Implementation track

A build tracker for turning the source-of-truth docs into a working platform.

This page defines workstreams, status labels, package boundaries, and acceptance criteria. It is intentionally HTML so it can evolve with the rest of the project documentation.

Tracker legend

Status labels

StatusMeaning
LockedAccepted planning decision unless new evidence changes it.
OpenNeeds design, implementation, vendor validation, or owner decision.
LaterIntentionally deferred until after MVP or validation.
RiskHigh-risk item requiring explicit safeguards or external validation before shipping.
Workstreams

Build package map

WorkstreamStatusScopeAcceptance signal
Docs/source of truthLockedHTML docs package, source map, risk register, roadmap, implementation tracker.Docs reflect agreed product, privacy, trust/safety, and roadmap decisions.
App foundationOpen — production-edge preflight, backup posture, local/external smoke, smoke-member provision/cleanup, seed, and owner dashboard gate implementedRust/Axum, templates, config, Docker, Postgres, migrations, local dev scripts, owner diagnostics, production-edge diagnostics, and future Redis hooks if needed.App boots locally and in container; shallow health check passes; Docker image and VPS compose skeleton include a shallow healthcheck; local doctor validates deployment profile, HTTPS origin/HSTS posture, secure cookies, owner gate/session posture, backup posture/target writability, database/migrations, owner catalog sanity, checkout lifecycle counts/stale-expiry posture, media root writability, and preview fixture integrity; vps-bootstrap-plan checks private env/template/compose posture plus backup/manifest/custody volume persistence before service startup, deployment-rehearsal-plan prints the secret-free disposable test-VPS operator sequence before official VPS transplant, and production-preflight blocks local profile, placeholder/non-HTTPS origin, insecure cookies, missing owner gate, long owner sessions, and local-only backup posture before exposure; local smoke/seed commands can create disposable validation records and one login-ready test member, local HTTP smoke can exercise browser-facing routes/forms over an ephemeral loopback server, local owner smoke can exercise the gated owner dashboard forms over ephemeral loopback HTTP, local-owner-visual-smoke can hold open a disposable owner dashboard for browser QA, owner-dashboard-review-plan can guide the secret-free manual browser review for layout/privacy and write hash-ready owner_dashboard_visual_review evidence artifacts, owner-dashboard-review-artifact-check can verify those artifact markers/sentinels/SHA before evidence recording, payment-provider-review-plan can write hash-ready adult/AI-adult processor-fit evidence artifacts, payment-provider-review-artifact-check can verify those provider-review markers/sentinels/SHA before evidence recording, owner-operational-summary can export a sanitized owner-facing readiness artifact across doctor/evidence/payment/visual/backup/restore posture, the gated /owner dashboard can mirror derived operational readiness status without evidence paths/raw logs/provider material/backup IDs/secrets, and external edge smoke can verify final-origin proxy gates after HTTPS attachment; smoke-member provision creates a short-lived recovery-confirmed disposable member with operator-file recovery-key custody, cleanup revokes its active sessions/entitlements, external member smoke can verify disposable-member login, account, library, media byte ranges, downloads, checkout return non-authority, owner gate posture, and logout through the same final origin; deployment-evidence commands record sanitized pass/fail evidence plus artifact hashes, including first-class owner_dashboard_visual_review records; and private-vps-readiness combines preflight, evidence, origin consistency, backup posture, sealed backup manifest completeness, and encrypted/offsite custody retention before widening private testing; /owner stays disabled unless an owner key is configured.
Design systemOpen — first premium no-NPM browser shell implementedLuxury synthetic private club UI, dark cinematic palette, responsive layout, motion rules.Landing, invite entry, and member library now use the first polished server-rendered HTML/CSS shell with no frontend package chain or scripts; future work can layer in production media art direction and motion after asset policy is settled.
