diff --git a/.planning/HANDOFF.json b/.planning/HANDOFF.json
index 681d3e7..f650d6b 100644
--- a/.planning/HANDOFF.json
+++ b/.planning/HANDOFF.json
@@ -1,39 +1,54 @@
{
"version": "1.0",
- "timestamp": "2026-06-26T10:30:00.000Z",
- "phase": "module-planning",
- "phase_name": "dkv-fleet-module",
+ "timestamp": "2026-07-01T13:42:33.474Z",
+ "phase": "09",
+ "phase_name": "cert-manager-module",
+ "phase_dir": ".planning/phases/09-cert-manager-module",
+ "plan": null,
+ "task": null,
+ "total_tasks": null,
"status": "paused",
- "stopped_at": "Context limit approaching — pausing before module planning",
- "resume_command": "/gsd-resume-work",
- "blockers": [],
+ "completed_tasks": [
+ {"id": 1, "name": "Dashboard grid: widget-fix noCompactor deployed", "status": "done", "commit": "dashboard fix"},
+ {"id": 2, "name": "Phase 9 added to ROADMAP.md", "status": "done", "commit": "a32f5f9"},
+ {"id": 3, "name": "09-CONTEXT.md written with all decisions", "status": "done", "commit": "a32f5f9"}
+ ],
+ "remaining_tasks": [
+ {"id": 4, "name": "Run /gsd-ui-phase 9 to generate UI-SPEC.md", "status": "not_started"},
+ {"id": 5, "name": "Run /gsd-plan-phase 9 after UI-SPEC exists", "status": "not_started"},
+ {"id": 6, "name": "Run /gsd-execute-phase 9", "status": "not_started"}
+ ],
+ "blockers": [
+ {
+ "description": "UI-SPEC.md missing — plan-phase UI safety gate blocks planning",
+ "type": "process",
+ "workaround": "Run /gsd-ui-phase 9 first, OR /gsd-plan-phase 9 --skip-ui"
+ }
+ ],
+ "async_jobs": [],
"human_actions_pending": [],
"decisions": [
- "UI-Umbau abgeschlossen: Sidebar ohne Footer/Admin, Admin als eigene Seite (wie Einstellungen), Kategorien einzeln einklappbar",
- "Self-Delete Frontend-Schutz implementiert (Backend war bereits geschützt)",
- "Alle Änderungen committed (ba02b25) und gepusht"
+ {"decision": "Server-side processing via NestJS API", "rationale": "User specified", "phase": "09"},
+ {"decision": "Ephemeral — no DB, no file storage", "rationale": "User specified", "phase": "09"},
+ {"decision": "node-forge library for cert operations", "rationale": "Pure JS, handles PEM/DER/PFX/P7B, Docker-friendly", "phase": "09"},
+ {"decision": "Operations: inspect, split (chain→individual), merge (certs→chain or PFX), convert between formats", "rationale": "User clarified 'teilen' = split not share", "phase": "09"},
+ {"decision": "Password support for PFX/PKCS12 read+write", "rationale": "User requirement", "phase": "09"},
+ {"decision": "Tab UI: Analysieren / Aufteilen / Zusammenführen / Konvertieren", "rationale": "Discussed in context", "phase": "09"},
+ {"decision": "Module slug: cert-manager, category: security-tools", "rationale": "Context decision", "phase": "09"}
],
- "next_module": {
- "name": "DKV Flottenkosten-Modul",
- "description": "Import und Auswertung von DKV-Kraftstoffkarten-Rechnungen pro Fahrzeug und Fahrer",
- "user_files": [
- "user-files/invoice.pdf — DKV E-Rechnung April 2026, CTL GmbH, 3.666,40 EUR",
- "user-files/fahrzeuge.xlsx — Fahrzeugstammdaten (roh)",
- "user-files/fahrzeuge_bereinigt.xlsx — Fahrzeugstammdaten (bereinigt)",
- "user-files/Bildschirmfoto 2026-06-24 um 13.27.56.png — Screenshot bestehendes Flottenmanagement-Tool"
- ],
- "data_insights": {
- "invoice_structure": "Pro Fahrzeug (Kennzeichen): Datum, Tankstelle, Transaktionsnummer, KM-Stand, Produkt (Diesel/Super95/Autostrom AC/DC), Menge, Preis brutto/netto, Gesamtbetrag",
- "vehicle_types": "Mix Verbrenner (Diesel, Euro95) und Elektro (kWh AC/DC)",
- "vehicles_seen": "GP JL 728E, GP JL 729, GP JL 740E, GP JL 742, GP JL 752E, GP JL 799, GP ML 715, GP ML 720, GP ML 721, GP ML 729, GP-JL 275E, GP-JL 278E, GP-JL 282E, GP-JL 298, GP-JL 732, GP-JL 736, GP-JL 748E, GP-JL 760E, GP-JL 767E, GP-JL 912, GP-JL 913E, GP-JL 914E, GP-JL 934E, GP-JL753E, GP-JL916E, GP-ML 702, GP-ML 736",
- "total_invoice": "3.666,40 EUR inkl. 19% USt."
- },
- "open_questions": [
- "Was soll das Modul konkret können? (Import PDF/CSV, Kostenübersicht pro Fahrzeug/Fahrer, Auswertungen, Export?)",
- "Gibt es Fahrerzuordnung zu Fahrzeugen in fahrzeuge.xlsx?",
- "DKV-PDF-Import automatisch geparst oder manuell?",
- "Welche Auswertungen gewünscht (monatlich, pro Fahrer, Kraftstofftyp)?"
