Commit Graph

547 Commits

Author SHA1 Message Date
Jakub Zych
0c173df25c docs(08-10): add the Phase 8 security review; mark Wave 0 green
08-SECURITY-REVIEW.md: status: verified, 11/11 T-08 threats closed,
0 open, 0 accepted risks. Performed directly by the 08-10 executor
(no Task/Agent tool available this run, per the plan's documented
fallback) with re-executed named-test evidence for every threat; found
and fixed one real gap during the review (see the paired fix commit).

08-VALIDATION.md: 08-W0-01 through 08-W0-06 flip to green with their
automated commands re-run; nyquist_compliant and wave_0_complete are
now true. 08-W0-07/08-W0-08 (the full scripts/check-phase8.sh gate)
stay pending until 08-10 Task 3 actually executes it.
2026-09-24 00:12:36 +02:00
Jakub Zych
034f63907d feat(08-10): fail-closed 08-SECURITY-REVIEW.md checks in check-phase8.sh
stage_security_review now also refuses a nonzero threats_open count and
any missing required T-08-* threat row, not just a missing/unverified
file. Adds --security-review-only, a focused mode running just this
stage (Task 2's own verify command) with no services booted.
2026-09-24 00:12:28 +02:00
Jakub Zych
eb40d1bdc4 docs(08-10): add the 103-method PHP-to-Go OAuth test map
Auditable one-to-one map of every PHP OAuth functional/security test
method to its named Go test/subtest evidence, mechanically verified by
fonoteka.go/parity/oauth_audit_test.go's TestPHPTestMap.
2026-09-24 00:05:58 +02:00
Jakub Zych
f4259560c2 test(08-10): close wristband 103-method PHP audit gaps
- register loopback http:// acceptance, javascript: URI rejection, and
  error-body no-secret/no-stack-trace evidence
- token-exchange plain PKCE rejection even when verifier equals the
  stored (non-S256) challenge
2026-09-24 00:05:41 +02:00
Jakub Zych
d358bbf907 docs(08-09): complete parity-and-real-mcp-gate plan 2026-09-23 23:23:12 +02:00
Jakub Zych
e87346f9e3 feat(08-09): complete the fail-closed Phase 8 final unchanged-MCP gate
Fills in every scripts/check-phase8.sh stage skeleton with real logic:
disposable Postgres (docker run + pg_isready), the assembled Go app built
and served against it with a throwaway onboarding-seeded gate account,
the real unchanged fonoteka-mcp process started with all three required
environment variables, and the full scripted SDK lifecycle -- discovery
(MCP's own RFC 9728 401 hint, verified separately from authorization
server metadata), DCR, PKCE authorize, JWT login/consent, token, an MCP
tool call, refresh, replay of the spent refresh token, revoke, and a
post-revoke refresh failure -- delegated to the new
scripts/check-phase8-mcp-client.mjs driver, which resolves the MCP SDK's
auth helpers from fonoteka-mcp's own node_modules (no new dependency,
same pattern as parity/capture_clients.mjs). Both repositories'
vet/test/race, the full parity/corpus/secret-scan gate, the existing
check-phase8-ui.mjs --final-gate UI harness, an unchanged-client git-diff
check for both MCP_ROOT and NUXT_ROOT, and a 08-SECURITY-REVIEW.md
status:verified gate close out the stage list.

--contract-self-test validates structure only (stage names/order,
cleanup trap, loopback-only binding, the three MCP env vars, the
redaction helper, no pre-final full-run flag, read-only unchanged-client
references) in well under 30 seconds -- it boots no services. The
--red-contract self-test from Task 1 is preserved unchanged. run_full_gate
(the no-flag invocation) is 08-10 Task 3's sole execution site; 08-09
never invokes it.
