Commit Graph

369 Commits

Author SHA1 Message Date
Jakub Zych
c0b1e3cfae feat(08-02): implement exact RFC 7591 registration in wristband
- Register validates redirect_uris/grant_types/response_types/auth-method
  in PHP's exact order, strips control characters and caps client_name at
  255 runes, and generates client_id/secret via crypto/rand base64url
- confidential clients return the raw secret once; only its sha256 hex
  persists (constant-time-comparable fixed transform)
- sweep-unconsented, the atomic cap check and the create all run inside one
  wristband.Backend.WithinTx transaction (T-08-DCR-FLOOD)
- 64 KiB body bound via http.MaxBytesReader collapses to the endpoint's
  native invalid_client_metadata body, matching D-21
2026-09-23 19:37:54 +02:00
Jakub Zych
c026b83f41 test(08-02): add failing RFC 7591 registration RED test in wristband
- TestPhase8RedRegistration asserts the exact public-client DCR success
  contract and fails while Server.Register is a 501 stub
- adds the Backend/Tx transaction-scoped store bundle (ClientStore,
  AuthCodeStore, RefreshTokenStore, AccessTokenIssuer) and wristband's own
  in-memory implementation for framework-level tests (D-07)
- adds crypto.go's fixed-transform helpers (random base64url, sha256 hex,
  constant-time compare, S256) and Options/Server seams for the DCR
  lifetimes, cap, sweep age and 64 KiB body bound (D-03/D-21)
2026-09-23 19:37:03 +02:00
Jakub Zych
deee2cc8d7 docs(08-01): complete metadata RED infrastructure plan 2026-09-23 19:20:35 +02:00
Jakub Zych
c578bb58d7 feat(08-01): implement exact RFC 8414 metadata writer in wristband
- Server.Metadata now writes the unwrapped 11-field PHP-parity document
  through a local no-envelope, no-trailing-newline JSON writer with the
  PHP Cache-Control: no-cache, private header (D-06); response types,
  grant types and PKCE method stay fixed protocol constants
- TestPhase8RedMetadata now passes; TestMetadataExactBytes and
  TestMetadataUsesConfiguredOptions cover byte-exact output and the four
  configurable Options fields
2026-09-23 19:10:26 +02:00
Jakub Zych
24d35d85e8 test(08-01): add failing RFC 8414 metadata RED test and fail-closed verifier
- wristband.Server.Metadata is a compiling 501 stub; TestPhase8RedMetadata
  asserts the exact unwrapped PHP metadata document, headers and status and
  fails with the PHASE8_RED:metadata sentinel (D-06)
- scripts/check-phase8-red.sh implements the shared go/shell RED contract
  for the rest of Phase 8: exact selected test/package failure plus sentinel,
  rejecting unrelated fail actions, compile/setup failures, panics,
  malformed JSON, missing/duplicate sentinels and zero selection (D-04/D-18)
2026-09-23 19:09:14 +02:00
Jakub Zych
a59e69211d docs(08): finalize oauth plans after final checker pass 2026-09-23 18:42:49 +02:00
Jakub Zych
2d7ac66605 docs(phase-07): add security threat verification 2026-09-23 18:19:43 +02:00
Jakub Zych
e23cbac240 fix(08): revise oauth plans after checker feedback 2026-09-23 17:46:38 +02:00
Jakub Zych
3c6a505c5f fix(08): revise plans based on checker feedback 2026-09-23 17:13:47 +02:00
Jakub Zych
241af16ba7 docs(08): create OAuth authorization server plans 2026-09-23 13:38:58 +02:00
Jakub Zych
716d0ea40d docs(08): approve UI design contract 2026-09-23 12:53:09 +02:00
Jakub Zych
dd96f59e57 docs(8): revise UI design contract 2026-09-23 12:50:25 +02:00
Jakub Zych
2aafa6f2a2 docs(08): add UI design contract 2026-09-23 12:44:34 +02:00
Jakub Zych
37fbcdc6de docs(phase-08): add validation strategy and resolve research decisions 2026-09-23 12:32:31 +02:00
Jakub Zych
a3a4636c29 docs(08): research OAuth authorization server 2026-09-23 12:14:03 +02:00
Jakub Zych
47b856b1c6 docs(state): record phase 8 context session 2026-09-23 11:37:14 +02:00
Jakub Zych
251ac038e2 docs(08): capture phase context 2026-09-23 11:37:13 +02:00
Jakub Zych
b435304570 docs(phase-7): complete phase execution
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:53:42 +02:00
Jakub Zych
e537b67a37 docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:52:45 +02:00
Jakub Zych
3a15105a1b docs(state): record 07-08 completion and tracking
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:51:26 +02:00
Jakub Zych
b74484eabc docs(07-08): complete the avatar bucket publish plan
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:50:01 +02:00
Jakub Zych
44900f0d16 feat(07-08): publish the uploads bucket on serve
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:43:47 +02:00
Jakub Zych
33f716ddef docs(07-08): plan avatar bucket publish on serve and Handler 2026-09-23 10:33:19 +02:00
