docs(08): finalize oauth plans after final checker pass

This commit is contained in:
Jakub Zych
2026-09-23 18:42:49 +02:00
parent 2d7ac66605
commit a59e69211d
5 changed files with 653 additions and 14 deletions

View File

@@ -132,9 +132,9 @@ Unchanged MCP inputs:
- Every request id, code, verifier, client secret, access token, and refresh token is represented only by a typed placeholder in committed fixtures; private vars are mode 0600.
- Nine manifest entries become ported only after their exact route replay passes; pending never increments passing.
</behavior>
<action>D-16: extend the existing capture script/rules and use the Phase 2 isolated-PHP process to record the locked lifecycle. Issue the confidential client through `fonoteka:oauth-client`; exercise scope ceiling truncation and invalid-scope redirect with `client_secret_basic`. Capture all secret-bearing values with explicit pkce/token/credential categories into the private store, confirm both vars files are 0600, and commit only symbolic variable references. Add full and projected replays through `newConfiguredTarget` with real Postgres. After each of the four raw and five JWT route subtests passes, change only those manifest entries to `status: ported`; keep honest corpus accounting.</action>
<action>D-16: extend the existing capture script/rules and use the Phase 2 isolated-PHP process to record the locked lifecycle. Issue the confidential client through `fonoteka:oauth-client`; exercise scope ceiling truncation and invalid-scope redirect with `client_secret_basic`. Capture all secret-bearing values with explicit pkce/token/credential categories into the task-verifiable private files `/tmp/summercms-parity/mcp-lifecycle.vars` and `/tmp/summercms-parity/pkce.vars`; create each with mode 0600, retain them only through the focused verification below, and commit only symbolic variable references. Add full and projected replays through `newConfiguredTarget` with real Postgres. After each of the four raw and five JWT route subtests passes, change only those manifest entries to `status: ported`; keep honest corpus accounting.</action>
<verify>
<automated>(cd ../fonoteka.go &amp;&amp; go test ./parity -run '^TestOAuthFlows$' -count=1)</automated>
<automated>(cd ../fonoteka.go &amp;&amp; go test ./parity -run '^TestOAuthFlows$' -count=1 &amp;&amp; go run ./parity/check_corpus.go --manifest parity/manifest.yaml --fixtures parity/fixtures --check-secrets) &amp;&amp; test "$(stat -c '%a' /tmp/summercms-parity/mcp-lifecycle.vars)" = 600 &amp;&amp; test "$(stat -c '%a' /tmp/summercms-parity/pkce.vars)" = 600</automated>
</verify>
<acceptance_criteria>
- `mcp-lifecycle.yaml` contains the locked sequence and placeholder references, not recoverable credential values.