2026-09-23 23:18:15 +02:00
Jakub Zych
6cc07a42e2 fix(08-09): match wristband OAuth byte contract to live-recorded PHP
Recording the full mcp-lifecycle fixture against real isolated PHP
(08-09-PLAN.md Task 2) uncovered three byte-level gaps between wristband's
assumed contract and actual production PHP behavior:

- Every explicit "Cache-Control: no-store" PHP sets is actually delivered
  as "no-store, private" (Laravel's session-cookie default merges "private"
  onto any explicit value); wristband's own default for unheadered JSON
  error responses is "no-cache, private" (matching the house convention
  already used elsewhere), not empty.
- PHP's redirect responses (authorize success and every error redirect)
  render Symfony's default HTML redirect body with Content-Type
  "text/html; charset=utf-8"; Go's bare 302 with no body never matched.
  wristband/redirect_html.go ports that exact byte template, including
  PHP's htmlspecialchars(ENT_QUOTES) escaping (Go's html.EscapeString uses
  different quote entities).

tide/normalize.go: isIDKey now also masks "_ids" plural array fields
(e.g. collection_ids), a latent parity-corpus gap no prior fixture had
exercised with a literal, non-empty, non-placeholder array value.
2026-09-23 23:12:02 +02:00
Jakub Zych
246a488412 test(08-09): add check-phase8.sh gate skeleton with RED self-test
- Declares the ordered Phase 8 stage list and stage function skeletons
- --red-contract <stage> is a permanent RED-harness self-test hook
  (exit 86, PHASE8_STAGE:<stage>:FAIL:PHASE8_RED:real-mcp-stage)
- --contract-self-test and the full gate are completed in Task 3/08-10
2026-09-23 22:44:20 +02:00
Jakub Zych
f13f76ed4b docs(08-08): complete mcp-me-prerequisite plan 2026-09-23 22:23:40 +02:00
Jakub Zych
27845490e8 docs(08-07): complete oauth-client-command plan 2026-09-23 22:05:44 +02:00
Jakub Zych
398353b135 feat(08-07): wire repeatable bonfire flags and export client-issuing helpers
- bonfire.wrap registers a Repeatable Flag as a Cobra StringSlice so
  Input.Flags returns every repeated --name=value occurrence in order;
  scalar/bare flags are unaffected (D-19)
- wristband.IssueClientCredentials/RejectRedirectURI export the exact
  random-id/secret/hash and redirect-URI validation RFC 7591
  registration already uses, so the fonoteka:oauth-client operator
  command shares one hash/validation path with DCR (T-08-SECRET-TIMING)
2026-09-23 21:56:00 +02:00
Jakub Zych
7096a90235 test(08-07): add failing repeatable-flag RED anchor for bonfire
- TestPhase8RedBonfireFlags asserts Input.Flags preserves ordered
  repeated --redirect-uri/--scope values while existing scalar --mode
  flags via Input.Flag stay unaffected
- Adds the compiling seam (Flag.Repeatable, Input.Flags,
  cobraInput.Flags) without wiring Cobra StringSlice registration yet,
  so the test fails with PHASE8_RED:bonfire-flags (D-19)
2026-09-23 21:54:44 +02:00
Jakub Zych
d70e412138 docs(08-06): complete lifecycle and sweeps plan 2026-09-23 21:42:32 +02:00
Jakub Zych
dab2b8f31a feat(08-06): implement refresh rotation, replay lineage-kill, and token sweep
rotateRefreshToken ports OAuthCodeManager::rotateRefresh: a fresh refresh
token rotates atomically (revoke old access token, mint successor, link
rotated_to_id) while a replayed (already-rotated) token instead revokes the
whole lineage and commits that kill before Token maps it to invalid_grant
outside the transaction (T-08-REFRESH-REPLAY). Token also runs the D-17
expiry sweep (DeleteExpiredCodes/DeleteExpiredRefreshTokens) before grant
processing. Server.Revoke is the new cascade-revoke seam a connected-app
controller uses instead of touching refresh rows directly.
