776 lines
64 KiB
Markdown
776 lines
64 KiB
Markdown
# JobTracker master work plan
|
||
|
||
Prepared: 2026-08-02
|
||
|
||
Authoritative sources:
|
||
|
||
- `docs/todo/work.md` (UX/reliability programme, lines 1-922)
|
||
- `docs/todo/ollama.md` (production local-AI programme, lines 1-825)
|
||
- `docs/audits/audit-remediation-backlog.md` (validated security and reliability prerequisites)
|
||
|
||
This file is the authoritative merged implementation plan. It avoids duplicate implementations: Strategy Snapshot, CV processing, durable operations, notifications, entitlement, AI privacy, provider routing, tenant-safe workers and restart recovery are each represented once and retain references to both source programmes.
|
||
|
||
## Status and completion rules
|
||
|
||
Allowed statuses are `NOT STARTED`, `IN PROGRESS`, `IMPLEMENTED — NOT VERIFIED`, `VERIFIED LOCALLY`, `DEPLOYED — NOT VERIFIED`, `DONE`, `BLOCKED`, and `DEFERRED`.
|
||
|
||
`DONE` requires every applicable acceptance criterion, focused and regression tests, browser/accessibility/theme/mobile checks, tenant and entitlement checks, documentation, migration/rollback evidence, and production verification. Repository-only work that still requires production is at most `VERIFIED LOCALLY`.
|
||
|
||
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **MAIL-001**.
|
||
|
||
## Consolidated dependency order
|
||
|
||
```text
|
||
SEC-001 -> SEC-002 -> SEC-003 -> SEC-004
|
||
| | \-> SEC-005A -> SEC-005B
|
||
| \--------------> BG-001
|
||
|
|
||
+-> SEC-006 -> SEC-007 -> AI-004
|
||
+-> SEC-008 ----------------> SEC-009
|
||
|
||
CORE-001 -> CORE-002 -> BG-001 -> OPS-001A -> OPS-001B -> OPS-001C
|
||
OPS-001A -> POL-001 -> POL-002 -> AI-001 -> AI-002
|
||
PROD-002 -> POL-002 -> AI-001
|
||
PROD-002 -> PROD-003
|
||
PROD-001 -> PROD-003 -> PROD-004
|
||
AI-001 + AI-002 -> AI-003 and AI-004
|
||
|
||
UX-001/UX-002/QA-001 may proceed after their security prerequisites.
|
||
CAREER-001 -> CAREER-002; MAIL-001, JOBS-001, JOBS-002, UX-003 and PRODUCT-001 follow foundations.
|
||
All implemented surfaces -> VER-001 -> REL-001.
|
||
```
|
||
|
||
Ordering differences from the suggested list:
|
||
|
||
- SEC-001 canonical origin precedes Microsoft legacy relinking and email recovery because those links cannot prove ownership while request Host can influence their origin.
|
||
- SEC-006/SEC-007 parser hardening precedes the CV queue migration; moving an unsafe parser into a queue does not make it safe.
|
||
- SEC-008 attachment consistency precedes complete account deletion.
|
||
- The synthetic workload inventory/evaluation set (PROD-002) can proceed without production access and should inform routing and benchmarks early.
|
||
- Production inventory, benchmark and rollout remain independent blockers; repository-side queue, policy and UX work continues without them.
|
||
|
||
## Requirement coverage index
|
||
|
||
| Source section | Covered by |
|
||
|---|---|
|
||
| Work Phase 1 baseline/plan (36-61) | This master plan, the progress/handoff/decisions files, compatibility pointer under `docs/plans/`, VER-001 |
|
||
| Work Phase 2 authentication (63-100) | UX-001, SEC-003, SEC-004, SEC-005 |
|
||
| Work Phase 3 theme (102-133) | UX-002 |
|
||
| Work Phase 4 job search (135-172) | JOBS-001 |
|
||
| Work Phase 5 keyword quality (174-263) | QA-001, PROD-002 |
|
||
| Work Phase 6 Career Workspace (265-307) | CAREER-001 |
|
||
| Work Phase 7 CV 504 (309-386) | SEC-006, SEC-007, OPS-001A/B/C, AI-001, AI-004 |
|
||
| Work Phase 8 CV Builder/FlowCV (388-452) | CAREER-002 |
|
||
| Work Phase 9 consolidated email (454-527) | MAIL-001, POL-001, POL-002 |
|
||
| Work Phase 10 Kanban dark mode (529-560) | UX-003 |
|
||
| Work Phase 11 application table/workspace (562-634) | CORE-002, JOBS-002, AI-003, MAIL-001 |
|
||
| Work Phases 12-13 Free/Pro (636-721) | POL-001, PRODUCT-001 |
|
||
| Work Phase 14 Strategy Snapshot (723-777) | CORE-001, CORE-002, OPS-001A/B/C, POL-001, POL-002, AI-001, AI-003 |
|
||
| Work Phase 15 action verification (779-855) | VER-001 |
|
||
| Work quality/browser/completion (857-922) | Every UI package, VER-001, REL-001 |
|
||
| Ollama Phases 1-2 inventory/safety (58-176) | PROD-001 |
|
||
| Ollama Phase 3 workloads/evaluation (177-258) | PROD-002 |
|
||
| Ollama Phases 4-6 candidate/tuning/decision (259-397) | PROD-003 |
|
||
| Ollama Phase 7 routing/privacy (398-451) | POL-001, POL-002, AI-002 |
|
||
| Ollama Phases 8-9 queue/backpressure (452-573) | BG-001, OPS-001A/B/C, AI-001 |
|
||
| Ollama Phase 10 fallback (574-608) | POL-002, AI-002, PROD-004 |
|
||
| Ollama Phase 11 frontend states (609-639) | OPS-001C, AI-003, AI-004 |
|
||
| Ollama Phases 12-14 observability/rollout/validation (640-775) | PROD-004, REL-001 |
|
||
| Ollama tests/report (776-825) | Every AI package, VER-001, REL-001 |
|
||
|
||
## Work items
|
||
|
||
### SEC-001 — Canonical external origin and application Host guard
|
||
|
||
- **Source programme:** shared security prerequisite; Work 17-34; Ollama 26-56; audit P0-2A/JT-002.
|
||
- **Original requirement references:** `work.md:17-34`; `ollama.md:26-56`; `audit-remediation-backlog.md` P0-2A.
|
||
- **Related findings:** JT-002.
|
||
- **Priority:** P0 security prerequisite.
|
||
- **Dependencies:** confirmed canonical production URL; none in code.
|
||
- **Affected components:** ASP.NET startup/configuration, security-link/OAuth/billing/reminder URL builders, cookie policy, config tests, environment/deploy preflight docs.
|
||
- **Acceptance criteria:** Production requires one canonical HTTPS origin; request/forwarded Host never changes an external URL; unknown production Host is rejected; local Development/Test remains explicit and working.
|
||
- **Required tests:** origin parser/startup; every URL caller; hostile Host/forwarded headers; Unicode/ports/paths; secure-cookie behavior; relevant backend regression suite.
|
||
- **Required browser verification:** local login/reset/verification navigation when a local email sink is available; no visual redesign.
|
||
- **Required production verification:** canonical and hostile Host smoke after SEC-002; not required to claim local verification.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** production/ingress verification depends on SEC-002; a live local Production-mode process launch was rejected by the execution policy before starting, so it is not claimed.
|
||
- **Evidence:** `docs/verification/sec-001-canonical-origin.md`; `ExternalOriginTests`; focused security/controller slice 79/79; full backend 474/474; Release build; Compose config; normalized deploy-shell syntax.
|
||
- **Commit:** none.
|
||
- **Remaining work:** verify canonical and hostile Host behavior through the complete proxy path in SEC-002; exercise reset/verification navigation with a safe local email sink; deploy and verify before `DONE`.
|
||
|
||
### SEC-002 — Production ingress, forwarded headers and Compose separation
|
||
|
||
- **Source programme:** shared production/security prerequisite; Work 17-34; Ollama 123-176; audit P0-2B/JT-002.
|
||
- **Original requirement references:** `work.md:17-34`; `ollama.md:123-176`; audit P0-2B.
|
||
- **Related findings:** JT-002, JT-013, JT-020.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** SEC-001; actual proxy network/IP supplied by operator for production verification.
