// Package wristband implements the app-agnostic RFC 8414 / OAuth // authorization-server surface ported from Płytarium's hand-rolled PHP OAuth // server (08-CONTEXT.md D-05). It never imports an application package, a // GORM type, or any fonoteka model: every deployment-specific value (issuer, // scopes, endpoint paths, TTLs) arrives through Options, and every app-owned // concern (users, collections, persistence) stays out of this package. // // D-06: PHP's RFC-minimal response shapes are wristband's defaults. There // are no response hooks; callers cannot alter the wire bytes beyond the // values exposed on Options. package wristband import "net/http" // Options configures a Server's advertised endpoints and metadata values. // Every field has a PHP-parity default via DefaultOptions except Issuer, // which the caller must set from app.url with its trailing slash trimmed // exactly once (D-03). wristband never hardcodes an app's issuer. type Options struct { // Issuer is app.url with exactly one trailing slash trimmed by the // caller. Every metadata endpoint URL is built by appending a fixed // RFC path suffix to Issuer. Issuer string // ServiceDocumentationPath is appended to Issuer for the metadata // service_documentation field. PHP default: "/help". ServiceDocumentationPath string // ScopesSupported is the RFC 8414 scopes_supported list. PHP default: // ["read","write","ai","offline_access"]. ScopesSupported []string // TokenEndpointAuthMethodsSupported is the RFC 8414 // token_endpoint_auth_methods_supported list. PHP default: // ["none","client_secret_post","client_secret_basic"]. TokenEndpointAuthMethodsSupported []string // AuthorizationResponseIssParameterSupported is the RFC 9207 metadata // capability flag. PHP default: true. AuthorizationResponseIssParameterSupported bool } // DefaultOptions returns PHP-parity defaults for every metadata option // other than Issuer, which the caller must set from app.url. func DefaultOptions() Options { return Options{ ServiceDocumentationPath: "/help", ScopesSupported: []string{"read", "write", "ai", "offline_access"}, TokenEndpointAuthMethodsSupported: []string{"none", "client_secret_post", "client_secret_basic"}, AuthorizationResponseIssParameterSupported: true, } } // Server is the app-agnostic wristband authorization-server surface. It is // constructed with Options and never imports an application package. type Server struct { opts Options } // NewServer constructs a Server from Options. func NewServer(opts Options) *Server { return &Server{opts: opts} } // Metadata handles GET /.well-known/oauth-authorization-server, writing the // exact unwrapped RFC 8414 document (D-06). // // TODO(08-01 Task 2): wire the exact writer and PHP-parity document; this // stub intentionally does not yet satisfy TestPhase8RedMetadata. func (s *Server) Metadata(w http.ResponseWriter, r *http.Request) { w.WriteHeader(http.StatusNotImplemented) }