Skip to content

docs: v0.41.0 staleness sweep - #468

Merged
osanderson merged 1 commit into
mainfrom
docs/staleness-sweep-v0.41
Sep 30, 2026
Merged

osanderson merged 1 commit into
mainfrom
docs/staleness-sweep-v0.41

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

Docs checked against v0.41.0 with the same four mechanical checks as the previous sweep (#405), rather than by reading prose:

  1. Identifier scan: every pkg.Identifier in Markdown and Go doc comments resolved against the packages' exported API. Clean; the only hits were method shorthand (client.ExchangeCode for (*Client).ExchangeCode) and local variables in code comments.
  2. Snippets compiled and run: all 11 Go blocks in GETTING_STARTED compiled and vetted in a scratch module against this checkout. Steps 2–4 (server construction) and step 7's serverresource.NewVerifier were then run with real values and succeeded as written.
  3. Behaviour claims: checked for statements v0.41.0 changed (resource status codes and challenges, invalid_dpop_proof, required redirect URIs, CIBA ping and session handling, interaction state, conformance leg counts). None stale.
  4. Links and anchors: every relative Markdown link and backticked repo path. One real break (below); the other hits are the OIDF suite checkout's own paths and gitignored generated plan files.

Fixes

  • Dead anchor: conformance/server/oidf-config/README.md's heading "Client Credentials Grant ({baseline,…}-client-credentials.config.json)" gave GitHub an anchor with the file names in it, so both links to #client-credentials-grant (from conformance/README.md and within the file) went nowhere. The heading is now just "Client Credentials Grant", with the config names on the section's first line.
  • GETTING_STARTED step 5: it said a.Handle must come back to CompleteAuthorization but not how the consent submission gets a.Interaction back. New paragraph: encode it with MarshalText, keep it with the handle where only the application can write it (server-side session or signed cookie), and restore it with server.ParseInteractionRequest. It also explains why a modified copy can't widen the grant, and points to the federated-union demo.
  • server/doc.go: the overview's method list now includes LookupBackchannelInteraction.

🤖 Generated with Claude Code

Mechanical checks over the docs against v0.41.0 (identifier scan,
GETTING_STARTED snippets compiled and server setup run with real
values, behaviour claims for this release's changes, link and anchor
check). Every identifier resolves and every snippet compiles and runs;
three fixes:

- conformance/server/oidf-config/README.md: the Client Credentials
  Grant heading carried its config file names, so GitHub's anchor
  wasn't #client-credentials-grant and both links to it were dead. The
  names move into the section.
- GETTING_STARTED.md step 5: the consent submission needs the
  InteractionRequest again; say how to keep it (MarshalText /
  ParseInteractionRequest, where only the app can write) and why a
  modified copy can't widen a grant.
- server/doc.go lists LookupBackchannelInteraction with the other CIBA
  methods.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

Copy link
Copy Markdown

@osanderson
osanderson merged commit 8c48523 into main Sep 30, 2026
13 checks passed
@osanderson
osanderson deleted the docs/staleness-sweep-v0.41 branch September 30, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant