fix(user): revoke all sessions and access tokens on password change

- Store user password hash in session during login

- Validate password hash compatibility on requests to prevent session reuse

- Revoke all user access tokens and clear session on ChangePassword
This commit is contained in:
ryan
2026-06-13 10:27:28 +08:00
parent eb999eba09
commit 26e12594a2
5 changed files with 167 additions and 21 deletions
+1
View File
@@ -17,6 +17,7 @@ const (
TokenAuthKey = "token_auth" // 标记当前请求是否通过 Access Token 鉴权
TokenAdminKey = "token_admin" // Access Token 本身是否具有管理员权限
SessionTokenKey = "oauth_session_token" //nolint:gosec // false positive: this is a session key, not hardcoded credentials
PasswordHashKey = "password_hash"
)
// OAuth State 缓存 Key 格式与过期时间