|
||
- **Affected components:** production/development Compose selection, nginx forwarded headers, explicit known proxy/network config, deploy script/runbook, CI deployment invocation.
|
||
- **Acceptance criteria:** dev override is never auto-loaded in production; no direct production application ports; exact-host ingress contract; sanitized two-hop forwarding; rollback command documented.
|
||
- **Required tests:** merged Compose assertions, production config tests, nginx/proxy integration, deploy shell checks.
|
||
- **Required browser verification:** canonical public/API navigation through local proxy.
|
||
- **Required production verification:** exact Traefik route, closed ports, correct HTTPS/client IP/cookies.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** external Traefik topology, production CIDR/network inventory, firewall state and provider routes are unavailable for production verification; the pinned nginx base image was not installed locally and was not pulled without internet permission.
|
||
- **Evidence:** `docs/verification/sec-002-ingress-compose.md`; production Compose has no published frontend/backend/Ollama ports; dev Compose publishes only 3000/5202/11434; proxy parser tests; nginx syntax/substitution checks; frontend build; backend 476/476.
|
||
- **Commit:** none.
|
||
- **Remaining work:** inventory/set the non-overlapping production CIDR; verify operator Traefik exact-host/header replacement and firewall; build the pinned image in approved CI; run local/prod proxy and hostile-Host smoke before `DONE`.
|
||
|
||
### SEC-003 — Microsoft tenant and issuer trust policy
|
||
|
||
- **Source programme:** Work authentication/audit prerequisite.
|
||
- **Original requirement references:** `work.md:91-100`; audit P0-1A/JT-001.
|
||
- **Related findings:** JT-001.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** supported single/multitenant mode configured.
|
||
- **Affected components:** Microsoft token validator, smart auth scheme, sign-in configuration, mocked validator tests.
|
||
- **Acceptance criteria:** exact issuer/`tid`; (`tid`,`oid`) returned; invalid/missing/mismatched tenant rejected; unused raw bearer trust path removed or proven necessary and hardened.
|
||
- **Required tests:** all tenant modes, issuer/audience/signature/lifetime, personal/organizational, same `oid` across tenants.
|
||
- **Required browser verification:** mocked Microsoft success/failure/cancel only; real provider later if safely configured.
|
||
- **Required production verification:** configured tenant mode and synthetic/provider smoke without exposing tokens.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** none for validator implementation; real Microsoft smoke needs provider configuration.
|
||
- **Evidence:** `docs/verification/sec-003-microsoft-tenant.md`; tenant/issuer validator matrix; raw bearer branch removed; focused 42/42 and full backend 491/491; Compose and deploy-shell config checks.
|
||
- **Commit:** none.
|
||
- **Remaining work:** production inventory/configuration and mocked/real safe provider smoke; SEC-004 canonical pair persistence/relinking must complete before JT-001 closes or Microsoft is enabled in production.
|
||
|
||
### SEC-004 — Canonical Microsoft links and safe legacy relinking
|
||
|
||
- **Source programme:** Work authentication/audit prerequisite.
|
||
- **Original requirement references:** `work.md:91-100`; audit P0-1B/JT-001.
|
||
- **Related findings:** JT-001.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** SEC-001, SEC-003, SEC-005A and SEC-005B recent reauthentication/email proof.
|
||
- **Affected components:** `ApplicationUser`, EF model/migration, auth exchange/link/unlink/recovery UI and APIs.
|
||
- **Acceptance criteria:** composite tenant/object key is unique owner; no email auto-link; no silent legacy backfill/merge; legitimate legacy users have explicit non-locking recovery.
|
||
- **Required tests:** fresh/legacy SQLite+MariaDB migration, collisions, two tenants/same email, last-credential guard, 2FA, mocked relink.
|
||
- **Required browser verification:** local mocked new sign-in and legacy relink.
|
||
- **Required production verification:** anonymized legacy inventory before migration; monitored relink window.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** real Microsoft/browser/SMTP and disposable MariaDB checks are unavailable; production legacy inventory is unknown.
|
||
- **Evidence:** `docs/verification/sec-004-microsoft-identity.md`; focused auth 34/34; backend 507/507; frontend 152/152 and build; dual-provider SQL; disposable SQLite legacy/unique-index rehearsal.
|
||
- **Commit:** none.
|
||
- **Remaining work:** real mocked-browser Microsoft popup/relink flow with an SMTP sink; disposable MariaDB migration; production counts-only legacy inventory, rolling-version smoke and monitored relink window before `DONE`.
|
||
|
||
### SEC-005A — Session and recovery revocation
|
||
|
||
- **Source programme:** Work auth constraints; shared recovery prerequisite.
|
||
- **Original requirement references:** `work.md:17-34,63-100`; audit P0-4A/P0-4B, JT-007/JT-008.
|
||
- **Related findings:** JT-007, JT-008.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** SEC-001; coordinates with SEC-004.
|
||
- **Affected components:** logout, password reset/change, local session validation, trusted devices, pending 2FA challenges and auth tests.
|
||
- **Acceptance criteria:** logout revokes the exact copied `sid`; reset revokes all sessions/devices without disabling 2FA; password change rotates the current session, revokes others and preserves only the current trusted device; session validation binds `sid` to user; stale pending 2FA fails after a security-stamp change.
|
||
- **Required tests:** valid/expired logout cookie; copied session; reset across users/devices; password rotation; trusted-device retention/removal; `sid`/user mismatch; pending 2FA stamp.
|
||
- **Required browser verification:** logout in two tabs; password change/reset with a local email sink; 2FA recovery.
|
||
- **Required production verification:** copied-cookie/reset/change smoke without logging token values.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** browser and production checks require safe running environments.
|
||
- **Evidence:** `docs/verification/sec-005a-session-revocation.md`; focused 48/48; full backend 497/497.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser/runtime and production verification before `DONE`; SEC-005B owns email state.
|
||
|
||
### SEC-005B — Verified registration and pending-email transitions
|
||
|
||
- **Source programme:** Work auth constraints; shared identity/recovery prerequisite.
|
||
- **Original requirement references:** `work.md:17-34,63-100`; audit P0-4B, JT-007/JT-008.
|
||
- **Related findings:** JT-007, JT-008.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** SEC-001, SEC-005A; coordinates with SEC-004.
|
||
- **Affected components:** registration, verification/resend, profile DTOs, pending-email request/confirm/cancel APIs, `ApplicationUser`, one additive EF migration/snapshot, auth/profile UI and tests.
|
||
- **Acceptance criteria:** verification-required registration creates no session and returns typed 202; active email never changes before proof; latest pending request wins; confirmation uses Identity change-email semantics, conditionally updates username, clears pending state and revokes all sessions/devices.
|
||
- **Required tests:** registration/no-cookie transition; verify then login; enumeration-resistant resend; duplicate/latest/mismatched/expired/replayed pending email; username preservation; passwordless/provider users; SQLite and MariaDB migration paths.
|
||
- **Required browser verification:** mocked/local-sink register/resend/verify and request/cancel/confirm email at desktop/mobile with keyboard access.
|
||
- **Required production verification:** safe SMTP link/origin and version-skew smoke; no real personal address.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** in-app browser localhost access was denied by its admin policy check; no safe SMTP sink, disposable MariaDB, or production environment is available.
|
||
- **Evidence:** `docs/verification/sec-005b-email-ownership.md`; focused backend 35/35; full backend 501/501; frontend 151/151 and build; SQLite upgrade and dual-provider migration scripts; isolated API 202/no-cookie and 403/no-cookie checks.
|
||
- **Commit:** none.
|
||
- **Remaining work:** real-browser desktop/mobile/keyboard flows with a local email sink; expired/replayed token and custom-username integration checks; disposable MariaDB migration execution; production SMTP/origin/version-skew verification before `DONE`.
|
||
|
||
### SEC-006 — Compatible document-parser dependency update
|
||
|
||
- **Source programme:** Work CV 504; Ollama parser prerequisite; audit P0-3A.
|
||
- **Original requirement references:** `work.md:309-386`; `ollama.md:44-56,177-258`; audit JT-006.
|
||
- **Related findings:** JT-006, JT-017.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** approved package-index access during implementation; synthetic benign corpus.
