feat(auth): migrate console login to passwordless
Replace console password auth with a passwordless surface — the pre-session
login doors plus an identifier-first discovery endpoint — and remove the
password paths.
- Login doors (Public, pre-session): email-OTP, passkey assertion, op.console
login with in-game approval, and setup-token redeem.
- /api/v1/auth/options: identifier-first discovery reporting which console
methods an email can use. The single sanctioned existence oracle; methods
are computed with no role branch, so staff and player accounts in the same
credential state return byte-identical bodies (staffness invisible by
construction).
- Remove password auth: drop StaffUser.PasswordHash and the /auth/login,
/auth/change-password and /users/{id}/reset-password endpoints (and test).
- Data layer: UserByEmail, verified-email uniqueness, setup-token store
(migration 0012).
- Reconcile docs/openapi.yaml with the served surface; the method/path/face/
tier parity gate (TestOpenAPIMatchesServedRoutes) passes.
- felis TUI: in-game MC bind, owner/break-glass OP provisioning, version.
- Velocity /felis command suite.
Consolidates the accumulated backend migration work; the frontend (panel/)
is left untouched. Full Go tree green on WSL (go build ./... && go test ./...).
This commit is contained in:
46 files changed
+5554
-1651
No files matched your search
@@ -0,0 +1,58 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io"
|
||||
"runtime"
|
||||
"runtime/debug"
|
||||
)
|
||||
|
||||
// version is the build stamp injected at link time via
|
||||
//
|
||||
// -ldflags "-X main.version=<git describe>"
|
||||
//
|
||||
// deploy/bootstrap.sh computes it from the checked-out source with
|
||||
// `git describe --tags --always --dirty`: the release channel builds the newest
|
||||
// vX.Y.Z tag (a clean name like v1.0.0-earlyAccess), the dev channel builds main
|
||||
// HEAD (a tag+distance+gSHA string). It stays "dev" for an un-stamped local
|
||||
// `go build`, where ReadBuildInfo below still surfaces the vcs revision.
|
||||
var version = "dev"
|
||||
|
||||
// cmdVersion prints the build stamp. It takes no flags and never touches the
|
||||
// cluster, so it is safe to run as any user (unlike setup/breakGlass).
|
||||
func cmdVersion(args []string, stdout, stderr io.Writer) int {
|
||||
fmt.Fprintf(stdout, "felis %s\n", resolvedVersion())
|
||||
fmt.Fprintf(stdout, " go: %s %s/%s\n", runtime.Version(), runtime.GOOS, runtime.GOARCH)
|
||||
if rev, ok := vcsRevision(); ok {
|
||||
fmt.Fprintf(stdout, " revision: %s\n", rev)
|
||||
}
|
||||
return 0
|
||||
}
|
||||
|
||||
// resolvedVersion prefers the ldflag stamp, then the module version recorded by
|
||||
// `go install`, and only reports "unknown" when neither is present.
|
||||
func resolvedVersion() string {
|
||||
if version != "" {
|
||||
return version
|
||||
}
|
||||
if bi, ok := debug.ReadBuildInfo(); ok && bi.Main.Version != "" {
|
||||
return bi.Main.Version
|
||||
}
|
||||
return "unknown"
|
||||
}
|
||||
|
||||
// vcsRevision returns the git commit the binary was built from when the build
|
||||
// carried VCS stamping (local `go build` in a checkout; the docker build strips
|
||||
// .git, so there the ldflag version carries the identity instead).
|
||||
func vcsRevision() (string, bool) {
|
||||
bi, ok := debug.ReadBuildInfo()
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
for _, s := range bi.Settings {
|
||||
if s.Key == "vcs.revision" && s.Value != "" {
|
||||
return s.Value, true
|
||||
}
|
||||
}
|
||||
return "", false
|
||||
}
|
||||
Reference in new issue
Block a user