feat: add shared backend authorization seams

This commit is contained in:
zn-admin committed 2026-08-13 16:03:20 +08:00
1 parent d0207fcebe
commit 48dd5d07c8
9 files changed
+1086

No files matched your search

@@ -0,0 +1,69 @@
# Task: Complete remaining Go backend modules
## Identity
- Task ID: 20260813-go-remaining-modules-7d3a9e42
- Mode: Feature
- Branch: codex/20260813-go-remaining-modules-7d3a9e42-go-remaining-modules
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-remaining-7d3a9e42
- Base commit: d0207fcebe6ea4fb3ba80dce8c012b3c2170de40
- Owner: codex
- Status: Planning
## Scope
- Complete every ADR-003 Go backend module that remains after the foundation,
database-refreshed identity, current-session HTTP, and password
login/logout slices already present at the task base.
- Freeze language-neutral compatibility contracts before each remaining
vertical slice and keep the TypeScript implementation as an executable
source-of-truth consumer until cutover.
- Implement the remaining Identity and Administration behavior; Assets and
storage/file serving; Billing and Usage; Jobs, providers, Webhooks, and the
embedded WorkerLoop; and the remaining public/compatibility HTTP surface.
- Compose all migrated routes into the separately runnable Go application and
prove route-surface coverage without moving production traffic.
- Keep production cutover, Next Route Handler deletion, Node Worker drain,
Docker/ACK/Ingress ownership changes, and real RDS/OSS rollout outside this
feature task.
## Intent And Constraints
- Follow vertical red-green TDD at stable external HTTP Interfaces and deep
domain/Adapter seams; do not create one shallow repository Interface per
table.
- Preserve current same-origin paths, method/status/JSON behavior, Cookie and
tenant authorization, owner-scoped not-found behavior, idempotency, job
state, wallet arithmetic, storage metadata, provider, and Webhook semantics.
- Keep PostgreSQL as the production source of relational truth and continue
using `claim_generation_jobs` and `billing_post_wallet_entry` for
cross-instance concurrency. Never replace them with process-local locks.
- Keep one owner for external side effects and every write path. The Go
implementation remains locally runnable and contract-tested but unrouted in
production until a later explicit cutover.
- Keep Alibaba Cloud OSS behind an object-storage Adapter and retain an
explicit local-development Adapter; do not claim horizontal production
safety until real OSS and RDS/TLS checks pass.
- Preserve the currently deployed ACK-001 Web/HTTP-polling-Worker topology and
all production Secrets/manifests during this implementation task.
- Work only in the owned worktree and task record; canonical project memory is
reserved for a serialized Integration Gate.
## Outcome
- Not completed.
## Verification
- Not run.
## Follow-ups
- Validate the complete backend against migrated non-production RDS with the
real application role and verified-CA TLS before production cutover.
- Validate OSS compatibility, provider credentials, external Webhooks, Worker
drain/recovery, and rollout/rollback against production-like infrastructure.
## Promotion Candidates
- None recorded.