fix(08): revise plans based on checker feedback
This commit is contained in:
113
.planning/phases/08-oauth2-1-authorization-server/08-07-PLAN.md
Normal file
113
.planning/phases/08-oauth2-1-authorization-server/08-07-PLAN.md
Normal file
@@ -0,0 +1,113 @@
|
||||
---
|
||||
phase: 08-oauth2-1-authorization-server
|
||||
plan: 07
|
||||
type: execute
|
||||
wave: 7
|
||||
depends_on: [08-06]
|
||||
files_modified:
|
||||
- bonfire/command.go
|
||||
- bonfire/root.go
|
||||
- bonfire/output_test.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/plugin.go
|
||||
autonomous: true
|
||||
requirements: [AUTH-05, AUTH-07]
|
||||
must_haves:
|
||||
truths:
|
||||
- "D-19: Operators can create, update, and list OAuth clients with repeatable flags and one-time secret output."
|
||||
- "D-04: Command issuance stores only a hash and never leaks secret material through list/update output."
|
||||
artifacts:
|
||||
- path: "../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go"
|
||||
provides: "Exact fonoteka:oauth-client command"
|
||||
- path: "bonfire/command.go"
|
||||
provides: "Typed repeatable string-slice flag contract"
|
||||
key_links:
|
||||
- from: "oauth_client.go"
|
||||
to: "wristband client issuance"
|
||||
via: "shared validation/hash/one-time-secret path"
|
||||
pattern: "wristband"
|
||||
---
|
||||
|
||||
<objective>
|
||||
Provision confidential and ceiling-bounded OAuth clients through the exact app command.
|
||||
|
||||
Purpose: Deliver operator management separately from the personal-token MCP bootstrap surface.
|
||||
Output: Repeatable bonfire flags, client command, plugin registration, and command tests.
|
||||
</objective>
|
||||
|
||||
<execution_context>
|
||||
@/home/jin/.codex/get-shit-done/workflows/execute-plan.md
|
||||
@/home/jin/.codex/get-shit-done/templates/summary.md
|
||||
</execution_context>
|
||||
|
||||
<context>
|
||||
@.planning/PROJECT.md
|
||||
@.planning/ROADMAP.md
|
||||
@.planning/STATE.md
|
||||
@.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md
|
||||
@.planning/phases/08-oauth2-1-authorization-server/08-06-SUMMARY.md
|
||||
</context>
|
||||
|
||||
<tasks>
|
||||
|
||||
<task type="auto" tdd="true">
|
||||
<name>Task 1: Specify repeatable flags and command output in executable RED</name>
|
||||
<files>bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go</files>
|
||||
<behavior>
|
||||
- Repeated redirect/scope flags preserve order without breaking scalar/bare flags.
|
||||
- Create prints id, secret, warning once; update/list never reveal secret/hash.
|
||||
- Tests compile and fail only through separate `PHASE8_RED:bonfire-flags` and `PHASE8_RED:oauth-command` markers.
|
||||
</behavior>
|
||||
<action>D-18: and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first; mark only missing bonfire behavior with `PHASE8_RED:bonfire-flags` and missing app-command behavior with `PHASE8_RED:oauth-command`. Use the shared verifier to reject syntax/setup/missing tests.</action>
|
||||
<verify>
|
||||
<automated>scripts/check-phase8-red.sh bonfire-flags go test ./bonfire -run 'Test.*Flag' -count=1 && scripts/check-phase8-red.sh oauth-command bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1"</automated>
|
||||
</verify>
|
||||
<done>RED command tests execute and fail only for absent repeatable-flag/command behavior.</done>
|
||||
</task>
|
||||
|
||||
<task type="auto" tdd="true">
|
||||
<name>Task 2: Add repeatable flags and exact OAuth client command</name>
|
||||
<files>bonfire/command.go, bonfire/root.go, bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go</files>
|
||||
<behavior>
|
||||
- Flag/Input distinguish scalar and repeated values; existing callers remain compatible.
|
||||
- Create/update/list share wristband validation/issuance and artisan clients have null registration_ip.
|
||||
</behavior>
|
||||
<action>D-19: extend bonfire with explicit string-slice flags and `Input.Flags(name)`, using Cobra StringSlice only for that kind. Implement the exact name/redirect-uri/scope/auth-method/client-id/list signature thinly over wristband and ClientStore; never parse os.Args. Print the exact creation lines/warning and never recover or print secrets on list/update. Register through plugin command capability.</action>
|
||||
<verify>
|
||||
<automated>go test ./bonfire -run 'Test.*Flag' -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1</automated>
|
||||
</verify>
|
||||
<done>Operators can safely provision and inspect OAuth clients with exact repeatable flags and no secret recovery.</done>
|
||||
</task>
|
||||
|
||||
</tasks>
|
||||
|
||||
<threat_model>
|
||||
## Trust Boundaries
|
||||
|
||||
| Boundary | Description |
|
||||
|----------|-------------|
|
||||
| Operator CLI → client store | Trusted input creates recoverable-once credentials. |
|
||||
|
||||
## STRIDE Threat Register
|
||||
|
||||
| Threat ID | Category | Component | Disposition | Mitigation Plan |
|
||||
|-----------|----------|-----------|-------------|-----------------|
|
||||
| T-08-SECRET-TIMING | Information Disclosure | issued client | mitigate | Shared hash/validation path and one-time secret. |
|
||||
| T-08-SCOPE-CEILING | Elevation | command | mitigate | Validated stored ceiling used by authorize. |
|
||||
| T-08-REQUEST-LEAK | Information Disclosure | output | mitigate | Exact positive output and secret/hash rejection tests. |
|
||||
| T-08-SC | Tampering | Cobra | mitigate | Existing pinned dependency only. |
|
||||
</threat_model>
|
||||
|
||||
<verification>
|
||||
- Bonfire and command tests pass.
|
||||
- List/update output contains no client secret or hash.
|
||||
</verification>
|
||||
|
||||
<success_criteria>
|
||||
- Exact create/update/list command behavior is runnable and secret-safe.
|
||||
</success_criteria>
|
||||
|
||||
<output>
|
||||
Create `.planning/phases/08-oauth2-1-authorization-server/08-07-SUMMARY.md` when done.
|
||||
</output>
|
||||
Reference in New Issue
Block a user