feat: add Go current-session HTTP adapter

This commit is contained in:
zn-admin committed 2026-08-13 13:39:41 +08:00
1 parent c849077591
commit 772795e7eb
10 files changed
+1608 -7

No files matched your search

@@ -0,0 +1,85 @@
# Task: Implement Go current-session HTTP adapter
## Identity
- Task ID: 20260813-go-auth-me-http-8d6f3a21
- Mode: Feature
- Branch: codex/20260813-go-auth-me-http-8d6f3a21-go-auth-me-http
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-me-8d6f3a21
- Base commit: c8490775916c46141e06e3a86ea5bb76eb8c3f1d
- Owner: codex
- Status: Ready for Integration
## Scope
- Freeze the current `GET /api/auth/me` response and transport behavior in a language-neutral contract consumed by TypeScript and Go tests.
- Add a Go HTTP Identity Adapter that reassembles the legacy chunked Cookie, delegates authorization to the existing deep Identity Resolver, and returns the current public session projection.
- Compose the Adapter into the runnable Go process for local/black-box verification while leaving Next.js, Ingress, Docker, ACK manifests, and production route ownership unchanged.
- Keep login, logout, password mutation, authorization policy for other routes, Middleware replacement, and production traffic cutover outside this slice.
## Intent And Constraints
- Use the external HTTP Interface and the existing `identity.Resolver.Resolve` Interface as the two agreed TDD seams; do not test private helper structure.
- Preserve the current `/api/auth/me` anonymous behavior: invalid, absent, expired, stale, disabled, or unauthorized sessions return HTTP 200 with `authenticated: false`, not 401.
- Preserve database/configuration failures as server failures rather than disguising them as anonymous sessions.
- Reuse the exact 20-name Cookie reassembly contract and database-authoritative session refresh; do not parse raw Cookie claims in the HTTP Module.
- Preserve `authRequired` and `authConfigured` semantics and the public user projection without exposing access tokens, token type, session version, or internal rejection reasons.
- Preserve Next.js method behavior: `HEAD` executes the GET path without a response body, `OPTIONS` returns 204 with `Allow: GET, HEAD, OPTIONS`, and unsupported standard methods return an empty 405 without `Allow`.
- Preserve the pinned Next.js parser's last-value-wins behavior for duplicate protected Cookie names, and treat reassembled values above the existing 60,000-character writer ceiling as anonymous before Resolver invocation.
- Keep ACK-001 deploy truth and all production path routing unchanged; the Go route remains unrouted externally in this task.
## Outcome
- Added `contracts/auth/current-session-v1.json` as the language-neutral v1
contract for `/api/auth/me`: runtime auth configuration, method/status/header
behavior, anonymous and database-refreshed public projections, sensitive
session-field exclusion, and infrastructure-failure classification.
- Added a TypeScript contract consumer over the real auth config and App Route
`GET`, plus the pinned Next.js automatic method implementation for
`HEAD`/`OPTIONS`/unsupported methods.
- Added the Go `httpapi.NewAuthMeHandler` deep HTTP Module. It owns exact Cookie
chunk reassembly, Next-compatible duplicate-name handling, the 60,000-byte
reader guard, Identity Resolver error classification, method handling, and a
whitelist-only public response projection.
- Added an exact Go auth-config parser and application composition from
environment -> PostgreSQL Adapter -> Identity Resolver -> auth/me Handler.
Application tests prove a signed Cookie is refreshed from the persistence
snapshot and cannot preserve forged role/profile claims or leak token/session
metadata.
- Kept the Next.js route, Middleware, Docker, Compose, ACK manifests, Worker,
Secrets, and all production routing unchanged. The Go endpoint is runnable
only on the separate local process until a later path-level cutover.
## Verification
- TDD RED: the Go HTTP tests initially failed to compile because
`AuthState`, `SessionResolver`, and `NewAuthMeHandler` did not exist; the
application tests then failed before auth config and route composition were
implemented. Focused tests passed after each implementation slice.
- `npm test -- --reporter=dot`: 37 files and 141 tests passed.
- `npm run go:test`: all five Go packages passed.
- `npm run go:vet`: passed.
- `npm run go:build`: passed for `./cmd/zhinian-api`.
- `npx tsc --noEmit --incremental false --pretty false`: passed after the
concurrent `next build` process finished regenerating `.next/types`.
- `npm run build`: Next.js 15.5.18 production build passed with all 33 pages.
- `npm run deploy:check`: all 8 ACK manifest assertions passed.
- `git diff --check`, `gofmt -l backend`, project-docs validation, task doc
drift, and the forbidden production-routing diff check all passed.
## Follow-ups
- Add a local-account authorization snapshot Adapter if authenticated local-mode
Go development is required; today a configured valid Cookie on the local
backend fails with an explicit 500 rather than silently trusting claims.
- Add real PostgreSQL/RDS and verified-CA transport integration coverage before
any production auth route cutover.
- Migrate login, logout, password mutation, Middleware enforcement, and other
protected routes in later independently contract-tested slices.
## Promotion Candidates
- Promote `contracts/auth/current-session-v1.json` as the current-session HTTP
compatibility truth when the task is integrated.
- Record that the Go application can serve `/api/auth/me` locally while ACK-001
and all production route ownership remain with Next.js.