feat: add Go password session lifecycle

This commit is contained in:
2026-08-13 15:34:46 +08:00
parent 772795e7eb
commit d0207fcebe
19 changed files with 2483 additions and 16 deletions

View File

@@ -19,6 +19,9 @@ type Options struct {
// composition tests and alternate runtime backends. Production defaults to
// the PostgreSQL Store opened below.
AuthorizationLoader identity.AuthorizationSnapshotLoader
// CredentialAuthenticator is the narrow Password Login persistence seam.
// Production defaults to the same PostgreSQL Store used for authorization.
CredentialAuthenticator identity.CredentialAuthenticator
}
type App struct {
@@ -73,9 +76,34 @@ func New(options Options) (*App, error) {
if err != nil {
return nil, err
}
var passwordIssuer httpapi.PasswordSessionIssuer
if authConfig.Configured {
authenticator := options.CredentialAuthenticator
if authenticator == nil {
authenticator = database.Store
}
passwordIssuer = identity.NewPasswordLogin(authenticator, nil)
}
cookieSecure := getenv("ZHINIAN_AUTH_COOKIE_SECURE")
publicBaseURL := firstAuthEnv(getenv, "NEXT_PUBLIC_APP_URL", "ZHINIAN_PUBLIC_BASE_URL")
authPassword, err := httpapi.NewAuthPasswordHandler(httpapi.PasswordAuthConfig{
Configured: authConfig.Configured,
SessionSecret: authConfig.SessionSecret,
CookieSecure: cookieSecure,
PublicBaseURL: publicBaseURL,
}, passwordIssuer)
if err != nil {
return nil, err
}
authLogout := httpapi.NewAuthLogoutHandler(httpapi.LogoutConfig{
CookieSecure: cookieSecure,
PublicBaseURL: publicBaseURL,
})
foundation := httpapi.NewHandler(readiness)
mux := http.NewServeMux()
mux.Handle("/api/auth/me", authMe)
mux.Handle("/api/auth/password", authPassword)
mux.Handle("/api/auth/logout", authLogout)
mux.Handle("/", foundation)
closeOnError = false
return &App{