fix(08): revise oauth plans after checker feedback

This commit is contained in:
Jakub Zych
2026-09-23 17:46:38 +02:00
parent 3c6a505c5f
commit e23cbac240
13 changed files with 444 additions and 197 deletions

View File

@@ -20,7 +20,7 @@ Decimal phases appear between their surrounding integers in numeric order.
- [x] **Phase 5: Data layer full fidelity** - All 25 models and their squashed migrations with fillable/hidden/cast/soft-delete discipline (completed 2026-09-18)
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-21)
- [x] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password (completed 2026-09-22)
- [ ] **Phase 8: OAuth2.1 authorization server** - zitadel/oidc server for fonoteka-mcp and the ChatGPT connector
- [ ] **Phase 8: OAuth2.1 authorization server** - direct standard-library `wristband` server for fonoteka-mcp and the ChatGPT connector
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
- [ ] **Phase 10: Admin Vue SPA** - Login, navigation, lists, forms and relation manager for five controllers
- [ ] **Phase 11: Jobs, realtime and search infrastructure** - River, Centrifugo and Typesense sync brought up before the API phases that need them
@@ -318,26 +318,26 @@ Plans:
3. The token endpoint returns exactly `WWW-Authenticate: Basic realm="OAuth"` on `invalid_client`, the backend personal-token 401 remains unchanged with no added challenge, and fonoteka-mcp's own rich Bearer challenge plus protected-resource metadata are verified through its actual discovery flow, not just a Go unit test.
4. Connected apps can be listed and revoked; `OAuthClient`/`OAuthAuthCode`/`OAuthRefreshToken` models persist correctly; fonoteka-mcp completes its install and auth flow unchanged; client-secret comparison uses `crypto/subtle.ConstantTimeCompare`.
**Plans**: 6 plans
**Plans**: 10 plans
**Research flag:** yes
Plans:
**Wave 1**
- [ ] 08-01-PLAN.md — Define and prove the app-agnostic metadata and DCR engine
- [ ] 08-01-PLAN.md — Mount exact connector-visible metadata and establish fail-closed RED verification
**Wave 2** *(blocked on 08-01)*
- [ ] 08-02-PLAN.md — Correct OAuth schema and implement transaction-scoped Postgres stores
- [ ] 08-02-PLAN.md — Deliver persistent connector-visible DCR with corrected schema and transaction-scoped stores
**Wave 3** *(blocked on 08-02)*
- [ ] 08-03-PLAN.md — Mount persistent metadata and DCR on the assembled raw route surface
- [ ] 08-03-PLAN.md — Create durable PKCE-bound authorize requests on the assembled raw route surface
**Wave 4** *(blocked on 08-03)*
- [ ] 08-04-PLAN.md — Implement ordered authorize validation and atomic PKCE code exchange
- [ ] 08-04-PLAN.md — Implement atomic PKCE-bound authorization-code exchange
**Wave 5** *(blocked on 08-04)*
@@ -354,7 +354,7 @@ Plans:
**Wave 8** *(blocked on 08-07 and 08-08)*
- [ ] 08-09-PLAN.md — Replay PHP OAuth flows and run the unchanged real MCP lifecycle through the pre-security gate
- [ ] 08-09-PLAN.md — Replay PHP OAuth flows and assemble the self-validating final unchanged-MCP gate
**Wave 9** *(blocked on 08-09; blocking security checkpoint)*