2026-09-23 21:26:35 +02:00
Jakub Zych
b2c2cc0bb7 test(08-06): add failing refresh-lifecycle RED anchor and store interface
TestPhase8RedLifecycleFramework drives exchange -> rotate -> replay against
the real (in-memory-backed) Server.Token and fails while rotateRefreshToken
is 08-04's invalid_grant placeholder (PHASE8_RED:lifecycle-framework,
verified fail-closed via scripts/check-phase8-red.sh). Extends the
RefreshTokenStore/AuthCodeStore interfaces with the store seams Task 2's
implementation needs (ByAPITokenIDForUpdate, MarkRotated,
DeleteExpiredCodes, DeleteExpiredRefreshTokens) and updates the framework's
in-memory test double to satisfy them.
2026-09-23 21:26:05 +02:00
Jakub Zych
da01ea105c docs(08-05): record fetchguard flake resolution in deferred items 2026-09-23 21:15:43 +02:00
Jakub Zych
64f9009d3d test(fetchguard): widen streaming-cap ceiling to stop flake under parallel runs
TestFetchTooLargeIsStreaming asserted the server wrote at most 64 KiB, but
the handler keeps flushing 64-byte chunks until the client's close propagates,
which under a loaded full-suite run exceeds that (observed ~80 KiB). The
assertion guards against unbounded buffering toward 8 MiB, so 1 MiB keeps
the intent and removes the flake.
2026-09-23 21:15:43 +02:00
Jakub Zych
7f37311120 docs(08-05): complete consent plan 2026-09-23 21:11:45 +02:00
Jakub Zych
fac9648ac9 feat(08-05): add read-only UI-contract harness for consent and connected apps
check-phase8-ui.mjs encodes 08-UI-SPEC.md's full consent/connected-app
state matrix, accessibility, responsive, and i18n contract as a versioned
32-scenario catalog across 7 categories. --contract-self-test validates
catalog completeness, guarded Nuxt source-file hashes (proving the
harness itself never writes inside vue-fonoteka-app), and that
@playwright/test resolves from the already-installed dependency, all
without booting a browser or service (runs in ~50ms).

--final-gate (running verify:oauth-return-path, verify:oauth-i18n, and
the real Playwright matrix) is scaffolded but refuses to run without
PHASE8_UI_ALLOW_FINAL_GATE=1 and is explicitly 08-10's closing-checkpoint
responsibility, not executed by this plan.
2026-09-23 21:04:34 +02:00
Jakub Zych
a1fa9c6f44 feat(08-05): add wristband consent issue/deny operations
Server.PendingRequest/IssueCode/DenyPending port PHP
OAuthConsentController::pendingFor/OAuthCodeManager::issueCode as
app-agnostic protocol operations (08-CONTEXT.md D-08): every missing,
foreign-owner, used, expired, or already-issued pending row collapses to
the identical ErrPendingNotFound (T-08-CROSS-USER/T-08-REQUEST-LEAK).
IssueCode trusts the caller's already-computed granted scopes/collection
ids and returns the ordered redirect_to URL built through the existing
RFC 3986 encoder.

AuthCodeStore.MarkIssued gains scopes/collectionIDs/expiresAt parameters
(PHP's issueCode overwrites all three, not just code_hash/user_id) and
ClientStore gains MarkConsented, both required for D-08's consented_at
stamping and server-derived grant persistence. Options gains CodeTTL
(600s PHP-parity default) following the established Options-extension
pattern.
