Add local auth: users, sessions, register/login/logout/me (#4)
Implements pansy's local (email + password) authentication and the session layer that OIDC (#5) will also reuse. - store: users.go (create/get-by-id/get-by-email/count) and sessions.go (create/get/touch/delete/delete-expired), scanning the existing 0001 schema. - service: the business-logic seam. auth.go (Register/Login/session lifecycle/Providers) + password.go (argon2id, 64 MiB/1/4, PHC-encoded, constant-time verify) + service.go (Service, clock injection, token hashing). First user is admin; closed registration still allows the bootstrap user; unknown-email and wrong-password are indistinguishable (same error, same argon2 work via a dummy hash). - api: POST /auth/register|login|logout, GET /auth/me|providers, plus a requireAuth middleware that resolves the HttpOnly session cookie (SameSite=Lax, Secure under https) to the actor. Handlers stay thin. - main: wires the service and a periodic expired-session sweep; sessions are also dropped lazily on access. Sliding 30-day expiry. - tests: service (register/login/expiry/renewal/cleanup, password) and api (cookie flow, middleware, validation, providers). Verified end-to-end via curl: register -> me -> restart -> session persists -> logout -> 401. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01JdQpdYYsTgtkJBxbcpAszi
This commit is contained in:
+24
-4
@@ -13,13 +13,21 @@ import (
|
||||
sloggin "github.com/samber/slog-gin"
|
||||
|
||||
"gitea.stevedudenhoeffer.com/steve/pansy/internal/config"
|
||||
"gitea.stevedudenhoeffer.com/steve/pansy/internal/service"
|
||||
)
|
||||
|
||||
// handlers carries the dependencies shared by every HTTP handler. Handlers stay
|
||||
// thin: decode the request, call a service method, encode the result.
|
||||
type handlers struct {
|
||||
cfg *config.Config
|
||||
svc *service.Service
|
||||
}
|
||||
|
||||
// New builds the gin engine with the standard middleware stack and registers the
|
||||
// API routes. The embedded SPA fallback is registered separately by the caller
|
||||
// via RegisterSPA (see spa.go) so the API can be built and tested without a web
|
||||
// build present.
|
||||
func New(cfg *config.Config) *gin.Engine {
|
||||
// API routes against the given service. The embedded SPA fallback is registered
|
||||
// separately by the caller via RegisterSPA (see spa.go) so the API can be built
|
||||
// and tested without a web build present.
|
||||
func New(cfg *config.Config, svc *service.Service) *gin.Engine {
|
||||
gin.SetMode(gin.ReleaseMode)
|
||||
|
||||
r := gin.New()
|
||||
@@ -33,9 +41,21 @@ func New(cfg *config.Config) *gin.Engine {
|
||||
_ = r.SetTrustedProxies(nil)
|
||||
}
|
||||
|
||||
h := &handlers{cfg: cfg, svc: svc}
|
||||
|
||||
v1 := r.Group("/api/v1")
|
||||
v1.GET("/healthz", healthz)
|
||||
|
||||
// Auth endpoints are exempt from requireAuth (you can't be logged in yet);
|
||||
// /me is the one that needs a session. Feature routers in later issues attach
|
||||
// h.requireAuth() to their own protected groups.
|
||||
auth := v1.Group("/auth")
|
||||
auth.POST("/register", h.register)
|
||||
auth.POST("/login", h.login)
|
||||
auth.POST("/logout", h.logout)
|
||||
auth.GET("/providers", h.providers)
|
||||
auth.GET("/me", h.requireAuth(), h.me)
|
||||
|
||||
return r
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user