior server-side without deleting existing user data or renaming persisted roles prematurely.
3. **Production authority:** Work says no production deploy unless instructed; Ollama programme and the current request authorize only scoped local-AI production work after inventory/backup/rollback. No other production mutation is authorized.
4. **Schema ownership:** OPS-001A chose one EF-owned, provider-conditional migration for `UserOperations` and deliberately omitted reconciler DDL. MariaDB script generation passes; executable server verification remains.
5. **Compose documentation:** docs claim a separate dev override, but the filename is auto-loaded by production deploy. SEC-002 corrects actual behavior.
6. **CV Builder premise:** programme asks for capabilities already present. CAREER-002 begins with a browser/code gap analysis and changes only evidenced gaps.