Account/session systemOpen — invite gate, recovery rotation, and session hygiene implementedPseudonymous account, owner-issued invite codes, recovery key, Argon2id credential versions, explicit recovery custody confirmation and rotation, opaque server sessions, aggregate session hygiene, CSRF-token digests.Browser membership creation now requires a valid unused invite code; invite codes are shown once through CLI or gated owner browser creation, stored only as SHA-256 digests, and redeemed into pseudonymous member IDs without email or identity binding. Lifecycle works without email by default; authenticated recovery confirmation, recovery-key rotation, logout-current, and logout-all are CSRF-protected; account screens show current expiry and active-session count without device/IP/user-agent ledgers; credential rotation requires current-key proof, revokes old credentials and active sessions, opens a fresh session, and re-locks library/media access until the new key is confirmed; broader future-form hardening remains next steps.
Age gate abstractionOpenSelf-attestation now; pluggable pass/fail verifier later.Nocturne stores no ID documents and can swap verification mechanism.
Payment entitlementRisk — local proof/reversal ledger, browser owner grants, checkout sessions, expiry cleanup, browser maintenance controls, webhook replay inbox, provider decision matrix, and provider-review evidence artifacts implementedAdult-compatible processor, subscription/pass, live hosted checkout, webhook endpoint/signature verification, entitlement sync, refunds/cancellations.Processor approval and sandbox/live flow remain open; current code has preview entitlements, local owner grant/list/revoke commands, gated /owner browser grant/revoke forms for pseudonymous member IDs, payment proof record/list/refund/chargeback/void commands, provider-neutral checkout sessions, success/cancel return pages that never grant access, stale checkout expiry cleanup through CLI or gated /owner controls, provider-neutral webhook record/list/replay commands plus gated browser replay controls, source-reference hooks, entitlement/payment event records, and a payment provider decision matrix plus payment-provider-review-plan/payment-provider-review-artifact-check so access gates, non-authoritative returns, checkout expiry, idempotent paid replay, linked reversals, and adult/AI-adult provider fit can be validated and hashed before live provider code is chosen.
Media pipelineOpen — protected showcase metadata, content-drop readiness/checklist/controls, content operations report, advisory release schedules, disk-backed streaming, inline viewing, byte ranges, route limits, and local owner workflow and manual review checklist implementedCatalog metadata, private storage, video/image delivery, optional downloads, no public URLs.Member library pages can render owner-curated protected showcase panels from catalog metadata without public media URLs, storage keys, scripts, or frontend packages. Member media pages render protected image/video files inline, file and download responses stream from disk with authenticated byte ranges, selected assets can expose explicit attachment downloads, media routes enforce ephemeral hashed-session request limits, and owner-only local import/list/drop-readiness/content-ops-report/drop-review/content-drop-schedule/content-drop-unschedule/drop-level publish/draft/archive/item publish/draft/archive/feature/unfeature commands plus gated browser dashboard content operations queue, checklist, and schedule set/clear controls preserve the no-public-URL boundary while surfacing blocked/ready/live/archived drop states, advisory release timing, active trust/safety reports, visibility mix, download policy counts, and private delivery posture before publishing and moving collections as reversible drops; release schedules are owner-only metadata with no autopublish runner and browser schedule writes never publish media, and production proxy/object-storage hardening remains next.
Controlled participationOpen — member UI, browser reactions, aggregate unlock goals, local Signals, polls, requests, and owner review dashboard implementedOwner-granted Signals, owner-created polls/options, private request queue, aggregate reactions, aggregate unlock goals, drop seasons.Members can shape future content through confirmed, entitled, pseudonymous browser actions at /participation plus private reaction buttons on catalog/media pages without chat, public posting, links, attachments, public profiles, leaderboards, activity feeds, or raw IP/user-agent records; local Hermes screening now routes request text before/inside the private queue; active aggregate unlock goals render count/threshold progress for members; the gated /owner dashboard can review pending requests, aggregate reactions, and active/completed aggregate goals; reward fulfillment remains later.
