Files
summercms/.planning/phases/08-oauth2-1-authorization-server/08-VALIDATION.md
Jakub Zych 0c173df25c docs(08-10): add the Phase 8 security review; mark Wave 0 green
08-SECURITY-REVIEW.md: status: verified, 11/11 T-08 threats closed,
0 open, 0 accepted risks. Performed directly by the 08-10 executor
(no Task/Agent tool available this run, per the plan's documented
fallback) with re-executed named-test evidence for every threat; found
and fixed one real gap during the review (see the paired fix commit).

08-VALIDATION.md: 08-W0-01 through 08-W0-06 flip to green with their
automated commands re-run; nyquist_compliant and wave_0_complete are
now true. 08-W0-07/08-W0-08 (the full scripts/check-phase8.sh gate)
stay pending until 08-10 Task 3 actually executes it.
2026-09-24 00:12:36 +02:00

8.5 KiB

phase, slug, status, nyquist_compliant, wave_0_complete, created, updated
phase slug status nyquist_compliant wave_0_complete created updated
08 oauth2-1-authorization-server draft true true 2026-09-23 2026-09-24

Phase 08 — Validation Strategy

Per-phase validation contract for feedback sampling during execution.


Test Infrastructure

Property Value
Framework Go 1.27 testing; existing testcontainers-backed Postgres harness; Node.js 22 plus the unchanged fonoteka-mcp only for end-to-end gates
Config file Existing go.work, repository package tests, ../fonoteka.go/plugins/golem15/fonoteka/classes/TestMain, and planned scripts/check-phase8.sh
Quick run command go test ./wristband -count=1
App-focused command `cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestOAuth
Full suite command scripts/check-phase8.sh — Plan 08-10 Task 3 only
Estimated runtime Every task command is focused and designed for ≤30 seconds; the sole final two-repository parity/race/UI/real-MCP gate may take several minutes

Sampling Rate

  • After every task commit: Run the narrowest affected package test; go test ./wristband -count=1 is the default framework check.
  • After every task: Run only the named package/test, shell syntax, source assertion, or contract self-test shown in that task; focused Postgres tests select one behavior family.
  • Final blocking checkpoint only (08-10 Task 3): scripts/check-phase8.sh runs both repositories' vet/test/race, full parity/corpus, full UI, secret scan, security review, and unchanged real-MCP lifecycle exactly once.
  • Max feedback latency: Task-level commands are designed for ≤30 seconds. Complete repository suites, race, full parity/corpus, browser UI, Docker services, and real MCP are forbidden before the final checkpoint.

Per-Task Verification Map

Task ID Plan Wave Requirement Threat Ref Secure Behavior Test Type Automated Command File Exists Status
08-W0-01 08-01, 08-03, 08-04, 08-06, 08-10 1, 3, 4, 6, 9 AUTH-05 T-08-PKCE / T-08-CODE-REPLAY Mounted metadata plus deterministic authorize, PKCE S256, code exchange, refresh, and ordered redirects have focused tests unit/route `go test ./wristband -run 'Test(Metadata Authorize Token
08-W0-02 08-02, 08-04, 08-06, 08-10 2, 4, 6, 9 AUTH-05, AUTH-07 T-08-DCR-FLOOD / T-08-CODE-REPLAY / T-08-REFRESH-REPLAY Nullability, persistent DCR, row locks, single-use codes, committed lineage kill, sweeps, and indexes work on real Postgres integration cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/classes/auth -run '^TestOAuth' -count=1 ✅ W0 ✅ green (2026-09-24)
08-W0-03 08-01-05, 08-10 1-5, 9 AUTH-06 T-08-DCR-FLOOD / T-08-SURFACE Metadata/DCR/authorize/token raw routing, parsers, rate limits, 64 KiB bound, exact bare bodies, and headers remain isolated route/integration cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestOAuth' -count=1 ✅ W0 ✅ green (2026-09-24)
08-W0-04 08-05, 08-06, 08-10 5-6, 9 AUTH-07 T-08-SCOPE-CEILING / T-08-CROSS-USER Consent, active-collection binding, connected-app ownership, list, and revoke semantics match PHP Postgres integration cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/controllers/... -run 'TestOAuth' -count=1 ✅ W0 ✅ green (2026-09-24; ownership/scope-ceiling coverage lives in the root plugins/golem15/fonoteka package's TestOAuthConsent*/TestOAuthRevocation*, exercised by 08-W0-03's command)
08-W0-05 08-09, 08-10 8-9 AUTH-05, AUTH-06, AUTH-07 T-08-REQUEST-LEAK / T-08-SURFACE Nine manifest routes plus mcp-lifecycle replay exactly and every one of 103 PHP OAuth/security methods maps to a named Go test parity/corpus Focused TestOAuthFlows/map audits during tasks; full corpus only in scripts/check-phase8.sh at 08-10 Task 3 ✅ W0 ✅ green (2026-09-24; parity/oauth_audit_test.go:TestPHPTestMap confirms all 103 rows; full corpus gate is Task 3)
08-W0-06 08-08, 08-09 7-8 AUTH-07 T-08-SURFACE Exact authenticated /api/v1/fonoteka/me lets the unchanged MCP process initialize without expanding the profile API surface integration/e2e `cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'TestMe TestTokenSurface' -count=1` ✅ W0
08-W0-07 08-09, 08-10 8-9 AUTH-05, AUTH-07 All T-08 threats 08-09 self-validates the gate contract; 08-10 final checkpoint alone runs real SDK discovery, DCR, PKCE, JWT consent, token, tool, refresh/replay, revoke, and post-revoke failure unchanged e2e scripts/check-phase8.sh only at 08-10 Task 3 ✅ W0 ⬜ pending (08-10 Task 3, not yet executed)
08-W0-08 08-05, 08-09, 08-10 5, 8-9 AUTH-05, AUTH-07 T-08-CROSS-USER / T-08-SURFACE 08-05 self-validates scenario coverage; 08-10 final checkpoint alone executes invalid-handle, return-path, consent/apps, accessibility, mobile, and en/pl browser checks without Nuxt changes browser/contract Full scripts/check-phase8-ui.mjs plus Nuxt verifiers only inside final scripts/check-phase8.sh ✅ W0 ⬜ pending (08-10 Task 3, not yet executed)

Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky

08-10 Task 2 update (2026-09-24): 08-W0-01 through 08-W0-06's automated commands were re-run during the security review and are green; their File Exists columns flip to ✅ now that 08-PHP-TEST-MAP.md, 08-SECURITY-REVIEW.md and this file's own task IDs are finalized. 08-W0-07/08-W0-08 stay ⬜ pending until 08-10 Task 3 actually executes scripts/check-phase8.sh with no flags — that command has not run yet as of this update.


Wave 0 Requirements

  • wristband/*_test.go — metadata, authorize, token, DCR, PKCE, refresh/replay, deterministic clock/random, ordered RFC3986 encoding, and 64 KiB body-bound tests.
  • ../fonoteka.go/plugins/golem15/fonoteka/updates/*oauth*_test.go — additive nullability/index correction with safe up/down behavior.
  • ../fonoteka.go/plugins/golem15/fonoteka/classes/auth/oauth_store_test.go — real-Postgres transaction, row-lock, concurrent single-use, sweep, and lineage tests.
  • ../fonoteka.go/plugins/golem15/fonoteka/controllers/api/*oauth*_test.go — exact raw/JWT endpoint bodies, headers, status codes, consent ownership, and connected-app behavior.
  • ../fonoteka.go/plugins/golem15/fonoteka/controllers/api/*me*_test.go — minimal inv_token-authenticated MCP bootstrap contract.
  • ../fonoteka.go/parity/oauth_flow_test.go and mcp-lifecycle fixture — projected existing flows and clean lifecycle/replay coverage.
  • scripts/check-phase8.sh — two-repository vet/test/race, corpus, secret, security-review, and real-MCP gate. Stage bodies complete since 08-09; not yet executed end to end (08-10 Task 3).
  • scripts/check-phase8-ui.mjs — read-only unchanged-Nuxt state, accessibility, return-path, i18n, and responsive contract gate.
  • scripts/check-phase8-red.sh — machine-readable go test -json verifier requiring exact selected test/package/sentinel and zero unexpected fail actions, plus exact exit-86 stage/sentinel shell protocol.
  • 08-SECURITY-REVIEW.md — map every T-08-* threat to a failing-when-broken test and close all high-severity threats. status: verified, threats_open: 0, 11/11 closed (2026-09-24).

Manual-Only Verifications

All phase behaviors are automated. Live Claude, ChatGPT, and Grok connections are explicitly deferred to cutover UAT; they are not Phase 8 acceptance checks.


Validation Sign-Off

  • All final plan tasks have an automated command or an explicit Wave 0 dependency.
  • Sampling continuity: no three consecutive implementation tasks lack automated verification.
  • Wave 0 covers every currently missing test/gate reference above.
  • No watch-mode flags appear in validation commands.
  • Task-level feedback is designed for ≤30 seconds; all complete suite/race/parity/UI/real-MCP work appears only in 08-10 Task 3.
  • nyquist_compliant: true is set after task IDs are finalized and every mapping is implemented.

Approval: 08-10 Tasks 1-2 complete and green (2026-09-24). Task 3's scripts/check-phase8.sh full-gate execution and the blocking human security checkpoint are still outstanding -- this file's status: field stays draft until that checkpoint is approved.