117 lines
5.9 KiB
Markdown
117 lines
5.9 KiB
Markdown
---
|
|
phase: 08-oauth2-1-authorization-server
|
|
plan: 03
|
|
type: execute
|
|
wave: 3
|
|
depends_on: [08-02]
|
|
files_modified:
|
|
- ../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml
|
|
- ../fonoteka.go/config/app.yaml
|
|
- ../fonoteka.go/plugins/golem15/fonoteka/plugin.go
|
|
- ../fonoteka.go/plugins/golem15/fonoteka/routes.go
|
|
- ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go
|
|
autonomous: true
|
|
requirements: [AUTH-05, AUTH-06, AUTH-07]
|
|
must_haves:
|
|
truths:
|
|
- "D-03: The assembled app exposes configured PHP-default TTLs, caps, issuer, resource, consent URL, and registration bound."
|
|
- "D-09: Metadata and registration are raw routes and registration alone carries its named throttle."
|
|
- "D-10: No oauth guard is registered; OAuth access remains on inv_token."
|
|
- "D-12: Backend challenge ownership stays unchanged and RFC 9728 behavior remains in fonoteka-mcp."
|
|
artifacts:
|
|
- path: "../fonoteka.go/plugins/golem15/fonoteka/plugin.go"
|
|
provides: "Configured store-backed wristband server construction"
|
|
- path: "../fonoteka.go/plugins/golem15/fonoteka/routes.go"
|
|
provides: "Raw metadata and register route mounting"
|
|
key_links:
|
|
- from: "plugin.go"
|
|
to: "wristband.New"
|
|
via: "configured Options and GORM backend"
|
|
pattern: "wristband\\.New"
|
|
---
|
|
|
|
<objective>
|
|
Mount the proven discovery/DCR engine on the real application with persistent state and exact raw-route isolation.
|
|
|
|
Purpose: Deliver the first connector-visible vertical outcome without mixing schema work into protocol implementation.
|
|
Output: OAuth config, boot wiring, raw routes, and assembled Postgres-backed tests.
|
|
</objective>
|
|
|
|
<execution_context>
|
|
@/home/jin/.codex/get-shit-done/workflows/execute-plan.md
|
|
@/home/jin/.codex/get-shit-done/templates/summary.md
|
|
</execution_context>
|
|
|
|
<context>
|
|
@.planning/PROJECT.md
|
|
@.planning/ROADMAP.md
|
|
@.planning/STATE.md
|
|
@.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md
|
|
@.planning/phases/08-oauth2-1-authorization-server/08-UI-SPEC.md
|
|
@.planning/phases/08-oauth2-1-authorization-server/08-02-SUMMARY.md
|
|
</context>
|
|
|
|
<tasks>
|
|
|
|
<task type="auto" tdd="true">
|
|
<name>Task 1: Specify assembled discovery and registration in RED</name>
|
|
<files>../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go</files>
|
|
<behavior>
|
|
- Assembled routes return exact metadata and persistent public/confidential DCR responses.
|
|
- Route table rejects JWT, inv_token, inv.scope, body-limit, and house middleware; register has only its named throttle.
|
|
- Failures use `PHASE8_RED:registration-app`, not compile/setup/missing-test failure.
|
|
</behavior>
|
|
<action>D-18: add an assembled-router real-Postgres test against existing boot seams. Assert bytes and headers before decoding, exact configured defaults, route isolation, and no oauth guard. Keep the test compiling against 08-01/08-02 contracts and mark only absent app wiring with `PHASE8_RED:registration-app`.</action>
|
|
<verify>
|
|
<automated>scripts/check-phase8-red.sh registration-app bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestOAuth(Metadata|Register|RawRoute|Config)' -count=1"</automated>
|
|
</verify>
|
|
<done>Assembled tests execute and fail solely because config/boot/routes are not wired.</done>
|
|
</task>
|
|
|
|
<task type="auto" tdd="true">
|
|
<name>Task 2: Configure, boot, and route persistent discovery and DCR</name>
|
|
<files>../fonoteka.go/plugins/golem15/fonoteka/config/config.yaml, ../fonoteka.go/config/app.yaml, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go, ../fonoteka.go/plugins/golem15/fonoteka/routes.go, ../fonoteka.go/plugins/golem15/fonoteka/oauth_registration_test.go</files>
|
|
<behavior>
|
|
- Defaults are pending/code 600s, access 3600s, refresh 30 days, DCR cap 200, stale age 24h, resource URL, and 65,536-byte register maximum.
|
|
- Issuer trims the app URL once; metadata and registration use the actual GORM backend.
|
|
</behavior>
|
|
<action>D-03: add `plugins.golem15.fonoteka.oauth.*` defaults and use `app.url` as issuer. Construct the backend and wristband server in Plugin.Boot and retain it for later route/command factories. D-09: mount metadata and register inside the existing raw group; pass `throttle:fonoteka-oauth-register` only to register. D-10: register no oauth guard. D-12: preserve the exact backend personal-token 401 and do not add protected-resource metadata or rich Bearer challenges.</action>
|
|
<verify>
|
|
<automated>cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestOAuth(Metadata|Register|RawRoute|Config)' -count=1</automated>
|
|
</verify>
|
|
<done>An unchanged connector can discover and dynamically register against the assembled app with persistent Postgres state and exact route boundaries.</done>
|
|
</task>
|
|
|
|
</tasks>
|
|
|
|
<threat_model>
|
|
## Trust Boundaries
|
|
|
|
| Boundary | Description |
|
|
|----------|-------------|
|
|
| Internet → raw routes | Unauthenticated protocol traffic enters the assembled app. |
|
|
| Config → public metadata | Deployment values become client trust anchors. |
|
|
|
|
## STRIDE Threat Register
|
|
|
|
| Threat ID | Category | Component | Disposition | Mitigation Plan |
|
|
|-----------|----------|-----------|-------------|-----------------|
|
|
| T-08-DCR-FLOOD | Denial of Service | register route | mitigate | Named per-IP limiter plus framework body/cap controls. |
|
|
| T-08-SURFACE | Elevation | route groups | mitigate | Assembled route-table test for exact middleware. |
|
|
| T-08-SC | Tampering | dependencies | mitigate | No new package. |
|
|
</threat_model>
|
|
|
|
<verification>
|
|
- Focused assembled discovery/DCR tests pass.
|
|
- `go vet ./... && go test ./...` passes in both repositories at the wave boundary.
|
|
</verification>
|
|
|
|
<success_criteria>
|
|
- Metadata and DCR are reachable through the real app with exact PHP-compatible responses.
|
|
- Public/confidential clients persist and raw routes remain isolated.
|
|
</success_criteria>
|
|
|
|
<output>
|
|
Create `.planning/phases/08-oauth2-1-authorization-server/08-03-SUMMARY.md` when done.
|
|
</output>
|