Localize Axum interaction forms
This commit is contained in:
@@ -40,16 +40,10 @@ Blocked by: HMX-M02
|
||||
|
||||
## HMX-M04 — Localize Axum interaction forms
|
||||
|
||||
|
||||
Outcome: media-type enforcement, body limits, URL-encoded/multipart extraction, typed decoding, and rejections have one private Axum owner.
|
||||
Outcome: the interaction-form boundary is privately owned without public extraction, decoding, limit, or rejection drift.
|
||||
Delta: architecture/004 assurance/002
|
||||
Path: HTTP request -> `InteractionRequest` extraction -> typed `Form<T>` or custom multipart model -> registered handler/rejection.
|
||||
Build: move the complete form boundary with its tests; add compile coverage for documented `Form<T>` spellings and custom `FromInteractionForm` extraction.
|
||||
Risk: extraction order, limits, rejection status/body, or public adapter signatures change.
|
||||
Checks: `cargo test -p hemx-axum`; `cargo test -p hemx-derive`; focused URL-encoded, multipart, limit, rejection, and compile-pass/fail assertions; `redgate check`.
|
||||
Non-goals: framework-owned CSRF/auth policy, a general extractor abstraction, or changing native form semantics.
|
||||
Residual risk: none beyond the existing application-owned security policy boundary after focused route proof.
|
||||
State: Ready
|
||||
Checks: Axum interaction boundary suite; derive Form<T> spelling check; custom multipart typed extraction; Redgate; diff check; fresh review.
|
||||
State: Done
|
||||
Blocked by: none
|
||||
|
||||
## Closure
|
||||
|
||||
Reference in New Issue
Block a user