docs(08): finalize oauth plans after final checker pass
This commit is contained in:
@@ -132,9 +132,9 @@ Unchanged MCP inputs:
|
||||
- Every request id, code, verifier, client secret, access token, and refresh token is represented only by a typed placeholder in committed fixtures; private vars are mode 0600.
|
||||
- Nine manifest entries become ported only after their exact route replay passes; pending never increments passing.
|
||||
</behavior>
|
||||
<action>D-16: extend the existing capture script/rules and use the Phase 2 isolated-PHP process to record the locked lifecycle. Issue the confidential client through `fonoteka:oauth-client`; exercise scope ceiling truncation and invalid-scope redirect with `client_secret_basic`. Capture all secret-bearing values with explicit pkce/token/credential categories into the private store, confirm both vars files are 0600, and commit only symbolic variable references. Add full and projected replays through `newConfiguredTarget` with real Postgres. After each of the four raw and five JWT route subtests passes, change only those manifest entries to `status: ported`; keep honest corpus accounting.</action>
|
||||
<action>D-16: extend the existing capture script/rules and use the Phase 2 isolated-PHP process to record the locked lifecycle. Issue the confidential client through `fonoteka:oauth-client`; exercise scope ceiling truncation and invalid-scope redirect with `client_secret_basic`. Capture all secret-bearing values with explicit pkce/token/credential categories into the task-verifiable private files `/tmp/summercms-parity/mcp-lifecycle.vars` and `/tmp/summercms-parity/pkce.vars`; create each with mode 0600, retain them only through the focused verification below, and commit only symbolic variable references. Add full and projected replays through `newConfiguredTarget` with real Postgres. After each of the four raw and five JWT route subtests passes, change only those manifest entries to `status: ported`; keep honest corpus accounting.</action>
|
||||
<verify>
|
||||
<automated>(cd ../fonoteka.go && go test ./parity -run '^TestOAuthFlows$' -count=1)</automated>
|
||||
<automated>(cd ../fonoteka.go && go test ./parity -run '^TestOAuthFlows$' -count=1 && go run ./parity/check_corpus.go --manifest parity/manifest.yaml --fixtures parity/fixtures --check-secrets) && test "$(stat -c '%a' /tmp/summercms-parity/mcp-lifecycle.vars)" = 600 && test "$(stat -c '%a' /tmp/summercms-parity/pkce.vars)" = 600</automated>
|
||||
</verify>
|
||||
<acceptance_criteria>
|
||||
- `mcp-lifecycle.yaml` contains the locked sequence and placeholder references, not recoverable credential values.
|
||||
|
||||
Reference in New Issue
Block a user