refactor(api): drop dead login concurrency limiter and reconcile passwordless comments

The passwordless migration (b330d77) removed the password-login route, leaving
concurrencyLimiter — its bcrypt concurrency cap — with no caller, and scattered
stale "local-password" / "change-password" references through the surviving auth
code's comments.

- Remove the dead concurrencyLimiter (type + newConcurrencyLimiter + acquire):
  no caller, no struct field, no test. Reword the one streamLimiter doc that
  contrasted against it.
- Realign comments in repo.go, pgrepo.go, session.go, util.go to the passwordless
  reality: staff lookups feed email-OTP / passkey / setup redeem, not a password
  compare; RevokeUserSessionsExcept and DeleteAllPasskeyCredentialsForUser are
  retained (uncalled) for the P5 account-remediation path (#78); "local sessions"
  no longer implies a password.

Comments and dead code only; no behavior change. Full WSL test tree green.
This commit is contained in:
flyemoji committed 2026-07-04 21:47:12 +09:00
1 parent 0c1cc598c1
commit 3b43f05a83
5 files changed
+44 -78

No files matched your search

+9 -9
View File
@@ -15,23 +15,23 @@ import (
"time"
)
// Local-password sessions (spec §B). The remote face authenticates statelessly
// with a Cloudflare-Access JWT and sets no cookie; local-password auth, used on
// op.console when Zero Trust is not configured (and as the demo's primary web
// login), needs a server-minted session. We store only the sha-256 of the opaque
// cookie value, mirroring how service tokens are stored, so a database read never
// yields a usable cookie.
// Local sessions (spec §B, passwordless). The remote face authenticates statelessly
// with a Cloudflare-Access JWT and sets no cookie; the passwordless console login
// (email-OTP / passkey / setup redeem), used on op.console when Zero Trust is not
// configured (and as the demo's primary web login), needs a server-minted session.
// We store only the sha-256 of the opaque cookie value, mirroring how service tokens
// are stored, so a database read never yields a usable cookie.
const (
// sessionCookieName is the host-only session cookie. It carries no Domain
// attribute, so an op.console session is never sent to the player console.
sessionCookieName = "felis_session"
// sessionTTL bounds a local-password session. Staff re-authenticate after it.
// sessionTTL bounds a local session. Staff re-authenticate after it.
sessionTTL = 12 * time.Hour
)
// LocalAuthEnabledKey is the platform_settings key that gates whether
// local-password sessions are honored. It is flipped on by `felis breakGlass`
// local sessions are honored. It is flipped on by `felis breakGlass`
// direct-to-Postgres at first-run and read live per-request, so enabling local
// auth needs no pod roll. Exported so the break-glass writer and this
// per-request reader share one source of truth instead of drifting copies.
@@ -109,7 +109,7 @@ func hostIsAdminConsole(r *http.Request, rootDomain, adminHostname string) bool
}
// SessionAuth is the composite ExternalAuth for the web face. It prefers a
// local-password session cookie and otherwise delegates to the remote JWT
// local session cookie and otherwise delegates to the remote JWT
// verifier, so both auth models coexist on one face:
//
// - No cookie → delegate to Delegate (the Cloudflare-Access JWT path).