Hermes moderationOpen — deterministic local request screening and minimal owner review UI implementedPolicy taxonomy, request screening, moderation states, owner review console.Current request path rejects links, runs local policy screening, records moderation state/rule/reason/version, and exposes pending private requests in the gated /owner dashboard; richer taxonomy calibration, enforcement events, and production moderation operations remain open.
Takedown/reportingRisk — public intake guardrails, local owner workflow, gated browser review, and private-VPS SLA/escalation runbook implementedReport form, non-identifying intake guardrails, quarantine path, evidence handling, owner decision record, escalation checklist.Public /report, local CLI commands, and the gated /owner dashboard create/review private report cases, record event notes, optionally archive catalog/request targets or quarantine media assets, and keep reports free of raw IP/user-agent/email/attachment storage. Public reports are external cases with no member ID and no public-controlled quarantine; public intake now enforces an 8 KiB body cap, hidden honeypot, boot-secret-backed stateless form token, three-second dwell time, 30-minute expiry, and 200 active-case owner queue cap without per-IP tracking. The private-VPS escalation runbook defines urgent/high/normal/low SLA targets, quarantine-first handling, external escalation triggers, and evidence minimization; jurisdiction/provider-specific procedures and production operator auth remain open.
Observability/securityOpen — initial media limits, public intake caps, edge/backup posture checks, production preflight, proxy templates, local/external smoke, smoke-member provisioning, seed, and local doctor implementedPurpose-bound logs, rate limits, health/doctor diagnostics, backup/restore, deployment monitoring, incident overrides.Media file/download routes now have ephemeral per-session limits keyed by hashed session IDs; public report intake uses non-identifying form abuse controls instead of raw IP/user-agent ledgers; default form posts are capped at 16 KiB, public report posts at 8 KiB, HSTS is emitted only for an https:// public origin, production doctor mode fails closed for missing HTTPS origin, secure cookies, owner gate, or backup posture, vps-bootstrap-plan checks private env/template/compose posture plus backup/manifest/custody volume persistence, deployment-rehearsal-plan prints the evidence/backup/readiness rehearsal sequence for a disposable test-VPS shape, and production-preflight blocks placeholder origins and before-exposure posture failures; Caddy/nginx templates now set first-pass body caps, private upstream proxying, security headers, and disabled access logs by default; nginx adds memory-only sensitive-POST throttles, stock Caddy requires a separately validated privacy-minimizing trusted-edge control before widening, and deployment evidence rejects edge labels that do not attest either posture; scripts/external-edge-smoke.sh checks final-origin health, security headers, diagnostics non-exposure, unauthenticated member/media gates, direct private-media path denial, and body caps after proxy attachment; smoke-member-provision creates disposable public-edge test credentials without identity fields or plaintext recovery-key storage, scripts/external-member-smoke.sh checks disposable authenticated member paths, and smoke-member-cleanup revokes active smoke sessions/entitlements after the test window; deployment-evidence-record/list/check preserves sanitized operator evidence without raw logs or secrets, the gated /owner operational readiness cockpit mirrors derived evidence/backup/provider/restore status without raw paths or sensitive material, and private-vps-readiness gates private-test widening on preflight, evidence, origin consistency, backup posture, sealed backup manifest completeness, and encrypted/offsite custody retention; backup-status/backup-plan print non-destructive PostgreSQL/media backup guidance, backup-manifest-record/list/check track secret-free sealed artifact hashes, backup-custody-record/list/check track encrypted/offsite custody retention metadata, and restore-drill-plan prints scaffold-only isolated restore-drill/evidence commands; broader WAF/rate-limit tuning, monitoring, remediation, automated backups, offsite custody, completed restore drills, and production load testing remain.
Native lounge/chatLaterSlow-mode text lounge, no links/attachments/DMs, Hermes pre-screening.Not started until MVP proves need and moderation maturity.
Initial schema outline

