docs(plans): Vikunja probe record; lead decision 51
Researcher ran P1-P7 on a scratch Vikunja 2.7.0. Scope names in addendum A are wrong, polling on updated misses column moves and deletions, and If-Match isn't enforced. Decision 51 rules on each. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -824,3 +824,27 @@ which stay with him. Each item names who decided it and what happened.
|
||||
- The three views: accepted as demonstrations. Counting a person's
|
||||
edit in the same second as a broker write as external is the
|
||||
cautious side, and stays.
|
||||
51. **Sage's rulings on the Vikunja probes (2026-10-04).** Source:
|
||||
Researcher, `agents/researcher/work/2026-10-04_vikunja-probes.md`
|
||||
(sha256 ef0beec6…), probes P1 to P7 against a scratch
|
||||
`vikunja/vikunja:2.7.0` (digest e2204a1c…), since removed. Where the
|
||||
probes and addendum A disagree, the probes win.
|
||||
- Token scopes: addendum A's example group names don't exist, and
|
||||
Vikunja refuses unknown groups with 400. Darkwing rewrites the
|
||||
scope map from the real route groups in addendum B.
|
||||
- Polling on `updated` misses bucket moves between columns that
|
||||
aren't done, bulk label sets and deletions. The hourly reconcile
|
||||
alone would leave a person's column move unseen for up to an hour.
|
||||
Darkwing proposes in addendum B how the 30-second poll catches moves
|
||||
and deletions too, for example by also listing the task ids in each
|
||||
bucket of the project's kanban view. At slice 1 scale that costs a
|
||||
few requests per poll.
|
||||
- Vikunja doesn't enforce `If-Match`. The broker compares before it
|
||||
writes and the race window stays, as 6.8 already says. The broker
|
||||
writes with `PATCH` of owned fields only, never `PUT`, which
|
||||
clears omitted fields. Labels change only through the single add and
|
||||
remove routes, never as a `labels` key in a `PATCH` body.
|
||||
- A 401 means either an expired token or one out of scope. The broker
|
||||
checks `expires_at` itself, both after minting (Vikunja accepts a
|
||||
past date) and before each use, then treats any 401 as a refusal
|
||||
and logs both possible causes.
|
||||
|
||||
Reference in New Issue
Block a user