fix(08-09): match wristband OAuth byte contract to live-recorded PHP
Recording the full mcp-lifecycle fixture against real isolated PHP (08-09-PLAN.md Task 2) uncovered three byte-level gaps between wristband's assumed contract and actual production PHP behavior: - Every explicit "Cache-Control: no-store" PHP sets is actually delivered as "no-store, private" (Laravel's session-cookie default merges "private" onto any explicit value); wristband's own default for unheadered JSON error responses is "no-cache, private" (matching the house convention already used elsewhere), not empty. - PHP's redirect responses (authorize success and every error redirect) render Symfony's default HTML redirect body with Content-Type "text/html; charset=utf-8"; Go's bare 302 with no body never matched. wristband/redirect_html.go ports that exact byte template, including PHP's htmlspecialchars(ENT_QUOTES) escaping (Go's html.EscapeString uses different quote entities). tide/normalize.go: isIDKey now also masks "_ids" plural array fields (e.g. collection_ids), a latent parity-corpus gap no prior fixture had exercised with a literal, non-empty, non-placeholder array value.
This commit is contained in:
@@ -142,7 +142,7 @@ func (s *Server) Token(w http.ResponseWriter, r *http.Request) {
|
||||
Scope: scope,
|
||||
}
|
||||
writeExactJSON(w, http.StatusOK, body, map[string]string{
|
||||
"Cache-Control": "no-store",
|
||||
"Cache-Control": "no-store, private",
|
||||
"Pragma": "no-cache",
|
||||
})
|
||||
}
|
||||
@@ -409,5 +409,9 @@ func (s *Server) Revoke(ctx context.Context, apiTokenID uint) error {
|
||||
}
|
||||
|
||||
func writeTokenError(w http.ResponseWriter, status int, code string) {
|
||||
writeExactJSON(w, status, tokenErrorBody{Error: code}, nil)
|
||||
// PHP's rfcError() sets no explicit Cache-Control; Laravel's own
|
||||
// session-cookie default for an otherwise-unheadered JSON response is
|
||||
// "no-cache, private" (matches the live-recorded byte contract, same
|
||||
// default the house wire.WriteJSON convention already uses elsewhere).
|
||||
writeExactJSON(w, status, tokenErrorBody{Error: code}, map[string]string{"Cache-Control": "no-cache, private"})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user