fix(08): revise plans based on checker feedback
This commit is contained in:
@@ -223,7 +223,7 @@ Plans:
|
||||
4. The guarded outbound fetch helper rejects a non-allow-listed host and enforces a byte cap and timeout on a user-supplied cover URL fetch (manual cover URL, Discogs cover).
|
||||
5. OpenAPI is generated from swaggo/swag annotations on handlers and `openapi-typescript` produces valid TypeScript types from it; CORS and JSON body-size limits match the PHP deployment.
|
||||
|
||||
**Plans**: 6 plans
|
||||
**Plans**: 10 plans
|
||||
|
||||
Plans:
|
||||
**Wave 1** *(parallel)*
|
||||
@@ -325,27 +325,40 @@ Plans:
|
||||
|
||||
**Wave 1**
|
||||
|
||||
- [ ] 08-01-PLAN.md — Discover and dynamically register clients through the real app and corrected OAuth schema
|
||||
- [ ] 08-01-PLAN.md — Define and prove the app-agnostic metadata and DCR engine
|
||||
|
||||
**Wave 2** *(blocked on 08-01)*
|
||||
|
||||
- [ ] 08-02-PLAN.md — Complete S256 authorize, JWT consent, and atomic authorization-code exchange
|
||||
- [ ] 08-02-PLAN.md — Correct OAuth schema and implement transaction-scoped Postgres stores
|
||||
|
||||
**Wave 3** *(blocked on 08-02)*
|
||||
|
||||
- [ ] 08-03-PLAN.md — Rotate refresh grants, kill replayed lineages, and manage connected apps
|
||||
- [ ] 08-03-PLAN.md — Mount persistent metadata and DCR on the assembled raw route surface
|
||||
|
||||
**Wave 4** *(blocked on 08-03)*
|
||||
|
||||
- [ ] 08-04-PLAN.md — Provision confidential clients and serve the MCP personal-token bootstrap
|
||||
- [ ] 08-04-PLAN.md — Implement ordered authorize validation and atomic PKCE code exchange
|
||||
|
||||
**Wave 5** *(blocked on 08-04)*
|
||||
|
||||
- [ ] 08-05-PLAN.md — Replay PHP OAuth flows and run the unchanged real MCP lifecycle
|
||||
- [ ] 08-05-PLAN.md — Wire JWT consent and prove the unchanged Nuxt UI contract
|
||||
|
||||
**Wave 6** *(blocked on 08-05; blocking security checkpoint)*
|
||||
**Wave 6** *(blocked on 08-05)*
|
||||
|
||||
- [ ] 08-06-PLAN.md — Close 103-method coverage, independent security review, and final phase gate
|
||||
- [ ] 08-06-PLAN.md — Rotate refresh grants, kill replayed lineages, and manage connected apps
|
||||
|
||||
**Wave 7** *(parallel; blocked on 08-06)*
|
||||
|
||||
- [ ] 08-07-PLAN.md — Provision confidential clients through the exact operator command
|
||||
- [ ] 08-08-PLAN.md — Serve the MCP personal-token bootstrap on the existing token surface
|
||||
|
||||
**Wave 8** *(blocked on 08-07 and 08-08)*
|
||||
|
||||
- [ ] 08-09-PLAN.md — Replay PHP OAuth flows and run the unchanged real MCP lifecycle through the pre-security gate
|
||||
|
||||
**Wave 9** *(blocked on 08-09; blocking security checkpoint)*
|
||||
|
||||
- [ ] 08-10-PLAN.md — Close 103-method coverage, independent security review, and the final fail-closed gate
|
||||
|
||||
### Phase 9: Backend admin authentication and schema pipeline
|
||||
|
||||
@@ -483,7 +496,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
||||
| 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 |
|
||||
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
||||
| 8. OAuth2.1 authorization server | 0/10 | Not started | - |
|
||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||
| 10. Admin Vue SPA | 0/TBD | Not started | - |
|
||||
| 11. Jobs, realtime and search infrastructure | 0/TBD | Not started | - |
|
||||
|
||||
Reference in New Issue
Block a user