1.1 KiB
1.1 KiB
Design
- Sessions are in-memory platform sessions keyed by a random bearer token. Clients send the token as
Authorization: Bearer <token>. - The local development platform seeds one explicit platform administrator account so real login can reach the admin console:
- account/email:
operator.local@example.test - password:
operator-local
- account/email:
- Passwords are stored as PBKDF2-SHA256 hashes with per-user salts using only Go standard library primitives.
- Public registration creates a pending user with
server-adminrole and returnsstatus=pendingrather than authenticating the user. - Current-user profile and theme updates operate only on the authenticated session user and return bounded DTOs.
- User management updates reuse
PUT /api/v1/users/{id}and allow status, roles, display name, email, and profile fields to be changed through service validation.
Security Notes
- Password hashes are not returned in DTOs.
- Pending/disabled users cannot log in.
- The frontend local fallback is disabled unless
VITE_ENABLE_LOCAL_AUTH_FALLBACK=true, and its fallback user is not a platform admin.