2.2 KiB
Decision: Direct OAuth2.1-style wristband Port
Date: 2026-09-23
Status: Accepted for Phase 8
Supersedes: Phase 8 assumptions that named zitadel/oidc as the server engine
Decision
Phase 8 implements the Płytarium authorization server as an app-agnostic framework package named wristband using Go's standard library (crypto/rand, crypto/sha256, crypto/subtle, encoding/base64, encoding/json, net/http, and net/url). It does not add zitadel/oidc.
wristband owns the byte-specific RFC metadata, authorization, token, dynamic-registration, PKCE, scope, redirect, refresh-rotation, replay-revocation, and expiry-sweep behavior. fonoteka.go owns GORM persistence, users/collections, ordinary inv_ access-token issuance, consent and connected-app controllers, configuration, routes, and the operator command.
Rationale
Płytarium's unchanged clients depend on the existing PHP response bytes, metadata shape, error bodies, inv_ access-token model, ordered redirects, and app-specific consent state. zitadel/oidc is an OIDC provider with different defaults and cannot directly reproduce that token model without replacing the behavior that justified selecting it. The direct port remains small and uses standard cryptographic/HTTP primitives while preserving framework/app separation.
Header Ownership
- The Go authorization server emits exactly
WWW-Authenticate: Basic realm="OAuth"for token-endpointinvalid_client. - The existing backend personal-token 401 remains
{"error":"Invalid token"}with no added challenge. - fonoteka-mcp, as the resource server, continues to emit RFC 9728 protected-resource metadata and its rich Bearer
resource_metadatachallenge.
Consequences
- No external Go package is installed in Phase 8.
- Client-secret and PKCE comparisons use
crypto/subtle.ConstantTimeCompareon fixed transforms. - OAuth access tokens remain ordinary configured-prefix
inv_personal tokens verified by the existinginv_tokenguard. - Historical STACK/ARCHITECTURE notes that describe the earlier ecosystem assumption remain historical; the Phase 8 context, roadmap, requirements, plans, and this note are authoritative for implementation.