docs(08-06): complete lifecycle and sweeps plan

This commit is contained in:
Jakub Zych
2026-09-23 21:42:32 +02:00
parent dab2b8f31a
commit d70e412138
3 changed files with 174 additions and 9 deletions

View File

@@ -3,14 +3,14 @@ gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
stopped_at: Completed 08-05-PLAN.md
last_updated: "2026-09-23T19:11:27.527Z"
stopped_at: Completed 08-06-PLAN.md
last_updated: "2026-09-23T19:42:20.033Z"
last_activity: 2026-09-23
progress:
total_phases: 15
completed_phases: 7
total_plans: 55
completed_plans: 50
completed_plans: 51
percent: 47
---
@@ -26,11 +26,11 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position
Phase: 08 (oauth2-1-authorization-server) — EXECUTING
Plan: 6 of 10
Plan: 7 of 10
Status: Ready to execute
Last activity: 2026-09-23
Progress: [█████████░] 91%
Progress: [█████████░] 93%
## Performance Metrics
@@ -96,6 +96,7 @@ Progress: [█████████░] 91%
| Phase 08 P03 | 20min | 2 tasks | 6 files |
| Phase 08 P04 | 15min | 2 tasks | 5 files |
| Phase 08 P05 | 55min | 3 tasks | 12 files |
| Phase 08 P06 | 50min | 3 tasks | 10 files |
## Accumulated Context
@@ -233,6 +234,10 @@ Recent decisions affecting current work:
- [Phase 08]: [Phase 08 P05] Consent scope ordering follows auth.MintableScopes's declared read/write/ai order, not PHP array_intersect's incidental first-array order — 08-UI-SPEC.md explicitly documents canonical read -> write -> ai order as the fixed contract
- [Phase 08]: [Phase 08 P05] POST /oauth/mcp/token mounted in this plan, closing 08-04's deliberate D-09 deferral — Only once consent produces a real issued code does an end-to-end /token call through the real route have anything to exchange
- [Phase 08]: [Phase 08 P05] AUTH-05/06/07 remain Pending in REQUIREMENTS.md — Refresh rotation (08-06) and connected-apps list/revoke are still outstanding pieces of those requirements; this plan ships consent plus the token mount only
- [Phase 08 P06]: rotateRefreshToken commits lineage-kill revocation inside WithinTx and returns nil (success) on replay, mapping a captured replayed flag to invalid_grant outside the transaction -- mirrors PHP rotateRefresh's own commit-then-throw shape
- [Phase 08 P06]: RevokeLineage walks forward only through RotatedToID; sufficient for both replay-kill and connected-app-revoke because every normal rotation already revokes its own predecessor's access token and connected-app revoke always starts from the terminal row
- [Phase 08 P06]: Fixed RevokeLineage (GORM adapter and in-memory test double) to also revoke each visited row's linked access token -- the 08-02-era method only stamped the refresh row itself, leaving a replayed lineage's live access token usable
- [Phase 08 P06]: AUTH-05/06/07 remain Pending in REQUIREMENTS.md: refresh-rotation and connected-apps pieces are done, but AUTH-05/07's unchanged-fonoteka-mcp clause needs 08-08/08-09, and AUTH-06's CSRF/rate-limit/cache-header claims are reconciled by 08-10's security review
### Pending Todos
@@ -254,6 +259,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-23T19:11:27.509Z
Stopped at: Completed 08-05-PLAN.md
Last session: 2026-09-23T19:42:20.015Z
Stopped at: Completed 08-06-PLAN.md
Resume file: None