Add local auth: users, sessions, register/login/logout/me (#4)
Implements pansy's local (email + password) authentication and the session layer that OIDC (#5) will also reuse. - store: users.go (create/get-by-id/get-by-email/count) and sessions.go (create/get/touch/delete/delete-expired), scanning the existing 0001 schema. - service: the business-logic seam. auth.go (Register/Login/session lifecycle/Providers) + password.go (argon2id, 64 MiB/1/4, PHC-encoded, constant-time verify) + service.go (Service, clock injection, token hashing). First user is admin; closed registration still allows the bootstrap user; unknown-email and wrong-password are indistinguishable (same error, same argon2 work via a dummy hash). - api: POST /auth/register|login|logout, GET /auth/me|providers, plus a requireAuth middleware that resolves the HttpOnly session cookie (SameSite=Lax, Secure under https) to the actor. Handlers stay thin. - main: wires the service and a periodic expired-session sweep; sessions are also dropped lazily on access. Sliding 30-day expiry. - tests: service (register/login/expiry/renewal/cleanup, password) and api (cookie flow, middleware, validation, providers). Verified end-to-end via curl: register -> me -> restart -> session persists -> logout -> 401. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01JdQpdYYsTgtkJBxbcpAszi
This commit is contained in:
@@ -17,6 +17,24 @@ var (
|
||||
// ErrVersionConflict means the row's version did not match the one supplied
|
||||
// with a PATCH/DELETE; the caller should refetch and retry.
|
||||
ErrVersionConflict = errors.New("version conflict")
|
||||
|
||||
// ErrInvalidInput means the caller supplied structurally invalid data (empty
|
||||
// required field, malformed value). Mapped to 400.
|
||||
ErrInvalidInput = errors.New("invalid input")
|
||||
// ErrInvalidCredentials means a login attempt failed. It is deliberately
|
||||
// identical for an unknown email and a wrong password so neither can be
|
||||
// enumerated. Mapped to 401.
|
||||
ErrInvalidCredentials = errors.New("invalid credentials")
|
||||
// ErrEmailTaken means registration collided with an existing account's email.
|
||||
// Mapped to 409.
|
||||
ErrEmailTaken = errors.New("email already registered")
|
||||
// ErrRegistrationClosed means local self-service signup is disabled and at
|
||||
// least one user already exists (the very first user may always register to
|
||||
// bootstrap the instance). Mapped to 403.
|
||||
ErrRegistrationClosed = errors.New("registration closed")
|
||||
// ErrLocalAuthDisabled means PANSY_LOCAL_AUTH=false, so local register/login
|
||||
// are rejected in favor of OIDC. Mapped to 403.
|
||||
ErrLocalAuthDisabled = errors.New("local authentication disabled")
|
||||
)
|
||||
|
||||
// Enumerated string values mirrored from the schema CHECK constraints.
|
||||
|
||||
Reference in New Issue
Block a user