Auth — the module and its seams

Auth — the module and its seams An architecture diagram generated by Archify. user · Deps.Users: contracts.Users · Deps · other modules' contracts/ · Deps user Deps.Users: contracts.Users Deps notification · Deps.Notify · Mailer · Hosts · Deps · other modules' contracts/ · Deps notification Deps.Notify · Mailer · Hosts Deps tenant · Deps.Tenants: jobs.TenantLister · Deps · other modules' contracts/ · Deps tenant Deps.Tenants: jobs.TenantLister Deps admin · native shell · Authorize · the login route · consumers · consumer admin · native shell Authorize · the login route consumer a client module (clients) · Authorize: httpx.Authorizer · consumers · consumer a client module (clients) Authorize: httpx.Authorizer consumer contracts/ · Session · Role · 6 events · role:manage · modules/auth contracts/ Session · Role · 6 events · role:manage module.go · Module(Deps{…}) → Auth · SeedRoles · no Spec · modules/auth module.go Module(Deps{…}) → Auth · SeedRoles · no Spec internal/ · Service: Login · Identify · Allowed · OIDC · Sweep · modules/auth internal/ Service: Login · Identify · Allowed · OIDC · Sweep /api/v1/auth · RegisterRoutes · login · logout · me · password · roles · oidc · kit/ seams /api/v1/auth · RegisterRoutes login · logout · me · password · roles · oidc admin screens · none · admin owns /admin/login · kit/ seams admin screens none · admin owns /admin/login events · auth.logged_in · logged_out · login_failed · +3 · kit/ seams events auth.logged_in · logged_out · login_failed · +3 jobs · auth-sweep · hourly cron · kit/ seams jobs auth-sweep · hourly cron migrations/000008_auth · sessions, roles, password_tokens · kit/ seams migrations/000008_auth sessions, roles, password_tokens Events · permissions NewService RegisterRoutes · OIDC if configured SQL over Tx[Tenant] events.Publish Sweep none Deps Deps Deps login · Allowed Authorize modules/auth kit/ seams Deps · other modules' contracts/ consumers Legend Frontend Backend Database Message bus

Promises

  • • role:manage guards the roles routes; login, forgot, reset and the OIDC legs are Public; logout, me and password are SignedIn
  • • logged_in from Login and OIDC; logged_out; login_failed in its own transaction; reset_requested; password_reset; role_set

Needs

  • • Users is contracts.Users, the user service; Notify, Mailer and Hosts are notification's; Tenants is tenant's Active lister
  • • OIDC is config auth.oidc; no issuer, no OIDC routes. PublicHost decides Secure and __Host-. SeedRoles takes main's operator list

Proof

  • • authtest: fake and real service pass one conformance suite; internal tests: tenant row, expiry cap, lockout, no token in any row
  • • e2e/admin-tasks.spec.ts signs in at /admin/login, which posts to /api/v1/auth/login; OIDC only against authtest's issuer