Files
summercms/.planning/phases/08-oauth2-1-authorization-server/08-SOURCE-AUDIT.md
2026-09-23 17:46:38 +02:00

7.3 KiB

Phase 08 Source Coverage Audit

All required GOAL, REQ, RESEARCH, CONTEXT, VALIDATION, and UI-SPEC items are planned. Deferred ideas remain excluded.

Source ID Feature / requirement Plan Status Notes
GOAL — PHP-compatible authorization server serves unchanged MCP/connector with exact header ownership 01-10 COVERED Direct standard-library wristband per locked D-01; real-client proof in 09.
REQ AUTH-05 Metadata, DCR, S256 authorize/consent, code/refresh grants, resource handling, exact discovery/challenges 01, 03-07, 09-10 COVERED Backend Basic challenge and MCP RFC 9728 ownership are tested separately.
REQ AUTH-06 Form/query/JSON source rules, CSRF-free raw routes, rate limits, unwrapped responses, cache headers 01, 03-05, 09-10 COVERED Route-table, byte, header, parity, and final audit coverage.
REQ AUTH-07 Persistent OAuth models, connected-app list/revoke, unchanged MCP install/auth/tool flow 02-03, 05-10 COVERED Includes schema correction, /me, lifecycle, and real MCP.
RESEARCH R-01 Additive nullability/index migration and pointer models 02 COVERED Persistent DCR slice includes safe rollback refusal.
RESEARCH R-02 App-agnostic transaction-scoped store bundle with GORM row locks in app tier 02-04 COVERED Framework never imports GORM/fonoteka; DCR is connector-visible at the end of 02.
RESEARCH R-03 Commit refresh replay lineage kill before returning invalid_grant 06, 10 COVERED Persisted post-error evidence and concurrency tests.
RESEARCH R-04 Ordered RFC3986 redirects and endpoint-specific parsers 04-05, 09-10 COVERED Exact bytes/parity.
RESEARCH R-05 No new package; standard-library crypto/HTTP and package-legitimacy audit not applicable 01-10 COVERED T-08-SC included in every threat model.
RESEARCH R-06 103 PHP-method audit and complete validation architecture 10 COVERED Exact distribution and executable missing-name gate.
RESEARCH R-07 Real MCP /me prerequisite and 64 KiB DCR bound 01, 08-10 COVERED Both resolved questions are locked as D-20/D-21.
CONTEXT D-01 Direct stdlib port; no zitadel/oidc; correct roadmap/requirement wording 01-04, planning update COVERED No dependency install.
CONTEXT D-02 Query/form/JSON parameter sources 02-04, 09-10 COVERED JSON-only register, query-only authorize, JSON token rejection and ParseForm precedence.
CONTEXT D-03 TTLs, caps, issuer/resource/consent configuration 01-04 COVERED Metadata mounted in 01; exact DCR/TTL defaults wired in 02.
CONTEXT D-04 Full T-08 security treatment and constant-time comparisons 01-10 COVERED Independent security agent and blocking approval in 10.
CONTEXT D-05 wristband owns RFC surface/state machine 01-04 COVERED Each opening plan ends in an assembled connector-visible slice.
CONTEXT D-06 PHP-minimal response shapes are defaults; no hooks 01-05 COVERED Exact response/header tests and parity.
CONTEXT D-07 App stores, issuer, transaction boundary, row locks 02-04 COVERED Persistent DCR plus real Postgres concurrency tests.
CONTEXT D-08 App owns consent and connected apps 05-06 COVERED Exact UI payloads and ownership.
CONTEXT D-09 Raw routes and per-route token/register throttles 01-05, 10 COVERED Metadata in 01, register in 02, authorize in 03, token in 05 wiring; route-table inspection throughout.
CONTEXT D-10 Retire reserved oauth guard; access stays inv_token 03-05, 08, 10 COVERED Negative guard/source tests.
