feat: add Go current-session HTTP adapter
This commit is contained in:
1 parent
c849077591
commit
772795e7eb
10 files changed
+1608
-7
No files matched your search
@@ -0,0 +1,85 @@
|
||||
# Task: Implement Go current-session HTTP adapter
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-auth-me-http-8d6f3a21
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-auth-me-http-8d6f3a21-go-auth-me-http
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-me-8d6f3a21
|
||||
- Base commit: c8490775916c46141e06e3a86ea5bb76eb8c3f1d
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Freeze the current `GET /api/auth/me` response and transport behavior in a language-neutral contract consumed by TypeScript and Go tests.
|
||||
- Add a Go HTTP Identity Adapter that reassembles the legacy chunked Cookie, delegates authorization to the existing deep Identity Resolver, and returns the current public session projection.
|
||||
- Compose the Adapter into the runnable Go process for local/black-box verification while leaving Next.js, Ingress, Docker, ACK manifests, and production route ownership unchanged.
|
||||
- Keep login, logout, password mutation, authorization policy for other routes, Middleware replacement, and production traffic cutover outside this slice.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Use the external HTTP Interface and the existing `identity.Resolver.Resolve` Interface as the two agreed TDD seams; do not test private helper structure.
|
||||
- Preserve the current `/api/auth/me` anonymous behavior: invalid, absent, expired, stale, disabled, or unauthorized sessions return HTTP 200 with `authenticated: false`, not 401.
|
||||
- Preserve database/configuration failures as server failures rather than disguising them as anonymous sessions.
|
||||
- Reuse the exact 20-name Cookie reassembly contract and database-authoritative session refresh; do not parse raw Cookie claims in the HTTP Module.
|
||||
- Preserve `authRequired` and `authConfigured` semantics and the public user projection without exposing access tokens, token type, session version, or internal rejection reasons.
|
||||
- Preserve Next.js method behavior: `HEAD` executes the GET path without a response body, `OPTIONS` returns 204 with `Allow: GET, HEAD, OPTIONS`, and unsupported standard methods return an empty 405 without `Allow`.
|
||||
- Preserve the pinned Next.js parser's last-value-wins behavior for duplicate protected Cookie names, and treat reassembled values above the existing 60,000-character writer ceiling as anonymous before Resolver invocation.
|
||||
- Keep ACK-001 deploy truth and all production path routing unchanged; the Go route remains unrouted externally in this task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added `contracts/auth/current-session-v1.json` as the language-neutral v1
|
||||
contract for `/api/auth/me`: runtime auth configuration, method/status/header
|
||||
behavior, anonymous and database-refreshed public projections, sensitive
|
||||
session-field exclusion, and infrastructure-failure classification.
|
||||
- Added a TypeScript contract consumer over the real auth config and App Route
|
||||
`GET`, plus the pinned Next.js automatic method implementation for
|
||||
`HEAD`/`OPTIONS`/unsupported methods.
|
||||
- Added the Go `httpapi.NewAuthMeHandler` deep HTTP Module. It owns exact Cookie
|
||||
chunk reassembly, Next-compatible duplicate-name handling, the 60,000-byte
|
||||
reader guard, Identity Resolver error classification, method handling, and a
|
||||
whitelist-only public response projection.
|
||||
- Added an exact Go auth-config parser and application composition from
|
||||
environment -> PostgreSQL Adapter -> Identity Resolver -> auth/me Handler.
|
||||
Application tests prove a signed Cookie is refreshed from the persistence
|
||||
snapshot and cannot preserve forged role/profile claims or leak token/session
|
||||
metadata.
|
||||
- Kept the Next.js route, Middleware, Docker, Compose, ACK manifests, Worker,
|
||||
Secrets, and all production routing unchanged. The Go endpoint is runnable
|
||||
only on the separate local process until a later path-level cutover.
|
||||
|
||||
## Verification
|
||||
|
||||
- TDD RED: the Go HTTP tests initially failed to compile because
|
||||
`AuthState`, `SessionResolver`, and `NewAuthMeHandler` did not exist; the
|
||||
application tests then failed before auth config and route composition were
|
||||
implemented. Focused tests passed after each implementation slice.
|
||||
- `npm test -- --reporter=dot`: 37 files and 141 tests passed.
|
||||
- `npm run go:test`: all five Go packages passed.
|
||||
- `npm run go:vet`: passed.
|
||||
- `npm run go:build`: passed for `./cmd/zhinian-api`.
|
||||
- `npx tsc --noEmit --incremental false --pretty false`: passed after the
|
||||
concurrent `next build` process finished regenerating `.next/types`.
|
||||
- `npm run build`: Next.js 15.5.18 production build passed with all 33 pages.
|
||||
- `npm run deploy:check`: all 8 ACK manifest assertions passed.
|
||||
- `git diff --check`, `gofmt -l backend`, project-docs validation, task doc
|
||||
drift, and the forbidden production-routing diff check all passed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Add a local-account authorization snapshot Adapter if authenticated local-mode
|
||||
Go development is required; today a configured valid Cookie on the local
|
||||
backend fails with an explicit 500 rather than silently trusting claims.
|
||||
- Add real PostgreSQL/RDS and verified-CA transport integration coverage before
|
||||
any production auth route cutover.
|
||||
- Migrate login, logout, password mutation, Middleware enforcement, and other
|
||||
protected routes in later independently contract-tested slices.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Promote `contracts/auth/current-session-v1.json` as the current-session HTTP
|
||||
compatibility truth when the task is integrated.
|
||||
- Record that the Go application can serve `/api/auth/me` locally while ACK-001
|
||||
and all production route ownership remain with Next.js.
|
||||
Reference in new issue
Block a user