--- phase: 05-dashboard-calendar plan: 05 type: execute wave: 4 depends_on: ["05-01", "05-02", "05-03", "05-04"] files_modified: [] autonomous: false requirements: [DASH-01, DASH-02, DASH-03, DASH-04, DASH-05, DASH-06, DASH-07, CAL-01, CAL-02, CAL-03] must_haves: truths: - "Human confirms the dashboard grid, all four widgets, settings, and calendar integration work end-to-end" artifacts: [] key_links: [] --- Final human verification of the complete Phase 05 dashboard & calendar experience. All implementation is automated in plans 05-01 through 05-04; this plan pauses for the user to visually and functionally confirm the full flow before the phase closes. Purpose: Catch visual/interaction regressions that automated tests cannot (drag feel, theme correctness, real calendar fetch). Closes the phase against ROADMAP success criteria 1-5. Output: Human sign-off (or a gap list to feed `/gsd-plan-phase --gaps`). No new symbols — verification-only plan. @$HOME/.claude/gsd-core/workflows/execute-plan.md @$HOME/.claude/gsd-core/templates/summary.md @.planning/ROADMAP.md @.planning/phases/05-dashboard-calendar/05-UI-SPEC.md @.planning/phases/05-dashboard-calendar/05-01-SUMMARY.md @.planning/phases/05-dashboard-calendar/05-02-SUMMARY.md @.planning/phases/05-dashboard-calendar/05-03-SUMMARY.md @.planning/phases/05-dashboard-calendar/05-04-SUMMARY.md Task 1: Pre-flight — start stack and run full test suite - .planning/phases/05-dashboard-calendar/05-01-SUMMARY.md - .planning/phases/05-dashboard-calendar/05-02-SUMMARY.md - .planning/phases/05-dashboard-calendar/05-03-SUMMARY.md - .planning/phases/05-dashboard-calendar/05-04-SUMMARY.md Confirm the full Docker Compose stack is running (web + api + postgres). Run the complete web test suite and the api type-check to confirm the phase is green before asking the human to verify. If anything fails, report it and do NOT proceed to the human checkpoint. Ensure CALENDAR_ENCRYPTION_KEY is set in the api environment so calendar endpoints respond. cd apps/web && pnpm test && cd ../api && npx tsc --noEmit - `cd apps/web && pnpm test` exits 0 (full suite green) - `cd apps/api && npx tsc --noEmit` exits 0 - Docker stack reachable (web responds, api /health responds) Full automated suite green and stack running; ready for human verification. Complete Phase 05 dashboard & calendar: a configurable drag-and-drop widget grid as the portal start page, four widgets (Clock, Search, Notes, Calendar), per-user layout persistence, a Settings page (via avatar menu) with widget config and calendar source management, and multi-protocol calendar integration (CalDAV / Exchange / ICS). Open the portal in a browser (logged in as a normal user). Dashboard grid + persistence (DASH-01/02/07): 1. Confirm the start page shows the empty-state ("Keine Widgets aktiv") with a visible pencil edit button. 2. Click the pencil (top-right) — grid lines appear, "Widget hinzufuegen" button appears. 3. Add each widget type from the catalog modal (Clock, Search, Notes, Calendar). Confirm all four appear. 4. In edit mode, drag a widget to a new position and resize it. Confirm snapping + reflow. 5. Click the checkmark to exit edit mode. Reload the page — confirm the layout persists exactly (DASH-07). Clock (DASH-03): confirm it ticks. In Settings > Dashboard > Widgets, set a timezone and toggle date — confirm the widget updates. Search (DASH-04): pick a provider (Google/Bing/DuckDuckGo), type a query, press Enter/click — confirm a new browser tab opens the correct search. Add a custom provider in Settings and confirm it appears in the dropdown. Notes (DASH-06): type Markdown (bold, checkbox list). Confirm live rendering + toolbar. Wait ~1s, reload — confirm content persisted (autosave). Set a custom title in Settings. Settings (D-19/D-20): open via the avatar menu (NOT the sidebar). Confirm the sub-sidebar with Dashboard > Widgets / Kalender and the "Zurueck zum Dashboard" link. Calendar (CAL-01/02/03, DASH-05): in Settings > Dashboard > Kalender add a real ICS source (e.g. a public .ics URL). Confirm connection success. Confirm the Calendar widget lists upcoming events with source color dots. Toggle the source's visibility off — confirm its events disappear from the widget. (CalDAV/Exchange: test if you have credentials; ICS is the minimum.) Cross-cutting: - Toggle dark/light theme — confirm all widgets (esp. Notes Markdown editor) render correctly in both. - Switch DE/EN — confirm all dashboard/settings strings translate (no raw keys). - Resize the browser narrow (<768px) — confirm widgets stack vertically (D-22). Report any visual or functional issue; otherwise approve. Type "approved" if everything works, or describe each issue found. ## Trust Boundaries No new trust boundaries — verification-only plan; all enforcement was implemented and threat-modeled in plans 05-01 through 05-04. ## STRIDE Threat Register | Threat ID | Category | Component | Disposition | Mitigation Plan | |-----------|----------|-----------|-------------|-----------------| | T-05-V1 | Information Disclosure | manual calendar source test | accept | Human uses own test credentials in a dev stack; no production data | - Full web test suite green (Task 1) - API type-check green (Task 1) - Human confirms all ROADMAP Phase 05 success criteria 1-5 - Human approves the complete dashboard + calendar experience, OR - A concrete gap list is produced for `/gsd-plan-phase 05 --gaps` Create `.planning/phases/05-dashboard-calendar/05-05-SUMMARY.md` when done