- Add deployment-name branding to titles, mastheads, and OG tags
- Share one grant delivery-state query with lineage across grants
surfaces
- Show pool status/usage, org owners, and config readiness
- Make billing views projection-aware with recency and sync vocabulary
- Guard FedWiki creation without domains and render route-aware 404s
Enforce 10j's verified gaps (schema-hardening change):
- Migration 00010: partial unique indexes for one default pool and one
primary assignment per workspace, plus CHECKs pinning
pool/provider/subscription vocabularies and provider lifecycle
timestamps.
- Workspace creation shares a transactional provisioning function;
extension validates its target pool; last-tier deletion of a defaulted
ladder is guarded; signup completes plan-less on a broken ladder.
- Boot asserts integration slug parity and validates declared config
enums; Stripe invoice amounts are range-checked; domain cancellation
runs a final evidence probe; rule authoring is additive-only.
Resume only app-paused schedules so operator pauses survive restarts.
Apply dormancy handling to Discourse and FedWiki.
Remove the unused pool-scoped grant route, hide internal transition
errors, and update specs and tests to use the canonical grant endpoint.
Render grant extension controls only for active grant-backed provisions.
Scan for valid walkthrough subjects and skip when Discourse is
unreachable.
Add a fresh-stack target and document the supported e2e workflow.
Replace product-kind branching and direct position writes with enclosed
database functions driven by structural product shape.
Migrate grant and provision data, unify operator issuance, update
subscription and expiry flows, and add migration and integration proofs.
Squash the pre-production migration history into fresh core, fedwiki,
and stripe baselines and reduce the canonical source list to those
three streams.
Update sqlc configs, generated queries, raw SQL, tests, and docs while
keeping provider tables schema-qualified.
BREAKING: existing local database volumes must be wiped because goose
version history restarts from the new baselines.
Fix HTMX expired-session handling, CSP-blocked form behaviors, reorder
recovery, billing currency display, plan/checkout guards, FedWiki quota
edge cases, and operator/member empty/error states.
Add entitlement uniqueness migrations, canonical migration source
wiring,
and regression coverage for the remediated flows. Update status docs
with
the audit triage and model inventory.
The operator grant forms use <input type="datetime-local">, which submits a
naive wall-clock string with no timezone. The handlers parsed it with time.Parse,
whose default for a zone-less value is UTC — so for an operator behind UTC, a
near-future pick resolved to a past instant, GrantExpirationWorkflow saw a
past valid_until and fired immediately, and the plan reverted to the default at
once instead of lasting the chosen window.
- Route IssueGrant and ExtendGrant through one parseGrantValidUntil helper.
- Interpret the value in the server's local zone (time.ParseInLocation), and when
the browser supplies valid_until_offset (grant-valid-until-tz.js, attached on
htmx:configRequest) resolve the exact instant regardless of server timezone.
- Reject a Valid Until in the past.
Add delivery-aware queries and wire them into server, templates,
and tests. Treat grants.status as lifecycle and use pool_provisions
joins for "currently delivering" semantics. Enable 422 validation
swaps and an error toast trigger; update docs and milestones.
Add per-field validation UI (is-invalid + invalid-feedback) and
propagate FieldErrors in view models. Replace HTMX "Back" buttons with
regular links. Initialize web.New() for collecting form errors. Register
a /partials/ 404 handler to prevent accidental dashboard swaps during
HTMX partial requests.
Introduce web.FieldErrors for server-side per-field messages. Update
templates to render is-invalid/invalid-feedback and add a fieldErr
template helper that scopes errors to a specific form instance. Update
operator handlers to validate inputs, populate FieldErrors, and render
form-specific error state; add a no-op fieldErr stub to fedwiki partials
so parsing succeeds.
Replace inline success alert banners with HX-Trigger-driven toasts.
Introduce fireSuccessToast helper and call it from renderers instead of
injecting Success into templates. Add backfill dry-run support and
preview
button plus UI text tweaks for org-type backfills.
Introduce a renderBody template func to dispatch dynamic body partials
from operator.html (real implementation in NewOperatorPartialsHandler).
Add GetOrganizationsPage and GetOrganizationDetailPage to render MPA
pages by setting BodyTemplate/BodyData and ActiveCapability on the
OperatorPageData. Refactor enrollment hydration into
loadOrgEnrollmentData,
update templates to use /operator/organizations links and target
Add default_plan_ladder_id with a forward data migration and update
the runtime to resolve the ladder's rank-0 tier at use-time. Regenerate
sqlc, update auto-provisioning, ReapplyDefaultsForPool, operator UI and
tests; add GetTierByLadderRank and pool/provision query helpers. Add a
CSP-safe confirm-action modal and wire operator actions to it. Close
plan-sole-writer safety gaps and serialize IssueGrant with a FOR UPDATE
pool lock to prevent ladder races.
Introduce operator enrollment partials and handlers that route plan-tier
granting and revocation through entitlements.Transition(). Add
member-facing
tier labels, plan architecture and grant-plan-safety documentation, plus
unit and e2e tests. Also add small querier helpers and wire Temporal
client
hooks for trial expiration scheduling.