12 KiB
phase, plan, subsystem, tags, requires, provides, affects, tech-stack, key-files, key-decisions, patterns-established, requirements-completed, duration, completed
| phase | plan | subsystem | tags | requires | provides | affects | tech-stack | key-files | key-decisions | patterns-established | requirements-completed | duration | completed | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 08-oauth2-1-authorization-server | 08 | auth |
|
|
|
|
|
|
|
|
~20min | 2026-09-23 |
Phase 08 Plan 08: MCP /me Prerequisite Summary
GET /api/v1/fonoteka/me on the personal-token group returns exactly scopes/collection_ids/user_id/name straight off the inv_token guard's already-matched credential, with no bearer reparse and no second database query, unblocking 08-09's real fonoteka-mcp gate.
Performance
- Duration: ~20 min
- Started: ~2026-09-23T20:00:00Z (approx.)
- Completed: 2026-09-23T20:19:37Z
- Tasks: 2 completed (2 commits: RED then GREEN, both in fonoteka.go; no summercms.go changes this plan)
- Files modified: 4 (3 created, 1 modified, all in fonoteka.go)
Accomplishments
controllers/api.MeTokenserves the exact PHPMeTokenController::mecontract as a Go handler:{"data":{"scopes":[...],"collection_ids":[...],"user_id":...,"name":...}}, sourced entirely frombouncer.Credential/bouncer.User-- the request context values the realinv_tokenguard already populated during its own bearer-parse/hash/DB-lookup pass, so the handler performs zero additional querieswire.Sliceon bothscopesandcollection_idsguarantees neither array ever serializes as JSONnull, even for a token minted with no explicit scopes/collections (aTestMeTokenHandlerNilScopesAndCollectionIDsSerializeAsEmptyArraysAndNullableNameregression proves this directly against the raw response bytes)TestMeTokenHandlerReusesMatchedCredentialWithoutReQueryingproves the "no second lookup" contract mechanically: it mutates the persisted token row'snamecolumn after the credential was matched and asserts the response still reflects the original in-memory value -- if the handler ever re-queried, this test would catch itGET /meis mounted as the third route on the existing/api/v1/fonotekapersonal-token group, inheritinginv_token,throttle:fonoteka-api-token,inv.scope:readin that exact order (proven by route-table inspection, not just manual reading ofroutes.go); missing/unknown-token 401 and wrong-scope 403 bytes are byte-identical to the pre-existing token-surface contract, with no new header- Both the Phase 8 RED sentinel (
PHASE8_RED:mcp-meinfonoteka, verified fail-closed viascripts/check-phase8-red.shagainst the genuine pre-implementation state -- route unmounted, 404 instead of the exact positive body) and the full GREEN suite (go vet/go test/go test -raceacross every subpackage ofplugins/golem15/fonotekaplusplugins/golem15/user) are green
Task Commits
Both tasks carry tdd="true"; RED then GREEN landed as separate commits, both in fonoteka.go (this plan makes no summercms.go changes):
- Task 1: RED anchor --
686d622(test):TestPhase8RedMCPMe(positive payload, missing/wrong-scope negative bytes, route-table isolation) fails withPHASE8_RED:mcp-meagainst the unmounted route;controllers/api.MeTokenships as a compiling 501 stub so the package and its new test files build. Verified fail-closed viascripts/check-phase8-red.sh. - Task 2: implement and mount --
19ac5fd(feat): the realMeTokenhandler andGET /memounted on the personal-token group inroutes.go.
Plan metadata: committed as part of this summary/state-update commit.
