Fills in every scripts/check-phase8.sh stage skeleton with real logic: disposable Postgres (docker run + pg_isready), the assembled Go app built and served against it with a throwaway onboarding-seeded gate account, the real unchanged fonoteka-mcp process started with all three required environment variables, and the full scripted SDK lifecycle -- discovery (MCP's own RFC 9728 401 hint, verified separately from authorization server metadata), DCR, PKCE authorize, JWT login/consent, token, an MCP tool call, refresh, replay of the spent refresh token, revoke, and a post-revoke refresh failure -- delegated to the new scripts/check-phase8-mcp-client.mjs driver, which resolves the MCP SDK's auth helpers from fonoteka-mcp's own node_modules (no new dependency, same pattern as parity/capture_clients.mjs). Both repositories' vet/test/race, the full parity/corpus/secret-scan gate, the existing check-phase8-ui.mjs --final-gate UI harness, an unchanged-client git-diff check for both MCP_ROOT and NUXT_ROOT, and a 08-SECURITY-REVIEW.md status:verified gate close out the stage list. --contract-self-test validates structure only (stage names/order, cleanup trap, loopback-only binding, the three MCP env vars, the redaction helper, no pre-final full-run flag, read-only unchanged-client references) in well under 30 seconds -- it boots no services. The --red-contract self-test from Task 1 is preserved unchanged. run_full_gate (the no-flag invocation) is 08-10 Task 3's sole execution site; 08-09 never invokes it.
12 KiB
Executable File
12 KiB
Executable File