|
||
- **Affected components:** Python requirements/lock/hash, parser tests and image build.
|
||
- **Acceptance criteria:** compatible fixed versions; no unaccepted reachable High/Critical parser advisory; clean reproducible install; benign extraction parity.
|
||
- **Required tests:** dependency resolution/audit, Python suite, generated benign corpus.
|
||
- **Required browser verification:** none for dependency-only package.
|
||
- **Required production verification:** image digest and smoke before activation.
|
||
- **Status:** `BLOCKED`.
|
||
- **Blocker:** repository instructions prohibit internet/package resolution without explicit permission; fixed-version compatibility cannot be resolved or verified offline.
|
||
- **Evidence:** audit lists reachable Pillow/pypdf/multipart/Starlette advisories and compatibility conflict.
|
||
- **Commit:** none.
|
||
- **Remaining work:** explicit package-index permission, compatible fixed-version resolution, lock/hash refresh, audit, benign corpus parity and image smoke; do not execute malicious files.
|
||
|
||
### SEC-007 — Bounded isolated document processing
|
||
|
||
- **Source programme:** Work CV 504; Ollama privacy/queue; audit P0-3B/P0-3C.
|
||
- **Original requirement references:** `work.md:309-386`; `ollama.md:177-258,452-573`; audit JT-006/JT-011.
|
||
- **Related findings:** JT-006, JT-011.
|
||
- **Priority:** P0.
|
||
- **Dependencies:** SEC-006.
|
||
- **Affected components:** backend upload/fallback, FastAPI parser child, queue backpressure, container non-root/resource/tmp cleanup.
|
||
- **Acceptance criteria:** bounded file/page/pixel/decompression/memory/time work; child/process group killed; no binary backend fallback; safe cleanup/errors; private tokenized service remains.
|
||
- **Required tests:** generated boundary/corrupt fixtures, harmless sleeping child, cancellation/restart cleanup, outage/no-fallback, container assertions.
|
||
- **Required browser verification:** synthetic CV upload status/failure; authorized private CV local-only only after safeguards.
|
||
- **Required production verification:** measured memory/CPU limits and canary synthetic extraction.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** follows dependency update; production sizing requires access.
|
||
- **Evidence:** audit parser call path and limits design.
|
||
- **Commit:** none.
|
||
- **Remaining work:** split behavioral and container commits if needed.
|
||
|
||
### SEC-008 — Recoverable attachment mutations
|
||
|
||
- **Source programme:** audit prerequisite for account lifecycle and workspace files.
|
||
- **Original requirement references:** Work 17-34 and file/application requirements; audit P0-5/JT-010.
|
||
- **Related findings:** JT-010.
|
||
- **Priority:** P0 data integrity.
|
||
- **Dependencies:** coordinate file-root/journal format with SEC-009.
|
||
- **Affected components:** attachment controller/file helper/reconciler/tests.
|
||
- **Acceptance criteria:** every DB/filesystem failure converges to committed or durable retryable state; no silent orphan/missing file; rename is metadata-only; owner/path isolation.
|
||
- **Required tests:** invalid later file, cancellation, DB/move/delete failure, restart stages, traversal/symlink, two users.
|
||
- **Required browser verification:** upload/rename/delete/refresh with synthetic files.
|
||
- **Required production verification:** report-only orphan inventory and monitored journal counters.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** in-app browser localhost is policy-blocked; no production report-only inventory/monitoring or MariaDB environment is available. This host denied disposable symlink creation, so that branch is code-inspected only.
|
||
- **Evidence:** audit JT-010 execution path; `docs/verification/sec-008-attachment-consistency.md`; 20/20 focused and 525/525 full backend tests; isolated User A/User B upload/download/rename/delete HTTP rehearsal.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser upload/rename/delete/refresh; executable symlink test on a capable host; production report-only orphan inventory and counters; MariaDB runtime; reconcile suffix markers before any rollback.
|
||
|
||
### SEC-009 — Complete readable export and account deletion lifecycle
|
||
|
||
- **Source programme:** Work audit constraint; Ollama private-data lifecycle; audit P0-6A/P0-6B.
|
||
- **Original requirement references:** `work.md:17-34`; `ollama.md:17-22,427-450`; audit JT-009.
|
||
- **Related findings:** JT-009, JT-013, JT-022.
|
||
- **Priority:** P0 data lifecycle.
|
||
- **Dependencies:** SEC-005 revoke-all, SEC-008, owner inventory, backup-retention/tombstone decision.
|
||
- **Affected components:** domain inventory/export ZIP, owner-scoped files/caches/queues, deletion saga, provider tokens, migrations, backup restore/runbooks/UI.
|
||
- **Acceptance criteria:** readable complete redacted export; idempotent live deletion across rows/files/tokens/queue/cache; no other tenant impact; backup retention truthful; restore tombstones prevent resurrection.
|
||
- **Required tests:** two users/every entity, manifest/checksums/redaction, fault/restart/idempotence, provider failures, disposable restore replay.
|
||
- **Required browser verification:** disposable self/admin export/delete and confirmations.
|
||
- **Required production verification:** backup retention/tombstone rehearsal before self-service enablement.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** legal/operator retention and production restore decisions; repository work can proceed to disabled/dark launch.
|
||
- **Evidence:** audit JT-009 inventory/design.
|
||
- **Commit:** none.
|
||
- **Remaining work:** owner inventory/export first, deletion second.
|
||
|
||
### CORE-001 — Restore default SQLite/MariaDB behavior parity
|
||
|
||
- **Source programme:** Work Strategy/Career failures; audit P1-1.
|
||
- **Original requirement references:** `work.md:723-777`; audit JT-003.
|
||
- **Related findings:** JT-003.
|
||
- **Priority:** P0 broken default workflow.
|
||
- **Dependencies:** none.
|
||
- **Affected components:** Career/Application workspace date-order/filter queries and provider matrix tests.
|
||
- **Acceptance criteria:** variants/runs/history/workspace return correct owner/empty/non-owner results on both supported providers.
|
||
- **Required tests:** fresh/seeded HTTP provider matrix, date/month/timezone boundaries.
|
||
- **Required browser verification:** SQLite Career/Application workspace after API tests.
|
||
- **Required production verification:** MariaDB smoke after deployment.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** production MariaDB execution and browser checks remain unavailable; direct blank-file EF-only migration is separate JT-019 schema-ownership debt while fresh application startup passes.
|
||
- **Evidence:** audit runtime reproduction JT-003; `docs/verification/core-001-sqlite-provider-parity.md`; 3/3 real-provider tests; 509/509 backend regression; isolated fresh-SQLite owner/empty/non-owner HTTP matrix.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser Career/Application workspace verification and executable MariaDB smoke after safe provider/deployment access; address EF-only blank-chain drift under JT-019 rather than editing already-applied historical migrations here.
|
||
|
||
### CORE-002 — Remove ambiguous application-workspace routes
|
||
|
||
- **Source programme:** Work Strategy and embedded workspace; audit P1-2.
|
||
- **Original requirement references:** `work.md:562-634,723-777`; audit JT-004.
|
||
- **Related findings:** JT-004.
|
||
- **Priority:** P0 broken core route.
|
||
- **Dependencies:** CORE-001; inventory frontend/API consumers.
|
||
- **Affected components:** workspace/timeline/interview controllers, API clients/tests/docs.
|
||
- **Acceptance criteria:** one action per verb/path; owner 200, non-owner 404, anonymous 401; UI panels load.
|
||
- **Required tests:** route-table uniqueness, HTTP ownership, frontend panel tests.
|
||
- **Required browser verification:** direct/deep-link workspace panels and Back/Forward.
|
||
- **Required production verification:** authenticated workspace smoke.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** in-app browser localhost is policy-blocked; no production/MariaDB HTTP environment is available.
|
||
- **Evidence:** audit runtime ambiguous route reproduction; `docs/verification/core-002-route-uniqueness.md`; reflection route regression; 31/31 focused and 511/511 full backend; 153/153 frontend and build; owner 200/non-owner 404/anonymous 401 HTTP matrix.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser direct/deep-link, Back/Forward and rendered-panel verification; production authenticated smoke before `DONE`.
|
||
|
||
### BG-001 — Tenant-safe hosted-worker foundation
|
||
|
||
- **Source programme:** both; shared prerequisite.
