|
|
|
|
# Changelog
|
|
|
|
|
|
|
|
|
|
All notable changes to this project will be documented in this file.
|
|
|
|
|
|
|
|
|
|
This project follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/) and Semantic Versioning once `0.1.0` is tagged.
|
|
|
|
|
|
|
|
|
|
## [Unreleased]
|
|
|
|
|
|
|
|
|
|
### Added
|
|
|
|
|
|
Reorganize docs: move working/audit files to docs/ and add conventions
Working documents and audits were spread across the project root,
mixing with standard npm/GitHub files (README, CHANGELOG, CONTRIBUTING,
SECURITY, BRAND). Moves them under docs/ for a clean root and adds
docs/conventions.md as the canonical document for codebase-wide
naming and structure rules.
Files moved to docs/ (via git mv, history preserved):
- audit-1-5.md (current ecosystem audit)
- AUDIT_KIMI.md
- AUDIT_OPENCODE.md
- AUDIT_claude.md (historical audits from prior tools)
- before_0_1.md (pre-0.1 release checklist)
- buss.md (bus design doc, no longer live)
- NEXT_STEPS.md (roadmap)
Files staying in root (npm/GitHub convention):
- README.md, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md, BRAND.md
References updated to point at docs/:
- CHANGELOG.md (line 11)
- README.md (line 105)
- SECURITY.md (line 3)
- src/web/routes/active/security/+page.svelte (line 46)
docs/conventions.md captures three rules accepted as binding for the
codebase:
1. Module identifier — every artifact and lib uses its 4-letter alias
(BUSS, CONN, SESS, PERM, TIMR, LOGR, CACH, STOR, FMTS, FEND, ADOM,
AAPP, AUTH, LANG, HTTP, SIUM, ERRS) for both string values and
constant name prefixes. Drift from this rule (BUS_*, CONNECTION_*,
SESSION_*, …) is being closed in the next audit pass.
2. Constant naming — `<MOD>_<CATEGORY>_<NAME>` strictly. No
exceptions (no DEFAULT_TIMER_* style).
3. Category vocabulary — fixed list of category tokens (ERR, EVENT,
DIAGNOSTIC_EVENTS, METHOD, STATE, STATUS, KIND, REASON, TYPE, MODE,
DEFAULT, LIMIT, ID_PREFIX, LOG_CATEGORY, LOG_MSG, ERROR_MSG,
ERROR_NAME, CONTEXT_KEY). Ad-hoc categories (AUTO_REAUTH,
AUTO_INVALIDATE, BUFFER_POLICY, CHANNEL_STATE) fold into one of
these.
The document also formalizes the layer rules and ErrCode shape that
will be implemented in upcoming commits.
svelte-check 1395/0 errors. No code-side regressions; the moves are
file-only.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
5 months ago
|
|
|
- Release-readiness checklist in `docs/before_0_1.md`.
|
|
|
|
|
- Root documentation site under `/active`.
|
|
|
|
|
- Versioning and deprecation policy page under `/active/get-started/versioning`.
|
|
|
|
|
- Full ecosystem integration harness under `/test/ecosystem`.
|
|
|
|
|
- Server/client split for authentication, permissions and cache.
|
|
|
|
|
- Rate-limit port wiring for critical authentication flows.
|
|
|
|
|
- Runtime warnings for memory auth/cache adapters in production mode.
|
|
|
|
|
- OAuth PKCE regression tests for persisted verifier handling.
|
|
|
|
|
- Public-surface regression tests for the composed App root and its always-on/scoped artifacts.
|
|
|
|
|
- Permission client regression coverage for stale `check`, `batch` and `what` responses after actor changes.
|
|
|
|
|
- Bundle smoke script for the minimal `createActiveApp({})` runtime budget.
|
|
|
|
|
- Static smoke script for generated docs/test routes and public app assets.
|
|
|
|
|
|
|
|
|
|
### Changed
|
|
|
|
|
|
|
|
|
|
- MFA is excluded from the stable auth engine surface until it is implemented end-to-end.
|
|
|
|
|
- CSRF cookie defaults are verified as strict in auth regression tests.
|
|
|
|
|
- Mono-lang is documented as a type-loose null-object fallback when no schema is configured.
|
|
|
|
|
|
|
|
|
|
### Security
|
|
|
|
|
|
|
|
|
|
- Added security policy and pre-`0.1.0` threat-model notes.
|
|
|
|
|
|
|
|
|
|
## [0.1.0] - Unreleased
|
|
|
|
|
|
|
|
|
|
Initial public stabilization target.
|