Likely core tables

Membership

  • members
  • member_credentials
  • sessions
  • csrf_tokens
  • age_attestations
  • entitlements
  • entitlement_events
  • audit_events

Commerce

  • plans
  • passes
  • payments
  • payment_events
  • payment_checkout_sessions
  • payment_webhook_events
  • processor_customers later/if needed
  • refunds later

Content

  • collections
  • catalog_items
  • media_assets
  • media_variants
  • content_release_schedule
  • content_flags

Participation

  • participation_signal_grants
  • participation_polls
  • participation_poll_options
  • participation_poll_votes
  • participation_requests with Hermes screening metadata
  • participation_reactions
  • unlock_goals with aggregate-only source definitions

Safety

  • trust_safety_reports with private case metadata
  • trust_safety_events with owner/system notes
  • moderation_evidence later
  • policy_rules later
  • enforcement_actions later
  • security_events
MVP acceptance

Definition of a useful private MVP

Decision log

Current planning decisions

DecisionStatusNotes
Use HTML documents, not Markdown, for source-of-truth docs.LockedImproves visual review and enables richer planning artifacts.
Defer native chat from MVP.LockedUse controlled participation first; revisit after retention data.
No regional IP pricing.LockedConflicts with privacy story and adds geolocation complexity.
No DRM.LockedUse honest access control; do not harm legitimate user experience.
No NPM frontend dependency chain by default.LockedMinimizes supply-chain risk and supports auditability.
$20/month baseline price.Locked for planningFinal processor fees/tax may affect public presentation.
One-time 30-day pass.Locked for entitlement/payment foundationthirty_day_pass is seeded as a processor-neutral plan and can be owner-granted locally, represented by a provider-neutral checkout session, created through a local payment proof record, or applied through the provider-neutral webhook replay inbox; live processor support still remains future work.
Downloads.Locked for Phase 3BDownloads are per-asset policy decisions. Default is view_only; download_allowed exposes a separate authenticated attachment route while inline viewing remains the primary UX.
Private testing is owner-invite-only.Locked for private MVP widening/join requires a valid unused invite. Owner CLI commands and gated /owner browser forms create/list/revoke one-time codes while storing only code digests, optional non-identifying labels, timestamps, status, and pseudonymous redemption member IDs. Raw codes are printed/shown once and never listed later.
Account/session persistence uses PostgreSQL.Locked for Phase 2ARoutes now persist pseudonymous members, Argon2id recovery-key hashes, credential versions, recovery-confirmation timestamps, self-attestation records, session digests, and CSRF-token digests. The account page exposes only current session timing and active-session count; logout-all revokes member sessions by digest and clears stored CSRF tokens. Recovery-key rotation is current-key-proven and CSRF-protected: old active credentials are revoked, old sessions and their CSRF-token digests are closed, a fresh session is opened, and recovery confirmation resets until the replacement key is confirmed. No plaintext recovery key, raw session ID, email, IP address, or user-agent is stored in the account/session schema.
Preview, manual, payment-proof, and webhook-replayed entitlements unlock the gated library during foundation testing.Locked for Phase 2B/4A/4BNew and backfilled members receive a temporary foundation preview entitlement; owners can list, grant, and revoke time-boxed entitlements through local commands or gated /owner browser forms, then record paid proof or replay provider-neutral payment events locally before a live provider exists. Revocation closes media/library access immediately without adding identity fields, and browser owner notes/source references reject links, email-like strings, IP-like strings, and identity-like references.
