Replace console password auth with a passwordless surface — the pre-session
login doors plus an identifier-first discovery endpoint — and remove the
password paths.
- Login doors (Public, pre-session): email-OTP, passkey assertion, op.console
login with in-game approval, and setup-token redeem.
- /api/v1/auth/options: identifier-first discovery reporting which console
methods an email can use. The single sanctioned existence oracle; methods
are computed with no role branch, so staff and player accounts in the same
credential state return byte-identical bodies (staffness invisible by
construction).
- Remove password auth: drop StaffUser.PasswordHash and the /auth/login,
/auth/change-password and /users/{id}/reset-password endpoints (and test).
- Data layer: UserByEmail, verified-email uniqueness, setup-token store
(migration 0012).
- Reconcile docs/openapi.yaml with the served surface; the method/path/face/
tier parity gate (TestOpenAPIMatchesServedRoutes) passes.
- felis TUI: in-game MC bind, owner/break-glass OP provisioning, version.
- Velocity /felis command suite.
Consolidates the accumulated backend migration work; the frontend (panel/)
is left untouched. Full Go tree green on WSL (go build ./... && go test ./...).
42 lines
1.1 KiB
Markdown
42 lines
1.1 KiB
Markdown
# AGENTS.md
|
|
|
|
This file helps Autohand understand how to work with this project.
|
|
|
|
## Project Overview
|
|
|
|
- **Language**: Go
|
|
- **Package Manager**: go
|
|
|
|
## Commands
|
|
|
|
- **Build**: `go build`
|
|
- **Run**: `go run .`
|
|
- **Test**: `go test ./...`
|
|
- **Format**: `go fmt ./...`
|
|
- **Vet**: `go vet ./...`
|
|
|
|
## Instruction Sources
|
|
|
|
- Check saved memories and preferences before implementation work.
|
|
- Follow this AGENTS.md file for repository-specific guidance.
|
|
- AGENTS.md takes precedence over CLAUDE.md when both files provide instructions.
|
|
|
|
## Code Style
|
|
|
|
- Follow Go idioms and conventions
|
|
- Use short variable names in small scopes
|
|
- Handle errors explicitly
|
|
- Follow existing patterns in the codebase
|
|
- Use meaningful variable and function names
|
|
- Add comments for complex logic
|
|
- Keep functions focused and small
|
|
|
|
## Constraints
|
|
|
|
- Do not modify files outside the project directory
|
|
- Ask before making breaking changes
|
|
- Prefer editing existing files over creating new ones
|
|
- Do not delete files without confirmation
|
|
- Keep dependencies minimal - avoid adding new ones without good reason
|
|
- Do not commit sensitive data (API keys, secrets, credentials)
|