|
||
- **Original requirement references:** `work.md:17-34,723-777`; `ollama.md:44-56,452-529`; audit JT-005.
|
||
- **Related findings:** JT-005, JT-012, JT-022.
|
||
- **Priority:** P0/P1.
|
||
- **Dependencies:** CORE-001/CORE-002; do not activate workers before OPS-001B, POL-001 and POL-002.
|
||
- **Affected components:** rules/reminders/export/enrichment/CV/AI hosted services, owner context, worker kill switches and tests.
|
||
- **Acceptance criteria:** explicit owner selection, deny-on-null avoided safely, idempotent results, structured failures, no cross-owner work, disabled workers remain off.
|
||
- **Required tests:** two-owner/no-HttpContext, enable/disable, restart/retry/clock, fake email/AI.
|
||
- **Required browser verification:** notification/result surfaces only after OPS-001C.
|
||
- **Required production verification:** one-worker canary and owner-safe metrics.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** activation blocked until policy/notification prerequisites; foundation code is not blocked.
|
||
- **Evidence:** audit JT-005 service inspection; `docs/verification/bg-001-tenant-workers.md`; real-SQLite two-owner worker suite with fake email/AI; full backend 532/532; Compose validation; isolated default-off startup/health/no-export check.
|
||
- **Commit:** none.
|
||
- **Remaining work:** OPS-001B persistent notification/idempotency before reminders/rules; POL-001/002 and durable AI queue before enrichment; restart/clock tests; browser result surfaces; monitored single-worker production canary. Keep all four switches false.
|
||
|
||
### OPS-001A — Durable operation record and lease state machine
|
||
|
||
- **Source programme:** both; shared CV/Strategy/AI operation foundation.
|
||
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:452-529`.
|
||
- **Related findings:** JT-005, JT-013, JT-014, JT-022.
|
||
- **Priority:** P1 foundation.
|
||
- **Dependencies:** BG-001; explicit schema ownership.
|
||
- **Affected components:** `UserOperation` entity, owner/idempotency/claim indexes, state/lease store, provider-aware EF migration and tests.
|
||
- **Acceptance criteria:** stable owner-scoped ID; atomic idempotent create/claim; bounded states/retries/leases/deadlines/cancellation; restart recovery; no raw private payload field.
|
||
- **Required tests:** concurrent create/claim, two tenants, transition guards, lease expiry/final attempt, cancellation, retry delay, deadlines, migration up/down/provider SQL.
|
||
- **Required browser verification:** not applicable until OPS-001C exposes owner APIs.
|
||
- **Required production verification:** executable MariaDB upgrade/down rehearsal and monitored schema rollout.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** no disposable MariaDB or production environment; application consumers deliberately not migrated yet.
|
||
- **Evidence:** `docs/verification/ops-001a-durable-operations.md`; 7/7 focused and 539/539 full backend tests; SQLite upgrade/down/up and fresh startup; dual-provider scripts.
|
||
- **Commit:** none.
|
||
- **Remaining work:** MariaDB execution/production rollout; task-specific producers must validate references/policies and use OPS-001B/C rather than storing private payloads.
|
||
|
||
### OPS-001B — Persistent operation notifications and terminal outbox
|
||
|
||
- **Source programme:** both; shared completion/failure visibility and reminder safety.
|
||
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:512-529,609-639`.
|
||
- **Related findings:** JT-005, JT-012, JT-014, JT-022.
|
||
- **Priority:** P1 foundation.
|
||
- **Dependencies:** OPS-001A; keep real SMTP/AI workers disabled.
|
||
- **Affected components:** owner notification entity/store, operation terminal transactions, unread/dismiss state, provider-safe schema and tests.
|
||
- **Acceptance criteria:** success/failure/cancellation notification is committed atomically with terminal state; owner isolation; idempotent single notification; no private content; retained across restart.
|
||
- **Required tests:** every terminal state, duplicate completion, DB failure rollback, two owners, unread/read/dismiss, migration provider scripts.
|
||
- **Required browser verification:** deferred to OPS-001C.
|
||
- **Required production verification:** schema rollout and synthetic notification canary only.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** MariaDB execution unavailable; repository implementation can continue.
|
||
- **Evidence:** `docs/verification/ops-001b-notifications.md`; 9/9 focused and 541/541 full backend tests; forced transaction rollback; SQLite upgrade/down/up; current model snapshot; generated SQLite/MariaDB up/down SQL.
|
||
- **Commit:** none.
|
||
- **Remaining work:** execute the migration on MariaDB; expose owner APIs/UI in OPS-001C; complete browser and production canaries. No email delivery is part of this package.
|
||
|
||
### OPS-001C — Owner operation/notification APIs and frontend queue client
|
||
|
||
- **Source programme:** both; shared queued-operation UX.
|
||
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:499-510,609-639`.
|
||
- **Related findings:** JT-014, JT-015, JT-022.
|
||
- **Priority:** P1 foundation.
|
||
- **Dependencies:** OPS-001A/B; POL-001 locked-state admission precedes AI producers.
|
||
- **Affected components:** status/list/cancel/retry APIs, notification read/dismiss APIs, frontend polling/status/notification client and shell badge.
|
||
- **Acceptance criteria:** stable status URL, owner-only list/detail/cancel/retry; refresh/navigation recovery; honest states/errors; completion badge/read/dismiss; no duplicate submission or private diagnostics.
|
||
- **Required tests:** two-user API, refresh/poll/retry/cancel, invalid/expired IDs, component/keyboard/accessibility states.
|
||
- **Required browser verification:** queued/refresh/navigate/retry/cancel/completion notification with synthetic handler at 375/768/1440 and light/dark.
|
||
- **Required production verification:** authenticated synthetic polling/notification smoke.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser localhost remains policy-blocked, but repository/API/component work can continue.
|
||
- **Evidence:** `docs/verification/ops-001c-operation-ui.md`; 12/12 focused backend, 544/544 backend, 3/3 focused UI, 156/156 frontend and production build; isolated two-user HTTP owner/cross-owner matrix.
|
||
- **Commit:** none.
|
||
- **Remaining work:** real browser responsive/theme/keyboard/refresh checks, MariaDB/production smoke and feature-specific producers in AI-003/004. No generic create API is exposed.
|
||
|
||
### POL-001 — Canonical Free/Pro entitlement policy
|
||
|
||
- **Source programme:** Work Free/Pro and Ollama entitlement enforcement.
|
||
- **Original requirement references:** `work.md:636-721`; `ollama.md:17-22,412-449,501-529,638`.
|
||
- **Related findings:** JT-012, JT-022.
|
||
- **Priority:** P1 security/business policy.
|
||
- **Dependencies:** OPS-001A operation admission contract.
|
||
- **Affected components:** role/subscription capability service, API authorization, worker admission/recheck, usage accounting, auth DTO, frontend locked states.
|
||
- **Acceptance criteria:** exactly Free and Pro externally; Free has no AI; server rejects direct/batch/background bypass; Pro/expired/downgraded/admin behavior consistent; non-AI data remains accessible.
|
||
- **Required tests:** endpoint inventory for Free/Pro/expired/downgraded/admin, worker recheck, usage, direct requests and two tenants.
|
||
- **Required browser verification:** locked state/upgrade action/dismissal and Pro execution; mobile/theme/accessibility.
|
||
- **Required production verification:** configured Stripe/role mapping only when operator activation is approved.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser localhost is denied; Stripe/MariaDB/production are unavailable. Usage accounting is complete only for AI Workspace, so provider rollout remains blocked until durable execution centralizes it.
|
||
- **Evidence:** `docs/verification/pol-001-free-pro-entitlements.md`; focused backend 74/74; full backend 568/568; focused frontend 22/22; full frontend 47 suites/157 tests; production build.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser locked/Pro state checks; mocked Stripe expiry/downgrade lifecycle; central all-task usage accounting through AI-003/004 producers; production role/config smoke. PRODUCT-001 separately removes the known landing-page price/third-tier/unlimited claims.
|
||
|
||
### POL-002 — AI privacy, consent and external-fallback policy
|
||
|
||
- **Source programme:** both.
|
||
- **Original requirement references:** `work.md:17-34,495-505,723-777`; `ollama.md:398-451,574-608`.
