docs(plans): Vikunja probe record; lead decision 51

Researcher ran P1-P7 on a scratch Vikunja 2.7.0. Scope names in
addendum A are wrong, polling on updated misses column moves and
deletions, and If-Match isn't enforced. Decision 51 rules on each.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-04 18:31:47 -05:00
co-authored by Claude Opus 5.5
parent 1595553ad9
commit 5175ca10f2
3 changed files with 256 additions and 0 deletions
+24
View File
@@ -824,3 +824,27 @@ which stay with him. Each item names who decided it and what happened.
- The three views: accepted as demonstrations. Counting a person's
edit in the same second as a broker write as external is the
cautious side, and stays.
51. **Sage's rulings on the Vikunja probes (2026-10-04).** Source:
Researcher, `agents/researcher/work/2026-10-04_vikunja-probes.md`
(sha256 ef0beec6…), probes P1 to P7 against a scratch
`vikunja/vikunja:2.7.0` (digest e2204a1c…), since removed. Where the
probes and addendum A disagree, the probes win.
- Token scopes: addendum A's example group names don't exist, and
Vikunja refuses unknown groups with 400. Darkwing rewrites the
scope map from the real route groups in addendum B.
- Polling on `updated` misses bucket moves between columns that
aren't done, bulk label sets and deletions. The hourly reconcile
alone would leave a person's column move unseen for up to an hour.
Darkwing proposes in addendum B how the 30-second poll catches moves
and deletions too, for example by also listing the task ids in each
bucket of the project's kanban view. At slice 1 scale that costs a
few requests per poll.
- Vikunja doesn't enforce `If-Match`. The broker compares before it
writes and the race window stays, as 6.8 already says. The broker
writes with `PATCH` of owned fields only, never `PUT`, which
clears omitted fields. Labels change only through the single add and
remove routes, never as a `labels` key in a `PATCH` body.
- A 401 means either an expired token or one out of scope. The broker
checks `expires_at` itself, both after minting (Vikunja accepts a
past date) and before each use, then treats any 401 as a refusal
and logs both possible causes.