fix/p0-security-hardening #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/p0-security-hardening"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Make the project's documentation match the code and remove the sprawl. The docs claimed Phase 2.8 (drug interactions) was 'planning/0%' and the backend '~91% complete' — both wrong: 2.8 is implemented and live, plus the P0/P1 security and test work is done. Five root CI/CD docs described a 'docker-build' CI job that was removed; ~18 backend/ status snapshots and ~24 docs/implementation duplicates cluttered the tree. Deletions (85 files): - Root: 4 stale CI/CD reports (CI-CD-{COMPLETION-REPORT,IMPLEMENTATION-SUMMARY, STATUS-REPORT,FINAL-STATUS}.md) — all describe the removed docker-build job. - backend/: 18 phase/build/fix snapshots and code-dump .txt files. - docs/: the 3 one-time reorg reports; ~17 docs/implementation duplicates and process artifacts; 4 stale docs/development CI docs + git snapshots; redundant deployment/testing files. - thoughts/: STATUS.md (said Phase 2.4 in-progress), superseded phase notes and duplicative research inputs. tmp/ (928KB of CI debug logs, gitignored). Moves (18 files): - 9 genuine decision records -> docs/adr/ (Architecture Decision Records), date-prefixes stripped, with an index README. - 8 historical-but-valuable phase plans/specs + the old CI-CD-FINAL-SOLUTION -> docs/archive/ (now-populated, with a README explaining it's superseded material). thoughts/ tree removed. Rewrites (13 files) to match reality: - Drop the fake '% complete' figures everywhere in favor of Implemented / In-Progress / Planned with concrete endpoint/feature lists. - Phase 2.8 -> Implemented; add /api/interactions/* and /api/auth/{refresh, logout} to the endpoint lists; fix 'Rust 1.93' -> edition 2021. - Add a Security section (token_version validation, hashed refresh-token persistence, fail-fast config, real-IP audit) and correct the test-coverage and deployment claims to reality. - New canonical docs/development/CI-CD.md (4 jobs: format/clippy/build/test, mongo service, no docker-build + why). - README, docs/README, product/{STATUS,ROADMAP,PROGRESS,README,introduction}, implementation/README, development/README, testing/README, AI_AGENT_GUIDE, .cursorrules, .gooserules all updated. Verified: greps for 'Phase 2.8 (Planning)', 'PLANNING (0%)', 'Rust 1.93', '91%/10%/85% complete', and 'docker-build' return nothing outside docs/archive; all internal doc links resolve; backend/src untouched (cargo build clean).