docs(07): plan gap closure for the pending user-api parity routes
This commit is contained in:
@@ -272,7 +272,7 @@ Plans:
|
||||
3. A personal API token is created with a read|write|ai scope ceiling, listed, and revoked; a scope-checking middleware rejects an out-of-scope request.
|
||||
4. The must-change-password flag returns 423 on the authenticated surface except the locale and password-change routes, and locale resolves per request from the user's persisted `preferred_locale` with header fallback even while the lock is active.
|
||||
|
||||
**Plans**: 6 plans
|
||||
**Plans**: 7 plans
|
||||
|
||||
Plans:
|
||||
**Wave 1**
|
||||
@@ -296,6 +296,10 @@ Plans:
|
||||
|
||||
- [x] 07-06-PLAN.md — Full unit coverage, 07-VALIDATION.md sign-off
|
||||
|
||||
**Wave 6** *(gap closure; blocked on 07-06)*
|
||||
|
||||
- [ ] 07-07-PLAN.md — Re-record the logout blacklist under a persistent PHP cache, fix the already-activated HTML-500 quirk, and flip all 15 /_user/api/v1 routes plus both nuxt flows to ported
|
||||
|
||||
### Phase 8: OAuth2.1 authorization server
|
||||
|
||||
**Goal**: An RFC 8414/6749/7591-compliant OAuth2.1 server on zitadel/oidc serves fonoteka-mcp and the ChatGPT connector unchanged, including exact `WWW-Authenticate` and protected-resource-metadata headers. Security-load-bearing — bearer tokens, PKCE and constant-time secret comparison all live here; apply the security-review agent.
|
||||
|
||||
Reference in New Issue
Block a user