docs: correct stale and inaccurate documentation across the repo - #405
Merged
Merged
Conversation
A full review of the Markdown docs and package doc comments against the current code. The notable corrections: - server/doc.go said access tokens were DPoP-only with "mTLS binding not supported", and that refresh tokens rotate on every use; mTLS sender-constraining is supported, and refresh tokens are deliberately not rotated (FAPI 2.0 SP §5.3.2.1). - GETTING_STARTED.md's server.New example omitted the required ClientCertificateTrust dependency and failed as written, and pointed at a removed conformance-as helper instead of keys.NewLocalIssuerKeys. - ARCHITECTURE.md named types and APIs that don't exist or were never built as described (root Scope/Issuer types, DPoPKeyHandle, SelectSigningKey, AuthorizationPolicy, an Exposure tag on errors, configurable fail-closed audit, a "client:jarm" replay namespace, stores in the client/server packages), and linked a nonexistent "Hardening rules" section. It now also opens its conformance history with current results. - README.md omitted attestation-based client authentication and the client-side OAuthOnly option; SECURITY.md said there were no tagged releases; conformance docs carried outdated CIBA framing, module counts and a "twenty-one" leg count (there are 22). - UPGRADING.md gains v0.38.0's invalid_scope and error-text behaviour changes; CONTRIBUTING.md and AGENTS.md ask breaking PRs to add an UPGRADING.md section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
This was referenced Sep 28, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
A full review of every Markdown doc and the package doc comments against current
main. Each claim was checked against the code:.mdfiles and Go comments;Behavioral errors (most important)
server/doc.go: said every access token is DPoP-only and "mTLS binding [is] not supported". mTLS sender-constraining (RFC 8705 §3) is supported and certified.server/doc.go: said refresh tokens rotate on every use. They deliberately don't (FAPI 2.0 SP §5.3.2.1 forbids rotation except in extraordinary circumstances).server/doc.go: said production checks for store and key capabilities "will be added". They exist; the text now lists them.GETTING_STARTED.md: theserver.Newexample failed as written ("client certificate trust is required"). It now includesClientCertificateTrustand is gofmt'd.GETTING_STARTED.md: pointed at the removedselfIssuerKeySourceinstead ofkeys.NewLocalIssuerKeys.ARCHITECTURE.md
Named things that don't exist or were never built as described:
Scope/Issuer/SenderConstrainttypes;client.AuthorizationRequest/server.ValidatedAuthorizationRequest;DPoPKeyHandleand a DPoP key reference in the session store;server.SelectSigningKey;SubjectProvider;AuthorizationPolicy.Evaluate;Exposuretag on errors;replay.Storeand aclient:jarmnamespace;client/server;Each passage now describes the real API.
Linked a nonexistent "Hardening rules for every role's public API" section, as did
client/doc.goandresource/doc.go. These now point to "Design rules".The conformance history opened by saying CIBA is "deliberately not part of this automated certification loop". It now opens with current results (2026-09-27 run) and notes that the per-profile counts below are first-run figures.
Other docs
ClientAuthMethodenum and the feature list) and the client-sideOAuthOnlyoption.conformance.yml(comments and step name) andserver/scripts/README.md;run-all.shruns 22.invalid_scopeat PAR/CIBA (fix(server): return invalid_scope for a scope the client isn't allowed #403), and the character-checked server error text plus malformed-callback-code rejection (feat(client): expose the server's OAuth error response on client.Error #402).client/doc.go: CIBA methods,ParseSessionHandlebinding,ServerResponse;resource/doc.go: mTLSx5t#S256binding;keys/doc.go: custody declaration, JWKS/local issuer key sources,KeySourceAssurance;storage/doc.go: Session/Nonce/Backchannel stores exist, real namespaces;server/assurance.go: dropped a "HSM-backed keys will be added" note that contradicts the custody design.Deliberately left alone
The long per-profile conformance READMEs keep their dated "result of a live run" counts as history. Their
aud, federation and expected-failure content was checked and is current.Testing
go build ./...andgo vetpass.fapi.Newcounterexample and a suite Java class name.🤖 Generated with Claude Code
https://claude.ai/code/session_01GMAyPYDPGpfnwow3JLeooZ