Files
NianAIGC/.project-docs/30-worklog/tasks/20260814-go-bootstrap-admin-6e2b7d9c.md
T

49 lines
3.0 KiB
Markdown

# Task: Implement config-driven super-admin bootstrap in Go
## Identity
- Task ID: 20260814-go-bootstrap-admin-6e2b7d9c
- Mode: Feature
- Branch: main
- Worktree: /Users/brother7/Documents/AI/NianAIGC
- Base commit: 8affa4b25a93515547a5412d0cbd79dd9fcdc034
- Owner: dsh
- Status: Ready for Integration
## Scope
- Add config-driven first-super-administrator bootstrap to the Go backend, replacing the previous `scripts/bootstrap-admin.mjs` convention with startup-time creation from environment configuration.
- Human direction (2026-08-14): bootstrap credentials come from configuration, not a script or CLI step; there is no legacy account import requirement; production is a first deployment of the Go stack, not a cutover from a live Next.js deployment.
## Intent And Constraints
- Bootstrap only when the backend is PostgreSQL; local development keeps the seeded demo administrator.
- Create exactly once: skip when any super administrator exists, including disabled ones.
- Fail application startup on a misconfigured bootstrap (invalid phone, password shorter than 8 characters, database error) so the problem is visible instead of silently missing.
- Reuse the existing `administration.Service` validation, role model, and password hashing; no new store surface.
## Outcome
- Added `backend/internal/application/bootstrap_admin.go`:
- `BootstrapAdminConfig` with `Configured()`.
- `ParseBootstrapAdminConfig(getenv)` reading `ZHINIAN_BOOTSTRAP_ADMIN_PHONE`, `ZHINIAN_BOOTSTRAP_ADMIN_PASSWORD`, `ZHINIAN_BOOTSTRAP_ADMIN_NAME` (default `平台超级管理员`), mirroring the previous script variable names.
- `BootstrapSuperAdmin(ctx, backend, service, config)` performing the idempotent creation.
- Wired into `application.New` right after the administration service is composed; a successful bootstrap logs one line, a failure aborts startup with `bootstrap super administrator: ...`.
- Added `backend/internal/application/bootstrap_admin_test.go` with an in-memory fake store covering: config parsing/defaults, no-op without config, no-op on local backend, first-bootstrap creation with hashed password, second-run idempotency, skip when a disabled super admin exists, and short-password rejection.
- Documented the three variables and the startup behavior in `backend/README.md`.
## Verification
- `CGO_ENABLED=0 go test -count=1 ./...` — all 19 packages PASS (the local plain `go test` crashes with a macOS dyld `missing LC_UUID load command` issue unrelated to this change; the repository runner always uses `CGO_ENABLED=0`).
- `CGO_ENABLED=0 go vet ./...` — PASS.
- `CGO_ENABLED=0 go build ./cmd/zhinian-api` — PASS.
- `CGO_ENABLED=0 go test -race -count=1 ./internal/application/ -run Bootstrap` — PASS.
## Follow-ups
- Production schema initialization now happens by manually executed SQL instead of the ACK migration Job pod; see the 2026-08-14 human direction. Deployment guidance and canonical memory reconciliation for that change are tracked in the follow-up integration task.
## Promotion Candidates
- None; no canonical document changes in this task.