refactor(api): drop dead login concurrency limiter and reconcile passwordless comments

The passwordless migration (b330d77) removed the password-login route, leaving
concurrencyLimiter — its bcrypt concurrency cap — with no caller, and scattered
stale "local-password" / "change-password" references through the surviving auth
code's comments.

- Remove the dead concurrencyLimiter (type + newConcurrencyLimiter + acquire):
  no caller, no struct field, no test. Reword the one streamLimiter doc that
  contrasted against it.
- Realign comments in repo.go, pgrepo.go, session.go, util.go to the passwordless
  reality: staff lookups feed email-OTP / passkey / setup redeem, not a password
  compare; RevokeUserSessionsExcept and DeleteAllPasskeyCredentialsForUser are
  retained (uncalled) for the P5 account-remediation path (#78); "local sessions"
  no longer implies a password.

Comments and dead code only; no behavior change. Full WSL test tree green.
This commit is contained in:
flyemoji committed 2026-07-04 21:47:12 +09:00
1 parent 0c1cc598c1
commit 3b43f05a83
5 files changed
+44 -78

No files matched your search

+9 -6
View File
@@ -722,7 +722,7 @@ func (p *PGRepo) IsProtectedAdminLink(ctx context.Context, mcUUID string) (bool,
return ok, err
}
// ---- local-password auth (spec §B) ----
// ---- staff account lookups (spec §B, passwordless) ----
// UserByUsername loads a staff login projection by username, or ErrNotFound.
// The account is passwordless — staff authenticate via email-OTP / passkey, so
@@ -836,9 +836,10 @@ func (p *PGRepo) RevokeSession(ctx context.Context, tokenHash string) error {
return err
}
// RevokeUserSessionsExcept revokes every live session of a user except
// keepTokenHash — the change-password flow logs out the account's other devices
// while keeping the current one.
// RevokeUserSessionsExcept revokes every live session of a user except keepTokenHash
// — logs out an account's other devices while keeping the current one. Its original
// caller (the change-password flow) was removed in the passwordless migration; it is
// retained for the account-remediation path (P5, #78) and currently has no caller.
func (p *PGRepo) RevokeUserSessionsExcept(ctx context.Context, userID, keepTokenHash string) error {
_, err := p.db.ExecContext(ctx,
`UPDATE sessions SET revoked_at = now()
@@ -1030,8 +1031,10 @@ func (p *PGRepo) DeletePasskeyCredential(ctx context.Context, userID, id string)
// DeleteAllPasskeyCredentialsForUser unbinds every passkey a user holds. Unlike the
// single-credential delete this does NOT report ErrNotFound on zero rows: removing all of
// a user's passkeys when they have none is a successful no-op, since "the user holds no
// passkeys" is exactly the intended post-condition. The change-password flow calls it so a
// passkey planted through a transiently-hijacked session cannot survive the remediation.
// passkeys" is exactly the intended post-condition. It is the remediation that stops a
// passkey planted through a transiently-hijacked session from surviving; its original
// caller (the change-password flow) was removed in the passwordless migration, so it is
// currently uncalled, retained for the account-remediation/reset path (P5, #78).
func (p *PGRepo) DeleteAllPasskeyCredentialsForUser(ctx context.Context, userID string) error {
_, err := p.db.ExecContext(ctx,
`DELETE FROM webauthn_credentials WHERE user_id = $1`, userID)