Document the four features that landed on main in b44bc8c..85c790e:
- AGENTS.md: post-MVP section now covers server-driven auth discovery
(GET /api/config, AUTH_PASSWORD_ENABLED 403 enforcement,
OIDC_GENERIC_DISPLAY_NAME), the settings screen with GET/PUT /api/me,
and the critical Android sync/data-safety fixes (pull-all-lists,
client HLC tick per server op, no destructive migration, ProGuard
rules). Repo structure updated (httpapi config.go/me.go, ui/settings),
roadmap entries added, open-points list extended with test backlog for
the new endpoints.
- API.md: new sections for GET /api/config (public) and GET/PUT /api/me;
403 responses documented for register/login when password auth is off.
- SYNC.md: client pull loop (every tracked list, op_log pruning) and the
client HLC discipline (tick per incoming server op) that keeps LWW
correct across devices with skewed clocks.
- README: highlights for auth discovery/OIDC-only mode and the settings
screen.
Integration tests for the invite/join/membership feature that shipped
without any coverage:
- internal/store/liststore_test.go: CreateList adds owner as member with
invite code, GetLists returns owned+joined but not foreign lists,
GetList access control (owner/member yes, stranger and soft-deleted no),
JoinByInviteCode normalization/idempotency/role-keeping, lazy invite
code generation. Runs against TEST_DATABASE_URL, skips otherwise.
- internal/httpapi/api_test.go: full E2E over the real router — register,
create list (code in response), invite endpoint, join (lowercase),
cross-member op push/pull sync, stranger gets 404 on every list
endpoint, invalid code 400, idempotent re-join, and 401 gating of all
protected routes.
- lists.go Invite handler: store errors now map through apiError, so
non-members get 404 instead of 400 (consistent with Get/Push/Pull).
Docs updated to the actual post-MVP state: AGENTS.md (post-MVP features,
repo structure, roadmap with open points like join rate limiting),
API.md (join/invite endpoints, invite_code fields, membership rules),
SYNC.md (shared lists section), README (local-only default, sharing,
integration test recipe).