feat: add database-refreshed identity authorization

This commit is contained in:
zn-admin committed 2026-08-13 11:56:36 +08:00
1 parent 716a8031b1
commit c849077591
12 files changed
+1809 -15

No files matched your search

+6 -1
View File
@@ -7,7 +7,8 @@ unchanged until later route-by-route cutover work passes the shared contracts.
Implemented Modules:
- `identity`: legacy `zhinian_session` HMAC, parsing, and chunking contract.
- `identity`: legacy `zhinian_session` HMAC/chunking plus database-refreshed
account, organization, role, and `sessionVersion` authorization.
- `postgres`: fail-closed configuration, verified-CA TLS, readiness, and calls
to the existing atomic claim and wallet PostgreSQL functions.
- `httpapi`: process health and database readiness handlers.
@@ -32,3 +33,7 @@ ZHINIAN_DATA_BACKEND=local GO_BACKEND_PORT=8080 ./backend/zhinian-api
Only `/api/health` and `/api/ready` are implemented in this foundation. No
Ingress, Docker, ACK, Secret, or Worker ownership has moved to Go yet.
The Identity resolver and PostgreSQL authorization-snapshot Adapter are
implemented and tested, but no Go login or current-user HTTP route is exposed
yet. Route ownership remains with Next.js until a later path-level cutover.