- bonfire.wrap registers a Repeatable Flag as a Cobra StringSlice so
Input.Flags returns every repeated --name=value occurrence in order;
scalar/bare flags are unaffected (D-19)
- wristband.IssueClientCredentials/RejectRedirectURI export the exact
random-id/secret/hash and redirect-URI validation RFC 7591
registration already uses, so the fonoteka:oauth-client operator
command shares one hash/validation path with DCR (T-08-SECRET-TIMING)
- TestPhase8RedBonfireFlags asserts Input.Flags preserves ordered
repeated --redirect-uri/--scope values while existing scalar --mode
flags via Input.Flag stay unaffected
- Adds the compiling seam (Flag.Repeatable, Input.Flags,
cobraInput.Flags) without wiring Cobra StringSlice registration yet,
so the test fails with PHASE8_RED:bonfire-flags (D-19)
rotateRefreshToken ports OAuthCodeManager::rotateRefresh: a fresh refresh
token rotates atomically (revoke old access token, mint successor, link
rotated_to_id) while a replayed (already-rotated) token instead revokes the
whole lineage and commits that kill before Token maps it to invalid_grant
outside the transaction (T-08-REFRESH-REPLAY). Token also runs the D-17
expiry sweep (DeleteExpiredCodes/DeleteExpiredRefreshTokens) before grant
processing. Server.Revoke is the new cascade-revoke seam a connected-app
controller uses instead of touching refresh rows directly.
TestPhase8RedLifecycleFramework drives exchange -> rotate -> replay against
the real (in-memory-backed) Server.Token and fails while rotateRefreshToken
is 08-04's invalid_grant placeholder (PHASE8_RED:lifecycle-framework,
verified fail-closed via scripts/check-phase8-red.sh). Extends the
RefreshTokenStore/AuthCodeStore interfaces with the store seams Task 2's
implementation needs (ByAPITokenIDForUpdate, MarkRotated,
DeleteExpiredCodes, DeleteExpiredRefreshTokens) and updates the framework's
in-memory test double to satisfy them.
TestFetchTooLargeIsStreaming asserted the server wrote at most 64 KiB, but
the handler keeps flushing 64-byte chunks until the client's close propagates,
which under a loaded full-suite run exceeds that (observed ~80 KiB). The
assertion guards against unbounded buffering toward 8 MiB, so 1 MiB keeps
the intent and removes the flake.
check-phase8-ui.mjs encodes 08-UI-SPEC.md's full consent/connected-app
state matrix, accessibility, responsive, and i18n contract as a versioned
32-scenario catalog across 7 categories. --contract-self-test validates
catalog completeness, guarded Nuxt source-file hashes (proving the
harness itself never writes inside vue-fonoteka-app), and that
@playwright/test resolves from the already-installed dependency, all
without booting a browser or service (runs in ~50ms).
--final-gate (running verify:oauth-return-path, verify:oauth-i18n, and
the real Playwright matrix) is scaffolded but refuses to run without
PHASE8_UI_ALLOW_FINAL_GATE=1 and is explicitly 08-10's closing-checkpoint
responsibility, not executed by this plan.
Server.PendingRequest/IssueCode/DenyPending port PHP
OAuthConsentController::pendingFor/OAuthCodeManager::issueCode as
app-agnostic protocol operations (08-CONTEXT.md D-08): every missing,
foreign-owner, used, expired, or already-issued pending row collapses to
the identical ErrPendingNotFound (T-08-CROSS-USER/T-08-REQUEST-LEAK).
IssueCode trusts the caller's already-computed granted scopes/collection
ids and returns the ordered redirect_to URL built through the existing
RFC 3986 encoder.
AuthCodeStore.MarkIssued gains scopes/collectionIDs/expiresAt parameters
(PHP's issueCode overwrites all three, not just code_hash/user_id) and
ClientStore gains MarkConsented, both required for D-08's consented_at
stamping and server-derived grant persistence. Options gains CodeTTL
(600s PHP-parity default) following the established Options-extension
pattern.
