- Server.Token: JSON rejection before ParseForm, body-over-query precedence, Basic-over-form client auth, exact invalid_request/unsupported_grant_type/ invalid_client/invalid_grant bodies, Cache-Control/Pragma on success only - authenticateClient: public/confidential dispatch, constant-time secret compare (T-08-SECRET-TIMING) - exchangeAuthorizationCode: single WithinTx lock/consume/mint/refresh-create covering code/client/redirect/resource/PKCE binding and single-use replay (T-08-CODE-REPLAY), sequential and concurrent proofs - rotateRefreshToken: grant_type=refresh_token dispatches per PHP validity but is a deliberate invalid_grant placeholder; full rotation is 08-06 - full token_test.go behavior matrix appended alongside the RED anchor
9.8 KiB
9.8 KiB