Complete dashboard loose ends and reconcile blocked pilot work
All checks were successful
All checks were successful
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e394-2a69-7df0-8980-22a0ebe55216
This commit is contained in:
parent
387b7e9782
commit
35df9bb772
13 changed files with 325 additions and 55 deletions
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
|||
owner: the-custodian
|
||||
topic_slug: vergabe-teilnahme
|
||||
created: "2026-09-08"
|
||||
updated: "2026-09-11"
|
||||
updated: "2026-09-27"
|
||||
related: [HFACT-WP-0001, REUSE-WP-0022]
|
||||
state_hub_workstream_id: "27a95f7b-cec4-50ca-8383-c1c95d996217"
|
||||
---
|
||||
|
|
@ -63,7 +63,7 @@ status: wait
|
|||
priority: high
|
||||
assignee: the-custodian
|
||||
depends_on: [VERGABE-WP-0018-T02, HFACT-WP-0001-T05]
|
||||
blocking_reason: "Image main-fa9f082 is tested and published. Await HFACT-WP-0001-T05 governed worker evidence plus exact Railiance tenant, deployment, database, storage, access and recovery acceptance."
|
||||
blocking_reason: "Await HFACT-WP-0001-T05 natural governed Railiance worker trace and VERGABE-WP-0019 complete invited-user/recovery acceptance. Pilot placement and one sign-in are already evidenced; main-fa9f082 is superseded."
|
||||
state_hub_task_id: "6e428152-aad6-5184-8b1d-8860ec0b9ae6"
|
||||
```
|
||||
|
||||
|
|
@ -118,3 +118,14 @@ worker dependency. This record continues to own factory-produced delivery
|
|||
acceptance, so a manually prepared customer pilot cannot falsely close HFACT
|
||||
worker proof. The old main-fa9f082 image predates the required login gate and
|
||||
must not be used as the invited-pilot release merely because its CI passed.
|
||||
|
||||
|
||||
## Loose-end review — 2026-09-27
|
||||
|
||||
HFACT-WP-0001-T05 remains wait in prj-helixforge-factory: protected runtime and
|
||||
synthetic proof exist, but upstream admission and natural queue/model execution
|
||||
are outstanding. The September 12 pilot deployment, September 24 founder login
|
||||
and September 25 database restore supersede the old missing-placement summary.
|
||||
They do not close governed-worker proof, two-user product acceptance, or coherent
|
||||
off-host recovery. T03 and this workplan remain blocked on those existing owners;
|
||||
no duplicate tasks were opened.
|
||||
|
|
|
|||
|
|
@ -4,12 +4,12 @@ type: workplan
|
|||
title: "Admit the first invited company pilot with protected access and recoverable data"
|
||||
domain: communication
|
||||
repo: vergabe-teilnahme
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: the-custodian
|
||||
topic_slug: vergabe-teilnahme
|
||||
created: "2026-09-11"
|
||||
updated: "2026-09-25"
|
||||
updated: "2026-09-27"
|
||||
related: [VERGABE-WP-0018, RAPPS-WP-0014, HFACT-WP-0001, CUST-WP-0071]
|
||||
state_hub_workstream_id: "85b5f304-d497-5570-bebf-3a3669ef6a7d"
|
||||
---
|
||||
|
|
@ -68,7 +68,8 @@ Ruff. Source acceptance is not native customer admission.
|
|||
|
||||
```task
|
||||
id: VERGABE-WP-0019-T03
|
||||
status: progress
|
||||
status: wait
|
||||
blocking_reason: "Await RAPPS-WP-0014-T03 coherent PostgreSQL/media/issue-state recovery, populated document round-trip and off-host backup evidence; September 25 proves database restore and restart only."
|
||||
priority: high
|
||||
assignee: the-custodian
|
||||
depends_on: [VERGABE-WP-0019-T02, RAPPS-WP-0014-T02, RAPPS-WP-0014-T03]
|
||||
|
|
@ -207,7 +208,8 @@ preceding service-login failure. It does not create a Django account or session.