2026-09-23 20:59:24 +02:00
Jakub Zych
a459f74897 docs(08-04): complete token-exchange plan 2026-09-23 20:35:49 +02:00
Jakub Zych
4bd3b3db4f feat(08-04): implement atomic PKCE-bound code exchange in wristband
- Server.Token: JSON rejection before ParseForm, body-over-query precedence,
  Basic-over-form client auth, exact invalid_request/unsupported_grant_type/
  invalid_client/invalid_grant bodies, Cache-Control/Pragma on success only
- authenticateClient: public/confidential dispatch, constant-time secret
  compare (T-08-SECRET-TIMING)
- exchangeAuthorizationCode: single WithinTx lock/consume/mint/refresh-create
  covering code/client/redirect/resource/PKCE binding and single-use replay
  (T-08-CODE-REPLAY), sequential and concurrent proofs
- rotateRefreshToken: grant_type=refresh_token dispatches per PHP validity
  but is a deliberate invalid_grant placeholder; full rotation is 08-06
- full token_test.go behavior matrix appended alongside the RED anchor
2026-09-23 20:28:07 +02:00
Jakub Zych
5ca830beef test(08-04): add failing code-exchange RED test in wristband
- Server.Token 501 stub and TestPhase8RedCodeExchange (PHASE8_RED:code-exchange)
- Options gains AccessTokenTTL/RefreshTokenTTL with PHP-parity defaults
2026-09-23 20:25:16 +02:00
Jakub Zych
5dc8c35e06 docs(08-03): record parity test fix and fetchguard flake in deferred items 2026-09-23 20:16:21 +02:00
Jakub Zych
33ab188a2e docs(08-03): complete authorize plan 2026-09-23 20:11:54 +02:00
Jakub Zych
90752beb87 feat(08-03): implement exact authorize validation and pending creation in wristband
- Server.Authorize ports OAuthAuthorizeController::authorize's exact
  validation order: usable client, exact redirect, response_type=code,
  code_challenge_method=S256, challenge length, scope parsing/ceiling
  truncation, resource check, then opaque pending-request creation
- Unknown client/unregistered redirect are local text/plain 400s with no
  Location; every later failure is an ordered RFC3986 redirect with
  error/error_description/iss[/state], built via a dedicated encoder
  (never url.Values.Encode, which sorts keys and space-encodes as '+')
- Options gains Resource and PendingRequestTTL (both PHP-parity defaults)
  so authorize's resource check and 600s pending expiry are configurable
2026-09-23 20:08:37 +02:00
Jakub Zych
787e612ab3 test(08-03): add failing authorize RED test in wristband
- Server.Authorize stub returns 501
- TestPhase8RedAuthorize drives a full valid S256 request and asserts the
  exact 302 /connect success contract; fails with PHASE8_RED:authorize
  against the stub, verified fail-closed via check-phase8-red.sh
2026-09-23 20:01:18 +02:00
Jakub Zych
ae326b0941 docs(08-02): complete persistence and registration plan 2026-09-23 19:54:54 +02:00
Jakub Zych
c0b1e3cfae feat(08-02): implement exact RFC 7591 registration in wristband
- Register validates redirect_uris/grant_types/response_types/auth-method
  in PHP's exact order, strips control characters and caps client_name at
  255 runes, and generates client_id/secret via crypto/rand base64url
- confidential clients return the raw secret once; only its sha256 hex
  persists (constant-time-comparable fixed transform)
- sweep-unconsented, the atomic cap check and the create all run inside one
  wristband.Backend.WithinTx transaction (T-08-DCR-FLOOD)
- 64 KiB body bound via http.MaxBytesReader collapses to the endpoint's
  native invalid_client_metadata body, matching D-21
2026-09-23 19:37:54 +02:00
Jakub Zych
c026b83f41 test(08-02): add failing RFC 7591 registration RED test in wristband
- TestPhase8RedRegistration asserts the exact public-client DCR success
  contract and fails while Server.Register is a 501 stub
- adds the Backend/Tx transaction-scoped store bundle (ClientStore,
  AuthCodeStore, RefreshTokenStore, AccessTokenIssuer) and wristband's own
  in-memory implementation for framework-level tests (D-07)