- ]
- },
- "context_notes": "User hat DKV-Rechnung (PDF, 5 Seiten) und Fahrzeugdaten (xlsx) in user-files/ bereitgestellt. Screenshot zeigt bestehendes Flottenmanagement-Tool als Referenz. Modulplanung startet in neuer Session mit /gsd-resume-work."
+ "uncommitted_files": [
+ ".mcp.json",
+ ".planning/REQUIREMENTS.md",
+ ".planning/STATE.md",
+ "apps/api/src/auth/auth.service.ts",
+ "apps/api/src/user/user.controller.ts",
+ "apps/web/src/components/dashboard/dashboard-grid.tsx",
+ "apps/web/src/components/dashboard/widgets/note-widget.tsx",
+ "apps/web/src/components/dashboard/widgets/widget-wrapper.tsx",
+ "apps/web/src/components/settings/account-settings-form.tsx",
+ "apps/web/src/lib/auth-actions.ts",
+ "apps/web/src/lib/stores/dashboard-store.ts"
+ ],
+ "next_action": "Run /gsd-ui-phase 9 to generate UI-SPEC.md, then /gsd-plan-phase 9",
+ "context_notes": "Phase 9 (Cert Manager) fully discussed and context captured. Dashboard widget noCompactor fix deployed. plan-phase blocked by UI-SPEC gate."
}
diff --git a/.planning/phases/09-cert-manager-module/.continue-here.md b/.planning/phases/09-cert-manager-module/.continue-here.md
new file mode 100644
index 0000000..817896b
--- /dev/null
+++ b/.planning/phases/09-cert-manager-module/.continue-here.md
@@ -0,0 +1,72 @@
+---
+context: phase
+phase: 09-cert-manager-module
+task: null
+total_tasks: null
+status: planning
+last_updated: 2026-07-01T13:42:33.474Z
+---
+
+# BLOCKING CONSTRAINTS — Read Before Anything Else
+
+_No blocking constraints identified this session._
+
+
+Phase 9 (Cert Manager Module) ist vollständig besprochen und CONTEXT.md geschrieben.
+plan-phase wurde gestartet, aber durch den UI-SPEC Safety Gate blockiert — UI-SPEC.md fehlt noch.
+
+Nächster Schritt: `/gsd-ui-phase 9` ausführen, dann `/gsd-plan-phase 9`.
+
+
+
+
+- Dashboard-Grid-Fix: `compactType={null}` → `compactor={noCompactor}` (react-grid-layout v2 API) — deployed
+- Phase 9 zu ROADMAP.md hinzugefügt (commit a32f5f9)
+- `09-CONTEXT.md` mit allen Entscheidungen erstellt (commit a32f5f9)
+- plan-phase initialisiert → UI-SPEC-Gate erkannt und korrekt geblockt
+
+
+
+
+1. `/gsd-ui-phase 9` — UI-Design-Kontrakt (UI-SPEC.md) erstellen
+2. `/gsd-plan-phase 9` — Pläne erstellen (nach UI-SPEC)
+3. `/gsd-execute-phase 9` — Implementierung
+
+
+
+
+- **Verarbeitung**: Server-seitig (NestJS API), nicht client-seitig
+- **Persistenz**: Ephemer — kein DB, kein Dateisystem, alles In-Memory
+- **"Teilen"** = Aufteilen (fullchain → Einzelzertifikate), NICHT Versenden
+- **Zusammenführen** = PEM-Kette ODER PFX-Bundle (mit Passwort)
+- **Bibliothek**: `node-forge` (pure JS, PEM/DER/PFX/P7B)
+- **Passwort**: Konditionell bei PFX/PKCS12 (lesen + erstellen)
+- **UI**: 4 Tabs — Analysieren / Aufteilen / Zusammenführen / Konvertieren
+- **API**: 4 Endpoints: `/parse` `/split` `/merge` `/convert` unter `/modules/cert-manager`
+- **Modul**: slug=`cert-manager`, category=`security-tools`
+- **Muster**: Domaincheck-Modul als Vorlage (OnModuleInit seed, @UseModule guard)
+
+
+
+- UI-SPEC.md fehlt → plan-phase UI-Safety-Gate blockiert
+- Workaround: `/gsd-plan-phase 9 --skip-ui` (nicht empfohlen)
+
+
+## Required Reading (in order)
+1. `.planning/phases/09-cert-manager-module/09-CONTEXT.md` — alle Entscheidungen
+2. `apps/api/src/domaincheck/` — Modul-Pattern (NestJS)
+3. `apps/web/src/app/(portal)/modules/domaincheck/` — Frontend-Pattern
+
+## Infrastructure State
+- Docker: alle Container laufen (web, api, db)
+- dashboard-grid.tsx: `compactor={noCompactor}` — deployed und aktiv
+
+
+Phase 9 Cert Manager: vollständig geplant auf Konzeptebene. Bereit zur UI-Spec-Erstellung.
+Uncommitted files aus früheren Sessions (auth, user-controller, dashboard-store etc.) existieren noch — nicht Teil von Phase 9.
+
+
+
+Start with: `/gsd-ui-phase 9` — UI-Design-Kontrakt für Cert Manager erstellen
+Then: `/gsd-plan-phase 9`
+