Topic 6: Module 7 milestone and interview questions
9 min read·22 Sept 2026
Project Milestone
The notes assistant is now safe to expose over HTTP. Your repository should contain:
text
notes-assistant/
notes_assistant/
auth.py NEW: JWTTokenVerifier, mint_dev_token, auth_from_env, READ_SCOPE, WRITE_SCOPE
server.py UPDATED: token_verifier/auth parameters, notes:write check, auth_from_env in main
store.py, llm.py, config.py, host.py unchanged
examples/
m07_tokens.py shared settings and good/bad test tokens
m07_no_token_in_memory.py why stdio and in-memory calls carry no token
m07_issuer_slash.py the trailing-slash issuer pitfall
m07_pkce.py PKCE S256 checked against RFC 7636
m07_token_matrix.py HTTP status for every token
m07_scoped_calls.py read versus write scopes through a real client
m07_rejected.py catching and diagnosing a refused token
m07_client_metadata.py CIMD document and OAuthClientProvider
m07_auth_overhead.py verification and end-to-end latency
m07_step_up.py reading a scope challenge
m07_passthrough.py token passthrough versus a separate token
m07_identity_assertion.py enterprise ID-JAG client provider
m07_jwks_verifier.py RS256 with PyJWKClient
m07_production_wiring.py the JWKS verifier in build_server
m07_lab.py the end-to-end lab
tests/
test_auth.py NEW: 9 tests for the verifier and the HTTP doorCode explained
- In simple words: a map of what changed in the project this module.
- What happens:
auth.pyis new andserver.pyreached its final form; everything else innotes_assistant/is untouched. Theexamples/files are the module's scripts in the order you met them, andtests/test_auth.pyjoins the Module 5 tests. - Comes out: with the tests from earlier modules in place,
python -m pytest -qshould report everything passing, including the 9 new tests. To run the protected server yourself: setNOTES_AUTH_KEY,NOTES_AUTH_ISSUER, andNOTES_RESOURCE_URL, then start it withNOTES_TRANSPORT=streamable-http.
What the capstone (Module 11) will ask of this code, and where it already stands: "Protect the HTTP version with OAuth and validate the token audience" is done; "a token issued for a different server, checking it is rejected" is the wrong-audience row of the lab.