|
||
- **Related findings:** JT-012, JT-022, JT-025.
|
||
- **Priority:** P1 privacy/security.
|
||
- **Dependencies:** POL-001, PROD-002 task/privacy classification.
|
||
- **Affected components:** persistent settings, operation policy snapshot, payload minimization, admin diagnostics, fallback audit, UI privacy explanation.
|
||
- **Acceptance criteria:** local-only/default/fallback policy enforced server-side; private categories never leave without permission; minimum payload; provider/reason recorded; opt-out never overridden; no browser secrets.
|
||
- **Required tests:** task/privacy matrix, consent changes, payload capture/redaction, fallback allowed/prohibited, entitlement, two tenants.
|
||
- **Required browser verification:** user/admin controls and disclosure/locked/failure states.
|
||
- **Required production verification:** external egress capture with synthetic data only; no real private CV/email.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser localhost is denied; MariaDB/production/external-provider verification is unavailable. Task-specific payload minimization/accounting depend on AI-003/004.
|
||
- **Evidence:** `docs/verification/pol-002-ai-privacy.md`; focused backend 72/72 and final policy 28/28; sidecar 18/18; focused frontend 8/8; full backend 576/576; full frontend 47 suites/158 tests; production build; config and migration script checks.
|
||
- **Commit:** none.
|
||
- **Remaining work:** browser user/admin disclosure checks; MariaDB and production synthetic egress proof; AI-003/004 task-specific payload minimization, accounting and real producer verification. AI-001/002 now carry rechecked policy/task context and record bounded local-first provenance.
|
||
|
||
### AI-001 — Durable AI queue, backpressure and operation APIs
|
||
|
||
- **Source programme:** both.
|
||
- **Original requirement references:** `work.md:360-386,761-777`; `ollama.md:452-573,609-639`.
|
||
- **Related findings:** JT-005, JT-011, JT-013, JT-014.
|
||
- **Priority:** P1.
|
||
- **Dependencies:** BG-001, OPS-001A/B/C, POL-001, POL-002.
|
||
- **Affected components:** AI operation handlers/worker, priority/concurrency/capacity/deadline/circuit, API polling/retry/cancel, frontend shared queue UI.
|
||
- **Acceptance criteria:** HTTP returns 202/stable URL; bounded priority queue protects Ollama; exact state transitions; no duplicate billing/output; refresh/restart recovery; scheduled jobs cannot starve interactive work.
|
||
- **Required tests:** queue capacity/priority, atomic claim, circuit, timeout/retry/jitter, duplicate click/idempotency, cancellation, shutdown/restart, tenant and policy recheck.
|
||
- **Required browser verification:** synthetic operation status across refresh/nav/double-click/offline/retry/cancel.
|
||
- **Required production verification:** queue depth/age, one-worker canary, Ollama offline/restart and app/worker restart.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** real 202 producers/browser verification depend on AI-003/004; MariaDB/production are unavailable and the worker remains off.
|
||
- **Evidence:** `docs/verification/ai-001-durable-ai-queue.md`; focused queue/state/API tests 17/17; full backend 581/581; Compose config and diff checks.
|
||
- **Commit:** none.
|
||
- **Remaining work:** AI-003/004 task handlers and 202 endpoints; browser refresh/double-click/cancel/retry; MariaDB and monitored single-worker production canary. AI-002 supplies local-first circuit/provenance. Do not create a second CV- or Strategy-specific queue.
|
||
|
||
### AI-002 — Ollama adapter and local-first provider routing
|
||
|
||
- **Source programme:** Ollama local-first; Work privacy/Pro constraints.
|
||
- **Original requirement references:** `ollama.md:398-451,574-608`; `work.md:17-34,723-777`.
|
||
- **Related findings:** JT-012, JT-017, JT-022.
|
||
- **Priority:** P1.
|
||
- **Dependencies:** PROD-002, POL-001, POL-002, AI-001.
|
||
- **Affected components:** central task routing policy, Ollama/external adapters, sidecar/backend provider boundary, circuit/health, provider diagnostics/config.
|
||
- **Acceptance criteria:** deterministic then primary local then optional local then permitted external then clear failure; one policy considers task/privacy/entitlement/health/deadline/cost; no simultaneous duplicate completion.
|
||
- **Required tests:** routing matrix, Ollama adapter, schema failure, local circuit, fallback allowed/prohibited/unavailable, cost limits and deduplication.
|
||
- **Required browser verification:** provider-agnostic queued states and appropriate fallback disclosure.
|
||
- **Required production verification:** actual selected local model and controlled synthetic fallback.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser and production checks, actual local-model selection and controlled provider fallback depend on administrator browser policy plus PROD-001/003 access/benchmarks. Repository behavior is not blocked.
|
||
- **Evidence:** `docs/verification/ai-002-provider-routing.md`; V-098–V-100; focused backend 26/26, full backend 588/588, sidecar fake-transport 22/22, Compose/diff checks pass.
|
||
- **Commit:** none.
|
||
- **Remaining work:** AI-003/004 must register typed producers/handlers and explicit external task allowlists; complete monthly cross-feature accounting; browser/MariaDB/selected-model/controlled-provider/production verification. Old provider/model configuration remains available for rollback.
|
||
|
||
### PROD-001 — Read-only production AI inventory and rollout safety
|
||
|
||
- **Source programme:** Ollama Phases 1-2.
|
||
- **Original requirement references:** `ollama.md:58-176`.
|
||
- **Related findings:** JT-013, JT-017, JT-020, JT-021.
|
||
- **Priority:** P1 production gate.
|
||
- **Dependencies:** documented/configured production access; none for repository report templates.
|
||
- **Affected components:** production hardware assessment, current Ollama/app/network/config inventory, backup and rollout/rollback report.
|
||
- **Acceptance criteria:** sanitized measured OS/CPU/RAM/GPU/storage/Ollama/deployment inventory; no public Ollama; config/backup/restart/interruption/rollback recorded before mutation.
|
||
- **Required tests:** read-only commands only; backup mechanism evidence; no secrets/content in reports.
|
||
- **Required browser verification:** none.
|
||
- **Required production verification:** this item is itself production read-only verification.
|
||
- **Status:** `BLOCKED`.
|
||
- **Blocker:** repository docs state the local environment has no production route and CI SSH secrets are unavailable; no documented callable host/credential is present.
|
||
- **Evidence:** `docs/deployment/backup-restore.md` and `docs/operations/production-backup-verification.md` explicitly record the access gap.
|
||
- **Commit:** none.
|
||
- **Remaining work:** create sanitized report template locally; operator/documented access required for measured completion.
|
||
|
||
### PROD-002 — AI workload inventory and synthetic evaluation set
|
||
|
||
- **Source programme:** Ollama Phase 3; Work keyword/AI/CV/email features.
|
||
- **Original requirement references:** `ollama.md:177-258`; `work.md:174-263,309-386,454-527,723-777`.
|
||
- **Related findings:** JT-012, JT-022.
|
||
- **Priority:** P1.
|
||
- **Dependencies:** code inventory; no production access.
|
||
- **Affected components:** workload catalog, synthetic/redacted fixtures, deterministic-versus-AI and privacy/latency/output classifications.
|
||
- **Acceptance criteria:** every AI task has input/size/output/language/latency/quality/privacy/fallback/interactive/entitlement/current-provider classification; evaluation set covers every listed English/Norwegian/noisy/adversarial/long/invalid case without real data.
|
||
- **Required tests:** fixture validity, deterministic expected signals, strict JSON schemas, prompt-injection containment inputs.
|
||
- **Required browser verification:** none; fixtures later drive UI packages.
|
||
- **Required production verification:** none until benchmark.
|
||
- **Status:** `VERIFIED LOCALLY`.
|
||
- **Blocker:** none; authorized private CV is optional local-only and never committed/external.
|
||
- **Evidence:** `docs/verification/prod-002-ai-evaluation.md`; `docs/ai/workload-inventory.md`; fixture validation 1/1; full backend 569/569; frontend 47 suites/157 tests and build.
|
||
- **Commit:** none.
|
||
- **Remaining work:** PROD-003 later executes model benchmarks and sets measured thresholds. Revise classifications if POL-002 route tracing finds an omitted payload; no production/provider work is required for this package.
