--- phase: 8 slug: dashboard-widgets-vollimplementierung status: draft nyquist_compliant: false wave_0_complete: false created: 2026-07-01 --- # Phase 8 — Validation Strategy > Per-phase validation contract for feedback sampling during execution. --- ## Test Infrastructure | Property | Value | |----------|-------| | **Framework** | Vitest | | **Config file** | `apps/web/vitest.config.ts` / `apps/api/vitest.config.ts` | | **Quick run command** | `pnpm --filter web test --run` / `pnpm --filter api test --run` | | **Full suite command** | `pnpm test --run` | | **Estimated runtime** | ~30 seconds | --- ## Sampling Rate - **After every task commit:** Run `pnpm --filter web test --run && pnpm --filter api test --run` - **After every plan wave:** Run `pnpm test --run` - **Before `/gsd-verify-work`:** Full suite must be green - **Max feedback latency:** 30 seconds --- ## Per-Task Verification Map | Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | Status | |---------|------|------|-------------|------------|-----------------|-----------|-------------------|--------| | 08-01-01 | 08-01 | 1 | DASH-11 | — | N/A | unit | `pnpm --filter web test --run widget-registry` | ⬜ pending | | 08-01-02 | 08-01 | 1 | DASH-08 | — | Keyboard stopPropagation kein Grid-Konflikt | unit | `pnpm --filter web test --run calculator` | ⬜ pending | | 08-01-03 | 08-01 | 1 | DASH-08 | — | N/A | e2e | `pnpm --filter web test --run calculator` | ⬜ pending | | 08-02-01 | 08-02 | 2 | DASH-10 | — | N/A | unit | `pnpm --filter web test --run stopwatch` | ⬜ pending | | 08-02-02 | 08-02 | 2 | DASH-10 | — | N/A | unit | `pnpm --filter web test --run stopwatch` | ⬜ pending | | 08-02-03 | 08-02 | 2 | DASH-10 | — | N/A | integration | `pnpm --filter web test --run stopwatch` | ⬜ pending | | 08-03-01 | 08-03 | 3 | DASH-09 | T-08-05 | SSRF-Schutz blockiert private IPs/localhost | unit | `pnpm --filter api test --run favorites` | ⬜ pending | | 08-03-02 | 08-03 | 3 | DASH-09 | T-08-06 | Ownership-Check: userId+tenantId im WHERE | unit | `pnpm --filter api test --run favorites` | ⬜ pending | | 08-03-03 | 08-03 | 3 | DASH-09 | T-08-07 | iconUrl XSS: nur http/https URLs | integration | `pnpm --filter web test --run favorites` | ⬜ pending | | 08-04-01 | 08-04 | 4 | DASH-09 | — | N/A | unit | `pnpm --filter web test --run link-widget` | ⬜ pending | | 08-04-02 | 08-04 | 4 | DASH-09 | — | N/A | unit | `pnpm --filter web test --run link-widget` | ⬜ pending | | 08-04-03 | 08-04 | 4 | DASH-09 | — | N/A | integration | `pnpm --filter web test --run link-widget` | ⬜ pending | *Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky* --- ## Wave 0 Requirements Keine Wave-0-Infrastruktur-Setup nötig — Vitest bereits konfiguriert in beiden Apps. Bestehende Testinfrastruktur deckt alle Phase-8-Anforderungen. *Existing infrastructure covers all phase requirements.* --- ## Manual-Only Verifications | Behavior | Requirement | Why Manual | Test Instructions | |----------|-------------|------------|-------------------| | Calculator Tastatureingabe funktioniert im Dashboard | DASH-08 | Browser-Interaction + react-grid-layout-Konflikt | Dashboard öffnen, Calculator hinzufügen, Zahlen per Tastatur eingeben | | Favoriten-Icon wird korrekt geladen | DASH-09 | Icon-Discovery via echtem HTTP-Fetch | Favoriten-Widget hinzufügen, URL eingeben, Icon erscheint nach Speichern | | Stoppuhr läuft nach Seiten-Reload weiter | DASH-10 | Browser-State-Persistenz | Stoppuhr starten, Seite neu laden, Zeit läuft weiter | | Alle bestehenden Widgets funktionieren nach Constraint-Anpassung | DASH-11 | Visuelle Layout-Überprüfung | Dashboard laden, alle Widgets prüfen auf korrekte Größe und Bedienbarkeit | --- ## Validation Sign-Off - [ ] All tasks have `` verify or Wave 0 dependencies - [ ] Sampling continuity: no 3 consecutive tasks without automated verify - [ ] Wave 0 covers all MISSING references - [ ] No watch-mode flags - [ ] Feedback latency < 30s - [ ] `nyquist_compliant: true` set in frontmatter **Approval:** pending