feat: add Go password session lifecycle

This commit is contained in:
zn-admin committed 2026-08-13 15:34:46 +08:00
1 parent 772795e7eb
commit d0207fcebe
19 files changed
+2483 -16

No files matched your search

+14 -11
View File
@@ -7,11 +7,13 @@ unchanged until later route-by-route cutover work passes the shared contracts.
Implemented Modules:
- `identity`: legacy `zhinian_session` HMAC/chunking plus database-refreshed
account, organization, role, and `sessionVersion` authorization.
- `postgres`: fail-closed configuration, verified-CA TLS, readiness, and calls
to the existing atomic claim and wallet PostgreSQL functions.
- `httpapi`: process health, database readiness, and current-session handlers.
- `identity`: legacy `zhinian_session` HMAC/chunking, database-refreshed
authorization, and the password-login lifecycle.
- `postgres`: fail-closed configuration, verified-CA TLS, readiness, atomic
password lockout transactions, and calls to the existing claim and wallet
PostgreSQL functions.
- `httpapi`: process health, database readiness, current-session, password
login, and logout handlers.
- `application`: composition and the `cmd/zhinian-api` process entry point.
From the repository root:
@@ -31,10 +33,11 @@ server, use a different port:
ZHINIAN_DATA_BACKEND=local GO_BACKEND_PORT=8080 ./backend/zhinian-api
```
`/api/health`, `/api/ready`, and `/api/auth/me` are implemented in the local Go
process. No Ingress, Docker, ACK, Secret, or Worker ownership has moved to Go
yet, so Next.js remains the production owner of every route.
`/api/health`, `/api/ready`, `/api/auth/me`, `/api/auth/password`, and
`/api/auth/logout` are implemented in the separately runnable Go process. No
Ingress, Docker, ACK, Secret, or Worker ownership has moved to Go yet, so
Next.js remains the production owner of every route.
The current-session handler reuses the Identity resolver and PostgreSQL
authorization-snapshot Adapter, but login, logout, password mutation, and
production route ownership remain with Next.js until later path-level cutover.
The authentication handlers reuse the shared Cookie contracts and PostgreSQL
Adapters. Self-service/admin password mutation and production route ownership
remain with Next.js until later path-level cutover.