|
||
|
||
### PROD-003 — Production model benchmarks and model decision
|
||
|
||
- **Source programme:** Ollama Phases 4-6.
|
||
- **Original requirement references:** `ollama.md:259-397`.
|
||
- **Related findings:** JT-021.
|
||
- **Priority:** P1 production gate.
|
||
- **Dependencies:** PROD-001 measured hardware, PROD-002 evaluation set.
|
||
- **Affected components:** benchmark harness/evidence and `ollama-model-benchmark.md`.
|
||
- **Acceptance criteria:** exact candidate tags/license/version/quantization/resources/latency/throughput/quality/JSON/Norwegian/injection/failure/repeat results; measured context/tuning; primary/optional/deterministic/external decision.
|
||
- **Required tests:** repeated synthetic benchmark at 4K/8K and 16K only if safe; one inference initially; no very large/cloud model.
|
||
- **Required browser verification:** none.
|
||
- **Required production verification:** measured on actual machine; local workstation results are labeled separately.
|
||
- **Status:** `BLOCKED`.
|
||
- **Blocker:** PROD-001 production access/hardware inventory.
|
||
- **Evidence:** none yet.
|
||
- **Commit:** none.
|
||
- **Remaining work:** repository harness can be prepared after PROD-002.
|
||
|
||
### PROD-004 — Local-model rollout, fallback, observability and operations
|
||
|
||
- **Source programme:** Ollama Phases 9-14.
|
||
- **Original requirement references:** `ollama.md:531-775`.
|
||
- **Related findings:** JT-005, JT-013, JT-017, JT-021, JT-022.
|
||
- **Priority:** P1 production deployment.
|
||
- **Dependencies:** AI-001, AI-002, PROD-001/003, verified backup/rollback.
|
||
- **Affected components:** Ollama limits/model install, app config/migrations/worker, telemetry/health/runbook, validation matrix.
|
||
- **Acceptance criteria:** selected digest installed without deleting old model; bounded Ollama/app queues; local-first default; safe fallback; privacy-safe metrics/health; drain/restart/rollback; full production validation matrix.
|
||
- **Required tests:** offline/timeout/restart/congestion/concurrent/fallback/free/pro/two-tenant/notification matrix.
|
||
- **Required browser verification:** queued AI journeys in production using synthetic data.
|
||
- **Required production verification:** mandatory; no `DONE` without actual deploy, resource observation and restart recovery.
|
||
- **Status:** `BLOCKED`.
|
||
- **Blocker:** production access plus all dependencies.
|
||
- **Evidence:** none yet.
|
||
- **Commit:** none.
|
||
- **Remaining work:** repository runbooks/config only after measured values; no guessed limits/model.
|
||
|
||
### AI-003 — Strategy Snapshot durable-operation migration
|
||
|
||
- **Source programme:** both; one consolidated implementation.
|
||
- **Original requirement references:** `work.md:723-777`; `ollama.md:609-639,730-765`.
|
||
- **Related findings:** JT-003, JT-004, JT-005, JT-012, JT-014, JT-022.
|
||
- **Priority:** P1 broken user workflow.
|
||
- **Dependencies:** CORE-001/002, AI-001/002, POL-001/002.
|
||
- **Affected components:** Strategy button/API/operation handler/result persistence/UI status/notification.
|
||
- **Acceptance criteria:** root timeout reproduced; enqueue returns 202; stable result; success/failure/timeout/cancel/retry/idempotent double-click/refresh/restart; no duplicate usage/output.
|
||
- **Required tests:** endpoint/handler/provider fakes, all required states, entitlement/privacy/tenant checks, E2E.
|
||
- **Required browser verification:** complete queue/status/error/retry/cancel/refresh/back-forward/mobile/theme flow.
|
||
- **Required production verification:** local model success, timeout and restart recovery.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser localhost policy, selected local model, MariaDB, restart canary and production access remain unavailable; worker stays default-off.
|
||
- **Evidence:** `docs/verification/ai-003-strategy-snapshot-queue.md`; verification-log V-101–V-103; `docs/audits/evidence/ai-003/README.md`.
|
||
- **Commit:** `a621226` (`feat(ai): queue strategy snapshots`).
|
||
- **Remaining work:** real browser/mobile/theme/refresh/back-forward checks; selected-model timeout/quality test; MariaDB and production single-worker restart/canary/rollback; complete cross-feature usage accounting. No Strategy-specific queue was created.
|
||
|
||
### AI-004 — CV-processing 504 and durable-operation migration
|
||
|
||
- **Source programme:** both; one consolidated implementation.
|
||
- **Original requirement references:** `work.md:309-386`; `ollama.md:609-639,730-765`.
|
||
- **Related findings:** JT-006, JT-011, JT-014.
|
||
- **Priority:** P1 broken user workflow/security.
|
||
- **Dependencies:** SEC-006/007, OPS-001A/B/C, AI-001; authorized private file optional only after safe fixture reproduction.
|
||
- **Affected components:** browser upload/API/proxy/artifact/parser/normalization/result polling/recovery/UI queue states.
|
||
- **Acceptance criteria:** 504 origin established; enqueue/persist/progress/result; bounded processing/retry/cancel/cleanup; restart recovery; no timeout inflation; review gate preserved.
|
||
- **Required tests:** safe synthetic PDFs/DOCX/images, proxy/backend/parser/provider failure, duplicate/refresh/restart, E2E.
|
||
- **Required browser verification:** synthetic CV first; authorized private file via temporary local copy only, never logged/committed/external.
|
||
- **Required production verification:** synthetic/local-only canary, no external payload, restart recovery.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** SEC-006 dependency upgrades need internet permission; browser/private-file/MariaDB/production reproduction remains unavailable. Synthetic repository work can continue.
|
||
- **Evidence:** `docs/verification/ai-004-cv-processing-queue.md`; V-104–V-107; real SQLite synthetic integration proves 202/active deduplication/owner-scoped handler/retry provenance/notification/review gate; backend 594/594; frontend 161/161 and build.
|
||
- **Commit:** `c3c5af8` (`feat(cv)!: queue durable processing`).
|
||
- **Remaining work:** SEC-006/007 parser dependency/isolation and complete parser cancellation; browser synthetic upload/refresh/retry/cancel/review at required widths/themes/keyboard; selected-model and worker-restart canary; MariaDB/production rollout. Reconcile dormant extraction-row status immediately when an operation is cancelled before claim. Do not use the private CV before safeguards.
|
||
|
||
### UX-001 — Unified authentication page
|
||
|
||
- **Source programme:** Work Phase 2.
|
||
- **Original requirement references:** `work.md:63-100`.
|
||
- **Related findings:** JT-001, JT-007, JT-008, JT-015.
|
||
- **Priority:** P2 after auth safety.
|
||
- **Dependencies:** SEC-003/004/005 behavior contracts.
|
||
- **Affected components:** login/register UI, Microsoft/Google buttons, error/cancel/return handling, translations/tests.
|
||
- **Acceptance criteria:** one username/password card, `or`, normal Google/Microsoft alternatives, recovery/register links; prohibited provider-status clutter removed; no linking implication.
|
||
- **Required tests:** invalid credentials/provider failure/cancel/return, focus/order/labels.
|
||
- **Required browser verification:** 375/768/1440, light/dark, keyboard/focus, logged-out/provider mocks.
|
||
- **Required production verification:** real provider smoke only with authorized accounts.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** light/System-theme browser, configured/real-provider and production checks require the UX-002 preference work plus authorized provider/deployment environments.
|
||
- **Evidence:** `docs/verification/ux-001-unified-authentication.md`; V-108–V-110; focused 13/13, full frontend 47/47 suites and 166/166 tests, production build, responsive dark-theme browser captures at 375/768/1440.
|
||
- **Commit:** `93b8692` (`feat(auth): unify sign-in options`).
|
||
- **Remaining work:** light/System theme browser; configured-provider browser; real authorized Google/Microsoft cancel/return; production smoke. Keep identity migration separate.
|
||
|
||
### UX-002 — Deterministic theme state
|
||
|
||
- **Source programme:** Work Phase 3.
|
||
- **Original requirement references:** `work.md:102-133`.
|
||
- **Related findings:** JT-015.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** inspect all theme sources.
