diff --git a/.planning/PROJECT.md b/.planning/PROJECT.md index ea3dced..a3d3452 100644 --- a/.planning/PROJECT.md +++ b/.planning/PROJECT.md @@ -50,6 +50,11 @@ Validated in Phase 7: User plugin and authentication - [x] Locale resolves per request from preferred_locale then Accept-Language then app.locale, including while the lock is active - [x] `surf.ServeCommand` and `app.Handler` publish the uploads `*blob.Bucket` so assembled avatar POST is 200 +Validated in Phase 8: OAuth2.1 authorization server + +- [x] Direct standard-library OAuth 2.1-style authorization server (`wristband`): RFC 8414 metadata, RFC 7591 dynamic registration, authorize with S256 PKCE and JWT-guarded consent, authorization_code and rotating refresh_token grants with replay lineage-kill, RFC 8707 resource handling, connected-app list/revoke, `fonoteka:oauth-client` operator command, and the `/me` bootstrap the unchanged fonoteka-mcp process uses +- [x] Byte parity with recorded PHP across all nine OAuth routes and a 17-step MCP lifecycle; the real unmodified fonoteka-mcp completes discovery, DCR, PKCE, consent, token, tool call, refresh, replay rejection and revoke against the Go binary; `scripts/check-phase8.sh` is the sign-off gate (its Playwright UI matrix stage is a named carried-forward follow-up) + ### Active Framework kernel @@ -64,7 +69,7 @@ Data layer HTTP and auth - (user plugin / JWT / orgs / personal tokens / password lock — moved to Validated in Phase 7) -- [ ] OAuth2/OIDC provider (zitadel/oidc) that the MCP server and the ChatGPT connector use with the same flows as today (auth code + PKCE, refresh tokens, client management, `IssueOAuthClient` command) +- (OAuth authorization server — moved to Validated in Phase 8; shipped as the direct standard-library `wristband` package rather than zitadel/oidc) - [ ] All 154 Płytarium API routes ported with byte-compatible request and response shapes (collections, albums, artists, genres, styles, ratings, reservations, wishlist, sharing and invitations, notifications, realtime channel auth, CSV import/export, locale, user context, credentials) Background and integrations @@ -174,4 +179,4 @@ This document evolves at phase transitions and milestone boundaries. 4. Update Context with current state --- -*Last updated: 2026-09-23 after Phase 7 completion* +*Last updated: 2026-09-24 after Phase 8 completion*