feat: add config-driven super-admin bootstrap to Go backend
This commit is contained in:
1 parent
8affa4b25a
commit
ff055c972d
5 files changed
+345
No files matched your search
@@ -0,0 +1,48 @@
|
||||
# Task: Implement config-driven super-admin bootstrap in Go
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260814-go-bootstrap-admin-6e2b7d9c
|
||||
- Mode: Feature
|
||||
- Branch: main
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC
|
||||
- Base commit: 8affa4b25a93515547a5412d0cbd79dd9fcdc034
|
||||
- Owner: dsh
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Add config-driven first-super-administrator bootstrap to the Go backend, replacing the previous `scripts/bootstrap-admin.mjs` convention with startup-time creation from environment configuration.
|
||||
- Human direction (2026-08-14): bootstrap credentials come from configuration, not a script or CLI step; there is no legacy account import requirement; production is a first deployment of the Go stack, not a cutover from a live Next.js deployment.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Bootstrap only when the backend is PostgreSQL; local development keeps the seeded demo administrator.
|
||||
- Create exactly once: skip when any super administrator exists, including disabled ones.
|
||||
- Fail application startup on a misconfigured bootstrap (invalid phone, password shorter than 8 characters, database error) so the problem is visible instead of silently missing.
|
||||
- Reuse the existing `administration.Service` validation, role model, and password hashing; no new store surface.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added `backend/internal/application/bootstrap_admin.go`:
|
||||
- `BootstrapAdminConfig` with `Configured()`.
|
||||
- `ParseBootstrapAdminConfig(getenv)` reading `ZHINIAN_BOOTSTRAP_ADMIN_PHONE`, `ZHINIAN_BOOTSTRAP_ADMIN_PASSWORD`, `ZHINIAN_BOOTSTRAP_ADMIN_NAME` (default `平台超级管理员`), mirroring the previous script variable names.
|
||||
- `BootstrapSuperAdmin(ctx, backend, service, config)` performing the idempotent creation.
|
||||
- Wired into `application.New` right after the administration service is composed; a successful bootstrap logs one line, a failure aborts startup with `bootstrap super administrator: ...`.
|
||||
- Added `backend/internal/application/bootstrap_admin_test.go` with an in-memory fake store covering: config parsing/defaults, no-op without config, no-op on local backend, first-bootstrap creation with hashed password, second-run idempotency, skip when a disabled super admin exists, and short-password rejection.
|
||||
- Documented the three variables and the startup behavior in `backend/README.md`.
|
||||
|
||||
## Verification
|
||||
|
||||
- `CGO_ENABLED=0 go test -count=1 ./...` — all 19 packages PASS (the local plain `go test` crashes with a macOS dyld `missing LC_UUID load command` issue unrelated to this change; the repository runner always uses `CGO_ENABLED=0`).
|
||||
- `CGO_ENABLED=0 go vet ./...` — PASS.
|
||||
- `CGO_ENABLED=0 go build ./cmd/zhinian-api` — PASS.
|
||||
- `CGO_ENABLED=0 go test -race -count=1 ./internal/application/ -run Bootstrap` — PASS.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Production schema initialization now happens by manually executed SQL instead of the ACK migration Job pod; see the 2026-08-14 human direction. Deployment guidance and canonical memory reconciliation for that change are tracked in the follow-up integration task.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None; no canonical document changes in this task.
|
||||
Reference in new issue
Block a user