Skip to content

[OpenSpec] authoring-token-lifecycle #691

Description

@github-actions

⚠️ OpenSpec-managed issue — this content is automatically synced
from the openspec/ directory. Manual edits will be overwritten on next sync.

Artifacts

Specs

Tasks

  • 1.1 Read EditTokenForm.tsx:450-468 in tokens-studio/figma-plugin at 2.12.1 and record the
  • 2.1 Add lib/Service/OwnTokenService.php (store, name rule, duplicate check, value check by
  • 2.2 Render own tokens in CustomOverridesService after the registry overrides, without
  • 2.3 Add lib/Controller/OwnTokenController.php with list, create, update and delete on
  • 2.4 Add a unit test that fails when any shipped file under css/ other than
  • 3.1 Add lib/Service/TokenDeprecationService.php (record shape, replacement exists, date
  • 3.2 Admin endpoints on /settings/tokens/deprecations and the non-admin
  • 3.3 Write the deprecation comment above each deprecated own token in custom-overrides.css.
  • 3.4 "Record as deprecations" on the upload result. Verify: Playwright scenario "An
  • 3.5 When authoring-dtcg-export has landed: write $deprecated and the extension fields for
  • 4.1 "Your own tokens" section, "Add a token" dialog, row actions Edit, Deprecate and Remove.
  • 4.2 Deprecate dialog and deprecation badge on every --nldesign-* row, the deprecations list
  • 5.1 Add own_token_changed and token_deprecation_changed to ThemingAuditService::VOCABULARY
  • 5.2 Add ownTokens and tokenDeprecations to ConfigBundleService::export() and the import.
  • 5.3 Prove an importer without the new keys skips them. Verify: PHPUnit
  • 5.4 Newman: 200, 400, 401 and 403 paths for every new route, credentials from environment
  • 6.1 Localisation: section, dialog, badge, list, "Due for removal", "Notice only" and every
  • 6.2 Documentation: docs/features/token-editor.md gains own tokens and deprecations, and a
  • 6.3 WCAG AA contrast: an own colour token shows the editor's contrast hint against the page
  • 6.4 Dark mode: covered by task 2.2 and the Playwright dark scenario in 4.1.
  • 6.5 Incomplete token sets: own tokens do not depend on the active set. Switch to a set that
  • 6.6 Accessibility: the dialog traps focus and returns it, every field has a visible label,
  • 6.7 Security: admin endpoints use #[AuthorizedAdminSetting], the read endpoint carries no
  • 7.1 Run COMPOSER_PROCESS_TIMEOUT=0 composer check:strict once, then npm run lint,
  • 7.2 On a running instance, add an own token, use it in custom CSS, deprecate it with a

Design

See design.md for technical design details.


Synced from openspec/changes/authoring-token-lifecycle by OpenSpec workflow
App: thematiq

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    openspecOpenSpec-driven changeopenspec:tasksOpenSpec phase: Tasksspec:too-largeBuilder bounced: >20 unchecked tasks. Fallback needs-input; re-split via Specter.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions