# Guida OAuth2 — VTE Watch

Registrazione **External Application** in VTENEXT per login OAuth (fase store / MFA).

## 1. VTE Admin

1. Accedi a `https://vte.mypantarei.net` come amministratore
2. **Impostazioni → External Applications → Aggiungi**
3. Compila:
   - **Nome:** `VTE Watch`
   - **Tipo grant:** Authorization Code + **PKCE**
   - **Scope:** `rest.all.read`, `touch.all` (o `rest.all` se read/write)
   - **Redirect URI:** da definire dopo POC Zepp (URL scheme app)
4. Salva **Client ID** (e Secret se richiesto)

## 2. Abilitazione OAuth2

Verifica in VTE:

- **Settings → OAuth2 Server** — server abilitato
- Property `settings.oauth2_server.enabled` = true

## 3. Endpoint

| Uso | URL |
|-----|-----|
| Authorize | `https://vte.mypantarei.net/oauth2/v2.0/auth.php` |
| Token | `https://vte.mypantarei.net/oauth2/v2.0/token.php` |
| Revoke | `https://vte.mypantarei.net/oauth2/v2.0/revoke.php` |
| UserInfo | `https://vte.mypantarei.net/oauth2/v2.0/userinfo.php` |

## 4. Test curl (Client Credentials — solo smoke)

Dopo creazione app service account (se usata per test server-side):

```bash
curl -X POST 'https://vte.mypantarei.net/oauth2/v2.0/token.php' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -d 'grant_type=client_credentials&client_id=CLIENT_ID&client_secret=CLIENT_SECRET&scope=rest.all.read'
```

## 5. Test REST con Bearer

```bash
curl -X POST 'https://vte.mypantarei.net/restapi/v1/vtews/touch.get_todos' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer ACCESS_TOKEN' \
  -d '{"request":{}}'
```

## 6. QR setup aziendale

Genera JSON per gli utenti:

```json
{
  "vte_url": "https://vte.mypantarei.net",
  "client_id": "IL_TUO_CLIENT_ID"
}
```

Codifica in QR (qualsiasi generatore QR) → utente incolla JSON nelle impostazioni VTE Watch.

## 7. MFA

Con MFA utente attivo:

- **Access key:** bloccata da VTE
- **Password + OTP:** campo OTP nelle Settings App (`X-Otp` header)
- **OAuth:** login browser VTE gestisce MFA nativamente (preferito per store)

## Note Wilson / Touch

Wilson usa `touch.login` + Basic auth. VTE Watch MVP usa lo stesso flusso Touch.
Su `vte.mypantarei.net` il fix OAuth2+Basic per Wilson risulta già applicato.
