Files
summercms/.planning/phases/08-oauth2-1-authorization-server/08-03-PLAN.md
2026-09-23 17:13:47 +02:00

5.9 KiB

phase, plan, type, wave, depends_on, files_modified, autonomous, requirements, must_haves
phase plan type wave depends_on files_modified autonomous requirements must_haves
08-oauth2-1-authorization-server 03 execute 3
08-02
../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml
../fonoteka.go/config/app.yaml
../fonoteka.go/plugins/golem15/fonoteka/plugin.go
../fonoteka.go/plugins/golem15/fonoteka/routes.go
../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go
true
AUTH-05
AUTH-06
AUTH-07
truths artifacts key_links
D-03: The assembled app exposes configured PHP-default TTLs, caps, issuer, resource, consent URL, and registration bound.
D-09: Metadata and registration are raw routes and registration alone carries its named throttle.
D-10: No oauth guard is registered; OAuth access remains on inv_token.
D-12: Backend challenge ownership stays unchanged and RFC 9728 behavior remains in fonoteka-mcp.
path provides
../fonoteka.go/plugins/golem15/fonoteka/plugin.go Configured store-backed wristband server construction
path provides
../fonoteka.go/plugins/golem15/fonoteka/routes.go Raw metadata and register route mounting
from to via pattern
plugin.go wristband.New configured Options and GORM backend wristband.New
Mount the proven discovery/DCR engine on the real application with persistent state and exact raw-route isolation.

Purpose: Deliver the first connector-visible vertical outcome without mixing schema work into protocol implementation. Output: OAuth config, boot wiring, raw routes, and assembled Postgres-backed tests.

<execution_context> @/home/jin/.codex/get-shit-done/workflows/execute-plan.md @/home/jin/.codex/get-shit-done/templates/summary.md </execution_context>

@.planning/PROJECT.md @.planning/ROADMAP.md @.planning/STATE.md @.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md @.planning/phases/08-oauth2-1-authorization-server/08-UI-SPEC.md @.planning/phases/08-oauth2-1-authorization-server/08-02-SUMMARY.md Task 1: Specify assembled discovery and registration in RED ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go - Assembled routes return exact metadata and persistent public/confidential DCR responses. - Route table rejects JWT, inv_token, inv.scope, body-limit, and house middleware; register has only its named throttle. - Failures use `PHASE8_RED:registration-app`, not compile/setup/missing-test failure. D-18: add an assembled-router real-Postgres test against existing boot seams. Assert bytes and headers before decoding, exact configured defaults, route isolation, and no oauth guard. Keep the test compiling against 08-01/08-02 contracts and mark only absent app wiring with `PHASE8_RED:registration-app`. scripts/check-phase8-red.sh registration-app bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestOAuth(Metadata|Register|RawRoute|Config)' -count=1" Assembled tests execute and fail solely because config/boot/routes are not wired. Task 2: Configure, boot, and route persistent discovery and DCR ../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml, ../fonoteka.go/config/app.yaml, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go, ../fonoteka.go/plugins/golem15/fonoteka/routes.go, ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go - Defaults are pending/code 600s, access 3600s, refresh 30 days, DCR cap 200, stale age 24h, resource URL, and 65,536-byte register maximum. - Issuer trims the app URL once; metadata and registration use the actual GORM backend. D-03: add `plugins.golem15.fonoteka.oauth.*` defaults and use `app.url` as issuer. Construct the backend and wristband server in Plugin.Boot and retain it for later route/command factories. D-09: mount metadata and register inside the existing raw group; pass `throttle:fonoteka-oauth-register` only to register. D-10: register no oauth guard. D-12: preserve the exact backend personal-token 401 and do not add protected-resource metadata or rich Bearer challenges. cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestOAuth(Metadata|Register|RawRoute|Config)' -count=1 An unchanged connector can discover and dynamically register against the assembled app with persistent Postgres state and exact route boundaries.

<threat_model>

Trust Boundaries

Boundary Description
Internet → raw routes Unauthenticated protocol traffic enters the assembled app.
Config → public metadata Deployment values become client trust anchors.

STRIDE Threat Register

Threat ID Category Component Disposition Mitigation Plan
T-08-DCR-FLOOD Denial of Service register route mitigate Named per-IP limiter plus framework body/cap controls.
T-08-SURFACE Elevation route groups mitigate Assembled route-table test for exact middleware.
T-08-SC Tampering dependencies mitigate No new package.
</threat_model>
- Focused assembled discovery/DCR tests pass. - `go vet ./... && go test ./...` passes in both repositories at the wave boundary.

<success_criteria>

  • Metadata and DCR are reachable through the real app with exact PHP-compatible responses.
  • Public/confidential clients persist and raw routes remain isolated. </success_criteria>
Create `.planning/phases/08-oauth2-1-authorization-server/08-03-SUMMARY.md` when done.