- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH:
an unauthenticated request no longer reaches whichever phone is online alone.
- Mcp-Session-Id is no longer a credential; the Bearer token is checked on
every request (MCP auth spec).
- Refresh tokens live 90 days (was 30, equal to the access token, so they
were always dead when first needed).
- A rejected refresh no longer counts toward the IP ban: a client with an
expired token was retrying into a self-renewing ban on its own IP.
- 401s carry the RFC 9728 WWW-Authenticate discovery header.
Two self-contained scripts, no hardware or network needed:
- tests/verify_server.py boots the FastAPI app in-process against a
throwaway database and walks the full surface: health, MCP protocol
(202 notifications, version negotiation, tool schemas), the complete
OAuth flow (register -> authorize -> code -> token -> authenticated
MCP session), and the per-user safety config round-trip.
- tests/verify_relays.py drives both relay clients' pattern engines
against a recorded fake of the Intiface layer: indefinite durations,
the escalate hold contract, error-mid-ramp stops, pattern
supersession, tracked auto-stops, feature_index routing, and the
stop-unknown-device fallback.
Run before shipping changes: python tests/verify_server.py &&
python tests/verify_relays.py
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>