docs(project): record activation evidence
This commit is contained in:
@@ -1,14 +1,14 @@
|
|||||||
# Test Evidence: Atomic Project workflows
|
# Test Evidence: Atomic Project workflows
|
||||||
|
|
||||||
- **Test type:** Integration
|
- **Test type:** Integration
|
||||||
- **Requirement IDs:** `PRJ-001`–`PRJ-007`, `PRJ-017`, `AUTH-001`–`AUTH-004`, `DB-003`, `DB-007`
|
- **Requirement IDs:** `PRJ-001`–`PRJ-007`, `PRJ-012`, `PRJ-017`, `AUTH-001`–`AUTH-004`, `AUTH-011`, `DB-003`, `DB-007`
|
||||||
- **Scenario IDs:** `AC-PRJ-001`–`AC-PRJ-003`, `AC-PRJ-009`
|
- **Scenario IDs:** `AC-AUTH-010`, `AC-PRJ-001`–`AC-PRJ-003`, `AC-PRJ-006`, `AC-PRJ-009`
|
||||||
- **Test class/method:** `com.lab.labtimesheet.feature.project.service.ProjectServiceIntegrationTest`
|
- **Test class/method:** `com.lab.labtimesheet.feature.project.service.ProjectServiceIntegrationTest`
|
||||||
- **Implementation commit:** `25a855e`
|
- **Implementation commits:** `25a855e`, `dbf1202`
|
||||||
|
|
||||||
## Protected behavior
|
## Protected behavior
|
||||||
|
|
||||||
PostgreSQL transactions persist a planned Project with its initial membership and leadership term, reject unauthorized or duplicate direct additions, change exactly one Leader without moving Task assignments, and enforce role/membership visibility without ID disclosure.
|
PostgreSQL transactions persist a planned Project with its initial membership and leadership term, reject unauthorized or duplicate direct additions, change exactly one Leader without moving Task assignments, enforce role/membership visibility without ID disclosure, and activate only when current eligible membership/leadership and live-Task assignee guards pass.
|
||||||
|
|
||||||
## Test method
|
## Test method
|
||||||
|
|
||||||
@@ -16,7 +16,7 @@ A Spring Boot integration test uses the platform-owned PostgreSQL 18.4 Testconta
|
|||||||
|
|
||||||
## Hand-derived expected result
|
## Hand-derived expected result
|
||||||
|
|
||||||
Creation yields one Project, one active membership, and one current leadership term. Direct addition yields one membership per Project/Intern pair while allowing the same Intern in a second Project. Leader change yields one closed and one current term while the Task assignee ID remains unchanged. Admin, owner, and historical member visibility is allowed; unrelated IDs are denied uniformly.
|
Creation yields one Project, one active membership, and one current leadership term. Direct addition yields one membership per Project/Intern pair while allowing the same Intern in a second Project. Leader change yields one closed and one current term while the Task assignee ID remains unchanged. Activation persists `ACTIVE` and `activated_at` when every live Task is assigned to a current eligible membership; a live Task assigned to a closed membership leaves the Project `PLANNED` and the Task intact. Admin, owner, and historical member visibility is allowed; unrelated IDs are denied uniformly.
|
||||||
|
|
||||||
## RED
|
## RED
|
||||||
|
|
||||||
@@ -52,10 +52,16 @@ export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
|||||||
|
|
||||||
```text
|
```text
|
||||||
[INFO] Running com.lab.labtimesheet.feature.project.service.ProjectServiceIntegrationTest
|
[INFO] Running com.lab.labtimesheet.feature.project.service.ProjectServiceIntegrationTest
|
||||||
[INFO] Tests run: 4, Failures: 0, Errors: 0, Skipped: 0
|
[INFO] Tests run: 7, Failures: 0, Errors: 0, Skipped: 0
|
||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Activation transaction regression
|
||||||
|
|
||||||
|
**RED:** the focused PostgreSQL activation tests failed at test compilation because `ProjectService.activate(long, long)` did not exist.
