docs(08): finalize oauth plans after final checker pass
This commit is contained in:
@@ -16,7 +16,6 @@ files_modified:
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/classes/auth/oauth_store.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/classes/auth/oauth_store_test.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml
|
||||
- ../fonoteka.go/config/app.yaml
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/plugin.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/routes.go
|
||||
- ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go
|
||||
@@ -24,6 +23,7 @@ autonomous: true
|
||||
requirements: [AUTH-05, AUTH-06, AUTH-07]
|
||||
must_haves:
|
||||
truths:
|
||||
- "D-03: Configuration defaults pending requests and authorization codes to 600s, access tokens to 3600s, refresh tokens to 30 days, the DCR client cap to 200, and the unconsented-client sweep to 24h; derives issuer from app.url with its trailing slash trimmed, defaults the RFC 8707 resource to https://mcp.plytarium.com/mcp, and builds consent URLs as app.url + /connect?request=<opaque>."
|
||||
- "D-07: Public clients and multiple pending authorization requests persist through one transaction-scoped GORM adapter."
|
||||
- "D-17: Expiry sweeps delete only expired lifecycle rows and retain unexpired replay evidence."
|
||||
- "D-02/D-21: A connector can dynamically register through the assembled JSON-only 64 KiB-bounded route and receive an exact persistent response."
|
||||
@@ -111,7 +111,7 @@ Output: Corrected models/migration, wristband DCR, GORM backend, configured raw
|
||||
- Raw client secrets are returned once, SHA-256 hashes alone persist, and verification uses `crypto/subtle.ConstantTimeCompare` over fixed transforms.
|
||||
- Sweep/cap/create share one transaction; concurrent cap-1 registration yields one success and one native error.
|
||||
</behavior>
|
||||
<action>D-01/D-02/D-04/D-05/D-06/D-07/D-17/D-21: add app-agnostic Backend/Tx records, deterministic clock/entropy seams, fixed-transform crypto, a local exact response writer, and the RFC 7591 handler. Apply `http.MaxBytesReader` before decode and return the native `invalid_client_metadata` body for overflow/malformed/non-JSON. Strip control characters, cap names at 120, return raw secrets once, and persist hashes only. Implement the app GORM adapter using only the callback `*gorm.DB`; serialize stale sweep/cap/create in one transaction and expose later row-lock lifecycle methods without importing GORM into wristband. First validate exact `TestPhase8RedRegistration` and `TestPhase8RedRegistrationStore` JSON RED streams, then make focused unit/Postgres tests green.</action>
|
||||
<action>D-01/D-02/D-04/D-05/D-06/D-07/D-17/D-21: add app-agnostic Backend/Tx records, deterministic clock/entropy seams, fixed-transform crypto, a local exact response writer, and the RFC 7591 handler. Apply `http.MaxBytesReader` before decode and return the native `invalid_client_metadata` body for overflow/malformed/non-JSON. Strip control characters, cap names at 120, return raw secrets once, and persist hashes only. Implement the app GORM adapter using only the callback `*gorm.DB`; serialize stale sweep/cap/create in one transaction and expose later row-lock lifecycle methods without importing GORM into wristband. Before implementation, run `scripts/check-phase8-red.sh go PHASE8_RED:registration git.golem15.com/golem15/summercms/wristband TestPhase8RedRegistration -- go test -json ./wristband -run '^TestPhase8RedRegistration$' -count=1` and `scripts/check-phase8-red.sh go PHASE8_RED:registration-store git.golem15.com/golem15/fonoteka/plugins/golem15/fonoteka/classes/auth TestPhase8RedRegistrationStore -- bash -lc "cd ../fonoteka.go && go test -json ./plugins/golem15/fonoteka/classes/auth -run '^TestPhase8RedRegistrationStore$' -count=1"`; each invocation must observe its exact sentinel once, the anchored selected test and named package only, and zero unexpected fail actions/package/test events, build/setup/syntax failures, panics, malformed JSON events, or zero-test selection. Then make focused unit/Postgres tests green.</action>
|
||||
<verify>
|
||||
<automated>go test ./wristband -run '^Test(Register|Registration)' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/classes/auth -run '^TestOAuth(RegistrationStore|RegistrationCap)$' -count=1)</automated>
|
||||
</verify>
|
||||
@@ -126,7 +126,7 @@ Output: Corrected models/migration, wristband DCR, GORM backend, configured raw
|
||||
|
||||
<task type="auto" tdd="true">
|
||||
<name>Task 3: Configure and mount persistent DCR on the assembled raw surface</name>
|
||||
<files>../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml, ../fonoteka.go/config/app.yaml, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go, ../fonoteka.go/plugins/golem15/fonoteka/routes.go, ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go</files>
|
||||
<files>../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go, ../fonoteka.go/plugins/golem15/fonoteka/routes.go, ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go</files>
|
||||
<read_first>
|
||||
.planning/phases/08-oauth2-1-authorization-server/08-UI-SPEC.md
|
||||
../fonoteka.go/plugins/golem15/fonoteka/plugin.go
|
||||
@@ -141,7 +141,7 @@ Output: Corrected models/migration, wristband DCR, GORM backend, configured raw
|
||||
- Only register carries `throttle:fonoteka-oauth-register`; metadata remains raw with no middleware.
|
||||
- Config defaults are pending/code 600s, access 3600s, refresh 30 days, DCR cap 200, stale age 24h, resource URL, and register max 65,536.
|
||||
</behavior>
|
||||
<action>D-03: add `plugins.golem15.fonoteka.oauth.*` defaults and construct the store-backed server in Plugin.Boot while preserving 08-01 metadata. D-09: mount register in the raw group with only its named throttle. D-10/D-12: register no oauth guard and add no rich Bearer/resource-server surface. Add an assembled real-Postgres `TestPhase8RedRegistrationApp` first, validate its exact JSON RED stream, then assert exact bytes/headers, durable reload, middleware isolation, config values, and unchanged metadata.</action>
|
||||
<action>D-03: add `plugins.golem15.fonoteka.oauth.*` defaults and construct the store-backed server in Plugin.Boot while preserving 08-01 metadata. Read the existing `../fonoteka.go/config/app.yaml` only as the `app.url` source; do not modify it. D-09: mount register in the raw group with only its named throttle. D-10/D-12: register no oauth guard and add no rich Bearer/resource-server surface. Add an assembled real-Postgres `TestPhase8RedRegistrationApp`, then before implementation run `scripts/check-phase8-red.sh go PHASE8_RED:registration-app git.golem15.com/golem15/fonoteka/plugins/golem15/fonoteka TestPhase8RedRegistrationApp -- bash -lc "cd ../fonoteka.go && go test -json ./plugins/golem15/fonoteka -run '^TestPhase8RedRegistrationApp$' -count=1"`; it must observe the exact sentinel once, the anchored selected test and named package only, and zero unexpected fail actions/package/test events, build/setup/syntax failures, panics, malformed JSON events, or zero-test selection. Then assert exact bytes/headers, durable reload, middleware isolation, config values, and unchanged metadata.</action>
|
||||
<verify>
|
||||
<automated>(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestOAuth(RegisterAssembled|MetadataAssembled|RawRegistrationSurface)$' -count=1)</automated>
|
||||
</verify>
|
||||
|
||||
Reference in New Issue
Block a user