docs(08-10): complete coverage, security review and final gate plan
Phase 8 closed on user approval (Playwright UI matrix gap carried forward). AUTH-05/06/07 marked complete; ROADMAP and STATE reflect 10/10 plans done.
This commit is contained in:
@@ -66,9 +66,9 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
||||
- [x] **AUTH-02**: Organizations with roles; organization fields appear on the user payload through a fire-and-collect event so the fonoteka plugin extends the user plugin without editing it
|
||||
- [x] **AUTH-03**: Personal API tokens with a read|write|ai scope ceiling, token CRUD endpoints, and a scope-checking middleware
|
||||
- [x] **AUTH-04**: The must-change-password flag locks the authenticated surface with 423 except the locale and password-change routes
|
||||
- [ ] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
||||
- [ ] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
||||
- [ ] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
||||
- [x] **AUTH-05**: Direct standard-library OAuth2.1-style authorization server (`wristband`): RFC 8414 metadata, authorize with S256 PKCE and consent screen, authorization_code and rotating refresh_token grants, RFC 7591 dynamic registration, RFC 8707 resource handling, exact backend Basic invalid-client challenge, unchanged backend personal-token 401, and unchanged fonoteka-mcp-owned RFC 9728 protected-resource metadata/Bearer challenge
|
||||
- [x] **AUTH-06**: OAuth routes are form-urlencoded, CSRF-free, rate limited, and return unwrapped RFC 6749 bodies with the PHP cache headers
|
||||
- [x] **AUTH-07**: Connected apps can be listed and revoked; OAuthClient, OAuthAuthCode and OAuthRefreshToken models are ported; fonoteka-mcp completes its install and auth flow unchanged
|
||||
- [ ] **AUTH-08**: Backend admin users with roles and a permissions registry are separate from frontend users, and gate both navigation and admin controller access
|
||||
|
||||
### Płytarium API (API)
|
||||
@@ -196,9 +196,9 @@ Which phases cover which requirements. Updated during roadmap creation.
|
||||
| AUTH-02 | Phase 7 | Complete |
|
||||
| AUTH-03 | Phase 7 | Complete |
|
||||
| AUTH-04 | Phase 7 | Complete |
|
||||
| AUTH-05 | Phase 8 | Pending |
|
||||
| AUTH-06 | Phase 8 | Pending |
|
||||
| AUTH-07 | Phase 8 | Pending |
|
||||
| AUTH-05 | Phase 8 | Complete |
|
||||
| AUTH-06 | Phase 8 | Complete |
|
||||
| AUTH-07 | Phase 8 | Complete |
|
||||
| AUTH-08 | Phase 9 | Pending |
|
||||
| API-01 | Phase 12 | Pending |
|
||||
| API-02 | Phase 12 | Pending |
|
||||
|
||||
@@ -20,7 +20,7 @@ Decimal phases appear between their surrounding integers in numeric order.
|
||||
- [x] **Phase 5: Data layer full fidelity** - All 25 models and their squashed migrations with fillable/hidden/cast/soft-delete discipline (completed 2026-09-18)
|
||||
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21)
|
||||
- [x] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password (completed 2026-09-22)
|
||||
- [ ] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector
|
||||
- [x] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector (completed 2026-09-23)
|
||||
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
|
||||
- [ ] **Phase 10: Admin Vue SPA** - Login, navigation, lists, forms and relation manager for five controllers
|
||||
- [ ] **Phase 11: Jobs, realtime and search infrastructure** - River, Centrifugo and Typesense sync brought up before the API phases that need them
|
||||
@@ -358,7 +358,7 @@ Plans:
|
||||
|
||||
**Wave 9** *(blocked on 08-09; blocking security checkpoint)*
|
||||
|
||||
- [ ] 08-10-PLAN.md — Close 103-method coverage, independent security review, and the final fail-closed gate
|
||||
- [x] 08-10-PLAN.md — Close 103-method coverage, independent security review, and the final fail-closed gate
|
||||
|
||||
### Phase 9: Backend admin authentication and schema pipeline
|
||||
|
||||
@@ -496,7 +496,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
||||
| 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 |
|
||||
| 8. OAuth2.1 authorization server | 9/10 | In Progress| |
|
||||
| 8. OAuth2.1 authorization server | 10/10 | Complete | 2026-09-23 |
|
||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||
| 10. Admin Vue SPA | 0/TBD | Not started | - |
|
||||
| 11. Jobs, realtime and search infrastructure | 0/TBD | Not started | - |
|
||||
|
||||
@@ -2,16 +2,16 @@
|
||||
gsd_state_version: 1.0
|
||||
milestone: v1.0
|
||||
milestone_name: milestone
|
||||
status: executing
|
||||
stopped_at: Completed 08-09-PLAN.md
|
||||
last_updated: "2026-09-23T21:22:41.461Z"
|
||||
status: verifying
|
||||
stopped_at: Completed 08-10-PLAN.md (Phase 8 closed; Playwright UI matrix gap carried forward)
|
||||
last_updated: "2026-09-23T23:03:36.043Z"
|
||||
last_activity: 2026-09-23
|
||||
progress:
|
||||
total_phases: 15
|
||||
completed_phases: 7
|
||||
completed_phases: 8
|
||||
total_plans: 55
|
||||
completed_plans: 54
|
||||
percent: 47
|
||||
completed_plans: 55
|
||||
percent: 53