|
||||||
|
|
||||||
|
**GREEN:** after wiring the locked Project aggregate to Account eligibility and `TaskQueryService.countCurrentTasksAssignedOutside`, both focused activation tests passed. The valid Project became `ACTIVE`; the former-member assignee case threw `ProjectRuleViolationException`, retained `PLANNED`, and preserved its live Task.
|
||||||
|
|
||||||
## Affected suite
|
## Affected suite
|
||||||
|
|
||||||
**Command and result**
|
**Command and result**
|
||||||
@@ -66,10 +72,10 @@ export PATH="$JAVA_HOME/bin:$PATH"
|
|||||||
export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
||||||
./mvnw test
|
./mvnw test
|
||||||
|
|
||||||
[INFO] Tests run: 25, Failures: 0, Errors: 0, Skipped: 0
|
[INFO] Tests run: 111, Failures: 0, Errors: 0, Skipped: 0
|
||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
## External-test boundaries
|
## External-test boundaries
|
||||||
|
|
||||||
This test does not prove MockMvc authorization, Thymeleaf rendering, browser accessibility, real concurrent transaction races, Iteration 2 invitations/removals/completion, or Task-module business rules beyond preserving stored assignment IDs. `I1-PRJ-04` remains `IN_PROGRESS`: the activation Task-assignee guard will be implemented only after the Task feature exposes its concrete query service.
|
This test does not prove MockMvc authorization, Thymeleaf rendering, browser accessibility, a two-transaction lock race, or Iteration 2 invitations/removals/completion. Task query semantics have their own Task-owned unit evidence; this integration proves Project consumes that public service boundary atomically without importing Task persistence.
|
||||||
|
|||||||
@@ -4,11 +4,11 @@
|
|||||||
- **Requirement IDs:** `PRJ-001`–`PRJ-007`, `PRJ-012`, `PRJ-017`, `AUTH-001`–`AUTH-004`
|
- **Requirement IDs:** `PRJ-001`–`PRJ-007`, `PRJ-012`, `PRJ-017`, `AUTH-001`–`AUTH-004`
|
||||||
- **Scenario IDs:** `AC-PRJ-001`, `AC-PRJ-003`, `AC-PRJ-006`, `AC-PRJ-009`
|
- **Scenario IDs:** `AC-PRJ-001`, `AC-PRJ-003`, `AC-PRJ-006`, `AC-PRJ-009`
|
||||||
- **Test class/method:** `com.lab.labtimesheet.feature.project.model.entity.ProjectEntityTest`
|
- **Test class/method:** `com.lab.labtimesheet.feature.project.model.entity.ProjectEntityTest`
|
||||||
- **Implementation commit:** `25a855e`
|
- **Implementation commits:** `25a855e`, `dbf1202`
|
||||||
|
|
||||||
## Protected behavior
|
## Protected behavior
|
||||||
|
|
||||||
Project creation cannot produce an empty or leaderless aggregate; direct membership rejects ineligible or duplicate current members; leadership changes leave one current term; activation is owning-Mentor-only and rejects invalid Task assignees.
|
Project creation cannot produce an empty or leaderless aggregate; direct membership rejects ineligible or duplicate current members; leadership changes leave one current term; activation is owning-Mentor-only and requires an eligible active member, an eligible active current Leader, and valid current Task assignees.
|
||||||
|
|
||||||
## Test method
|
## Test method
|
||||||
|
|
||||||
@@ -16,7 +16,7 @@ Plain JUnit drives the aggregate through its public factory and mutation methods
|
|||||||
|
|
||||||
## Hand-derived expected result
|
## Hand-derived expected result
|
||||||
|
|
||||||
A planned Project starts with one current membership and one current leadership term. Adding a different eligible Intern yields two current memberships. Changing Leader closes one term and opens one term while retaining both memberships. Activation changes only `PLANNED` to `ACTIVE` when every supplied guard is true.
|
A planned Project starts with one current membership and one current leadership term. Adding a different eligible Intern yields two current memberships. Changing Leader closes one term and opens one term while retaining both memberships. Activation changes only `PLANNED` to `ACTIVE` when the owning Mentor acts, the supplied active-Intern set contains a current member and the current Leader, and every Task assignee guard passes.
