# Go backend foundation This directory contains the first implementation slice of ADR-003. It is a runnable compatibility foundation, but it is **not** the current production API owner: Next.js, the Node Worker, Docker Compose, and the ACK manifests remain unchanged until later route-by-route cutover work passes the shared contracts. Implemented Modules: - `identity`: legacy `zhinian_session` HMAC/chunking plus database-refreshed account, organization, role, and `sessionVersion` authorization. - `postgres`: fail-closed configuration, verified-CA TLS, readiness, and calls to the existing atomic claim and wallet PostgreSQL functions. - `httpapi`: process health, database readiness, and current-session handlers. - `application`: composition and the `cmd/zhinian-api` process entry point. From the repository root: ```bash npm run go:fmt npm run go:test npm run go:vet npm run go:build ``` The runner defaults to `CGO_ENABLED=0` for reproducible cross-platform builds. To exercise the local foundation manually without changing the existing Next server, use a different port: ```bash ZHINIAN_DATA_BACKEND=local GO_BACKEND_PORT=8080 ./backend/zhinian-api ``` `/api/health`, `/api/ready`, and `/api/auth/me` are implemented in the local Go process. No Ingress, Docker, ACK, Secret, or Worker ownership has moved to Go yet, so Next.js remains the production owner of every route. The current-session handler reuses the Identity resolver and PostgreSQL authorization-snapshot Adapter, but login, logout, password mutation, and production route ownership remain with Next.js until later path-level cutover.