@.planning/PROJECT.md
@.planning/ROADMAP.md
@.planning/STATE.md
@.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md
@.planning/phases/08-oauth2-1-authorization-server/08-06-SUMMARY.md
Task 1: Specify repeatable flags and command output in executable RED
bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go
- Repeated redirect/scope flags preserve order without breaking scalar/bare flags.
- Create prints id, secret, warning once; update/list never reveal secret/hash.
- Tests compile and fail only through separate `PHASE8_RED:bonfire-flags` and `PHASE8_RED:oauth-command` markers.
D-18: and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first; mark only missing bonfire behavior with `PHASE8_RED:bonfire-flags` and missing app-command behavior with `PHASE8_RED:oauth-command`. Use the shared verifier to reject syntax/setup/missing tests.
scripts/check-phase8-red.sh bonfire-flags go test ./bonfire -run 'Test.*Flag' -count=1 && scripts/check-phase8-red.sh oauth-command bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1"
RED command tests execute and fail only for absent repeatable-flag/command behavior.
Task 2: Add repeatable flags and exact OAuth client command
bonfire/command.go, bonfire/root.go, bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go
- Flag/Input distinguish scalar and repeated values; existing callers remain compatible.
- Create/update/list share wristband validation/issuance and artisan clients have null registration_ip.
D-19: extend bonfire with explicit string-slice flags and `Input.Flags(name)`, using Cobra StringSlice only for that kind. Implement the exact name/redirect-uri/scope/auth-method/client-id/list signature thinly over wristband and ClientStore; never parse os.Args. Print the exact creation lines/warning and never recover or print secrets on list/update. Register through plugin command capability.
go test ./bonfire -run 'Test.*Flag' -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1
Operators can safely provision and inspect OAuth clients with exact repeatable flags and no secret recovery.