Files Created/Modified
../fonoteka.go/plugins/golem15/fonoteka/controllers/api/me_token_controller.go--MeToken(real implementation, Task 2; compiling 501 stub in Task 1)../fonoteka.go/plugins/golem15/fonoteka/controllers/api/me_token_controller_test.go--TestMeTokenHandlerExactFourFieldsWithScopesAndCollectionIDs,TestMeTokenHandlerNilScopesAndCollectionIDsSerializeAsEmptyArraysAndNullableName,TestMeTokenHandlerReusesMatchedCredentialWithoutReQuerying(package-local unit tests injecting an already-matched credential/principal into context, matching theconnected_app_controller_test.goprecedent)../fonoteka.go/plugins/golem15/fonoteka/oauth_tools_test.go--TestPhase8RedMCPMe(RED anchor),TestOAuthToolsMePositiveAndNegativeContract,TestOAuthToolsMeRouteIsolation, plus shared helpersmeToolsInsertToken/meToolsBearerRequest/assertMeRouteIsolation../fonoteka.go/plugins/golem15/fonoteka/routes.go-- mountsGET /meon the existing/api/v1/fonotekapersonal-token group, after/genres
Decisions Made
See frontmatter key-decisions. The most load-bearing: shipping me_token_controller.go as a compiling 501 stub in the RED commit (rather than leaving the file entirely absent until Task 2) follows the exact precedent 08-04's Server.Token stub, 08-06's store-interface extensions, and 08-07's bonfire compiling seam all established -- a RED commit is allowed to add non-literally-listed compile prerequisites when the alternative is an uncompilable package, and this is tracked here as a Rule 3 (blocking issue) auto-fix rather than a silent scope change.
Deviations from Plan
Auto-fixed Issues
1. [Rule 3 - Blocking] me_token_controller.go added in the Task 1 RED commit, not literally in Task 1's files_modified
- Found during: Task 1, writing
me_token_controller_test.goandoauth_tools_test.go - Issue: Task 1's plan-listed files are only the two test files. Without
me_token_controller.goexisting at all,controllers/apiwould not compile once its test file referencedMeToken, andgo test ./plugins/golem15/fonoteka(the RED verify command's target) depends oncontrollers/apicompiling as a regular dependency. - Fix: Added a minimal
MeTokenstub returning an opaque 500, in the same file Task 2'sfiles_modifiedlist already names, so the RED commit compiles cleanly and the RED failure comes from the intended source (unmounted route, 404) rather than a build error. - Files modified:
../fonoteka.go/plugins/golem15/fonoteka/controllers/api/me_token_controller.go - Verification:
go vet ./plugins/golem15/fonoteka/...clean at the RED commit;scripts/check-phase8-red.shconfirms the RED failure is exactlyPHASE8_RED:mcp-mewith no build/setup/panic noise. - Committed in:
686d622(Task 1 RED commit)
Total deviations: 1 auto-fixed (compile prerequisite, no scope change) Impact on plan: None beyond making the RED commit itself buildable; Task 2 implemented the handler in the same file, at the same location, matching the plan's own file list.
Issues Encountered
None beyond the auto-fixed item above. Full go vet/go test ./... are green across every subpackage of fonoteka.go's plugins/golem15/fonoteka module (classes, classes/auth, console, controllers/api, middleware, models, updates) and plugins/golem15/user; go test -race on the touched packages (controllers/api, top-level fonoteka) is also green. go build ./... at the fonoteka.go workspace root is clean. This plan makes no summercms.go changes, so summercms.go's own go vet/go test ./... are unaffected (not re-run).
User Setup Required
None -- no external service configuration required.
Next Phase Readiness
GET /api/v1/fonoteka/meis live on the assembled app and ready for 08-09's realfonoteka-mcpprocess (started viascripts/check-phase8.sh, D-14) to call as its first authenticated request before constructing the MCP server.- The response's
scopesfield is exactly whatfonoteka-mcp'sscopeGatedTools-style factory needs to gate tool visibility (a read-only token never sees write/ai tools) -- no further backend change is anticipated for that consumption path. - AUTH-07 remains Pending in REQUIREMENTS.md: this plan ships the
/meprerequisite its text implicitly depends on, but the requirement's own "fonoteka-mcp completes its install and auth flow unchanged" clause is only provable once 08-09's real Node MCP gate runs end to end against the Go backend. - No blockers.
Self-Check: PASSED
- FOUND: ../fonoteka.go/plugins/golem15/fonoteka/controllers/api/me_token_controller.go
- FOUND: ../fonoteka.go/plugins/golem15/fonoteka/controllers/api/me_token_controller_test.go
- FOUND: ../fonoteka.go/plugins/golem15/fonoteka/oauth_tools_test.go
- FOUND: ../fonoteka.go/plugins/golem15/fonoteka/routes.go (modified)
- FOUND commits (fonoteka.go): 686d622, 19ac5fd
Phase: 08-oauth2-1-authorization-server Completed: 2026-09-23