|
||
- **Affected components:** theme provider/bootstrap/local/profile/cross-tab state and tests.
|
||
- **Acceptance criteria:** saved user > anonymous local > system only in System > default; no unexpected route/nav changes or startup flash; loop-free tab sync.
|
||
- **Required tests:** Light/Dark/System, login/logout/refresh/navigation/storage/preference listeners/tabs.
|
||
- **Required browser verification:** 375/768/1440, light/dark/system, refresh/navigation/two tabs/reduced motion.
|
||
- **Required production verification:** normal browser smoke after deploy.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** production and live authenticated multi-user browser environments are unavailable; repository/browser work is complete.
|
||
- **Evidence:** `docs/verification/ux-002-deterministic-theme-state.md`; V-111–V-113; focused 6/6, full frontend 48/48 suites and 172/172 tests, build, Light/Dark/System/navigation/refresh/two-tab browser checks and 375/768/1440 captures.
|
||
- **Commit:** `11734ee` (`fix(theme): make preference state deterministic`).
|
||
- **Remaining work:** live User A/User B preference switching and production browser smoke; retain existing preference keys during rollout.
|
||
|
||
### QA-001 — Job-analysis and keyword quality
|
||
|
||
- **Source programme:** Work Phase 5; Ollama deterministic workload rule.
|
||
- **Original requirement references:** `work.md:174-263`; `ollama.md:177-223`.
|
||
- **Related findings:** JT-021 (measurement), AI quality.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** PROD-002 fixtures; current pipeline/caching version inventory.
|
||
- **Affected components:** import cleanup/language/token/stop words/phrases/skills/scoring/prompt/postprocess/storage/UI label.
|
||
- **Acceptance criteria:** function/filler/chrome suppressed generically; technologies/punctuation/multiword phrases preserved; contextual generic terms; honest label; versioned regeneration behavior.
|
||
- **Required tests:** seven specified Norwegian/English/mixed/short/noisy/tech/filler fixtures.
|
||
- **Required browser verification:** result presentation/empty/error/long Norwegian text at three widths/themes.
|
||
- **Required production verification:** synthetic analysis comparison; no silent historical rewrite.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser presentation and production comparison remain; deterministic repository work is complete.
|
||
- **Evidence:** `docs/verification/qa-001-job-term-quality.md`; V-114–V-116; seven required fixtures, focused matcher 15/15, affected backend 54/54, full backend 601/601, focused UI 13/13, full frontend 172/172 and build.
|
||
- **Commit:** `da1aa8b` (`fix(match): prioritize meaningful job terms`).
|
||
- **Remaining work:** browser empty/error/long Norwegian/three-width/theme presentation; synthetic production comparison. No stored analysis migration exists.
|
||
|
||
### CAREER-001 — Career Workspace action-oriented redesign
|
||
|
||
- **Source programme:** Work Phase 6.
|
||
- **Original requirement references:** `work.md:265-307`.
|
||
- **Related findings:** JT-003, JT-015.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** CORE-001 and AI-004 status contract.
|
||
- **Affected components:** Career Workspace hierarchy/empty/onboarding/import review/completeness/recent docs/status UI.
|
||
- **Acceptance criteria:** concise actions for profile/import/review/resume/builder/general/job CV/recent/completeness/errors; long paragraph removed; approval gate preserved.
|
||
- **Required tests:** first/returning/incomplete/processing/failure state and navigation.
|
||
- **Required browser verification:** three widths, light/dark, keyboard/focus/loading/empty/error/Norwegian.
|
||
- **Required production verification:** synthetic account smoke.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** browser session was already finalized; three-width/theme/keyboard/Norwegian checks and production synthetic-account smoke remain.
|
||
- **Evidence:** `docs/verification/career-001-career-workspace.md`; V-117–V-119; focused 16/16, full frontend 49/49 suites and 178/178 tests, production build. State-aware actions/recent CVs are implemented and the Apply/Discard gate is unchanged.
|
||
- **Commit:** `268b3a0` (`feat(career): clarify workspace actions`).
|
||
- **Remaining work:** browser and production gates only; deeper builder/job-specific interaction belongs to CAREER-002/JOBS-001.
|
||
|
||
### CAREER-002 — CV Builder interaction redesign and external research
|
||
|
||
- **Source programme:** Work Phase 8.
|
||
- **Original requirement references:** `work.md:388-452`.
|
||
- **Related findings:** JT-003, JT-015, JT-025.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** CAREER-001, AI-004; inspect existing advanced builder before changing it.
|
||
- **Affected components:** builder list/editor/sections/entries/reorder/visibility/autosave/validation/preview/responsive/accessibility.
|
||
- **Acceptance criteria:** all specified section/edit/add/delete/reorder/hide/validation/save/nav/preview behaviors while preserving data/templates/render/export/version/import/profile separation.
|
||
- **Required tests:** editing/collapse/add/delete/reorder/save/failure/persistence/preview.
|
||
- **Required browser verification:** authorized FlowCV research if accessible, never bypass auth; original JobTracker design at three widths/themes/keyboard/focus.
|
||
- **Required production verification:** existing variants/edit/export/public render smoke.
|
||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||
- **Blocker:** fresh FlowCV inspection and JobTracker three-width/theme/keyboard checks require a new browser session; production synthetic-variant smoke requires access.
|
||
- **Evidence:** `docs/verification/career-002-cv-builder.md`; V-120–V-125. Save, navigation, custom entries, named controls, persistence and preview failure/retry pass 17/17 focused, 49/49 suites and 184/184 full plus build.
|
||
- **Commit:** `b58cc19`, `a5b74e0`, `2043349`.
|
||
- **Remaining work:** browser/FlowCV/production gates and honest deployed DOCX capability check only. Avoid rewriting already-working features.
|
||
|
||
### MAIL-001 — Consolidated job-email hub and explicit sending
|
||
|
||
- **Source programme:** Work Phase 9.
|
||
- **Original requirement references:** `work.md:454-527`.
|
||
- **Related findings:** JT-005, JT-012, JT-015, JT-022, JT-025.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** BG-001, OPS-001B/C notifications, POL-001/002, provider tenant safety.
|
||
- **Affected components:** Gmail Review/Correspondence routes, shared domain/components, Gmail/Graph/IMAP, detection/linking, drafts/send audit/application embedding.
|
||
- **Acceptance criteria:** one hub plus shared application view; linked/suggested messages; provider identity/search/filter/states; editable draft and explicit confirmed idempotent send; no autonomous AI/send; weak signals never auto-link.
|
||
- **Required tests:** link/unlink/dismiss/draft/send duplicate/uncertain/provider failure/reauth/two tenants/free/pro/application embed.
|
||
- **Required browser verification:** all states at three widths/themes/keyboard; mocked providers only unless safe configured account.
|
||
- **Required production verification:** provider read/draft/send requires explicit authorized synthetic account; never real unsolicited email.
|
||
- **Status:** `IN PROGRESS`.
|
||
- **Blocker:** real provider verification external; mocked/local implementation not blocked after dependencies.
|
||
- **Evidence:** `docs/verification/mail-001-job-email-hub.md`; V-126–V-135. Composer 7/7; send/read/store focused 12/12; delivery/capability 18/18; provider/correspondence 5/5; hub detail 5/5; backend 619/619; frontend 49/49 suites and 190/190 tests plus build.
|
||
- **Commit:** `6008b4a` (hub), `536d403` (neutral reads), `a20775c` (safe detail), `653f011` (ledger), `e9937ac` (Gmail/Graph delivery adapters and consent), `123fc55` (explicit-confirmed send API), `449faeb` (confirmed reply composer).
|
||
- **Remaining work:** abandoned-sending reconciliation; legacy follow-up SMTP retirement; export/deletion coverage; durable/new-message drafts; shared thread/application actions and category capabilities; free/pro and browser/production verification. Existing connections need explicit re-consent; IMAP remains read-only. No real email; uncertain sends need manual reconciliation.
|
||
|
||
### JOBS-001 — Job-search source and assessment redesign
|
||
|
||
- **Source programme:** Work Phase 4.
|
||
- **Original requirement references:** `work.md:135-172`.
|
||
- **Related findings:** JT-015, JT-021, JT-024.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** source provenance inventory; CORE fixes.
