fix(08): revise oauth plans after checker feedback
This commit is contained in:
@@ -54,29 +54,58 @@ Output: Repeatable bonfire flags, client command, plugin registration, and comma
|
||||
<task type="auto" tdd="true">
|
||||
<name>Task 1: Specify repeatable flags and command output in executable RED</name>
|
||||
<files>bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go</files>
|
||||
<read_first>
|
||||
.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md
|
||||
.planning/phases/08-oauth2-1-authorization-server/08-PATTERNS.md
|
||||
bonfire/command.go
|
||||
bonfire/root.go
|
||||
bonfire/output_test.go
|
||||
../fonoteka.go/plugins/golem15/fonoteka/console/console_test.go
|
||||
/media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/console/IssueOAuthClient.php
|
||||
/media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/tests/functional/OAuthClientCommandTest.php
|
||||
</read_first>
|
||||
<behavior>
|
||||
- Repeated redirect/scope flags preserve order without breaking scalar/bare flags.
|
||||
- Create prints id, secret, warning once; update/list never reveal secret/hash.
|
||||
- Tests compile and fail only through separate `PHASE8_RED:bonfire-flags` and `PHASE8_RED:oauth-command` markers.
|
||||
</behavior>
|
||||
<action>D-18: and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first; mark only missing bonfire behavior with `PHASE8_RED:bonfire-flags` and missing app-command behavior with `PHASE8_RED:oauth-command`. Use the shared verifier to reject syntax/setup/missing tests.</action>
|
||||
<action>D-18 and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first. Use exact `TestPhase8RedBonfireFlags`/`PHASE8_RED:bonfire-flags` and `TestPhase8RedOAuthClientCommand`/`PHASE8_RED:oauth-command` package/test/sentinel triples with `go test -json`; reject any unexpected failing action/package/test, compile/setup/panic/no-test result, or missing/duplicate sentinel.</action>
|
||||
<verify>
|
||||
<automated>scripts/check-phase8-red.sh bonfire-flags go test ./bonfire -run 'Test.*Flag' -count=1 && scripts/check-phase8-red.sh oauth-command bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1"</automated>
|
||||
<automated>scripts/check-phase8-red.sh go PHASE8_RED:bonfire-flags git.golem15.com/golem15/summercms/bonfire TestPhase8RedBonfireFlags -- go test -json ./bonfire -run '^TestPhase8RedBonfireFlags$' -count=1 && scripts/check-phase8-red.sh go PHASE8_RED:oauth-command git.golem15.com/golem15/fonoteka/plugins/golem15/fonoteka/console TestPhase8RedOAuthClientCommand -- bash -lc "cd ../fonoteka.go && go test -json ./plugins/golem15/fonoteka/console -run '^TestPhase8RedOAuthClientCommand$' -count=1"</automated>
|
||||
</verify>
|
||||
<acceptance_criteria>
|
||||
- Each RED stream contains exactly its named test fail plus named package fail and exact sentinel once; unrelated/compile/setup/panic/no-test failures are rejected.
|
||||
- Repeatable redirect/scope flags preserve input order, repeated/scalar/bare values remain distinguishable, and existing scalar callers retain behavior.
|
||||
- Command tests assert exact `client_id=`, `client_secret=`, warning lines once on create and forbid raw/hash secret output on update/list and error paths.
|
||||
</acceptance_criteria>
|
||||
<done>RED command tests execute and fail only for absent repeatable-flag/command behavior.</done>
|
||||
</task>
|
||||
|
||||
<task type="auto" tdd="true">
|
||||
<name>Task 2: Add repeatable flags and exact OAuth client command</name>
|
||||
<files>bonfire/command.go, bonfire/root.go, bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go</files>
|
||||
<read_first>
|
||||
bonfire/output_test.go
|
||||
bonfire/command.go
|
||||
bonfire/root.go
|
||||
../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go
|
||||
../fonoteka.go/plugins/golem15/fonoteka/plugin.go
|
||||
wristband/register.go
|
||||
/media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/console/IssueOAuthClient.php
|
||||
</read_first>
|
||||
<behavior>
|
||||
- Flag/Input distinguish scalar and repeated values; existing callers remain compatible.
|
||||
- Create/update/list share wristband validation/issuance and artisan clients have null registration_ip.
|
||||
</behavior>
|
||||
<action>D-19: extend bonfire with explicit string-slice flags and `Input.Flags(name)`, using Cobra StringSlice only for that kind. Implement the exact name/redirect-uri/scope/auth-method/client-id/list signature thinly over wristband and ClientStore; never parse os.Args. Print the exact creation lines/warning and never recover or print secrets on list/update. Register through plugin command capability.</action>
|
||||
<verify>
|
||||
<automated>go test ./bonfire -run 'Test.*Flag' -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1</automated>
|
||||
<automated>go test ./bonfire -run '^Test.*Flag' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/console -run '^TestOAuthClientCommand' -count=1)</automated>
|
||||
</verify>
|
||||
<acceptance_criteria>
|
||||
- Create supports ordered repeated `--redirect-uri` and `--scope`, validates auth method/ceiling through wristband, persists hash only with null registration IP, and prints the raw secret exactly once.
|
||||
- Update by client id changes only supplied values and never rotates/recovers a secret; list shows id/name/revocation/redirects/ceiling but no raw/hash credential.
|
||||
- Existing bonfire scalar and bare-flag tests remain unchanged and green; plugin command registration exposes exactly `fonoteka:oauth-client` without parsing `os.Args`.
|
||||
</acceptance_criteria>
|
||||
<done>Operators can safely provision and inspect OAuth clients with exact repeatable flags and no secret recovery.</done>
|
||||
</task>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user