7.3 KiB
7.3 KiB
Phase 08 Source Coverage Audit
All required GOAL, REQ, RESEARCH, CONTEXT, VALIDATION, and UI-SPEC items are planned. Deferred ideas remain excluded.
| Source | ID | Feature / requirement | Plan | Status | Notes |
|---|---|---|---|---|---|
| GOAL | — | PHP-compatible authorization server serves unchanged MCP/connector with exact header ownership | 01-10 | COVERED | Direct standard-library wristband per locked D-01; real-client proof in 09. |
| REQ | AUTH-05 | Metadata, DCR, S256 authorize/consent, code/refresh grants, resource handling, exact discovery/challenges | 01, 03-07, 09-10 | COVERED | Backend Basic challenge and MCP RFC 9728 ownership are tested separately. |
| REQ | AUTH-06 | Form/query/JSON source rules, CSRF-free raw routes, rate limits, unwrapped responses, cache headers | 01, 03-05, 09-10 | COVERED | Route-table, byte, header, parity, and final audit coverage. |
| REQ | AUTH-07 | Persistent OAuth models, connected-app list/revoke, unchanged MCP install/auth/tool flow | 02-03, 05-10 | COVERED | Includes schema correction, /me, lifecycle, and real MCP. |
| RESEARCH | R-01 | Additive nullability/index migration and pointer models | 02 | COVERED | Persistent DCR slice includes safe rollback refusal. |
| RESEARCH | R-02 | App-agnostic transaction-scoped store bundle with GORM row locks in app tier | 02-04 | COVERED | Framework never imports GORM/fonoteka; DCR is connector-visible at the end of 02. |
| RESEARCH | R-03 | Commit refresh replay lineage kill before returning invalid_grant |
06, 10 | COVERED | Persisted post-error evidence and concurrency tests. |
| RESEARCH | R-04 | Ordered RFC3986 redirects and endpoint-specific parsers | 04-05, 09-10 | COVERED | Exact bytes/parity. |
| RESEARCH | R-05 | No new package; standard-library crypto/HTTP and package-legitimacy audit not applicable | 01-10 | COVERED | T-08-SC included in every threat model. |
| RESEARCH | R-06 | 103 PHP-method audit and complete validation architecture | 10 | COVERED | Exact distribution and executable missing-name gate. |
| RESEARCH | R-07 | Real MCP /me prerequisite and 64 KiB DCR bound |
01, 08-10 | COVERED | Both resolved questions are locked as D-20/D-21. |
| CONTEXT | D-01 | Direct stdlib port; no zitadel/oidc; correct roadmap/requirement wording | 01-04, planning update | COVERED | No dependency install. |
| CONTEXT | D-02 | Query/form/JSON parameter sources | 02-04, 09-10 | COVERED | JSON-only register, query-only authorize, JSON token rejection and ParseForm precedence. |
| CONTEXT | D-03 | TTLs, caps, issuer/resource/consent configuration | 01-04 | COVERED | Metadata mounted in 01; exact DCR/TTL defaults wired in 02. |
| CONTEXT | D-04 | Full T-08 security treatment and constant-time comparisons | 01-10 | COVERED | Independent security agent and blocking approval in 10. |
| CONTEXT | D-05 | wristband owns RFC surface/state machine |
01-04 | COVERED | Each opening plan ends in an assembled connector-visible slice. |
| CONTEXT | D-06 | PHP-minimal response shapes are defaults; no hooks | 01-05 | COVERED | Exact response/header tests and parity. |
| CONTEXT | D-07 | App stores, issuer, transaction boundary, row locks | 02-04 | COVERED | Persistent DCR plus real Postgres concurrency tests. |
| CONTEXT | D-08 | App owns consent and connected apps | 05-06 | COVERED | Exact UI payloads and ownership. |
| CONTEXT | D-09 | Raw routes and per-route token/register throttles | 01-05, 10 | COVERED | Metadata in 01, register in 02, authorize in 03, token in 05 wiring; route-table inspection throughout. |
| CONTEXT | D-10 | Retire reserved oauth guard; access stays inv_token |
03-05, 08, 10 | COVERED | Negative guard/source tests. |
