Recording the full mcp-lifecycle fixture against real isolated PHP
(08-09-PLAN.md Task 2) uncovered three byte-level gaps between wristband's
assumed contract and actual production PHP behavior:
- Every explicit "Cache-Control: no-store" PHP sets is actually delivered
as "no-store, private" (Laravel's session-cookie default merges "private"
onto any explicit value); wristband's own default for unheadered JSON
error responses is "no-cache, private" (matching the house convention
already used elsewhere), not empty.
- PHP's redirect responses (authorize success and every error redirect)
render Symfony's default HTML redirect body with Content-Type
"text/html; charset=utf-8"; Go's bare 302 with no body never matched.
wristband/redirect_html.go ports that exact byte template, including
PHP's htmlspecialchars(ENT_QUOTES) escaping (Go's html.EscapeString uses
different quote entities).
tide/normalize.go: isIDKey now also masks "_ids" plural array fields
(e.g. collection_ids), a latent parity-corpus gap no prior fixture had
exercised with a literal, non-empty, non-placeholder array value.
- Server.Authorize ports OAuthAuthorizeController::authorize's exact
validation order: usable client, exact redirect, response_type=code,
code_challenge_method=S256, challenge length, scope parsing/ceiling
truncation, resource check, then opaque pending-request creation
- Unknown client/unregistered redirect are local text/plain 400s with no
Location; every later failure is an ordered RFC3986 redirect with
error/error_description/iss[/state], built via a dedicated encoder
(never url.Values.Encode, which sorts keys and space-encodes as '+')
- Options gains Resource and PendingRequestTTL (both PHP-parity defaults)
so authorize's resource check and 600s pending expiry are configurable
- Server.Authorize stub returns 501
- TestPhase8RedAuthorize drives a full valid S256 request and asserts the
exact 302 /connect success contract; fails with PHASE8_RED:authorize
against the stub, verified fail-closed via check-phase8-red.sh