refactor(api): drop dead login concurrency limiter and reconcile passwordless comments

The passwordless migration (b330d77) removed the password-login route, leaving
concurrencyLimiter — its bcrypt concurrency cap — with no caller, and scattered
stale "local-password" / "change-password" references through the surviving auth
code's comments.

- Remove the dead concurrencyLimiter (type + newConcurrencyLimiter + acquire):
  no caller, no struct field, no test. Reword the one streamLimiter doc that
  contrasted against it.
- Realign comments in repo.go, pgrepo.go, session.go, util.go to the passwordless
  reality: staff lookups feed email-OTP / passkey / setup redeem, not a password
  compare; RevokeUserSessionsExcept and DeleteAllPasskeyCredentialsForUser are
  retained (uncalled) for the P5 account-remediation path (#78); "local sessions"
  no longer implies a password.

Comments and dead code only; no behavior change. Full WSL test tree green.
This commit is contained in:
flyemoji committed 2026-07-04 21:47:12 +09:00
1 parent 0c1cc598c1
commit 3b43f05a83
5 files changed
+44 -78

No files matched your search

+2 -1
View File
@@ -12,7 +12,8 @@ const maxBodyBytes = 1 << 20 // 1 MiB
// requireJSONContentType rejects a request whose body is not declared
// application/json, returning 415 before any decode. It guards the credential-bearing
// auth writes (login, change-password) against a cross-site forgery: an HTML form can
// auth writes (email-OTP, passkey, op-login, setup redeem) against a cross-site
// forgery: an HTML form can
// only POST as application/x-www-form-urlencoded, multipart/form-data, or text/plain
// — never JSON — and a cross-site fetch that forces application/json triggers a CORS
// preflight this API never answers, so neither form can be forged off-origin. The