Files
summercms/wristband/authorize.go
Jakub Zych 787e612ab3 test(08-03): add failing authorize RED test in wristband
- Server.Authorize stub returns 501
- TestPhase8RedAuthorize drives a full valid S256 request and asserts the
  exact 302 /connect success contract; fails with PHASE8_RED:authorize
  against the stub, verified fail-closed via check-phase8-red.sh
2026-09-23 20:01:18 +02:00

26 lines
1.1 KiB
Go

// RFC 6749 authorization endpoint for MCP OAuth, ported from PHP
// OAuthAuthorizeController::authorize byte-for-byte including its
// validation order (08-CONTEXT.md D-02/D-04/D-05; canonical PHP source:
// OAuthAuthorizeController.php).
//
// D-02: query-only parsing (no body is ever read). The client and the exact
// registered redirect URI are validated before any redirect response is
// constructed (T-08-OPEN-REDIRECT): an unknown client or unregistered
// redirect is a local text/plain 400 with no Location header. Every later
// failure redirects to the now-trusted redirect_uri with an ordered
// error/error_description/iss[/state] query built through an RFC 3986
// encoder, never url.Values.Encode (08-RESEARCH.md Pattern 3/Pitfall 5).
package wristband
import (
"net/http"
)
// Authorize handles GET /oauth/mcp/authorize. It is not yet implemented
// (Wave 3 Task 1 RED anchor, 08-03-PLAN.md); TestPhase8RedAuthorize and
// TestPhase8RedAuthorizeApp fail against this stub until Task 2's GREEN
// commit.
func (s *Server) Authorize(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusNotImplemented)
}