Value-based replace can miss a code_verifier when an authorization code is a substring of it, which 502'd MCP token capture.
Co-authored-by: Cursor <cursoragent@cursor.com>
Consent returns the callback URL in JSON, so replay can fill {{oauth:code}} from $.data.redirect_to before the token request.
Co-authored-by: Cursor <cursoragent@cursor.com>
RFC 7591 registration returns a string client_id and unix client_id_issued_at; treating those as Carbon/integer foreign keys would fail PHP self-replay of MCP OAuth.
Co-authored-by: Cursor <cursoragent@cursor.com>
Album sync payloads hash the collection and stamp a checkpoint that
change across seed runs and must not fail PHP self-replay.
Co-authored-by: Cursor <cursoragent@cursor.com>
Re-running bootstrap against an already seeded PHP instance 409s.
Route --update must not recapture a complete seed fixture.
Co-authored-by: Cursor <cursoragent@cursor.com>
PHP album payloads leave discogs_id null. The id mask required an
integer and failed PHP self-replay on otherwise identical bodies.
Co-authored-by: Cursor <cursoragent@cursor.com>
Unquoted numeric id placeholders made recorded JSON illegal to parse.
Replay now recaptures, persists vars, expands the expected body, and
diffs against the live response.
Co-authored-by: Cursor <cursoragent@cursor.com>
Numeric seed ids like 1 were substring-replaced through /api/v1 paths
and 15-style JSON integers. Keep ReplaceAll for long secrets and isolate
short values so the corpus stays replayable.
Co-authored-by: Cursor <cursoragent@cursor.com>
Manifest seed paths are fixtures-relative. Skip re-hitting the backend
only when every seed step already has a recorded status so a hand-written
spec can be recorded in place.
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 3/3
- Capture a complete named session through the proxy
- Replay stateful flows with safe capture and strict differences
- Record manifest route cases and report complete coverage
SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-02-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
Drive ordered route cases through RecordFlow, resume in batches of
15, and print recorded/passing/failing/unrecorded coverage.
Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve named placeholders from a private variable store, mask
dates and ids after shape checks, and keep comparing independent steps.
Co-authored-by: Cursor <cursoragent@cursor.com>
Record Nuxt/MCP traffic as ordered flows via parity:proxy, pin
loopback upstream, and refuse oversized or credential-shaped fixtures.
Co-authored-by: Cursor <cursoragent@cursor.com>
Tasks completed: 2/2
- Record and replay one route through the summer CLI
- Lock the one-route tide record and replay contract
SUMMARY: .planning/phases/02-api-parity-harness-bootstrap/02-01-SUMMARY.md
Co-authored-by: Cursor <cursoragent@cursor.com>
- Reject unknown YAML fields, empty names, duplicate steps and unsafe sidecars
- Treat JSON key order as insignificant and fail missing keys and token types at $.path
- Bound request bodies and refuse oversized or malformed input before writing a fixture
Co-authored-by: Cursor <cursoragent@cursor.com>
- Add a generic tide flow schema with YAML fixture IO and HTTP record/replay
- Register parity:record and parity:replay on the bonfire summer tool
- Diff JSON scalars at $.path and non-JSON bodies at the changed byte offset
Co-authored-by: Cursor <cursoragent@cursor.com>
- Watch app sources with fsnotify, debounce, and one serialized build.App
- Restart the child only after a successful build and print rebuild latency
- Ignore generated app files and reap the child on cancellation
- Inject bonfire.Output from stdin/stdout/stderr with stdlib widgets and x/term
- Degrade spinner, progress, table and prompts without a TTY or color
- Reject plugin command names that are not namespace:verb
- Scaffold a compiling vendor.plugin module with go.mod, plugin.go and config/
- Register the module once in summer.yaml, go.work and the app go.mod
- Keep summer build on the same generate-and-compile path and print elapsed time
- App-owned festival bus with Fire, Collect and UntilHandled
- Recover listener panics with owner plugin IDs; isolate buses per app
- towel context accessors and hello command demo of all three modes
- Cover Fire/Collect/UntilHandled, priority, panics and bus isolation
- Require towel actor/org/collection/locale accessors on context
- Assert hello command demonstrates all three dispatch modes
- App-scoped typed Publish/Lookup with duplicate-provider errors
- Set plugin IDs before Register so HasPlugin sees the full set
- Greeter uses pact.OptionalMessage without importing optional