- adds crypto.go's fixed-transform helpers (random base64url, sha256 hex,
  constant-time compare, S256) and Options/Server seams for the DCR
  lifetimes, cap, sweep age and 64 KiB body bound (D-03/D-21)
2026-09-23 19:37:03 +02:00
Jakub Zych
deee2cc8d7 docs(08-01): complete metadata RED infrastructure plan 2026-09-23 19:20:35 +02:00
Jakub Zych
c578bb58d7 feat(08-01): implement exact RFC 8414 metadata writer in wristband
- Server.Metadata now writes the unwrapped 11-field PHP-parity document
  through a local no-envelope, no-trailing-newline JSON writer with the
  PHP Cache-Control: no-cache, private header (D-06); response types,
  grant types and PKCE method stay fixed protocol constants
- TestPhase8RedMetadata now passes; TestMetadataExactBytes and
  TestMetadataUsesConfiguredOptions cover byte-exact output and the four
  configurable Options fields
2026-09-23 19:10:26 +02:00
Jakub Zych
24d35d85e8 test(08-01): add failing RFC 8414 metadata RED test and fail-closed verifier
- wristband.Server.Metadata is a compiling 501 stub; TestPhase8RedMetadata
  asserts the exact unwrapped PHP metadata document, headers and status and
  fails with the PHASE8_RED:metadata sentinel (D-06)
- scripts/check-phase8-red.sh implements the shared go/shell RED contract
  for the rest of Phase 8: exact selected test/package failure plus sentinel,
  rejecting unrelated fail actions, compile/setup failures, panics,
  malformed JSON, missing/duplicate sentinels and zero selection (D-04/D-18)
2026-09-23 19:09:14 +02:00
Jakub Zych
a59e69211d docs(08): finalize oauth plans after final checker pass 2026-09-23 18:42:49 +02:00
Jakub Zych
2d7ac66605 docs(phase-07): add security threat verification 2026-09-23 18:19:43 +02:00
Jakub Zych
e23cbac240 fix(08): revise oauth plans after checker feedback 2026-09-23 17:46:38 +02:00
Jakub Zych
3c6a505c5f fix(08): revise plans based on checker feedback 2026-09-23 17:13:47 +02:00
Jakub Zych
241af16ba7 docs(08): create OAuth authorization server plans 2026-09-23 13:38:58 +02:00
Jakub Zych
716d0ea40d docs(08): approve UI design contract 2026-09-23 12:53:09 +02:00
Jakub Zych
dd96f59e57 docs(8): revise UI design contract 2026-09-23 12:50:25 +02:00
Jakub Zych
2aafa6f2a2 docs(08): add UI design contract 2026-09-23 12:44:34 +02:00
Jakub Zych
37fbcdc6de docs(phase-08): add validation strategy and resolve research decisions 2026-09-23 12:32:31 +02:00
Jakub Zych
a3a4636c29 docs(08): research OAuth authorization server 2026-09-23 12:14:03 +02:00
Jakub Zych
47b856b1c6 docs(state): record phase 8 context session 2026-09-23 11:37:14 +02:00
Jakub Zych
251ac038e2 docs(08): capture phase context 2026-09-23 11:37:13 +02:00
Jakub Zych
b435304570 docs(phase-7): complete phase execution
Avatar bucket publish closed the last UAT blocker. Phase 7 is 8/8
verified. Next is discuss Phase 8; do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:53:42 +02:00
Jakub Zych
e537b67a37 docs(07): verify phase after the avatar bucket gap close
Assembled avatar POST is 200. UAT is 12/12. AUTH-02 through AUTH-04
and I18N-02 are marked complete. Do not auto-advance.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:52:45 +02:00
Jakub Zych
3a15105a1b docs(state): record 07-08 completion and tracking
All eight Phase 7 plans have summaries. Avatar bucket publish is the
UAT gap close; phase verification still has to run.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:51:26 +02:00
Jakub Zych
b74484eabc docs(07-08): complete the avatar bucket publish plan
Serve and Handler now publish the uploads bucket; assembled avatar
POST is 200. Record the gap-closure outcome.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:50:01 +02:00
Jakub Zych
44900f0d16 feat(07-08): publish the uploads bucket on serve
Avatar upload 500s when serve never opens storage.uploads.bucket_url.
Wire OpenBucket + Publish on the CLI boot path so the user plugin can store files.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 10:43:47 +02:00