Spec catchup: drift fixes, account-settings split, notifications archive
Drift (specs aligned to shipped code): - social-follows: locked-account access rule for /users/:u/followers and /users/:u/following (owner + accepted-follower see; non-followers of private get 404). Adds the follow→notification lifecycle requirement. Fills the placeholder Purpose. - public-profiles: counts degrade to plain text (not anchors) for viewers who can't see the lists. Cross-references social-follows. Fills the placeholder Purpose. - journal-auth slimmed to cookie session + Terms gate. Auth methods moved out (see authentication-methods). Splits: - account-settings (14-line stub) deleted, content split into: - profile-settings (display name, bio, profile_visibility) - account-management (email change with verification, account deletion) - connected-services (Wahoo + future external integrations) - authentication-methods split out of journal-auth: passkeys (register/login/add/delete), magic links, 6-digit codes (login + register), method toggle on register/login forms, dev-console fallback. New specs: - sse-broker: /api/events, in-process broker, useUnreadNotifications hook, Caddy passthrough, multi-process forward-compat contract. Archived: notifications change → openspec/changes/archive/2026-04-26-notifications. Promoted the four delta spec files into top-level specs: - specs/notifications/ (new capability) - specs/activity-feed/ (added: public activity fan-out) - specs/journal-landing/ (added: Notifications navbar entry) - specs/social-follows/ (added: follow→notification lifecycle) Added openspec/CAPABILITIES.md grouped index covering all 40 specs with a Conventions section explaining cross-references, naming, and the catch-up-vs-change rule. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
0530dd3e59
commit
37073eafd7
21 changed files with 604 additions and 29 deletions
|
|
@ -1,16 +1,20 @@
|
|||
## Purpose
|
||||
# journal-auth Specification
|
||||
|
||||
Authentication for the Journal app, including OAuth token storage for external services in the sync_connections table.
|
||||
## Purpose
|
||||
Session management and the terms-of-service consent gate for the Journal app. The credentials a user authenticates with (passkeys, magic links, magic codes) and the registration UX live in `authentication-methods`; OAuth tokens for third-party services (Wahoo etc.) live in `connected-services`. This spec is the cross-cutting layer: cookie sessions, the Terms-version gate that wraps every authenticated request, and the rules for safely returning users to where they came from.
|
||||
|
||||
## Requirements
|
||||
|
||||
### Requirement: Store external service tokens
|
||||
The journal auth system SHALL store OAuth tokens for external services alongside user credentials.
|
||||
### Requirement: Cookie session for signed-in users
|
||||
The Journal SHALL identify signed-in users via a server-set HTTP cookie (`__session`) that carries a serialized JSON payload containing `userId`. The cookie SHALL be `HttpOnly`, `SameSite=Lax`, signed with the server secret, and have a finite max-age. Anonymous browsers SHALL render the public surface (anonymous home, public profiles, public routes/activities) without a session cookie present.
|
||||
|
||||
#### Scenario: Wahoo token storage
|
||||
- **WHEN** a user connects their Wahoo account
|
||||
- **THEN** access token, refresh token, expiry time, and Wahoo user ID are stored in the `wahoo_tokens` table
|
||||
- **AND** tokens are associated with the journal user ID
|
||||
#### Scenario: Set cookie on successful authentication
|
||||
- **WHEN** any authentication path (passkey finish, magic-link verify, code verify) succeeds
|
||||
- **THEN** the response carries a `Set-Cookie: __session=...` header binding the resulting `userId` to the browser
|
||||
|
||||
#### Scenario: Anonymous request renders public surface
|
||||
- **WHEN** a request arrives without `__session` (or with one that fails to verify)
|
||||
- **THEN** loaders treat the request as anonymous; routes that require auth either redirect to `/auth/login` or render the public layout per their own spec
|
||||
|
||||
### Requirement: Terms acknowledgement at signup
|
||||
The registration form SHALL require explicit acknowledgement of the Terms of Service before an account can be created.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue