docs(08-10): complete coverage, security review and final gate plan

Phase 8 closed on user approval (Playwright UI matrix gap carried forward).
AUTH-05/06/07 marked complete; ROADMAP and STATE reflect 10/10 plans done.
This commit is contained in:
Jakub Zych
2026-09-24 01:04:00 +02:00
parent 482944b160
commit 0fcd06fde8
3 changed files with 25 additions and 20 deletions

View File

@@ -66,9 +66,9 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
- [x] **AUTH-02**: Organizations with roles; organization fields appear on the user payload through a fire-and-collect event so the fonoteka plugin extends the user plugin without editing it
- [x] **AUTH-03**: Personal API tokens with a read|write|ai scope ceiling, token CRUD endpoints, and a scope-checking middleware
- [x] **AUTH-04**: The must-change-password flag locks the authenticated surface with 423 except the locale and password-change routes
- [ ] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
- [ ] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
- [ ] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
### Płytarium API (API)
@@ -196,9 +196,9 @@ Which phases cover which requirements. Updated during roadmap creation.
| AUTH-02 | Phase 7 | Complete |
| AUTH-03 | Phase 7 | Complete |
| AUTH-04 | Phase 7 | Complete |
| AUTH-05 | Phase 8 | Pending |
| AUTH-06 | Phase 8 | Pending |
| AUTH-07 | Phase 8 | Pending |
| AUTH-05 | Phase 8 | Complete |
| AUTH-06 | Phase 8 | Complete |
| AUTH-07 | Phase 8 | Complete |
| AUTH-08 | Phase 9 | Pending |
| API-01 | Phase 12 | Pending |
| API-02 | Phase 12 | Pending |