Payment proof, checkout sessions, and webhook replay records stay pseudonymous.Locked for Phase 4A/4B/4CMembers can create local checkout sessions and return through success/cancel pages, but those browser returns only set checkout state and never grant access. Stale pending/success-returned checkout sessions can be marked expired through CLI or gated /owner controls, expired sessions cannot be completed, and browser returns cannot resurrect them. Owners can record a paid proof or replay a provider-neutral paid webhook against a pseudonymous member ID, provider label, provider event ID, and provider/order reference; the path creates payment events and paid entitlements without storing email, processor customer identity, raw webhook payloads, IP address, or user-agent data. Browser owner payment maintenance stays no-script and does not render raw payloads, payload digests, card data, customer identity, raw IP/user-agent fields, or operator notes. Refund/chargeback/void commands and replay events update only currently paid proofs, record payment events, and revoke the linked entitlement by ID without touching unrelated active access. Provider-specific checkout/webhook code remains blocked until the payment provider matrix has written adult/AI-adult approval and technical requirements, then payment-provider-review-artifact-check verifies a sanitized evidence artifact before payment_provider_review is recorded.
Media routes and imports use private storage keys only.Locked for Phase 3A/B/C/library, /media/{asset_id}, /media/{asset_id}/file, and /media/{asset_id}/download require an authenticated member with active entitlement. Owner imports, content-drop readiness summaries, privacy-safe content operations reports, advisory release schedule set/clear operations, derived pre-publish checklists, drop-level visibility changes, catalog visibility changes, and protected showcase feature/unfeature metadata run through local CLI commands and gated /owner browser forms, validate relative storage keys or non-identifying owner copy, reject URL-like/public paths, copy files under the private media root, include active trust/safety reports as publish blockers, media file/download responses stream from disk with authenticated single byte ranges for video-friendly playback, and route limits track hashed session IDs instead of IP addresses. Release schedule labels/notes are owner-only advisory metadata, reject URL/email/IP/identity-like text, and do not automatically publish media.
Controlled participation starts as private Signals, not chat.Locked for Phase 5A/5C/5DLocal owner commands can grant poll_vote and content_request Signals, create polls/options, list private request queues, review request states, aggregate predefined reactions, and create/open/complete/archive aggregate unlock goals. Authenticated members can now use /participation to vote in open fixed-option polls, queue Hermes-screened private requests, view active aggregate unlock-goal progress, and react from catalog/media pages through CSRF-protected predefined buttons. Member actions require confirmed recovery custody plus active entitlement, consume Signals transactionally where applicable, reject request links, route request text through Hermes screening metadata, and store only pseudonymous member IDs without raw IP/user-agent, email, public profiles, attachments, public post records, leaderboards, or activity feeds.
Report/takedown starts as privacy-preserving public intake plus private owner workflow.Locked for Phase 6A/6CPublic /report can open external cases without login, email, raw IP/user-agent capture, ID documents, uploads, or public posting. Local commands and the gated /owner dashboard can open/list/review cases and optionally quarantine media assets or archive catalog/request targets. Reports store target IDs, complaint kind, priority, summary, optional contact reference/digest, optional evidence digest, timestamps, and owner notes without raw IP/user-agent/email, ID documents, or attachments. The public route now uses an 8 KiB form-body limit, hidden honeypot, boot-secret stateless token, three-second dwell time, 30-minute expiry, and 200 active-case queue cap instead of per-IP tracking.
Browser owner review must stay explicitly gated.Locked for Phase 5B/6B/owner is disabled until NOCTURNE_OWNER_KEY or NOCTURNE_OWNER_KEY_SHA256 is configured. The MVP gate uses a HMAC-signed timestamped opaque cookie with configurable server-side expiry plus CSRF token, no frontend package chain, no owner key storage in the database, no raw invite-code/digest recovery after creation, no customer identity fields in entitlement/payment operations, no provider-specific live payment admin, no raw payment payloads or operator notes in browser payment maintenance, and no storage-key/public-media-URL exposure in catalog management output.
