fix: route authenticated SSR through Go
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
# Task: Fix authenticated SSR through Go identity boundary
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260816-fix-authenticated-ssr-6c3f8a21
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260816-fix-authenticated-ssr-6c3f8a21-fix-authenticated-ssr
|
||||
- Worktree: D:\Datas\OthersProjects\NianAIGC-fix-authenticated-ssr-6c3f8a21
|
||||
- Base commit: b26f9679abc343beb64142694add9154a6885b04
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Fix authenticated Next.js SSR in the split production topology by moving per-request session refresh across the internal Go `/api/auth/me` HTTP boundary.
|
||||
- Add a regression test at the exported `getShellAuthState()` seam and strengthen ACK deployment assertions for the internal Go URL.
|
||||
- Preserve the existing direct-store path when the internal Go URL is absent so local Next.js full-stack development and tests remain supported.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Keep the Next production workload database-free; do not restore `ZHINIAN_DATA_BACKEND`, `DATABASE_URL`, RDS CA, or business credentials to Web.
|
||||
- Preserve signed chunked `zhinian_session` Cookie behavior and per-request account, organization, role, and sessionVersion revalidation in Go.
|
||||
- Forward only the session Cookie chunks to the internal service; never forward unrelated browser Cookies or expose the internal URL to client code.
|
||||
- Fail closed on internal identity transport, status, or response-shape errors; do not silently treat infrastructure failure as anonymous.
|
||||
- Work test-first at the `getShellAuthState()` boundary and keep changes surgical.
|
||||
|
||||
## Outcome
|
||||
|
||||
- `getOptionalAuthSession()` now keeps local full-stack behavior when no internal URL is configured, but in the split production topology it sends only the enumerated `zhinian_session` Cookie chunks to the internal Go `GET /api/auth/me` endpoint.
|
||||
- The Go response is validated before it can rebuild the server-side session. Authenticated responses require a configured platform identity, an active valid role, matching subject and account IDs, role-consistent auth mode, and organization binding for non-super-admin roles; only allowlisted user fields are retained. Anonymous responses return no session, while transport, non-success status, malformed payload, or identity mismatch errors fail closed.
|
||||
- ACK Web runtime configuration now supplies `ZHINIAN_GO_INTERNAL_BASE_URL=http://zhinian-go-api:8080`; the value remains server-only and Web remains database-free.
|
||||
- The manifest checker now pins the internal URL to the Go Service name and port and guards against reintroducing database configuration into Web.
|
||||
- Added a public-seam regression test for `getShellAuthState()` covering refreshed authenticated state, Cookie allowlisting, anonymous rejection, upstream failure, malformed payloads, and six privilege-boundary response variants found during final review.
|
||||
|
||||
## Verification
|
||||
|
||||
- RED: `cmd /c npx.cmd vitest run tests/auth-current-user-go-bridge.test.ts` failed before the implementation because authenticated SSR entered the Next database store and raised `ZHINIAN_DATA_BACKEND must be explicitly set...`.
|
||||
- First review RED: the six strict identity cases resolved instead of rejecting before the response validator was tightened; the missing-role case demonstrated authority fallback granting both admin and super-admin shell state.
|
||||
- GREEN: `cmd /c npx.cmd vitest run tests/auth-current-user-go-bridge.test.ts` — 1 file and 10 tests passed.
|
||||
- `cmd /c npx.cmd tsc --noEmit --incremental false` — passed.
|
||||
- `cmd /c npm.cmd test` — 58 files and 183 tests passed.
|
||||
- `cmd /c npm.cmd run deploy:check` — `ACK manifest assertions passed (9 files)`.
|
||||
- `cmd /c npm.cmd run build` — Next.js 15.5.18 production build passed; `/create` remains dynamically server-rendered.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Build and publish updated Web and deployment artifacts, apply them to the ACK cluster, then smoke-test an authenticated `/create` request. No live deployment was performed by this task.
|
||||
- Run a server-side ACK dry-run when cluster access is available; local verification is limited to repository tests and static manifest assertions.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. This change implements the already accepted Next.js-to-Go SSR identity boundary and does not introduce a new canonical architecture decision.
|
||||
Reference in New Issue
Block a user