Files

83 lines
4.0 KiB
Markdown

---
phase: 9
slug: cert-manager-module
status: draft
nyquist_compliant: false
wave_0_complete: false
created: 2026-07-01
---
# Phase 9 — Validation Strategy
> Per-phase validation contract for feedback sampling during execution.
---
## Test Infrastructure
| Property | Value |
|----------|-------|
| **Framework** | Vitest 3.x |
| **Config file** | `apps/api/vitest.config.ts` / `apps/web/vitest.config.ts` |
| **Quick run command** | `pnpm --filter api test --run apps/api/src/modules/cert-manager` |
| **Full suite command** | `pnpm --filter api test --run && pnpm --filter web test --run` |
| **Estimated runtime** | ~30 seconds |
---
## Sampling Rate
- **After every task commit:** Run `pnpm --filter api test --run apps/api/src/modules/cert-manager`
- **After every plan wave:** Run `pnpm --filter api test --run && pnpm --filter web test --run`
- **Before `/gsd-verify-work`:** Full suite must be green
- **Max feedback latency:** 30 seconds
---
## Per-Task Verification Map
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
| 09-01-01 | 01 | 0 | CERT-01 | — | node-forge installs without native build | unit | `pnpm --filter api test --run` | ❌ W0 | ⬜ pending |
| 09-01-02 | 01 | 1 | CERT-01 | — | PEM/DER/PFX parsed → subject/issuer/validity/SANs/fingerprint returned | unit | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
| 09-02-01 | 02 | 1 | CERT-02 | T-09-01 | Split returns correct number of certs; each is valid PEM | unit | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
| 09-03-01 | 03 | 2 | CERT-03 | T-09-01 | Merge produces valid PEM chain; PFX password-protected | unit | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
| 09-04-01 | 04 | 2 | CERT-04 | — | Round-trip PEM→DER→PEM produces identical cert | unit | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
| 09-05-01 | 05 | 2 | CERT-05 | T-09-02 | Wrong PFX password returns 400, not 500 | unit | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
| 09-06-01 | 06 | 3 | CERT-06 | — | Module appears in registry with slug cert-manager | integration | `pnpm --filter api test --run apps/api/src/modules/cert-manager` | ❌ W0 | ⬜ pending |
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
---
## Wave 0 Requirements
- [ ] `apps/api/src/modules/cert-manager/__tests__/cert-processor.service.spec.ts` — unit test stubs for CERT-01 through CERT-05
- [ ] `apps/api/src/modules/cert-manager/__tests__/cert-manager.controller.spec.ts` — controller test stubs
- [ ] `node-forge` package installed in `apps/api`
*Wave 0 installs node-forge and creates RED test stubs before implementation begins.*
---
## Manual-Only Verifications
| Behavior | Requirement | Why Manual | Test Instructions |
|----------|-------------|------------|-------------------|
| Module activatable via Marketplace UI | CERT-06 | Requires DB + running app + UI interaction | Navigate to Marketplace, activate cert-manager, verify /modules/cert-manager route loads |
| File download (binary formats DER/PFX) | CERT-04 | Browser Blob-URL behavior requires visual check | Upload PEM cert, convert to DER, verify download triggers correct binary file |
| Password prompt UX for PFX open | CERT-05 | Interactive UI flow | Upload password-protected PFX, verify modal appears, enter correct password, verify parse success |
---
## Validation Sign-Off
- [ ] All tasks have `<automated>` verify or Wave 0 dependencies
- [ ] Sampling continuity: no 3 consecutive tasks without automated verify
- [ ] Wave 0 covers all MISSING references
- [ ] No watch-mode flags
- [ ] Feedback latency < 30s
- [ ] `nyquist_compliant: true` set in frontmatter
**Approval:** pending