- Server.Authorize stub returns 501 - TestPhase8RedAuthorize drives a full valid S256 request and asserts the exact 302 /connect success contract; fails with PHASE8_RED:authorize against the stub, verified fail-closed via check-phase8-red.sh
26 lines
1.1 KiB
Go
26 lines
1.1 KiB
Go
// RFC 6749 authorization endpoint for MCP OAuth, ported from PHP
|
|
// OAuthAuthorizeController::authorize byte-for-byte including its
|
|
// validation order (08-CONTEXT.md D-02/D-04/D-05; canonical PHP source:
|
|
// OAuthAuthorizeController.php).
|
|
//
|
|
// D-02: query-only parsing (no body is ever read). The client and the exact
|
|
// registered redirect URI are validated before any redirect response is
|
|
// constructed (T-08-OPEN-REDIRECT): an unknown client or unregistered
|
|
// redirect is a local text/plain 400 with no Location header. Every later
|
|
// failure redirects to the now-trusted redirect_uri with an ordered
|
|
// error/error_description/iss[/state] query built through an RFC 3986
|
|
// encoder, never url.Values.Encode (08-RESEARCH.md Pattern 3/Pitfall 5).
|
|
package wristband
|
|
|
|
import (
|
|
"net/http"
|
|
)
|
|
|
|
// Authorize handles GET /oauth/mcp/authorize. It is not yet implemented
|
|
// (Wave 3 Task 1 RED anchor, 08-03-PLAN.md); TestPhase8RedAuthorize and
|
|
// TestPhase8RedAuthorizeApp fail against this stub until Task 2's GREEN
|
|
// commit.
|
|
func (s *Server) Authorize(w http.ResponseWriter, r *http.Request) {
|
|
w.WriteHeader(http.StatusNotImplemented)
|
|
}
|