Files
summercms/wristband/token.go
Jakub Zych 5ca830beef test(08-04): add failing code-exchange RED test in wristband
- Server.Token 501 stub and TestPhase8RedCodeExchange (PHASE8_RED:code-exchange)
- Options gains AccessTokenTTL/RefreshTokenTTL with PHP-parity defaults
2026-09-23 20:25:16 +02:00

22 lines
1.0 KiB
Go

// RFC 6749 token endpoint for MCP OAuth, ported from PHP
// OAuthTokenController::token / OAuthCodeManager::exchangeCode byte-for-byte
// including their validation order (08-CONTEXT.md D-02/D-04/D-05/D-07;
// canonical PHP source: OAuthTokenController.php, OAuthCodeManager.php).
//
// 08-04-PLAN.md ships the authorization_code grant only. grant_type=
// refresh_token is dispatched with the exact PHP-parity validity check (an
// unknown grant type is unsupported_grant_type; a known-but-not-yet-built
// grant is invalid_grant) but its full rotation/lineage-kill semantics
// (T-08-REFRESH-REPLAY) are ROADMAP.md Wave 6 (08-06-PLAN.md), not this
// plan's threat register.
package wristband
import "net/http"
// Token handles POST /oauth/mcp/token (D-09: raw route, no middleware).
// This is the Phase 8 Wave 4 RED stub (08-04-PLAN.md Task 1): it always
// responds 501 until Task 2 implements the real handler.
func (s *Server) Token(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusNotImplemented)
}