- Server.Token 501 stub and TestPhase8RedCodeExchange (PHASE8_RED:code-exchange) - Options gains AccessTokenTTL/RefreshTokenTTL with PHP-parity defaults
22 lines
1.0 KiB
Go
22 lines
1.0 KiB
Go
// RFC 6749 token endpoint for MCP OAuth, ported from PHP
|
|
// OAuthTokenController::token / OAuthCodeManager::exchangeCode byte-for-byte
|
|
// including their validation order (08-CONTEXT.md D-02/D-04/D-05/D-07;
|
|
// canonical PHP source: OAuthTokenController.php, OAuthCodeManager.php).
|
|
//
|
|
// 08-04-PLAN.md ships the authorization_code grant only. grant_type=
|
|
// refresh_token is dispatched with the exact PHP-parity validity check (an
|
|
// unknown grant type is unsupported_grant_type; a known-but-not-yet-built
|
|
// grant is invalid_grant) but its full rotation/lineage-kill semantics
|
|
// (T-08-REFRESH-REPLAY) are ROADMAP.md Wave 6 (08-06-PLAN.md), not this
|
|
// plan's threat register.
|
|
package wristband
|
|
|
|
import "net/http"
|
|
|
|
// Token handles POST /oauth/mcp/token (D-09: raw route, no middleware).
|
|
// This is the Phase 8 Wave 4 RED stub (08-04-PLAN.md Task 1): it always
|
|
// responds 501 until Task 2 implements the real handler.
|
|
func (s *Server) Token(w http.ResponseWriter, r *http.Request) {
|
|
w.WriteHeader(http.StatusNotImplemented)
|
|
}
|