Files
Felis/docs/changes/2026-06-27-console-auth-passwordless.md
T
flyemoji 096d59716e docs(changes): backfill detail docs for pre-ledger functional commits
Retroactively author 15 grouped detail docs covering the backend
functional (feat/fix) commits made before the change ledger was
established (fad48ff), closing the ledger's detail-doc axis for the
pre-convention history. Each doc groups a feature's constituent commits,
lists their SHAs with subjects, and carries a backfill note stating it
was reconstructed from git history on 2026-07-07 and not independently
re-verified (current tree green at 9911b8c).

Add a Detail docs section to INDEX.md linking every detail doc (the 6
existing + 15 backfill) to the commit(s) it covers, so a doc is findable
from the index without a column on the auto-generated ledger table. Catch
the table up with the missing 9911b8c row.

Scope: backend (Go/Java/K8s) only, per the ledger's stated convention
that frontend/panel commits are the collaborator's UI work; non-functional
commits (docs/style/chore/refactor) keep their table row without a
dedicated detail doc.
2026-07-07 20:55:51 +09:00

2.0 KiB
Raw Blame History

Console auth: local-password login → passwordless migration (ledger backfill)

  • Type: feature + refactor — retroactive ledger entry
  • Date: 2026-06-27 – 2026-07-04
  • Area: internal/api (auth handlers, sessions), internal/store (users schema)
  • Commits:
    • af14f02 feat(api): local-password authentication backend — login/logout/change-password on op.console; HttpOnly+Secure+SameSite=Lax host-only server-side sessions (SHA-256, 12h TTL); anti-enumeration uniform bcrypt; JSON-only credential writes (415 otherwise); fails closed unless local_auth_enabled
    • 0c1cc59 feat(auth): migrate console login to passwordless
    • 3b43f05 refactor(api): drop the dead login concurrency limiter and reconcile passwordless comments
    • c20b12c refactor(api): drop the dead password-era ResetMailer, reconcile passkey-unbind docs
  • Tasks: #27 (B1 thin thread), #79/#80/#81 (residue sweep + primitive adjudication)

What it did

Shipped the staff local-password door (af14f02) as the primary web login when Zero Trust is not in front of the API, then migrated the console to passwordless (0c1cc59) once email-OTP + passkey were the intended factors. The two refactors (3b43f05, c20b12c) then swept the password-era residue — the now-dead login concurrency limiter and the ResetMailer — so no unused password machinery lingered in the compile path, and reconciled the stale comments that referenced it.

Why

op.console needs a real login even in deployments without a Cloudflare-Access edge; the password backend was that. Once the passwordless factors landed, keeping the old password scaffolding around was a bug farm — the sweep is the closeout evidence that the migration was complete, not half-done.

Backfill note. Reconstructed 2026-07-07 from the commit history. af14f02 was covered by Go unit tests (content-type guard, anti-enumeration, forced-change lockdown) at its commit. Not independently re-verified for this doc; current tree green at 9911b8c (WSL oracle, go1.26.4).