docs(07): plan gap closure for the pending user-api parity routes

This commit is contained in:
Jakub Zych
2026-09-22 20:22:45 +02:00
parent d4e9c17816
commit f75e3e84db
2 changed files with 279 additions and 1 deletions

View File

@@ -272,7 +272,7 @@ Plans:
3. A personal API token is created with a read|write|ai scope ceiling, listed, and revoked; a scope-checking middleware rejects an out-of-scope request.
4. The must-change-password flag returns 423 on the authenticated surface except the locale and password-change routes, and locale resolves per request from the user's persisted `preferred_locale` with header fallback even while the lock is active.
**Plans**: 6 plans
**Plans**: 7 plans
Plans:
**Wave 1**
@@ -296,6 +296,10 @@ Plans:
- [x] 07-06-PLAN.md — Full unit coverage, 07-VALIDATION.md sign-off
**Wave 6** *(gap closure; blocked on 07-06)*
- [ ] 07-07-PLAN.md — Re-record the logout blacklist under a persistent PHP cache, fix the already-activated HTML-500 quirk, and flip all 15 /_user/api/v1 routes plus both nuxt flows to ported
### Phase 8: OAuth2.1 authorization server
**Goal**: An RFC 8414/6749/7591-compliant OAuth2.1 server on zitadel/oidc serves fonoteka-mcp and the ChatGPT connector unchanged, including exact `WWW-Authenticate` and protected-resource-metadata headers. Security-load-bearing — bearer tokens, PKCE and constant-time secret comparison all live here; apply the security-review agent.