refactor(api): drop dead login concurrency limiter and reconcile passwordless comments
The passwordless migration (b330d77) removed the password-login route, leaving concurrencyLimiter — its bcrypt concurrency cap — with no caller, and scattered stale "local-password" / "change-password" references through the surviving auth code's comments. - Remove the dead concurrencyLimiter (type + newConcurrencyLimiter + acquire): no caller, no struct field, no test. Reword the one streamLimiter doc that contrasted against it. - Realign comments in repo.go, pgrepo.go, session.go, util.go to the passwordless reality: staff lookups feed email-OTP / passkey / setup redeem, not a password compare; RevokeUserSessionsExcept and DeleteAllPasskeyCredentialsForUser are retained (uncalled) for the P5 account-remediation path (#78); "local sessions" no longer implies a password. Comments and dead code only; no behavior change. Full WSL test tree green.
This commit is contained in:
5 files changed
+44
-78
No files matched your search
@@ -12,7 +12,8 @@ const maxBodyBytes = 1 << 20 // 1 MiB
|
||||
|
||||
// requireJSONContentType rejects a request whose body is not declared
|
||||
// application/json, returning 415 before any decode. It guards the credential-bearing
|
||||
// auth writes (login, change-password) against a cross-site forgery: an HTML form can
|
||||
// auth writes (email-OTP, passkey, op-login, setup redeem) against a cross-site
|
||||
// forgery: an HTML form can
|
||||
// only POST as application/x-www-form-urlencoded, multipart/form-data, or text/plain
|
||||
// — never JSON — and a cross-site fetch that forces application/json triggers a CORS
|
||||
// preflight this API never answers, so neither form can be forged off-origin. The
|
||||
|
||||
Reference in new issue
Block a user