Files
summercms/.planning/phases/08-oauth2-1-authorization-server/08-SOURCE-AUDIT.md
2026-09-23 13:38:58 +02:00

6.9 KiB

Phase 08 Source Coverage Audit

All required GOAL, REQ, RESEARCH, CONTEXT, VALIDATION, and UI-SPEC items are planned. Deferred ideas remain excluded.

Source ID Feature / requirement Plan Status Notes
GOAL — PHP-compatible authorization server serves unchanged MCP/connector with exact header ownership 01-06 COVERED Direct standard-library wristband per locked D-01; real-client proof in 05.
REQ AUTH-05 Metadata, DCR, S256 authorize/consent, code/refresh grants, resource handling, exact discovery/challenges 01-05 COVERED Backend Basic challenge and MCP RFC 9728 ownership are tested separately.
REQ AUTH-06 Form/query/JSON source rules, CSRF-free raw routes, rate limits, unwrapped responses, cache headers 01-03, 05-06 COVERED Route-table, byte, header, parity, and final audit coverage.
REQ AUTH-07 Persistent OAuth models, connected-app list/revoke, unchanged MCP install/auth/tool flow 01, 03-06 COVERED Includes schema correction, /me, lifecycle, and real MCP.
RESEARCH R-01 Additive nullability/index migration and pointer models 01 COVERED Safe rollback refusal is explicit.
RESEARCH R-02 App-agnostic transaction-scoped store bundle with GORM row locks in app tier 01-03 COVERED Framework never imports GORM/fonoteka.
RESEARCH R-03 Commit refresh replay lineage kill before returning invalid_grant 03, 06 COVERED Persisted post-error evidence and concurrency tests.
RESEARCH R-04 Ordered RFC3986 redirects and endpoint-specific parsers 02, 05-06 COVERED Exact bytes/parity.
RESEARCH R-05 No new package; standard-library crypto/HTTP and package-legitimacy audit not applicable 01-06 COVERED T-08-SC included in every threat model.
RESEARCH R-06 103 PHP-method audit and complete validation architecture 06 COVERED Exact distribution and executable missing-name gate.
RESEARCH R-07 Real MCP /me prerequisite and 64 KiB DCR bound 01, 04-06 COVERED Both resolved questions are locked as D-20/D-21.
CONTEXT D-01 Direct stdlib port; no zitadel/oidc; correct roadmap/requirement wording 01, planning update COVERED No dependency install.
CONTEXT D-02 Query/form/JSON parameter sources 01-02, 05-06 COVERED JSON token rejection, ParseForm precedence, JSON-only register.
CONTEXT D-03 TTLs, caps, issuer/resource/consent configuration 01-03 COVERED Exact PHP defaults in plan 01.
CONTEXT D-04 Full T-08 security treatment and constant-time comparisons 01-06 COVERED Independent security agent and blocking approval in 06.
CONTEXT D-05 wristband owns RFC surface/state machine 01-03 COVERED Framework structure and import boundary explicit.
CONTEXT D-06 PHP-minimal response shapes are defaults; no hooks 01-03, 05 COVERED Exact response/header tests and parity.
CONTEXT D-07 App stores, issuer, transaction boundary, row locks 01-03 COVERED Real Postgres concurrency tests.
CONTEXT D-08 App owns consent and connected apps 02-03 COVERED Exact UI payloads and ownership.
CONTEXT D-09 Raw routes and per-route token/register throttles 01-02, 06 COVERED Route-table inspection.
CONTEXT D-10 Retire reserved oauth guard; access stays inv_token 01-04, 06 COVERED Negative guard/source tests.
CONTEXT D-11 Preserve configured inv_ prefix 02, 04-05 COVERED Actual MCP install/HTTP consumption.
CONTEXT D-12 Backend Basic challenge; MCP owns rich Bearer/resource metadata 01-06 COVERED Unit, route, and real-process evidence.
CONTEXT D-13 Replay projected MCP flows in Go tests 05 COVERED Stable named-step projections fail on disappearance.
CONTEXT D-14 Full real Node MCP lifecycle gate 05-06 COVERED Includes discovery, DCR, PKCE, login/consent, /me, tool, refresh.
CONTEXT D-15 No live vendor connection in Phase 8 — EXCLUDED Deferred to cutover by explicit decision.
CONTEXT D-16 Record clean mcp-lifecycle; nine routes ported honestly 05 COVERED Secret-scrubbed fixture and corpus audit.
CONTEXT D-17 On-request expiry sweep, expired rows only 01, 03 COVERED No timer/goroutine; replay evidence retained.
CONTEXT D-18 Port every named PHP OAuth test 01-06 COVERED Final one-to-one 103-method map.
CONTEXT D-19 Exact app-side fonoteka:oauth-client 04 COVERED Repeatable bonfire flags and one-time secret.
CONTEXT D-20 Exact personal-token /me MCP prerequisite 04-05 COVERED Existing guard/middleware and positive allow-list.
CONTEXT D-21 Register body bounded at 64 KiB with native error 01, 06 COVERED Bound precedes JSON decode.
VALIDATION W0-01 Framework metadata/authorize/token/register/PKCE/refresh tests 01-03, 06 COVERED Fast in-memory tests plus audit.
VALIDATION W0-02 Real-Postgres migration/store locking/replay/sweep tests 01-03, 06 COVERED Existing auth TestMain harness.
VALIDATION W0-03 Raw routing/parser/rate/body/header isolation 01-02, 06 COVERED Assembled route tests.
VALIDATION W0-04 Consent/collection/connected-app ownership 02-03, 06 COVERED Real-Postgres controllers.
VALIDATION W0-05 Nine routes, lifecycle replay, 103-method map 05-06 COVERED Corpus/fixture/map gates.
VALIDATION W0-06 Personal-token /me 04-06 COVERED MCP startup prerequisite.
VALIDATION W0-07 Full unchanged MCP and security gate 05-06 COVERED Final script plus review checkpoint.
UI-SPEC UI-01 Nuxt remains unchanged 02-06 COVERED Git status checks and backend-only files.
UI-SPEC UI-02 Consent read/allow/deny states and exact payload/status/redirect semantics 02, 05-06 COVERED Includes stale/foreign/used 404 and empty-scope 422.
UI-SPEC UI-03 Connected-app empty/populated/error/list/revoke contracts 03, 05-06 COVERED Positive allow-list, manual count, identical 404.
UI-SPEC UI-04 Untrusted names/hosts, scope order, server-derived collection, no secrets 02-03, 06 COVERED Sanitization, host-only, intersection, output audits.
UI-SPEC UI-05 Existing accessibility/responsive/i18n behavior is preserved 02-03, 05 COVERED No frontend changes; exact data/state selectors exercised.

Deferred and Out-of-Scope Audit

  • Summer-themed token prefix: excluded; inv_ remains locked.
  • River expiry job: excluded; request-time sweep ships here and River remains Phase 11.
  • Generic framework client command: excluded; app command ships in Plan 04.
  • Live Claude/ChatGPT/Grok connection: excluded; scripted SDK plus unchanged MCP is the Phase 8 acceptance gate.
  • Social login and oauth-identities: excluded; no plan creates those routes.
  • Frontend redesign/new UI: excluded; Nuxt must remain unchanged.

No required source item is missing.