|
|||
|
||||
```task
|
||||
id: VERGABE-WP-0019-T06
|
||||
status: progress
|
||||
status: wait
|
||||
blocking_reason: "Source and live SSO/recovery are delivered, and one founder sign-in passed September 24. Await invited recipient setup-to-welcome-to-workflow acceptance and a second ordinary user."
|
||||
priority: high
|
||||
assignee: the-custodian
|
||||
state_hub_task_id: "455b33f9-163a-5389-86a3-04000c32d176"
|
||||
|
|
@ -307,3 +309,18 @@ checks and six fresh anonymous Chromium checks pass, including actual provider
|
|||
logout POST and return to the portal without test overrides. Real-user identity
|
||||
switching is still awaiting operator evidence; no authenticated/MFA acceptance
|
||||
is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md.
|
||||
|
||||
|
||||
## Loose-end review — 2026-09-27
|
||||
|
||||
No further product implementation is identified in T03/T04/T06. T03 awaits
|
||||
railiance-apps recovery evidence for all three stores and an off-host copy;
|
||||
the September 25 age artifact stayed on the workstation and the two file
|
||||
claims were empty. A database restore does not close that contract. T04 needs
|
||||
Bernd Worsch and the company contact to demonstrate two ordinary users,
|
||||
document/task collaboration, revocation, restored workflow and support handoff.
|
||||
T06's September 24 founder login resolves the old issuer-login blocker, but
|
||||
cannot establish a fresh invited recipient's complete setup-to-company journey.
|
||||
Both previously progressing tasks now wait; the workplan is blocked. No new
|
||||
workplan or task was opened, and no live deployment or user impersonation was
|
||||
performed by this review.
|
||||
|
|
|
|||
|
|
@ -5,6 +5,7 @@ title: Dashboard und Ausschreibungen-CRUD
|
|||
status: finished
|
||||
phase: 4-of-12
|
||||
created: "2026-05-08"
|
||||
updated: "2026-09-27"
|
||||
depends_on: WP-0003
|
||||
domain: communication
|
||||
repo: vergabe-teilnahme
|
||||
|
|
@ -21,10 +22,13 @@ Entscheidungsregel-Auswertung, Archivierung und historische Erfassung.
|
|||
|
||||
---
|
||||
|
||||
## Dashboard-View mit Kacheln und Fristenliste
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T01
|
||||
title: Dashboard-View mit Kacheln und Fristenliste
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/views.py` — Dashboard-View:
|
||||
```python
|
||||
|
|
@ -67,12 +71,14 @@ Jede Kachel: Überschrift, Anzahl-Badge, Liste der Einträge mit Direktlinks.
|
|||
Nutze `.card`-Klasse, `status_badge`-Tag und relative Fristangaben (z. B. "in 3 Tagen").
|
||||
|
||||
Ablaufende Nachweise: Nachweis-Modell aus Bibliothek mit `gueltig_bis ≤ heute + 60 Tage`.
|
||||
```
|
||||
|
||||
## Ausschreibungsliste mit Filter und HTMX-Suche
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T02
|
||||
title: Ausschreibungsliste mit Filter und HTMX-Suche
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/views.py` — ListView:
|
||||
```python
|
||||
|
|
@ -107,12 +113,14 @@ Alle Filter-Änderungen: `hx-get="/ausschreibungen/" hx-target="#ausschreibungen
|
|||
|
||||
Tabelle: Titel, Ausschreiber, Status (status_badge), Abgabefrist (farbig wenn < 14 Tage),
|
||||
Verantwortlicher, Link zum Detail.
|
||||
```
|
||||
|
||||
## Ausschreibung anlegen — Form und View (UC-AS-01)
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T03
|
||||
title: Ausschreibung anlegen — Form und View (UC-AS-01)
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/forms.py`:
|
||||
```python
|
||||
|
|
@ -158,12 +166,14 @@ def ausschreibung_neu(request):
|
|||
`ausschreibungen/form.html` — einfaches, gut gelayoutetes Formular.
|
||||
Sections: Stammdaten, Fristen. Alle Felder nutzen `form-input` und `form-label`.
