--- phase: 08-oauth2-1-authorization-server plan: 07 type: execute wave: 7 depends_on: [08-06] files_modified: - bonfire/command.go - bonfire/root.go - bonfire/output_test.go - ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go - ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go - ../fonoteka.go/plugins/golem15/fonoteka/plugin.go autonomous: true requirements: [AUTH-05, AUTH-07] must_haves: truths: - "D-19: Operators can create, update, and list OAuth clients with repeatable flags and one-time secret output." - "D-04: Command issuance stores only a hash and never leaks secret material through list/update output." artifacts: - path: "../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go" provides: "Exact fonoteka:oauth-client command" - path: "bonfire/command.go" provides: "Typed repeatable string-slice flag contract" key_links: - from: "oauth_client.go" to: "wristband client issuance" via: "shared validation/hash/one-time-secret path" pattern: "wristband" --- Provision confidential and ceiling-bounded OAuth clients through the exact app command. Purpose: Deliver operator management separately from the personal-token MCP bootstrap surface. Output: Repeatable bonfire flags, client command, plugin registration, and command tests. @/home/jin/.codex/get-shit-done/workflows/execute-plan.md @/home/jin/.codex/get-shit-done/templates/summary.md @.planning/PROJECT.md @.planning/ROADMAP.md @.planning/STATE.md @.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md @.planning/phases/08-oauth2-1-authorization-server/08-06-SUMMARY.md Task 1: Specify repeatable flags and command output in executable RED bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go .planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md .planning/phases/08-oauth2-1-authorization-server/08-PATTERNS.md bonfire/command.go bonfire/root.go bonfire/output_test.go ../fonoteka.go/plugins/golem15/fonoteka/console/console_test.go /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/console/IssueOAuthClient.php /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/tests/functional/OAuthClientCommandTest.php - Repeated redirect/scope flags preserve order without breaking scalar/bare flags. - Create prints id, secret, warning once; update/list never reveal secret/hash. - Tests compile and fail only through separate `PHASE8_RED:bonfire-flags` and `PHASE8_RED:oauth-command` markers. D-18 and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first. Use exact `TestPhase8RedBonfireFlags`/`PHASE8_RED:bonfire-flags` and `TestPhase8RedOAuthClientCommand`/`PHASE8_RED:oauth-command` package/test/sentinel triples with `go test -json`; reject any unexpected failing action/package/test, compile/setup/panic/no-test result, or missing/duplicate sentinel. scripts/check-phase8-red.sh go PHASE8_RED:bonfire-flags git.golem15.com/golem15/summercms/bonfire TestPhase8RedBonfireFlags -- go test -json ./bonfire -run '^TestPhase8RedBonfireFlags$' -count=1 && scripts/check-phase8-red.sh go PHASE8_RED:oauth-command git.golem15.com/golem15/fonoteka/plugins/golem15/fonoteka/console TestPhase8RedOAuthClientCommand -- bash -lc "cd ../fonoteka.go && go test -json ./plugins/golem15/fonoteka/console -run '^TestPhase8RedOAuthClientCommand$' -count=1" - Each RED stream contains exactly its named test fail plus named package fail and exact sentinel once; unrelated/compile/setup/panic/no-test failures are rejected. - Repeatable redirect/scope flags preserve input order, repeated/scalar/bare values remain distinguishable, and existing scalar callers retain behavior. - Command tests assert exact `client_id=`, `client_secret=`, warning lines once on create and forbid raw/hash secret output on update/list and error paths. RED command tests execute and fail only for absent repeatable-flag/command behavior. Task 2: Add repeatable flags and exact OAuth client command bonfire/command.go, bonfire/root.go, bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go bonfire/output_test.go bonfire/command.go bonfire/root.go ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go ../fonoteka.go/plugins/golem15/fonoteka/plugin.go wristband/register.go /media/nvme/dev/golem15/fonoteka/plugins/golem15/fonoteka/console/IssueOAuthClient.php - Flag/Input distinguish scalar and repeated values; existing callers remain compatible. - Create/update/list share wristband validation/issuance and artisan clients have null registration_ip. D-19: extend bonfire with explicit string-slice flags and `Input.Flags(name)`, using Cobra StringSlice only for that kind. Implement the exact name/redirect-uri/scope/auth-method/client-id/list signature thinly over wristband and ClientStore; never parse os.Args. Print the exact creation lines/warning and never recover or print secrets on list/update. Register through plugin command capability. go test ./bonfire -run '^Test.*Flag' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/console -run '^TestOAuthClientCommand' -count=1) - Create supports ordered repeated `--redirect-uri` and `--scope`, validates auth method/ceiling through wristband, persists hash only with null registration IP, and prints the raw secret exactly once. - Update by client id changes only supplied values and never rotates/recovers a secret; list shows id/name/revocation/redirects/ceiling but no raw/hash credential. - Existing bonfire scalar and bare-flag tests remain unchanged and green; plugin command registration exposes exactly `fonoteka:oauth-client` without parsing `os.Args`. Operators can safely provision and inspect OAuth clients with exact repeatable flags and no secret recovery. ## Trust Boundaries | Boundary | Description | |----------|-------------| | Operator CLI → client store | Trusted input creates recoverable-once credentials. | ## STRIDE Threat Register | Threat ID | Category | Component | Disposition | Mitigation Plan | |-----------|----------|-----------|-------------|-----------------| | T-08-SECRET-TIMING | Information Disclosure | issued client | mitigate | Shared hash/validation path and one-time secret. | | T-08-SCOPE-CEILING | Elevation | command | mitigate | Validated stored ceiling used by authorize. | | T-08-REQUEST-LEAK | Information Disclosure | output | mitigate | Exact positive output and secret/hash rejection tests. | | T-08-SC | Tampering | Cobra | mitigate | Existing pinned dependency only. | - Bonfire and command tests pass. - List/update output contains no client secret or hash. - Exact create/update/list command behavior is runnable and secret-safe. Create `.planning/phases/08-oauth2-1-authorization-server/08-07-SUMMARY.md` when done.