test(08-04): add failing code-exchange RED test in wristband
- Server.Token 501 stub and TestPhase8RedCodeExchange (PHASE8_RED:code-exchange) - Options gains AccessTokenTTL/RefreshTokenTTL with PHP-parity defaults
This commit is contained in:
21
wristband/token.go
Normal file
21
wristband/token.go
Normal file
@@ -0,0 +1,21 @@
|
||||
// RFC 6749 token endpoint for MCP OAuth, ported from PHP
|
||||
// OAuthTokenController::token / OAuthCodeManager::exchangeCode byte-for-byte
|
||||
// including their validation order (08-CONTEXT.md D-02/D-04/D-05/D-07;
|
||||
// canonical PHP source: OAuthTokenController.php, OAuthCodeManager.php).
|
||||
//
|
||||
// 08-04-PLAN.md ships the authorization_code grant only. grant_type=
|
||||
// refresh_token is dispatched with the exact PHP-parity validity check (an
|
||||
// unknown grant type is unsupported_grant_type; a known-but-not-yet-built
|
||||
// grant is invalid_grant) but its full rotation/lineage-kill semantics
|
||||
// (T-08-REFRESH-REPLAY) are ROADMAP.md Wave 6 (08-06-PLAN.md), not this
|
||||
// plan's threat register.
|
||||
package wristband
|
||||
|
||||
import "net/http"
|
||||
|
||||
// Token handles POST /oauth/mcp/token (D-09: raw route, no middleware).
|
||||
// This is the Phase 8 Wave 4 RED stub (08-04-PLAN.md Task 1): it always
|
||||
// responds 501 until Task 2 implements the real handler.
|
||||
func (s *Server) Token(w http.ResponseWriter, r *http.Request) {
|
||||
w.WriteHeader(http.StatusNotImplemented)
|
||||
}
|
||||
Reference in New Issue
Block a user