Production-edge mode is explicit.Locked for Phase 7ANOCTURNE_DEPLOYMENT_PROFILE=production makes doctor fail if NOCTURNE_PUBLIC_ORIGIN is missing/non-HTTPS, secure cookies are disabled, the owner gate is unconfigured, or backup posture remains local-only. It also reports NOCTURNE_OWNER_SESSION_MAX_AGE_SECONDS and warns when production owner cookies exceed one hour. vps-bootstrap-plan adds a non-destructive private env/compose/proxy-template review before services start and fails if required backup/manifest/custody persistence volumes are missing. deployment-rehearsal-plan rejects unsafe rehearsal inputs and prints the disposable private test-VPS sequence without executing it. production-preflight is stricter: it requires production profile, final non-placeholder HTTPS origin, secure cookies, configured owner gate, owner session max age at or below one hour, and non-local backup posture before exposure. The application emits HSTS only for an HTTPS public origin and keeps detailed diagnostics local. Copy-safe Caddy/nginx templates now establish first-pass public-edge body limits, header stance, access-log minimization, and post-proxy smoke expectations; the external edge smoke script turns those expectations into repeatable public-origin checks.
External disposable smoke members use operator-file recovery-key custody and evidence records.Locked for Phase 7Dsmoke-member-provision creates a recovery-confirmed, age-attested disposable member, grants short manual access, and prefers a newly-created 0600 recovery-key file over terminal output. smoke-member-cleanup requires explicit confirmation and revokes active entitlements plus sessions without deleting pseudonymous history. The path is for private VPS validation only and stores no email, raw IP address, user-agent, ID document, or plaintext recovery key. Deployment evidence records then capture pass/fail metadata and optional artifact hashes without storing raw smoke logs, and private-vps-readiness fails if the required evidence is incomplete or tied to the wrong origin.
Backup/restore starts as a non-destructive operator runbook.Locked for Phase 7BNOCTURNE_BACKUP_POSTURE supports local, configured, and external. Local doctor checks fail production local-only posture, verify configured target writability, and keep recovery diagnostics local. backup-status/backup-plan print redacted, environment-variable-based pg_dump/media archive guidance plus manual restore drill steps. backup-manifest-record/list/check stores only local git-ignored artifact hashes for sealed dump/media pairs, and backup-custody-record/list/check stores only local git-ignored custody/retention metadata for encrypted offsite/provider handoffs. restore-drill-plan/backup-restore-drill-plan print the isolated drill checklist and backup_restore_drill evidence command while rejecting placeholder origins/source-tree evidence paths, but no automatic restore command exists.
Local smoke/seed helpers are disposable and profile-gated.Locked for Phase 7Clocal-smoke validates migrations, preview media, member recovery/session/CSRF, entitlement gates, checkout return state, payment webhook replay, participation, reactions, and report creation while writing disposable records. local-http-smoke starts an ephemeral loopback server and exercises health/docs, login, account, library, media byte ranges/downloads, checkout returns, participation forms, report intake, and owner posture over real HTTP. local-owner-smoke starts an ephemeral loopback server, requires NOCTURNE_OWNER_KEY, logs into the gated owner dashboard, exercises invite/access/content/catalog/payment/readiness/review/logout forms, and verifies no-script/privacy sentinels without printing the owner key, raw invite code, recovery key, storage keys, evidence paths, backup IDs, raw logs, or raw payload digests. local-owner-visual-smoke seeds disposable owner-review fixtures, starts a loopback owner dashboard, prints the review URL/checklist, and keeps the server open until Ctrl-C for manual browser QA without printing secrets. owner-dashboard-review-plan prints the matching secret-free manual browser checklist for owner layout/readability, privacy sentinels, logout re-locking, and sanitized owner_dashboard_visual_review evidence capture; artifact mode writes a 0600 hash-ready checklist/result file after a clean browser pass, and owner-dashboard-review-artifact-check verifies the local artifact markers, recordable result, SHA-256, and forbidden sentinels before evidence recording. local-seed creates one login-ready member, and local-reset-seed --confirm-local-reset truncates application tables before reseeding preview catalog/plans/media; all refuse production profile.