- Server.Token: JSON rejection before ParseForm, body-over-query precedence,
Basic-over-form client auth, exact invalid_request/unsupported_grant_type/
invalid_client/invalid_grant bodies, Cache-Control/Pragma on success only
- authenticateClient: public/confidential dispatch, constant-time secret
compare (T-08-SECRET-TIMING)
- exchangeAuthorizationCode: single WithinTx lock/consume/mint/refresh-create
covering code/client/redirect/resource/PKCE binding and single-use replay
(T-08-CODE-REPLAY), sequential and concurrent proofs
- rotateRefreshToken: grant_type=refresh_token dispatches per PHP validity
but is a deliberate invalid_grant placeholder; full rotation is 08-06
- full token_test.go behavior matrix appended alongside the RED anchor
- Server.Authorize ports OAuthAuthorizeController::authorize's exact
validation order: usable client, exact redirect, response_type=code,
code_challenge_method=S256, challenge length, scope parsing/ceiling
truncation, resource check, then opaque pending-request creation
- Unknown client/unregistered redirect are local text/plain 400s with no
Location; every later failure is an ordered RFC3986 redirect with
error/error_description/iss[/state], built via a dedicated encoder
(never url.Values.Encode, which sorts keys and space-encodes as '+')
- Options gains Resource and PendingRequestTTL (both PHP-parity defaults)
so authorize's resource check and 600s pending expiry are configurable
- Server.Authorize stub returns 501
- TestPhase8RedAuthorize drives a full valid S256 request and asserts the
exact 302 /connect success contract; fails with PHASE8_RED:authorize
against the stub, verified fail-closed via check-phase8-red.sh
- Register validates redirect_uris/grant_types/response_types/auth-method
in PHP's exact order, strips control characters and caps client_name at
255 runes, and generates client_id/secret via crypto/rand base64url
- confidential clients return the raw secret once; only its sha256 hex
persists (constant-time-comparable fixed transform)
- sweep-unconsented, the atomic cap check and the create all run inside one
wristband.Backend.WithinTx transaction (T-08-DCR-FLOOD)
- 64 KiB body bound via http.MaxBytesReader collapses to the endpoint's
native invalid_client_metadata body, matching D-21
- TestPhase8RedRegistration asserts the exact public-client DCR success
contract and fails while Server.Register is a 501 stub
- adds the Backend/Tx transaction-scoped store bundle (ClientStore,
AuthCodeStore, RefreshTokenStore, AccessTokenIssuer) and wristband's own
in-memory implementation for framework-level tests (D-07)
- adds crypto.go's fixed-transform helpers (random base64url, sha256 hex,
constant-time compare, S256) and Options/Server seams for the DCR
lifetimes, cap, sweep age and 64 KiB body bound (D-03/D-21)
- Server.Metadata now writes the unwrapped 11-field PHP-parity document
through a local no-envelope, no-trailing-newline JSON writer with the
PHP Cache-Control: no-cache, private header (D-06); response types,
grant types and PKCE method stay fixed protocol constants
- TestPhase8RedMetadata now passes; TestMetadataExactBytes and
TestMetadataUsesConfiguredOptions cover byte-exact output and the four
configurable Options fields
- wristband.Server.Metadata is a compiling 501 stub; TestPhase8RedMetadata
asserts the exact unwrapped PHP metadata document, headers and status and
fails with the PHASE8_RED:metadata sentinel (D-06)
- scripts/check-phase8-red.sh implements the shared go/shell RED contract
for the rest of Phase 8: exact selected test/package failure plus sentinel,
rejecting unrelated fail actions, compile/setup failures, panics,
malformed JSON, missing/duplicate sentinels and zero selection (D-04/D-18)
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com>
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.
Co-authored-by: Cursor <cursoragent@cursor.com>
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.
Co-authored-by: Cursor <cursoragent@cursor.com>
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.
Co-authored-by: Cursor <cursoragent@cursor.com>
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.
Co-authored-by: Cursor <cursoragent@cursor.com>
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.
Co-authored-by: Cursor <cursoragent@cursor.com>
Replay of the user-api corpus needs lagoon::validate.* catalogs and
underscore-to-space attribute names so Go 422 bodies match Winter.
Co-authored-by: Cursor <cursoragent@cursor.com>