fix(08): revise oauth plans after checker feedback
This commit is contained in:
@@ -8,22 +8,22 @@ All required GOAL, REQ, RESEARCH, CONTEXT, VALIDATION, and UI-SPEC items are pla
|
||||
| REQ | AUTH-05 | Metadata, DCR, S256 authorize/consent, code/refresh grants, resource handling, exact discovery/challenges | 01, 03-07, 09-10 | COVERED | Backend Basic challenge and MCP RFC 9728 ownership are tested separately. |
|
||||
| REQ | AUTH-06 | Form/query/JSON source rules, CSRF-free raw routes, rate limits, unwrapped responses, cache headers | 01, 03-05, 09-10 | COVERED | Route-table, byte, header, parity, and final audit coverage. |
|
||||
| REQ | AUTH-07 | Persistent OAuth models, connected-app list/revoke, unchanged MCP install/auth/tool flow | 02-03, 05-10 | COVERED | Includes schema correction, `/me`, lifecycle, and real MCP. |
|
||||
| RESEARCH | R-01 | Additive nullability/index migration and pointer models | 02 | COVERED | Safe rollback refusal is explicit. |
|
||||
| RESEARCH | R-02 | App-agnostic transaction-scoped store bundle with GORM row locks in app tier | 01-03 | COVERED | Framework never imports GORM/fonoteka. |
|
||||
| RESEARCH | R-01 | Additive nullability/index migration and pointer models | 02 | COVERED | Persistent DCR slice includes safe rollback refusal. |
|
||||
| RESEARCH | R-02 | App-agnostic transaction-scoped store bundle with GORM row locks in app tier | 02-04 | COVERED | Framework never imports GORM/fonoteka; DCR is connector-visible at the end of 02. |
|
||||
| RESEARCH | R-03 | Commit refresh replay lineage kill before returning `invalid_grant` | 06, 10 | COVERED | Persisted post-error evidence and concurrency tests. |
|
||||
| RESEARCH | R-04 | Ordered RFC3986 redirects and endpoint-specific parsers | 04-05, 09-10 | COVERED | Exact bytes/parity. |
|
||||
| RESEARCH | R-05 | No new package; standard-library crypto/HTTP and package-legitimacy audit not applicable | 01-10 | COVERED | T-08-SC included in every threat model. |
|
||||
| RESEARCH | R-06 | 103 PHP-method audit and complete validation architecture | 10 | COVERED | Exact distribution and executable missing-name gate. |
|
||||
| RESEARCH | R-07 | Real MCP `/me` prerequisite and 64 KiB DCR bound | 01, 08-10 | COVERED | Both resolved questions are locked as D-20/D-21. |
|
||||
| CONTEXT | D-01 | Direct stdlib port; no zitadel/oidc; correct roadmap/requirement wording | 01, planning update | COVERED | No dependency install. |
|
||||
| CONTEXT | D-02 | Query/form/JSON parameter sources | 01, 04, 09-10 | COVERED | JSON token rejection, ParseForm precedence, JSON-only register. |
|
||||
| CONTEXT | D-03 | TTLs, caps, issuer/resource/consent configuration | 01-03 | COVERED | Exact PHP defaults in plan 01. |
|
||||
| CONTEXT | D-01 | Direct stdlib port; no zitadel/oidc; correct roadmap/requirement wording | 01-04, planning update | COVERED | No dependency install. |
|
||||
| CONTEXT | D-02 | Query/form/JSON parameter sources | 02-04, 09-10 | COVERED | JSON-only register, query-only authorize, JSON token rejection and ParseForm precedence. |
|
||||
| CONTEXT | D-03 | TTLs, caps, issuer/resource/consent configuration | 01-04 | COVERED | Metadata mounted in 01; exact DCR/TTL defaults wired in 02. |
|
||||
| CONTEXT | D-04 | Full T-08 security treatment and constant-time comparisons | 01-10 | COVERED | Independent security agent and blocking approval in 10. |
|
||||
| CONTEXT | D-05 | `wristband` owns RFC surface/state machine | 01-03 | COVERED | Framework structure and import boundary explicit. |
|
||||
| CONTEXT | D-06 | PHP-minimal response shapes are defaults; no hooks | 01-03, 05 | COVERED | Exact response/header tests and parity. |
|
||||