|
||
- **Affected components:** discovery DTO/storage/source labels/filter/sort/cards/import flow.
|
||
- **Acceptance criteria:** every listing shows honest source/type/original link/retrieval/deadline; derived sources labeled; source preserved on import; scan/search/filter/location/work-mode/errors/duplicates/mobile improved.
|
||
- **Required tests:** provenance mapping/filter/import preservation/empty/loading/error/duplicates.
|
||
- **Required browser verification:** three widths/themes/keyboard/long text/Norwegian/import.
|
||
- **Required production verification:** official NAV/safe provider smoke; unavailable providers labeled.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** live provider checks may be external; synthetic fixtures suffice locally.
|
||
- **Evidence:** source requirement.
|
||
- **Commit:** none.
|
||
- **Remaining work:** no scraping or inferred-as-verified source.
|
||
|
||
### JOBS-002 — Applications table and embedded workspace
|
||
|
||
- **Source programme:** Work Phase 11.
|
||
- **Original requirement references:** `work.md:562-634`.
|
||
- **Related findings:** JT-003, JT-004, JT-015, JT-021.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** CORE-001/002, MAIL-001 embedding contract, AI-003 status.
|
||
- **Affected components:** applications table, filters/search/sort, route-backed drawer/modal/full-page fallback, workspace sections/focus/unsaved state.
|
||
- **Acceptance criteria:** scan-friendly priority columns; list context preserved; deep-link/back-forward/direct URL; accessible focus/close; mobile full-screen; no nested modal; full-page fallback.
|
||
- **Required tests:** route/history/filter persistence/focus/unsaved/direct link/mobile, tenant authorization.
|
||
- **Required browser verification:** three widths/themes/keyboard/back-forward/refresh/error/long data.
|
||
- **Required production verification:** existing application/workspace smoke.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** none after dependencies.
|
||
- **Evidence:** source requirement and existing workspace architecture.
|
||
- **Commit:** none.
|
||
- **Remaining work:** do not place every field in table or duplicate workspace data.
|
||
|
||
### UX-003 — Kanban theme-state correction
|
||
|
||
- **Source programme:** Work Phase 10.
|
||
- **Original requirement references:** `work.md:529-560`.
|
||
- **Related findings:** JT-015.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** UX-002 shared theme tokens preferably first.
|
||
- **Affected components:** Kanban column/card/drag/focus/loading/error styles and tests.
|
||
- **Acceptance criteria:** no white dark-mode targets; all listed drag/empty/card/hover/keyboard/error states have shared-token contrast and light/mobile quality.
|
||
- **Required tests:** component/visual state coverage.
|
||
- **Required browser verification:** three widths, light/dark, pointer and keyboard drag, focus/contrast.
|
||
- **Required production verification:** board smoke.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** browser verification required for completion.
|
||
- **Evidence:** reported visual defect not yet reproduced.
|
||
- **Commit:** none.
|
||
- **Remaining work:** smallest token-level root fix.
|
||
|
||
### PRODUCT-001 — Homepage plans and respectful Pro promotion
|
||
|
||
- **Source programme:** Work Phases 12-13.
|
||
- **Original requirement references:** `work.md:636-721`.
|
||
- **Related findings:** JT-012, JT-015, JT-022.
|
||
- **Priority:** P2.
|
||
- **Dependencies:** POL-001 canonical policy.
|
||
- **Affected components:** homepage/pricing/registration/settings/nav/metadata/upgrade prompts/locked states/translations/tests.
|
||
- **Acceptance criteria:** exactly Free (no AI/core tracking) and Pro (defined AI capabilities); no invented price/trial/limit; central capability data; concise dismissible non-dark-pattern promotion.
|
||
- **Required tests:** copy/capability consistency, Free/Pro/expired/downgraded locked states, dismissal/no false generation.
|
||
- **Required browser verification:** homepage and contextual prompts at three widths/themes/keyboard/accessibility.
|
||
- **Required production verification:** configured price text only if actual billing product exists; otherwise no invented values.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** public plan behavior depends on POL-001 compatibility decision; real billing activation is external.
|
||
- **Evidence:** source requirement.
|
||
- **Commit:** none.
|
||
- **Remaining work:** inventory all current contradictory plan claims.
|
||
|
||
### VER-001 — Complete application action matrix and regression pass
|
||
|
||
- **Source programme:** Work Phase 15; Ollama validation/tests.
|
||
- **Original requirement references:** `work.md:779-903`; `ollama.md:730-798`.
|
||
- **Related findings:** all relevant audit findings, especially JT-014/JT-015/JT-016.
|
||
- **Priority:** P1 verification gate.
|
||
- **Dependencies:** all implemented work packages; matrix may be populated incrementally earlier.
|
||
- **Affected components:** `docs/verification/application-action-matrix.md`, browser evidence, regression tests.
|
||
- **Acceptance criteria:** every meaningful safe control/action has route/role/plan/result/path/loading/success/failure/auth/tenant/tests/manual/automated/finding classification; failures fixed or accurately blocked.
|
||
- **Required tests:** full backend/frontend/Python/E2E plus regressions for confirmed defects.
|
||
- **Required browser verification:** running app, synthetic users/data, 375/768/1440, themes/keyboard/focus/refresh/back/tabs/slow/error; no real email/paid provider/destructive production action.
|
||
- **Required production verification:** applicable smoke actions only after deployment; local and production classifications remain distinct.
|
||
- **Status:** `NOT STARTED`.
|
||
- **Blocker:** browser tooling/access and external providers may block individual rows, not the matrix.
|
||
- **Evidence:** audit user-journey/action gaps.
|
||
- **Commit:** none.
|
||
- **Remaining work:** create early and update per package; final sweep last.
|
||
|
||
### REL-001 — Production validation and remaining audit closure
|
||
|
||
- **Source programme:** both final reports and production validation.
|
||
- **Original requirement references:** `work.md:905-922`; `ollama.md:640-825`; audit backlog remaining phases.
|
||
- **Related findings:** all open findings.
|
||
- **Priority:** P1 release gate.
|
||
- **Dependencies:** VER-001, PROD-004, completed repository packages, backup/rollback/access.
|
||
- **Affected components:** `docs/production/production-ai-validation.md`, operations runbook, deployment evidence, audit verification logs, final reports.
|
||
- **Acceptance criteria:** truthful production/local/mocked/blocked matrix; queue/model/routing/restart/tenant/Free-Pro/privacy verified; remaining findings explicitly open/deferred; rollback proven.
|
||
- **Required tests:** full release command matrix and production synthetic smoke.
|
||
- **Required browser verification:** production journeys requiring real deployment, no private data in evidence.
|
||
- **Required production verification:** mandatory for `DONE` where source programme requires rollout.
|
||
- **Status:** `BLOCKED`.
|
||
- **Blocker:** production access plus unfinished dependencies.
|
||
- **Evidence:** current production documents explicitly say production data/access not verified.
|
||
- **Commit:** none.
|
||
- **Remaining work:** continue safe local packages; do not claim production completion.
|
||
|
||
## Conflict register summary
|
||
|
||
Full decisions are in `docs/work-programmes/decisions.md`.
|
||
|
||
1. **AI provider architecture:** ADR-004/current roadmap say one deployment provider; the newer Ollama programme explicitly requires local-first plus controlled fallback. The new programme is the target, implemented centrally and compatibly; old config/models remain for rollback.
|
||
2. **Free AI:** current code gives Free users limited AI; the new programme says Free has no AI. POL-001 must change behavior server-side without deleting existing user data or renaming persisted roles prematurely.
|
||
3. **Production authority:** Work says no production deploy unless instructed; Ollama programme and the current request authorize only scoped local-AI production work after inventory/backup/rollback. No other production mutation is authorized.
|
||
4. **Schema ownership:** OPS-001A chose one EF-owned, provider-conditional migration for `UserOperations` and deliberately omitted reconciler DDL. MariaDB script generation passes; executable server verification remains.
|
||
5. **Compose documentation:** docs claim a separate dev override, but the filename is auto-loaded by production deploy. SEC-002 corrects actual behavior.
|
||
6. **CV Builder premise:** programme asks for capabilities already present. CAREER-002 begins with a browser/code gap analysis and changes only evidenced gaps.
|