{ "version": "1.0", "timestamp": "2026-06-12T08:33:19.724Z", "phase": "08", "phase_name": "stack-upgrade-backend-decomposition", "phase_dir": ".planning/phases/08-stack-upgrade-backend-decomposition", "plan": 8, "task": 0, "total_tasks": 3, "status": "paused", "completed_tasks": [ {"id": "08-01", "name": "xfail stubs + CR contract locks", "status": "done", "commit": "c636ac9"}, {"id": "08-02", "name": "CloudConnectionOut migration + schemas.py", "status": "done", "commit": "98dcf80"}, {"id": "08-03", "name": "CR-01/02/03 session-revocation + toastStore stub", "status": "done", "commit": "aa1c5ee"}, {"id": "08-04", "name": "Admin API decomposition → admin/ package", "status": "done", "commit": "f01fb0e"}, {"id": "08-05", "name": "Documents API decomposition → documents/ package", "status": "done", "commit": "81337bd"}, {"id": "08-06", "name": "Auth API decomposition → auth/ package (CR-01/02/03 preserved)", "status": "done", "commit": "5117e25"}, {"id": "08-07", "name": "Frontend api/client.js → 7 domain modules + utils.js", "status": "done", "commit": "7e99b6e"} ], "remaining_tasks": [ { "id": "08-08", "name": "Dependency upgrades — vite@6, @vueuse/core, tailwind-forms, backend == pins", "status": "not_started", "autonomous": false, "requires_human": "User must verify packages on npmjs.com before execution (see plan frontmatter user_setup)" } ], "blockers": [], "human_actions_pending": [ { "action": "Verify npm packages on npmjs.com before executing plan 08-08", "context": "Plan 08-08 is autonomous:false and requires manual package verification: @vueuse/core, @vueuse/integrations, sortablejs, @tailwindcss/forms, rollup-plugin-visualizer, @types/sortablejs, vite@^6.4.3, @vitejs/plugin-vue — each must show legitimate maintainer, weekly downloads > 10k, no recent malware advisories", "blocking": true } ], "decisions": [ { "decision": "list_documents registered directly on parent router in documents/__init__.py (not via include_router)", "rationale": "FastAPI 0.128 raises 'Prefix and path cannot be both empty' when include_router gets prefix='' and route.path=''. Direct router.add_api_route('') on parent avoids the check.", "phase": "08" }, { "decision": "extract_and_classify and get_storage_backend_for_document re-exported from api.documents.__init__", "rationale": "Test monkeypatching targets api.documents.X names. After decomposition these lived in sub-modules. Re-exporting from __init__ + late import in handler preserves the patch target without changing tests.", "phase": "08" }, { "decision": "Wave 2 agents committed directly to main (not worktree branches) due to permission lockdown in worktrees", "rationale": "Spawned agents with isolation=worktree were denied write access inside their worktree paths. The commits still landed on main in a non-isolated way. Recovery was done inline by orchestrator.", "phase": "08" } ], "uncommitted_files": [], "next_action": "Execute plan 08-08: /gsd:execute-phase 8 (after user verifies npm packages on npmjs.com)", "context_notes": "Wave 2 (plans 08-04 through 08-07) is fully done. Full backend suite 405/406 passed (1 pre-existing docx env skip). Wave 3 is plan 08-08 only, which is autonomous:false and needs npm package supply-chain verification before execution." }