| CONTEXT | D-07 | App stores, issuer, transaction boundary, row locks | 01-03 | COVERED | Real Postgres concurrency tests. |
|
||||
| CONTEXT | D-05 | `wristband` owns RFC surface/state machine | 01-04 | COVERED | Each opening plan ends in an assembled connector-visible slice. |
|
||||
| CONTEXT | D-06 | PHP-minimal response shapes are defaults; no hooks | 01-05 | COVERED | Exact response/header tests and parity. |
|
||||
| CONTEXT | D-07 | App stores, issuer, transaction boundary, row locks | 02-04 | COVERED | Persistent DCR plus real Postgres concurrency tests. |
|
||||
| CONTEXT | D-08 | App owns consent and connected apps | 05-06 | COVERED | Exact UI payloads and ownership. |
|
||||
| CONTEXT | D-09 | Raw routes and per-route token/register throttles | 03, 05, 10 | COVERED | Route-table inspection. |
|
||||
| CONTEXT | D-09 | Raw routes and per-route token/register throttles | 01-05, 10 | COVERED | Metadata in 01, register in 02, authorize in 03, token in 05 wiring; route-table inspection throughout. |
|
||||
| CONTEXT | D-10 | Retire reserved oauth guard; access stays `inv_token` | 03-05, 08, 10 | COVERED | Negative guard/source tests. |
|
||||
| CONTEXT | D-11 | Preserve configured `inv_` prefix | 04, 08-09 | COVERED | Actual MCP install/HTTP consumption. |
|
||||
| CONTEXT | D-12 | Backend Basic challenge; MCP owns rich Bearer/resource metadata | 03-05, 08-10 | COVERED | Unit, route, and real-process evidence. |
|
||||
@@ -36,13 +36,13 @@ All required GOAL, REQ, RESEARCH, CONTEXT, VALIDATION, and UI-SPEC items are pla
|
||||
| CONTEXT | D-19 | Exact app-side `fonoteka:oauth-client` | 07 | COVERED | Repeatable bonfire flags and one-time secret. |
|
||||
| CONTEXT | D-20 | Exact personal-token `/me` MCP prerequisite | 08-09 | COVERED | Existing guard/middleware and positive allow-list. |
|
||||
| CONTEXT | D-21 | Register body bounded at 64 KiB with native error | 01, 10 | COVERED | Bound precedes JSON decode. |
|
||||
| VALIDATION | W0-01 | Framework metadata/authorize/token/register/PKCE/refresh tests | 01, 04, 06, 10 | COVERED | Fast in-memory tests plus audit. |
|
||||
| VALIDATION | W0-01 | Framework metadata/authorize/token/register/PKCE/refresh tests | 01-04, 06, 10 | COVERED | Fast in-memory tests plus audit. |
|
||||
| VALIDATION | W0-02 | Real-Postgres migration/store locking/replay/sweep tests | 02, 04, 06, 10 | COVERED | Existing auth TestMain harness. |
|
||||
| VALIDATION | W0-03 | Raw routing/parser/rate/body/header isolation | 03-05, 10 | COVERED | Assembled route tests. |
|
||||
| VALIDATION | W0-04 | Consent/collection/connected-app ownership | 05-06, 10 | COVERED | Real-Postgres controllers. |
|
||||
| VALIDATION | W0-05 | Nine routes, lifecycle replay, 103-method map | 09-10 | COVERED | Corpus/fixture/map gates. |
|
||||
| VALIDATION | W0-06 | Personal-token `/me` | 08-09 | COVERED | MCP startup prerequisite. |
|
||||
| VALIDATION | W0-07 | Full unchanged MCP and security gate | 09-10 | COVERED | Final script plus review checkpoint. |
|
||||
| VALIDATION | W0-07 | Full unchanged MCP and security gate | 09-10 | COVERED | 09 self-validates gate structure; 10 final checkpoint is the sole long execution. |
|
||||
| UI-SPEC | UI-01 | Nuxt remains unchanged | 05-10 | COVERED | Read-only harness and scoped path-diff checks. |
|
||||
| UI-SPEC | UI-02 | Consent read/allow/deny states and exact payload/status/redirect semantics | 05, 09-10 | COVERED | Includes invalid-handle no-request, safe login return, stale/foreign/used 404, and empty-scope 422. |
|
||||
| UI-SPEC | UI-03 | Connected-app empty/populated/error/list/revoke contracts | 05-06, 09-10 | COVERED | Browser matrix plus positive allow-list, manual count, identical 404. |
|
||||
|
||||
Reference in New Issue
Block a user