fix(08): revise oauth plans after checker feedback
This commit is contained in:
@@ -108,12 +108,12 @@ PHP test inventory contract:
|
||||
</behavior>
|
||||
<action>D-18: enumerate all 103 PHP methods into `08-PHP-TEST-MAP.md`, map each to existing Phase 8 tests, and add focused coverage tests only where no named evidence exists. Add an executable audit that parses the inventory/map and Go test list so counts alone cannot hide missing or duplicate mappings. Close framework handler/store branches, app boot/config/route/controller/command branches, parity projections, UI harness invocation, and every exact response/header path. Do not replace behavior assertions with coverage-only calls or map one broad test to methods whose distinct assertions are absent.</action>
|
||||
<verify>
|
||||
<automated>go test ./wristband -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... ./parity -run 'Test(OAuth|Phase08|PHPTestMap|TokenSurface|MeToken)' -count=1</automated>
|
||||
<automated>go test ./wristband -run '^Test(Phase08Coverage|PHPTestMap)' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka ./parity -run '^Test(Phase08Coverage|PHPTestMap)$' -count=1)</automated>
|
||||
</verify>
|
||||
<acceptance_criteria>
|
||||
- The map contains exactly 103 unique PHP method rows distributed 11/8/2/7/10/10/7/10/8/30 by source suite.
|
||||
- The executable audit confirms every mapped Go `TestName[/subtest]` exists and executes; missing or duplicate rows make it fail.
|
||||
- Both repositories pass full `go vet ./...`, `go test ./...`, and `go test -race ./...`, including nested plugin modules.
|
||||
- The focused map/coverage audit is designed for under 30 seconds; complete repository vet/test/race runs only in Task 3's final gate.
|
||||
- Coverage additions retain exact byte/header/concurrency assertions for security branches.
|
||||
</acceptance_criteria>
|
||||
<done>All PHP OAuth behavior has one-to-one named Go evidence and the phase's code paths are covered by meaningful regression tests.</done>
|
||||
@@ -162,7 +162,7 @@ PHP test inventory contract:
|
||||
.planning/phases/08-oauth2-1-authorization-server/08-VALIDATION.md
|
||||
.planning/phases/08-oauth2-1-authorization-server/08-09-SUMMARY.md
|
||||
</read_first>
|
||||
<action>Present the completed automated evidence after the security-review agent has produced zero open high-severity findings. Do not ask the user to rerun automation; show the exact gate result, threat totals, 103-method audit result, nine-route parity result, real-MCP lifecycle result, and unchanged Nuxt/MCP worktree checks. Block completion if any displayed result is missing or non-green.</action>
|
||||
<action>After the security-review agent reports zero open high-severity findings, execute `scripts/check-phase8.sh` exactly once as the sole complete long gate. It must run both repositories' `go vet ./...`, `go test ./...`, and `go test -race ./...`; 103-method executable audit; nine-route/full-lifecycle parity and corpus secret scan; full return-path/i18n/Playwright UI matrix; disposable Postgres/app plus unchanged real MCP discovery/DCR/PKCE/JWT consent/token/`/me`/tool/refresh/replay/revoke; security-review fail-closed checks; and scoped unchanged Nuxt/MCP worktree assertions. Present the completed evidence; do not ask the user to rerun automation. Block completion if any displayed result is missing or non-green.</action>
|
||||
<verify>
|
||||
<automated>scripts/check-phase8.sh</automated>
|
||||
</verify>
|
||||
|
||||
Reference in New Issue
Block a user