Block a user
[Feature] Keep compatibility imports under
govoplan_core.access.* temporarily with deprecation warnings
[Feature] Move accounts, authentication, sessions, API keys, groups, memberships, roles, role assignments, and principal resolution into access
[Feature] Add manifest schema/versioning
[Feature] Add OpenAPI/route collision validation
[Feature] Add a documented deprecation policy for kernel API changes
[Feature] Add contract tests for manifests, route aggregation, migration registration, and capability discovery
[Feature] Move or clearly mark these as kernel-stable contracts:
[Task] Mark DataGrid work as explicitly deferred
[Feature] Keep generated WebUI/test artifacts ignored
[Feature] Keep module-matrix tests for core-only, files-only, mail-only, campaign-only, campaign+files, campaign+mail, full product
[Feature] Add dependency-boundary checks that forbid direct optional module imports
[Feature] Define which APIs are stable kernel contracts and which are temporary compatibility paths
[Feature] Document current module contract as the compatibility baseline
[Feature] Fix Swagger / OpenAPI integration
[Task] Deploy with monitoring
[Task] Rate limiting by API key
[Task] Version support + test endpoint
[Task] Docs: Swagger UI + openapi.json
[Feature] Finalize flight endpoint (with segments)
[Feature] Integrate real CO₂ calc logic