Files
summercms/.planning/phases/08-oauth2-1-authorization-server/08-07-PLAN.md
2026-09-23 17:13:47 +02:00

5.5 KiB

phase, plan, type, wave, depends_on, files_modified, autonomous, requirements, must_haves
phase plan type wave depends_on files_modified autonomous requirements must_haves
08-oauth2-1-authorization-server 07 execute 7
08-06
bonfire/command.go
bonfire/root.go
bonfire/output_test.go
../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go
../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go
../fonoteka.go/plugins/golem15/fonoteka/plugin.go
true
AUTH-05
AUTH-07
truths artifacts key_links
D-19: Operators can create, update, and list OAuth clients with repeatable flags and one-time secret output.
D-04: Command issuance stores only a hash and never leaks secret material through list/update output.
path provides
../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go Exact fonoteka:oauth-client command
path provides
bonfire/command.go Typed repeatable string-slice flag contract
from to via pattern
oauth_client.go wristband client issuance shared validation/hash/one-time-secret path wristband
Provision confidential and ceiling-bounded OAuth clients through the exact app command.

Purpose: Deliver operator management separately from the personal-token MCP bootstrap surface. Output: Repeatable bonfire flags, client command, plugin registration, and command tests.

<execution_context> @/home/jin/.codex/get-shit-done/workflows/execute-plan.md @/home/jin/.codex/get-shit-done/templates/summary.md </execution_context>

@.planning/PROJECT.md @.planning/ROADMAP.md @.planning/STATE.md @.planning/phases/08-oauth2-1-authorization-server/08-CONTEXT.md @.planning/phases/08-oauth2-1-authorization-server/08-06-SUMMARY.md Task 1: Specify repeatable flags and command output in executable RED bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go - Repeated redirect/scope flags preserve order without breaking scalar/bare flags. - Create prints id, secret, warning once; update/list never reveal secret/hash. - Tests compile and fail only through separate `PHASE8_RED:bonfire-flags` and `PHASE8_RED:oauth-command` markers. D-18: and D-19: add real command-root tests for create/update/list, exact lines, one-time secret, scope ceiling, and non-recovery. Define compiling flag/command seams first; mark only missing bonfire behavior with `PHASE8_RED:bonfire-flags` and missing app-command behavior with `PHASE8_RED:oauth-command`. Use the shared verifier to reject syntax/setup/missing tests. scripts/check-phase8-red.sh bonfire-flags go test ./bonfire -run 'Test.*Flag' -count=1 && scripts/check-phase8-red.sh oauth-command bash -lc "cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1" RED command tests execute and fail only for absent repeatable-flag/command behavior. Task 2: Add repeatable flags and exact OAuth client command bonfire/command.go, bonfire/root.go, bonfire/output_test.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client.go, ../fonoteka.go/plugins/golem15/fonoteka/console/oauth_client_test.go, ../fonoteka.go/plugins/golem15/fonoteka/plugin.go - Flag/Input distinguish scalar and repeated values; existing callers remain compatible. - Create/update/list share wristband validation/issuance and artisan clients have null registration_ip. D-19: extend bonfire with explicit string-slice flags and `Input.Flags(name)`, using Cobra StringSlice only for that kind. Implement the exact name/redirect-uri/scope/auth-method/client-id/list signature thinly over wristband and ClientStore; never parse os.Args. Print the exact creation lines/warning and never recover or print secrets on list/update. Register through plugin command capability. go test ./bonfire -run 'Test.*Flag' -count=1 && cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run TestOAuthClientCommand -count=1 Operators can safely provision and inspect OAuth clients with exact repeatable flags and no secret recovery.

<threat_model>

Trust Boundaries

Boundary Description
Operator CLI → client store Trusted input creates recoverable-once credentials.

STRIDE Threat Register

Threat ID Category Component Disposition Mitigation Plan
T-08-SECRET-TIMING Information Disclosure issued client mitigate Shared hash/validation path and one-time secret.
T-08-SCOPE-CEILING Elevation command mitigate Validated stored ceiling used by authorize.
T-08-REQUEST-LEAK Information Disclosure output mitigate Exact positive output and secret/hash rejection tests.
T-08-SC Tampering Cobra mitigate Existing pinned dependency only.
</threat_model>
- Bonfire and command tests pass. - List/update output contains no client secret or hash.

<success_criteria>

  • Exact create/update/list command behavior is runnable and secret-safe. </success_criteria>
Create `.planning/phases/08-oauth2-1-authorization-server/08-07-SUMMARY.md` when done.