From 7c66599f35353b27fb58ac77ef4b9c2161e1f1b4 Mon Sep 17 00:00:00 2001 From: lilleman Date: Sun, 2 Aug 2026 13:24:20 +0200 Subject: [PATCH] Todo and agents updates --- AGENTS.md | 6 +++++- todo.md | 1 + 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/AGENTS.md b/AGENTS.md index 21d3178..a51b79d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -150,6 +150,10 @@ Same test before adding a row to a table or the file map — a clause, not a par - Tests use the built-in `node --test` runner — no test framework dependency. - English everywhere. Keep code comments short and information-dense. Self explained code without any comment at all is the preferred solution. +- Do not comment about history in the code or README. Like "This function included X before, + but it moved to Y". +- Do not comment about the abscense of things, if it is not very undexpected. Banned is things + like "This function does not calculate pi, that is done in function Z". - Pin all dependencies and Docker images to exact, human-readable **semantic versions** — never ranges (`^`, `~`) and never digests/hashes. npm deps are kept exact by `.npmrc` (`save-exact=true`) + `npm ci`; the base image by tag (e.g. @@ -169,4 +173,4 @@ Same test before adding a row to a table or the file map — a clause, not a par Skip this if the changes are purely documentation and/or comments. - Use well formed, standard compliant, rich URIs. Prefer state in the URL over POST:ing in for for example list pages with filters and pagination. Do: "ids=x&ids=y" and not "ids[]=x&ids[]=y" - and not "ids=x,y". \ No newline at end of file + and not "ids=x,y". diff --git a/todo.md b/todo.md index bffea4c..9fcf88d 100644 --- a/todo.md +++ b/todo.md @@ -15,6 +15,7 @@ - [x] CI/CD - When renovate updates a dependency - also release a new version of plainpages based on what got updated with Renovate. Major typescript? New apiVersion + new major. A tiny patch to ejs? Only patch release etc. Before implementing, explain in detail how you will solve this. (`renovate.yml` gains an `auto-release` job (`needs: renovate`) that cuts one `vX.Y.Z` tag per run for what Renovate merged; level = highest `Release-Bump:` trailer Renovate stamps via `commitBody`, any dep's major/minor/patch mapped straight through (default patch). Decoupled from `apiVersion` (tag-only, `HOST_API_VERSION` untouched — a "major" is just a bigger image tag, never a plugin break); pre-1.0 shifts down so nothing auto-crosses into 1.0.0. Pure `auto-release/next-version.ts` + unit tests; tag pushed with renovate-bot's PAT so `release.yml` fires; documented in README → CI/CD.) - [ ] Add an e2e test for the admin plugin's OAuth2-clients (Hydra) screen. The full-flow e2e suite runs without Hydra (compose.full.yml), so /admin/clients register/detail/delete is only unit-covered (src/http/app.test.ts); wire Hydra into an e2e stack and drive the screen in the browser. - [ ] Build and publish docker image as CI/CD. +- [ ] The human developer understands the security model in the auth in this project. - [ ] Add i18n support. ## Architectural review findings (2026-07-02) -- 2.52.0