|
||||
Submit: "Speichern" (btn-primary), "Abbrechen" (btn-ghost, zurück zur Liste).
|
||||
```
|
||||
|
||||
## Ausschreibung-Detailseite (Phase 1 — Stammdaten)
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T04
|
||||
title: Ausschreibung-Detailseite (Phase 1 — Stammdaten)
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/views.py` — Detailview:
|
||||
```python
|
||||
|
|
@ -192,12 +202,14 @@ def ausschreibung_detail(request, pk):
|
|||
- Tab-Navigation zu Unterseiten (Lose, Anforderungen, Aufgaben, Bieterfragen, Preise, Abgabe, Nachbetrachtung)
|
||||
als horizontale Link-Leiste unterhalb des Titels
|
||||
- "Weitere Attribute" CustomAttribute-Panel (HTMX lazy-load, Implementierung in WP-0012)
|
||||
```
|
||||
|
||||
## Ausschreibung bearbeiten (Edit-View) und Status inline wechseln
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T05
|
||||
title: Ausschreibung bearbeiten (Edit-View) und Status inline wechseln
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/views.py`:
|
||||
|
||||
|
|
@ -236,12 +248,14 @@ def ausschreibung_status(request, pk):
|
|||
</select>
|
||||
</div>
|
||||
```
|
||||
```
|
||||
|
||||
## Teilnahmeentscheidung-Seite (Phase 2, UC-AS-04)
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T06
|
||||
title: Teilnahmeentscheidung-Seite (Phase 2, UC-AS-04)
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`ausschreibungen/views.py` — Teilnahmeentscheidungs-View:
|
||||
```python
|
||||
|
|
@ -272,12 +286,14 @@ def ausschreibung_entscheidung(request, pk):
|
|||
- Zeigt Regelergebnis aus dem Katalog als strukturierte Liste
|
||||
- Formular: Radio-Buttons für Teilnahme/Nichtteilnahme/Weitere Prüfung, Begründungsfeld
|
||||
- "Freigabe erteilen"-Button (öffnet Freigabe-Modal, Implementierung in WP-0012)
|
||||
```
|
||||
|
||||
## Entscheidungsregel-Auswertungs-Service
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T07
|
||||
title: Entscheidungsregel-Auswertungs-Service
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`vergabe_teilnahme/apps/ausschreibungen/services.py`:
|
||||
|
||||
|
|
@ -321,12 +337,14 @@ def _wende_regel_an(regel, ausschreibung):
|
|||
'begruendung': f'Restlaufzeit {delta} Tage unter Schwellenwert.'}
|
||||
return {'empfehlung': 'pruefen', 'begruendung': regel.begruendung or '—'}
|
||||
```
|
||||
```
|
||||
|
||||
## Ausschreibung archivieren und historisch erfassen (UC-AS-06, UC-AS-07)
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T08
|
||||
title: Ausschreibung archivieren und historisch erfassen (UC-AS-06, UC-AS-07)
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
**Archivieren:**
|
||||
```python
|
||||
|
|
@ -351,12 +369,14 @@ zugänglich — keine Einschränkung.
|
|||
|
||||
URL für historische Erfassung: `/ausschreibungen/neu/?historisch=1`
|
||||
Die View prüft diesen Parameter und setzt `historisch_erfassen` im initialen Form-Context.
|
||||
```
|
||||
|
||||
## Globale Suchleiste — HTMX-Endpunkt und Ergebnis-Template
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T09
|
||||
title: Globale Suchleiste — HTMX-Endpunkt und Ergebnis-Template
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`core/views.py`:
|
||||
```python
|
||||
|
|
@ -397,12 +417,14 @@ def global_search(request):
|
|||
|
||||
URL: `path('suche/', core_views.global_search, name='global_search')`
|
||||
Topbar-Formular (aus WP-0003-T02) zeigt Ergebnisse in `#search-results`.