Jakub Zych
ab84becf16 test(07): complete UAT - 11 passed, 1 issues 2026-09-23 10:33:16 +02:00
Jakub Zych
1bd9f9e056 docs(state): record phase 9 context session 2026-09-23 10:24:37 +02:00
Jakub Zych
8268ff780d docs(09): capture phase context 2026-09-23 10:24:22 +02:00
Jakub Zych
d20f99f2e6 docs(07-07): complete the user-api parity gap plan
Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 00:01:18 +02:00
Jakub Zych
31634f706f feat(07-07): localize lagoon validation with Laravel-shaped Polish messages
Replay of the user-api corpus needs lagoon::validate.* catalogs and
underscore-to-space attribute names so Go 422 bodies match Winter.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 23:56:58 +02:00
Jakub Zych
dd3cb7ac29 docs(07): record gap-closure planning in state 2026-09-22 20:41:30 +02:00
Jakub Zych
8a1a52915b fix(07): revise 07-07-PLAN.md for checker-found seeding blockers 2026-09-22 20:38:01 +02:00
Jakub Zych
f75e3e84db docs(07): plan gap closure for the pending user-api parity routes 2026-09-22 20:22:45 +02:00
Jakub Zych
d4e9c17816 docs(07): record the phase goal verification
The six plans are in, and three of the four success criteria hold. AUTH-01 stays blocked because the 15 user API routes are still pending against the recorded PHP bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:27:27 +02:00
Jakub Zych
9446981ffd docs(07-06): complete the unit coverage plan
The validation contract is signed off and the phase plan count is 6/6. Requirement checkboxes stay open while the user-api routes are still pending.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:21:31 +02:00
Jakub Zych
4754377442 feat(07-06): prove mint, refresh, and blacklist under concurrency
A minted token refreshes once, then the old jti is blacklisted. Memory and Postgres blacklists take concurrent Add and IsBlacklisted calls.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 19:20:14 +02:00
Jakub Zych
fa7bdb5f71 docs(07-05): complete the user API parity capture plan
Record that the 15 user routes stay pending until Go matches the PHP bodies, including the HTML 500 on a bad activation code and the still-valid token after logout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:44:05 +02:00
Jakub Zych
7d5d8659ec feat(07-05): allow the second parity test password
Change-password recordings need a distinct new password that the fixture scrubber still accepts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:43:27 +02:00
Jakub Zych
ecfcd23150 docs(07-04): complete the personal token and locale plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 18:09:31 +02:00
Jakub Zych
4e56ff98b0 docs(07-03): complete the account management plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:48:10 +02:00
Jakub Zych
3cf938867c docs(07-02): complete the user session plan
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:15:16 +02:00
Jakub Zych
ae9e11f65d docs(07-01): complete framework auth primitives plan 2026-09-22 13:43:15 +02:00
Jakub Zych
8fcaff77cf feat(07-01): add bcrypt, locale override, and validation rules
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:39:25 +02:00
Jakub Zych
bccd7f8f35 test(07-01): add failing tests for passwords, locale, and validation
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:36:08 +02:00
Jakub Zych
cad445a235 feat(07-01): add JWT mint, refresh, and blacklist primitives
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:34:58 +02:00
Jakub Zych
251f3cc4a0 test(07-01): add failing tests for JWT lifecycle primitives
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:33:37 +02:00
Jakub Zych
80eaeb87ea docs(07): mark phase planned, annotate roadmap waves 2026-09-22 12:39:05 +02:00
Jakub Zych
3aed5c88c3 docs(07): revise plans after checker review 2026-09-22 12:37:08 +02:00
Jakub Zych
57745e32a2 docs(07): create phase plan
Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
  override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
  fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
  change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
  proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
  instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)

Plan count and scope confirmed at the plan-count checkpoint.
2026-09-22 12:21:15 +02:00
Jakub Zych
0c41151863 docs(07): add pattern map 2026-09-22 11:51:06 +02:00
Jakub Zych
fb16132d21 docs(07): add validation strategy 2026-09-22 02:43:29 +02:00
Jakub Zych
0ef3a47d22 docs(07): research user plugin and authentication phase 2026-09-22 02:42:14 +02:00