|
||||||
|
|
||||||
## RED
|
## RED
|
||||||
|
|
||||||
@@ -54,6 +54,12 @@ export PATH="$JAVA_HOME/bin:$PATH"
|
|||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Activation guard regression
|
||||||
|
|
||||||
|
**RED:** after strengthening the aggregate test with the active-Intern set, compilation failed because `ProjectEntity.activate` still accepted only `(long, boolean, Instant)` and could not prove that the current Leader remained eligible and active.
|
||||||
|
|
||||||
|
**GREEN:** after adding the active-Intern input and aggregate checks, `./mvnw -Dtest=ProjectEntityTest test` passed 6 tests with zero failures, errors, or skips.
|
||||||
|
|
||||||
## Affected suite
|
## Affected suite
|
||||||
|
|
||||||
**Command and result**
|
**Command and result**
|
||||||
@@ -61,12 +67,13 @@ export PATH="$JAVA_HOME/bin:$PATH"
|
|||||||
```text
|
```text
|
||||||
export JAVA_HOME=/opt/homebrew/opt/openjdk@25
|
export JAVA_HOME=/opt/homebrew/opt/openjdk@25
|
||||||
export PATH="$JAVA_HOME/bin:$PATH"
|
export PATH="$JAVA_HOME/bin:$PATH"
|
||||||
./mvnw -Dtest=ProjectEntityTest test
|
export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
||||||
|
./mvnw -Dtest='Project*Test' test
|
||||||
|
|
||||||
[INFO] Tests run: 6, Failures: 0, Errors: 0, Skipped: 0
|
[INFO] Tests run: 25, Failures: 0, Errors: 0, Skipped: 0
|
||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
## External-test boundaries
|
## External-test boundaries
|
||||||
|
|
||||||
This unit test does not prove JPA/Flyway mappings, PostgreSQL constraints or transaction concurrency, Spring Security routing, Task-module query integration, or browser rendering.
|
This unit test does not prove JPA/Flyway mappings, PostgreSQL constraints or transaction concurrency, Spring Security routing, the Task query implementation, or browser rendering; those are covered at their narrower integration and web layers.
|
||||||
|
|||||||
@@ -1,14 +1,14 @@
|
|||||||
# Test Evidence: Authorized Project pages
|
# Test Evidence: Authorized Project pages
|
||||||
|
|
||||||
- **Test type:** Web
|
- **Test type:** Web
|
||||||
- **Requirement IDs:** `AUTH-001`, `AUTH-002`, `AUTH-006`, `PRJ-001`, `PRJ-004`–`PRJ-006`, `SEC-001`, `ERR-001`
|
- **Requirement IDs:** `AUTH-001`, `AUTH-002`, `AUTH-006`, `PRJ-001`, `PRJ-004`–`PRJ-006`, `PRJ-012`, `SEC-001`, `ERR-001`
|
||||||
- **Scenario IDs:** `AC-AUTH-001`, `AC-AUTH-002`, `AC-AUTH-007`, `I1-PRJ-05`
|
- **Scenario IDs:** `AC-AUTH-001`, `AC-AUTH-002`, `AC-AUTH-007`, `AC-PRJ-006`, `I1-PRJ-04`, `I1-PRJ-05`
|
||||||
- **Test class/method:** `com.lab.labtimesheet.feature.project.controller.ProjectControllerTest`
|
- **Test class/method:** `com.lab.labtimesheet.feature.project.controller.ProjectControllerTest`
|
||||||
- **Implementation commits:** `25a855e`, `a9ee99a`
|
- **Implementation commits:** `25a855e`, `a9ee99a`, `2f25731`, `dbf1202`
|
||||||
|
|
||||||
## Protected behavior
|
## Protected behavior
|
||||||
|
|
||||||
Authenticated users receive only authorized Project routes; guessed IDs return a non-disclosing not-found response; valid Mentor create requests use the authenticated identity; invalid forms do not mutate; state changes require CSRF.
