feat(08-05): add wristband consent issue/deny operations
Server.PendingRequest/IssueCode/DenyPending port PHP OAuthConsentController::pendingFor/OAuthCodeManager::issueCode as app-agnostic protocol operations (08-CONTEXT.md D-08): every missing, foreign-owner, used, expired, or already-issued pending row collapses to the identical ErrPendingNotFound (T-08-CROSS-USER/T-08-REQUEST-LEAK). IssueCode trusts the caller's already-computed granted scopes/collection ids and returns the ordered redirect_to URL built through the existing RFC 3986 encoder. AuthCodeStore.MarkIssued gains scopes/collectionIDs/expiresAt parameters (PHP's issueCode overwrites all three, not just code_hash/user_id) and ClientStore gains MarkConsented, both required for D-08's consented_at stamping and server-derived grant persistence. Options gains CodeTTL (600s PHP-parity default) following the established Options-extension pattern.
This commit is contained in:
@@ -69,6 +69,12 @@ type Options struct {
|
||||
// OAuthCodeManager::PENDING_TTL_SECONDS, D-03). PHP default: 600s.
|
||||
PendingRequestTTL time.Duration
|
||||
|
||||
// CodeTTL is how long an issued authorization code stays valid after
|
||||
// consent (PHP OAuthCodeManager::CODE_TTL_SECONDS, D-03). PHP default:
|
||||
// 600s. Consent issuance always sets a fresh expiry from this TTL
|
||||
// rather than reusing the pending row's original expiry.
|
||||
CodeTTL time.Duration
|
||||
|
||||
// AccessTokenTTL is how long an inv_ access token minted by a successful
|
||||
// code exchange or refresh rotation stays valid (PHP
|
||||
// OAuthCodeManager::ACCESS_TTL_SECONDS, D-03). PHP default: 3600s (1h).
|
||||
@@ -93,6 +99,7 @@ func DefaultOptions() Options {
|
||||
RegisterMaxBodyBytes: 65536,
|
||||
Resource: "https://mcp.plytarium.com/mcp",
|
||||
PendingRequestTTL: 600 * time.Second,
|
||||
CodeTTL: 600 * time.Second,
|
||||
AccessTokenTTL: 3600 * time.Second,
|
||||
RefreshTokenTTL: 30 * 24 * time.Hour,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user