docs(08-10): complete coverage, security review and final gate plan
Phase 8 closed on user approval (Playwright UI matrix gap carried forward). AUTH-05/06/07 marked complete; ROADMAP and STATE reflect 10/10 plans done.
This commit is contained in:
@@ -66,9 +66,9 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
||||
- [x] **AUTH-02**: Organizations with roles; organization fields appear on the user payload through a fire-and-collect event so the fonoteka plugin extends the user plugin without editing it
|
||||
- [x] **AUTH-03**: Personal API tokens with a read|write|ai scope ceiling, token CRUD endpoints, and a scope-checking middleware
|
||||
- [x] **AUTH-04**: The must-change-password flag locks the authenticated surface with 423 except the locale and password-change routes
|
||||
- [ ] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
||||
- [ ] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
||||
- [ ] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
||||
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
||||
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
||||
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
||||
- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
||||
|
||||
### Płytarium API (API)
|
||||
@@ -196,9 +196,9 @@ Which phases cover which requirements. Updated during roadmap creation.
|
||||
| AUTH-02 | Phase 7 | Complete |
|
||||
| AUTH-03 | Phase 7 | Complete |
|
||||
| AUTH-04 | Phase 7 | Complete |
|
||||
| AUTH-05 | Phase 8 | Pending |
|
||||
| AUTH-06 | Phase 8 | Pending |
|
||||
| AUTH-07 | Phase 8 | Pending |
|
||||
| AUTH-05 | Phase 8 | Complete |
|
||||
| AUTH-06 | Phase 8 | Complete |
|
||||
| AUTH-07 | Phase 8 | Complete |
|
||||
| AUTH-08 | Phase 9 | Pending |
|
||||
| API-01 | Phase 12 | Pending |
|
||||
| API-02 | Phase 12 | Pending |
|
||||
|
||||
Reference in New Issue
Block a user