|
Authenticated users receive only authorized Project routes; guessed IDs return a non-disclosing not-found response; valid Mentor create requests use the authenticated identity; invalid forms do not mutate; the planned-Project activation action is shown only to the owning Mentor; state changes require CSRF.
|
||||||
|
|
||||||
## Test method
|
## Test method
|
||||||
|
|
||||||
@@ -16,7 +16,7 @@ MockMvc exercises the real controller, binding, Bean Validation, exception mappi
|
|||||||
|
|
||||||
## Hand-derived expected result
|
## Hand-derived expected result
|
||||||
|
|
||||||
An authorized list request renders `projects/list`. An unauthorized direct ID returns 404. Member and leadership routes authorize through actor plus Project ID. A valid create redirects to the created detail ID; a blank name and zero Leader ID render field errors and make no service call. POST without CSRF returns 403.
|
An authorized list request renders `projects/list`. An unauthorized direct ID returns 404. Member and leadership routes authorize through actor plus Project ID. A valid create redirects to the created detail ID; a blank name and zero Leader ID render field errors and make no service call. An owning Mentor can submit activation and is redirected to detail; non-owners do not receive that control. POST without CSRF returns 403.
|
||||||
|
|
||||||
## RED
|
## RED
|
||||||
|
|
||||||
@@ -50,7 +50,7 @@ export PATH="$JAVA_HOME/bin:$PATH"
|
|||||||
|
|
||||||
```text
|
```text
|
||||||
[INFO] Running com.lab.labtimesheet.feature.project.controller.ProjectControllerTest
|
[INFO] Running com.lab.labtimesheet.feature.project.controller.ProjectControllerTest
|
||||||
[INFO] Tests run: 6, Failures: 0, Errors: 0, Skipped: 0
|
[INFO] Tests run: 10, Failures: 0, Errors: 0, Skipped: 0
|
||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -64,7 +64,7 @@ export PATH="$JAVA_HOME/bin:$PATH"
|
|||||||
export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
||||||
./mvnw test
|
./mvnw test
|
||||||
|
|
||||||
[INFO] Tests run: 25, Failures: 0, Errors: 0, Skipped: 0
|
[INFO] Tests run: 111, Failures: 0, Errors: 0, Skipped: 0
|
||||||
[INFO] BUILD SUCCESS
|
[INFO] BUILD SUCCESS
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -80,6 +80,12 @@ export DOCKER_HOST=unix:///Users/sechmachine/.orbstack/run/docker.sock
|
|||||||
|
|
||||||
**GREEN:** rerunning `./mvnw -Dtest=ProjectControllerTest test` after resolving the public actor view and conditionally rendering the link passed 8 tests with zero failures, errors, or skips.
|
**GREEN:** rerunning `./mvnw -Dtest=ProjectControllerTest test` after resolving the public actor view and conditionally rendering the link passed 8 tests with zero failures, errors, or skips.
|
||||||
|
|
||||||
|
## Activation-route regression
|
||||||
|
|
||||||
|
**RED:** the focused MockMvc run reported two expected failures: `POST /projects/30/activate` returned `404`, and the owning Mentor's planned-Project detail did not render the `Activate` action.
|
||||||
|
|
||||||
|
**GREEN:** after adding the CSRF-protected POST route and owner/status-conditional Thymeleaf form, the two focused tests passed; the full `ProjectControllerTest` class passed 10 tests with zero failures, errors, or skips.
|
||||||
|
|
||||||
## External-test boundaries
|
## External-test boundaries
|
||||||
|
|
||||||
This slice does not prove PostgreSQL query correctness, a real login flow, shared-shell navigation, browser accessibility, or Iteration 2 invitation/exit/completion pages. The activation route remains deferred with `I1-PRJ-04` until the Task feature query dependency is available.
|
This slice does not prove PostgreSQL query correctness, a real login flow, shared-shell navigation, browser accessibility, or Iteration 2 invitation/exit/completion pages. Server-side activation authorization and Task-assignee atomicity are covered by Project domain and PostgreSQL integration tests.
|
||||||
|
|||||||
Reference in New Issue
Block a user