|
||||
```
|
||||
|
||||
## Ausschreibungen-URL-Verkabelung und App-Namespace
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T10
|
||||
title: Ausschreibungen-URL-Verkabelung und App-Namespace
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
`vergabe_teilnahme/apps/ausschreibungen/urls.py`:
|
||||
```python
|
||||
|
|
@ -436,12 +458,14 @@ Jede referenzierte App-URL-Datei wird hier als leere Stub-Datei angelegt
|
|||
|
||||
Prüfe: `uv run manage.py check --deploy` → keine URL-Fehler.
|
||||
Smoke-Test: alle Hauptseiten (/ausschreibungen/, /ausschreibungen/neu/) laden ohne 500.
|
||||
```
|
||||
|
||||
## Ausschreibungs-Tests (Models und Views)
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T11
|
||||
title: Ausschreibungs-Tests (Models und Views)
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Erstelle `vergabe_teilnahme/apps/ausschreibungen/tests/`:
|
||||
|
||||
|
|
@ -468,12 +492,14 @@ class AusschreibungFactory(factory.django.DjangoModelFactory):
|
|||
ausschreiber = "Testausschreiber GmbH"
|
||||
status = 1
|
||||
```
|
||||
```
|
||||
|
||||
## Seed-Daten prüfen und Dashboard-Kacheln verifizieren
|
||||
|
||||
```task
|
||||
id: VT-WP-0004-T12
|
||||
title: Seed-Daten prüfen und Dashboard-Kacheln verifizieren
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Führe die gesamte Integrations-Smoke-Test-Sequenz durch:
|
||||
|
||||
|
|
@ -493,4 +519,37 @@ Führe die gesamte Integrations-Smoke-Test-Sequenz durch:
|
|||
10. `uv run pytest vergabe_teilnahme/apps/ausschreibungen/` → alle Tests grün
|
||||
|
||||
Erst wenn alle 10 Punkte erfüllt sind: Task als done markieren.
|
||||
```
|
||||
|
||||
## Completion review — 2026-09-27
|
||||
|
||||
The finished plan retained twelve stale todo blocks with nested Markdown fences.
|
||||
Reconciled the existing task IDs into one valid task block per section; no new
|
||||
tasks were created. T03–T07 and T10–T11 already had application implementations
|
||||
and model/view acceptance. T01 now includes the missing 60-day evidence-expiry
|
||||
card (including expired evidence). T02 now searches title and issuing authority
|
||||
alongside status/manager/archive filters with HTMX. T08 now validates and saves
|
||||
a historical result atomically in the existing Nachbetrachtung model and sets
|
||||
the corresponding terminal tender status. T09 now includes issuing authority,
|
||||
tasks and partners alongside the already implemented search categories.
|
||||
|
||||
The old illustrative fields are superseded by the current model: bid_manager
|
||||
replaces hauptverantwortung, and ergebnis belongs to Nachbetrachtung. Historical
|
||||
entry uses those models without a schema change. Existing approval, decision,
|
||||
archive, detail and URL implementations remain in place.
|
||||
|
||||
Validation: all 131 application tests pass on disposable SQLite; all 20 tender
|
||||
model/view tests also pass on disposable PostgreSQL 16. Vite build, Django system
|
||||
check and migration-drift check pass. Changed Python passes Ruff excluding the
|
||||
pre-existing E501 long lines. Local tests retain the pre-existing naive-datetime
|
||||
fixture and uncollected-static-directory warnings. T12 uses freshly migrated/seeded disposable PostgreSQL and local
|
||||
Chromium for dashboard/navigation, tender list/detail, HTMX search/status and
|
||||
historical creation. This is local source acceptance, not pilot-user evidence.
|
||||
|
||||
|
||||
The final T12 server-log review exposed a missing CSRF header on inline status
|
||||
POSTs. T05 now inherits the rendered Django CSRF token through base.html's
|
||||
HTMX headers. A CSRF-enforcing regression proves missing-token rejection and
|
||||
valid-token mutation. The Chromium check now changes to a different status,
|
||||
requires HTTP 200 for the POST, and checks persistence after reload; an unchanged
|
||||
seeded value is not accepted as proof. This supersedes the initial browser
|
||||
script's false-positive status assertion.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue