mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 08:36:37 +08:00
refactor(core): fix cross-domain auth imports, unify migration, add downstream scaffold
Architecture: - Move GetFromContext/SetToContext from plugins/domain/auth to pkg/util - Move auth context key constants to core/contracts (AuthUserObjKey, AuthTokenAuthKey, etc.) - Add AuthUserIDKey, AuthUserNameKey, GetCurrentUserID, RevokeToken to contracts.AuthService - All 4 domain plugin Apply() methods now resolve AuthService via core.Using IoC - Plugin route middleware uses authSvc.RequireAuthMiddleware() cast to gin.HandlerFunc - DisallowTokenAuth added to AuthService contract Migration: - Replace cmd/app.go SetMigrationRunner bridge with gooseEngine implementing core.MigrationEngine - Remove cmd/root.go PreRun migration hooks and runMigrations() function - Migrations now run via core.App.Start() → RunMigrations() Events: - Add complete domain event topic catalog and payload DTOs to core/contracts/events.go - 15 event topics across auth, user, admin, upload, message_gateway, risk_control Downstream: - Create downstream/ directory with README and custom_example plugin scaffold CI: - Update Makefile code-check architecture guards for Cordis layering - Enforce: core no gin/gorm/asynq, contracts no plugins/, pkg no plugins/, domain no cross-domain
This commit is contained in:
@@ -64,14 +64,23 @@ type AuthService interface {
|
||||
// GetCurrentUser retrieves the authenticated UserDTO from context.
|
||||
GetCurrentUser(ctx context.Context) (*UserDTO, error)
|
||||
|
||||
// GetCurrentUserID retrieves the authenticated user ID from session/context.
|
||||
GetCurrentUserID(ctx context.Context) (uint64, error)
|
||||
|
||||
// VerifyToken validates an access token and returns the associated user DTO.
|
||||
VerifyToken(ctx context.Context, token string) (*UserDTO, error)
|
||||
|
||||
// CreateSession establishes an authenticated session for the given user ID.
|
||||
CreateSession(ctx context.Context, userID uint64, extras map[string]any) (string, error)
|
||||
|
||||
// RevokeToken invalidates a specific access token by its hash.
|
||||
RevokeToken(ctx context.Context, tokenHash string) error
|
||||
|
||||
// RevokeUserSessions revokes all active sessions and cached tokens for a user.
|
||||
RevokeUserSessions(ctx context.Context, userID uint64) error
|
||||
|
||||
// DisallowTokenAuthMiddleware returns a middleware that rejects requests authenticated via access token.
|
||||
DisallowTokenAuthMiddleware() any
|
||||
}
|
||||
|
||||
// AuthRegistry allows downstream and domain plugins to register custom authentication providers.
|
||||
@@ -80,3 +89,12 @@ type AuthRegistry interface {
|
||||
GetOAuthProvider(name string) (OAuthProvider, bool)
|
||||
ListOAuthProviders() []string
|
||||
}
|
||||
|
||||
// Auth context keys — stored in Gin context by auth middleware, consumed by domain plugins.
|
||||
const (
|
||||
AuthUserIDKey = "user_id"
|
||||
AuthUserNameKey = "username"
|
||||
AuthUserObjKey = "user_obj"
|
||||
AuthTokenAuthKey = "token_auth" // marks if request uses access token auth
|
||||
AuthTokenAdminKey = "token_admin" // whether the access token has admin privileges
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user