| CONTEXT | D-11 | Preserve configured inv_ prefix |
04, 08-09 | COVERED | Actual MCP install/HTTP consumption. |
| CONTEXT | D-12 | Backend Basic challenge; MCP owns rich Bearer/resource metadata | 03-05, 08-10 | COVERED | Unit, route, and real-process evidence. |
| CONTEXT | D-13 | Replay projected MCP flows in Go tests | 09 | COVERED | Stable named-step projections fail on disappearance. |
| CONTEXT | D-14 | Full real Node MCP lifecycle gate | 09-10 | COVERED | Includes discovery, DCR, PKCE, login/consent, /me, tool, refresh. |
| CONTEXT | D-15 | No live vendor connection in Phase 8 | — | EXCLUDED | Deferred to cutover by explicit decision. |
| CONTEXT | D-16 | Record clean mcp-lifecycle; nine routes ported honestly |
09 | COVERED | Secret-scrubbed fixture and corpus audit. |
| CONTEXT | D-17 | On-request expiry sweep, expired rows only | 01-02, 04, 06 | COVERED | No timer/goroutine; replay evidence retained. |
| CONTEXT | D-18 | Port every named PHP OAuth test | 01-10 | COVERED | Final one-to-one 103-method map. |
| CONTEXT | D-19 | Exact app-side fonoteka:oauth-client |
07 | COVERED | Repeatable bonfire flags and one-time secret. |
| CONTEXT | D-20 | Exact personal-token /me MCP prerequisite |
08-09 | COVERED | Existing guard/middleware and positive allow-list. |
| CONTEXT | D-21 | Register body bounded at 64 KiB with native error | 01, 10 | COVERED | Bound precedes JSON decode. |
| VALIDATION | W0-01 | Framework metadata/authorize/token/register/PKCE/refresh tests | 01-04, 06, 10 | COVERED | Fast in-memory tests plus audit. |
| VALIDATION | W0-02 | Real-Postgres migration/store locking/replay/sweep tests | 02, 04, 06, 10 | COVERED | Existing auth TestMain harness. |
| VALIDATION | W0-03 | Raw routing/parser/rate/body/header isolation | 03-05, 10 | COVERED | Assembled route tests. |
| VALIDATION | W0-04 | Consent/collection/connected-app ownership | 05-06, 10 | COVERED | Real-Postgres controllers. |
| VALIDATION | W0-05 | Nine routes, lifecycle replay, 103-method map | 09-10 | COVERED | Corpus/fixture/map gates. |
| VALIDATION | W0-06 | Personal-token /me |
08-09 | COVERED | MCP startup prerequisite. |
| VALIDATION | W0-07 | Full unchanged MCP and security gate | 09-10 | COVERED | 09 self-validates gate structure; 10 final checkpoint is the sole long execution. |
| UI-SPEC | UI-01 | Nuxt remains unchanged | 05-10 | COVERED | Read-only harness and scoped path-diff checks. |
| UI-SPEC | UI-02 | Consent read/allow/deny states and exact payload/status/redirect semantics | 05, 09-10 | COVERED | Includes invalid-handle no-request, safe login return, stale/foreign/used 404, and empty-scope 422. |
| UI-SPEC | UI-03 | Connected-app empty/populated/error/list/revoke contracts | 05-06, 09-10 | COVERED | Browser matrix plus positive allow-list, manual count, identical 404. |
| UI-SPEC | UI-04 | Untrusted names/hosts, scope order, server-derived collection, no secrets | 05-06, 10 | COVERED | Sanitization, host-only, intersection, output audits. |
| UI-SPEC | UI-05 | Existing accessibility/responsive/i18n behavior is preserved | 05, 09-10 | COVERED | Existing return/i18n scripts plus read-only Playwright keyboard/focus/44px/mobile matrix. |
Deferred and Out-of-Scope Audit
- Summer-themed token prefix: excluded;
inv_remains locked. - River expiry job: excluded; request-time sweep ships here and River remains Phase 11.
- Generic framework client command: excluded; app command ships in Plan 07.
- Live Claude/ChatGPT/Grok connection: excluded; scripted SDK plus unchanged MCP is the Phase 8 acceptance gate.
- Social login and oauth-identities: excluded; no plan creates those routes.
- Frontend redesign/new UI: excluded; Nuxt must remain unchanged.
No required source item is missing.