Files
browser/openspec/changes/fix-platform-auth-session-api/design.md
T
2026-07-11 14:56:10 +08:00

1.1 KiB

Design

  • Sessions are in-memory platform sessions keyed by a random bearer token. Clients send the token as Authorization: Bearer <token>.
  • The local development platform seeds one explicit platform administrator account so real login can reach the admin console:
    • account/email: operator.local@example.test
    • password: operator-local
  • Passwords are stored as PBKDF2-SHA256 hashes with per-user salts using only Go standard library primitives.
  • Public registration creates a pending user with server-admin role and returns status=pending rather than authenticating the user.
  • Current-user profile and theme updates operate only on the authenticated session user and return bounded DTOs.
  • User management updates reuse PUT /api/v1/users/{id} and allow status, roles, display name, email, and profile fields to be changed through service validation.

Security Notes

  • Password hashes are not returned in DTOs.
  • Pending/disabled users cannot log in.
  • The frontend local fallback is disabled unless VITE_ENABLE_LOCAL_AUTH_FALLBACK=true, and its fallback user is not a platform admin.