docs(08): finalize oauth plans after final checker pass
This commit is contained in:
@@ -135,7 +135,7 @@ Existing serializer:
|
||||
</behavior>
|
||||
<action>Implement D-04, D-05, D-07, and D-17's refresh branch in wristband and the GORM adapter. Authenticate the client using the same Basic-over-form rule, hash the presented refresh secret, lock its row, reject expired/revoked/wrong-client grants, and rotate atomically by revoking the old access token, minting/persisting its successor, creating the next refresh secret/hash, and linking `rotated_to_id`. If a spent token is presented, traverse and revoke the whole lineage and associated access tokens, return nil from the transaction so the kill commits, then return `invalid_grant` from the handler. Keep the old scopes, collection IDs, offline flag, and client binding. Sweep only rows whose `expires_at` is past; do not delete unexpired replay evidence.</action>
|
||||
<verify>
|
||||
<automated>go test ./wristband -run 'Test(Refresh|Replay|Sweep)' -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/classes/auth -run 'TestOAuth(Refresh|Replay|Sweep)' -count=1</automated>
|
||||
<automated>go test ./wristband -run 'Test(Refresh|Replay|Sweep)' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/classes/auth -run 'TestOAuth(Refresh|Replay|Sweep)' -count=1)</automated>
|
||||
</verify>
|
||||
<acceptance_criteria>
|
||||
- Normal refresh and sequential/concurrent replay tests pass under real Postgres.
|
||||
|
||||
Reference in New Issue
Block a user