CONTEXT D-11 Preserve configured inv_ prefix 04, 08-09 COVERED Actual MCP install/HTTP consumption.
CONTEXT D-12 Backend Basic challenge; MCP owns rich Bearer/resource metadata 03-05, 08-10 COVERED Unit, route, and real-process evidence.
CONTEXT D-13 Replay projected MCP flows in Go tests 09 COVERED Stable named-step projections fail on disappearance.
CONTEXT D-14 Full real Node MCP lifecycle gate 09-10 COVERED Includes discovery, DCR, PKCE, login/consent, /me, tool, refresh.
CONTEXT D-15 No live vendor connection in Phase 8 — EXCLUDED Deferred to cutover by explicit decision.
CONTEXT D-16 Record clean mcp-lifecycle; nine routes ported honestly 09 COVERED Secret-scrubbed fixture and corpus audit.
CONTEXT D-17 On-request expiry sweep, expired rows only 01-02, 04, 06 COVERED No timer/goroutine; replay evidence retained.
CONTEXT D-18 Port every named PHP OAuth test 01-10 COVERED Final one-to-one 103-method map.
CONTEXT D-19 Exact app-side fonoteka:oauth-client 07 COVERED Repeatable bonfire flags and one-time secret.
CONTEXT D-20 Exact personal-token /me MCP prerequisite 08-09 COVERED Existing guard/middleware and positive allow-list.
CONTEXT D-21 Register body bounded at 64 KiB with native error 01, 10 COVERED Bound precedes JSON decode.
VALIDATION W0-01 Framework metadata/authorize/token/register/PKCE/refresh tests 01-04, 06, 10 COVERED Fast in-memory tests plus audit.
VALIDATION W0-02 Real-Postgres migration/store locking/replay/sweep tests 02, 04, 06, 10 COVERED Existing auth TestMain harness.
VALIDATION W0-03 Raw routing/parser/rate/body/header isolation 03-05, 10 COVERED Assembled route tests.
VALIDATION W0-04 Consent/collection/connected-app ownership 05-06, 10 COVERED Real-Postgres controllers.
VALIDATION W0-05 Nine routes, lifecycle replay, 103-method map 09-10 COVERED Corpus/fixture/map gates.
VALIDATION W0-06 Personal-token /me 08-09 COVERED MCP startup prerequisite.
VALIDATION W0-07 Full unchanged MCP and security gate 09-10 COVERED 09 self-validates gate structure; 10 final checkpoint is the sole long execution.
UI-SPEC UI-01 Nuxt remains unchanged 05-10 COVERED Read-only harness and scoped path-diff checks.
UI-SPEC UI-02 Consent read/allow/deny states and exact payload/status/redirect semantics 05, 09-10 COVERED Includes invalid-handle no-request, safe login return, stale/foreign/used 404, and empty-scope 422.
UI-SPEC UI-03 Connected-app empty/populated/error/list/revoke contracts 05-06, 09-10 COVERED Browser matrix plus positive allow-list, manual count, identical 404.
UI-SPEC UI-04 Untrusted names/hosts, scope order, server-derived collection, no secrets 05-06, 10 COVERED Sanitization, host-only, intersection, output audits.
UI-SPEC UI-05 Existing accessibility/responsive/i18n behavior is preserved 05, 09-10 COVERED Existing return/i18n scripts plus read-only Playwright keyboard/focus/44px/mobile matrix.

Deferred and Out-of-Scope Audit

  • Summer-themed token prefix: excluded; inv_ remains locked.
  • River expiry job: excluded; request-time sweep ships here and River remains Phase 11.
  • Generic framework client command: excluded; app command ships in Plan 07.
  • Live Claude/ChatGPT/Grok connection: excluded; scripted SDK plus unchanged MCP is the Phase 8 acceptance gate.
  • Social login and oauth-identities: excluded; no plan creates those routes.
  • Frontend redesign/new UI: excluded; Nuxt must remain unchanged.

No required source item is missing.