|
||||
---
|
||||
|
||||
# Project State
|
||||
@@ -27,10 +27,10 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
||||
|
||||
Phase: 08 (oauth2-1-authorization-server) — EXECUTING
|
||||
Plan: 10 of 10
|
||||
Status: Ready to execute
|
||||
Status: Phase complete — ready for verification
|
||||
Last activity: 2026-09-23
|
||||
|
||||
Progress: [██████████] 98%
|
||||
Progress: [██████████] 100%
|
||||
|
||||
## Performance Metrics
|
||||
|
||||
@@ -100,6 +100,7 @@ Progress: [██████████] 98%
|
||||
| Phase 08 P07 | 35min | 2 tasks | 9 files |
|
||||
| Phase 08 P08 | 20min | 2 tasks | 4 files |
|
||||
| Phase 08 P09 | 55min | 3 tasks | 25 files |
|
||||
| Phase 08 P10 | 55min | 3 tasks | 17 files |
|
||||
|
||||
## Accumulated Context
|
||||
|
||||
@@ -256,6 +257,9 @@ Recent decisions affecting current work:
|
||||
- [Phase ?]: [Phase 08 P09]: OAuthConsentController's basic-validation failure now writes Winter's generic production 500 HTML page (not a clean 422) -- PHP's bare $request->validate() on this route is never caught by a JSON exception renderer, confirmed live with APP_DEBUG=false
|
||||
- [Phase ?]: [Phase 08 P09]: All nine OAuth manifest routes are status: ported with seed_hook: genres; scripts/check-phase8.sh's stage bodies are fully implemented but never executed by this plan -- 08-10 Task 3 is the sole execution site
|
||||
- [Phase ?]: [Phase 08 P09]: AUTH-05/AUTH-06/AUTH-07 remain Pending in REQUIREMENTS.md -- this plan proves byte parity and builds the real-MCP gate machinery, but only 08-10's actual gate execution can prove the unchanged-fonoteka-mcp clause
|
||||
- [Phase 08]: Security review self-performed by the 08-10 executor (no Task/Agent spawner available), disclosed in 08-SECURITY-REVIEW.md's frontmatter and Reviewer Note — Per 08-CONTEXT.md D-04's documented fallback; every cited file:TestName was individually re-run, not inherited unverified
|
||||
- [Phase 08]: Checkpoint decision: approved closing Phase 8 with the Playwright UI matrix gap (check-phase8-ui.mjs:458) carried forward as a named follow-up — Every other scripts/check-phase8.sh stage ran green in the sole full gate execution; the Playwright matrix was a deliberate, never-authored fatal() left by 08-05 as 08-10's seam
|
||||
- [Phase 08]: AUTH-05, AUTH-06 and AUTH-07 marked complete in REQUIREMENTS.md — Each requirement's exact text is satisfied by the delivered backend/gate evidence; none mandates a Playwright-verified browser regression suite, so the carried-forward UI gap does not block completion
|
||||
|
||||
### Pending Todos
|
||||
|
||||
@@ -266,6 +270,7 @@ None yet.
|
||||
- ~~Phase 8 (OAuth2.1) pre-planning check of the PHP OAuth server for `ClientCredentialsStorage`/`TokenExchangeStorage`~~ — resolved 2026-09-23 during Phase 8 discussion/research: the PHP server is hand-rolled and supports only `authorization_code`/`refresh_token`, so neither interface is needed (see 08-CONTEXT.md, 08-RESEARCH.md).
|
||||
- Phase 9 (admin schema pipeline / relation manager) is the least-precedented design surface in the research — plan with `--research-phase`.
|
||||
- Phase 11 (River dual-driver split) is documented but unverified against a real build — plan with `--research-phase` and budget a timed-latency test.
|
||||
- Phase 8 UI gate: scripts/check-phase8-ui.mjs --final-gate's real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented (deliberate fatal() at check-phase8-ui.mjs:458, never authored by 08-05); stage_ui_harness must keep failing closed until a Playwright spec is authored. User approved Phase 8 closure on 2026-09-24 with this gap carried forward -- see 08-10-SUMMARY.md and .planning/phases/08-oauth2-1-authorization-server/deferred-items.md.
|
||||
|
||||
## Deferred Items
|
||||
|
||||
@@ -273,10 +278,10 @@ Items acknowledged and carried forward from previous milestone close:
|
||||
|
||||
| Category | Item | Status | Deferred At |
|
||||
|----------|------|--------|-------------|
|
||||
| *(none — first milestone)* | | | |
|
||||
| Phase 8 UI gate | `scripts/check-phase8-ui.mjs --final-gate`'s real Playwright browser matrix (32 UI-SPEC scenarios) is unimplemented -- deliberate `fatal()` at `scripts/check-phase8-ui.mjs:458`, never authored by 08-05. `stage_ui_harness` must keep failing closed until a Playwright config/spec outside the Nuxt checkout is authored (see .planning/phases/08-oauth2-1-authorization-server/deferred-items.md). Every other Phase 8 gate stage (real unchanged fonoteka-mcp lifecycle, both repos' vet/test/race, 169/169 parity corpus, secret scan, security review 11/11 closed, return-path 6/6, i18n 74 keys) is green. | Open — carried forward, user-approved | 08-10, 2026-09-24 |
|
||||
|
||||
## Session Continuity
|
||||
|
||||
Last session: 2026-09-23T21:22:41.441Z
|
||||
Stopped at: Completed 08-09-PLAN.md
|
||||
Last session: 2026-09-23T23:03:36.023Z
|
||||
Stopped at: Completed 08-10-PLAN.md (Phase 8 closed; Playwright UI matrix gap carried forward)
|
||||
Resume file: None
|
||||
|
||||
Reference in New Issue
Block a user