feat: add Go password session lifecycle
This commit is contained in:
@@ -0,0 +1,59 @@
|
||||
# Task: Implement Go password session lifecycle vertical slice
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260813-go-auth-lifecycle-3f9a6c12
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260813-go-auth-lifecycle-3f9a6c12-go-auth-lifecycle
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC-go-auth-lifecycle-3f9a6c12
|
||||
- Base commit: 772795e7ebd519441d98111e555288d56b75032b
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Freeze the current platform password-login and logout HTTP/session lifecycle in language-neutral contracts consumed by TypeScript and Go tests.
|
||||
- Add a deep Go Password Login Module that normalizes credentials, delegates one atomic login attempt, and creates the legacy version-one platform session.
|
||||
- Add a PostgreSQL Adapter that preserves the existing per-account `FOR UPDATE` transaction, failed-attempt lockout, successful-state reset, organization checks, and scrypt password compatibility.
|
||||
- Add Go HTTP Adapters for `POST /api/auth/password` and `GET|POST /api/auth/logout`, then compose them into the separately runnable Go process without moving production traffic.
|
||||
- Keep self-service/admin password mutation, account administration, captcha/login redirect routes, Middleware replacement, local JSON authentication, and production cutover outside this slice.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Use the external HTTP Handler, the Password Login Module's single `Login` Interface, and one atomic persistence `AttemptPasswordLogin` Interface as the agreed TDD seams.
|
||||
- Preserve existing Cookie wire/chunk/attribute/TTL behavior and database-authoritative role/profile/sessionVersion claims; never expose hashes, salts, counters, tokens, or internal errors.
|
||||
- Preserve PostgreSQL single-writer semantics: lock the account row; commit each failed-password transition; return 401 for failures one through four; on the fifth set a 15-minute lock, reset the counter to zero, commit, then return 423; successful login clears lock/fail state and updates `last_login_at` without rotating `session_version`.
|
||||
- Preserve account and active-organization enforcement, while applying the already accepted rule that every non-super-admin must have a matching active organization.
|
||||
- Match the existing Node scrypt format exactly (`N=16384`, `r=8`, `p=1`, key length 64; UTF-8 password and salt string; lowercase hex hash) so existing accounts can log in.
|
||||
- Preserve the password route's request normalization, safe local redirect behavior, stable public response, 30-attempt per-process IP limiter, and configuration/error status mapping. Infrastructure or Cookie-writing failures remain server failures and must not masquerade as invalid credentials.
|
||||
- Preserve logout's stateless 307 redirect and complete legacy Cookie clearing. No database session revocation is added.
|
||||
- Keep ACK-001, Next.js Route Handlers, Docker/Compose/ACK/Ingress, Worker, Secrets, and production route ownership unchanged; do not dual-write login state in production.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added language-neutral password-login and logout HTTP/session contracts, with real TypeScript Route Handler consumers and Go black-box Handler consumers.
|
||||
- Added the Go Password Login Module, which normalizes public credentials, delegates one atomic attempt, enforces exact platform role/organization rules, and creates a database-authoritative version-one session with a 24-hour lifetime.
|
||||
- Added the PostgreSQL credential Adapter with an account-row `FOR UPDATE` transaction, Node-compatible scrypt verification, committed failed-attempt transitions, fifth-attempt lockout, and successful state reset.
|
||||
- Added Go HTTP Adapters for password login and logout, including safe redirects, public response projection, per-IP throttling, complete signed/chunked Cookie writes, generic infrastructure failures, and all 20 legacy Cookie clears.
|
||||
- Composed the two routes into the separately runnable Go process and updated its README. Next.js, Node Worker, Docker, ACK, Ingress, Secrets, and production route ownership remain unchanged.
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm test`: PASS, 39 files and 148 tests.
|
||||
- `npx tsc --noEmit --incremental false --pretty false`: PASS.
|
||||
- `npm run go:test`: PASS across command, application, HTTP, Identity, and PostgreSQL packages.
|
||||
- `npm run go:vet`: PASS.
|
||||
- `npm run go:build`: PASS.
|
||||
- `npm run build`: PASS; only the pre-existing multiple-lockfile workspace-root warning was emitted.
|
||||
- `npm run deploy:check`: PASS for all eight ACK manifests.
|
||||
- `gofmt -l backend`, `git diff --check`, and the production deployment/routing forbidden-scope diff: PASS.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Exercise the PostgreSQL login transaction and verified-TLS path against a migrated non-production RDS instance before any path cutover.
|
||||
- Decide whether organization status reads need an explicit row lock after measuring the real administration/login concurrency pattern; this slice intentionally matches the current transaction behavior.
|
||||
- Migrate self-service and administrative password mutation in a later bounded slice.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
Reference in New Issue
Block a user