feat(web): add authenticated task BFF - #224
Closed
seonghobae wants to merge 7 commits into
Closed
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Sep 2, 2026
Contributor
Author
|
Superseded by #238 after verified complete non-force ancestry repair. Parent #223 advanced to #237 by ancestry only with zero file delta. #238 head |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Advances #209 as a dependency-ordered child of #223. This bounded slice adds authenticated Task create/list browser boundaries beneath a Project. It derives workspace authority only from Identity, validates the opaque UUIDv4 parent Project before dependency access, signs the exact Planning method/path, forwards no browser credential to Planning, fails closed on workspace/parent/schema/status mismatches, rejects duplicate or oversized Task collections, preserves tenant-indistinguishable missing-parent semantics, and exposes only browser-safe Task evidence.
Test-first RED starts at
af185e9e42c7624418a05999266f63e4ba736b16, which required Task handlers before production implementation. The current implementation uses a separateplanning-task-client.tsbounded boundary rather than extending the Goal/Project client further, and adds Next.js 15 dynamic GET/POST routes plus route-contract evidence.Keep this PR Draft until #223 is integrated/rebased without destructive history and the unchanged exact head satisfies focused/full tests, CI/security/review/thread/live-base gates. This slice adds no workspace UI and does not close #209.