Adds the full auth flow. Reads stay public; writes (currently only POST
/api/v1/mangas) require a CurrentUser. Both browsers and bot scripts hit
the same endpoints — they just present credentials differently.
Migration 0002_auth.sql introduces users.password_hash, a sessions
table, and an api_tokens table. Sessions and api_tokens store only
sha256(raw_token) — the raw value lives in the cookie or the
Authorization header.
New endpoints under /api/v1/auth/:
- POST /register — argon2id hash, creates a session, sets cookie.
- POST /login — verifies, rotates to a fresh session (old ones expire
naturally so other devices stay signed in).
- POST /logout — deletes the server-side session row + clears the
cookie via Max-Age=0.
- GET /me — current user via the new CurrentUser extractor.
- POST /tokens — issue a bot bearer token; raw value returned exactly
once at creation.
- DELETE /tokens/{id} — owner-only: 404 if unknown, 403 if it exists
but belongs to another user, 204 on success.
The CurrentUser axum extractor resolves cookie first, then
Authorization: Bearer; failure → AppError::Unauthenticated (401). New
AppError variants Unauthenticated/Forbidden/Conflict carry the matching
envelope codes; the top-level match in `code()` stays exhaustive.
Backend integration coverage in tests/api_auth.rs: register sets a
HttpOnly SameSite=Lax cookie and never leaks password_hash; duplicate
username → 409; weak password → 400; login rotates the cookie; wrong
password / unknown user → 401; /me with vs without cookie; logout
invalidates the cookie; bot-token roundtrip via Bearer; user A cannot
delete user B's token (403); unknown delete → 404.
Frontend:
- lib/api/auth.ts — typed wrappers; me() returns null on 401.
- lib/session.svelte.ts — per-tab user state with a seq counter to
guard against an in-flight /me clobbering a fresh setUser.
- lib/api/client.ts — request<T> returns undefined for 204.
- routes/login + routes/register — forms with action="javascript:void(0)"
so the no-JS path is a no-op (avoids the hydration-race where a
pre-attach click would submit via the browser default).
- routes/+layout.svelte — session-aware nav: spinner → user + Logout,
or Login / Register.
- e2e/auth-flow.spec.ts — login flips the layout, logout flips back;
bad credentials surface the API error message.
Config grows AuthConfig (cookie_secure, cookie_domain, session_ttl_days)
and CORS_ALLOWED_ORIGINS. CORS middleware is mounted in app::build and
stays a no-op (same-origin) until origins are listed.
Lockstep version bump to 0.3.0.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
64 lines
2.3 KiB
Rust
64 lines
2.3 KiB
Rust
//! `CurrentUser` axum extractor.
|
|
//!
|
|
//! Resolves a request to a logged-in user by trying, in order:
|
|
//! 1. a `mangalord_session` cookie (session lookup by `sha256(value)`);
|
|
//! 2. an `Authorization: Bearer <token>` header (api_token lookup).
|
|
//!
|
|
//! Both paths look up by hash, never by raw value. Failure to resolve
|
|
//! either way returns 401 via `AppError::Unauthenticated`.
|
|
|
|
use axum::async_trait;
|
|
use axum::extract::FromRequestParts;
|
|
use axum::http::request::Parts;
|
|
use axum_extra::extract::cookie::CookieJar;
|
|
use axum_extra::headers::authorization::Bearer;
|
|
use axum_extra::headers::Authorization;
|
|
use axum_extra::TypedHeader;
|
|
|
|
use crate::app::AppState;
|
|
use crate::auth::token::hash_token;
|
|
use crate::domain::User;
|
|
use crate::error::AppError;
|
|
use crate::repo;
|
|
|
|
pub const SESSION_COOKIE_NAME: &str = "mangalord_session";
|
|
|
|
pub struct CurrentUser(pub User);
|
|
|
|
#[async_trait]
|
|
impl FromRequestParts<AppState> for CurrentUser {
|
|
type Rejection = AppError;
|
|
|
|
async fn from_request_parts(
|
|
parts: &mut Parts,
|
|
state: &AppState,
|
|
) -> Result<Self, Self::Rejection> {
|
|
let jar = CookieJar::from_headers(&parts.headers);
|
|
if let Some(cookie) = jar.get(SESSION_COOKIE_NAME) {
|
|
let hash = hash_token(cookie.value());
|
|
if let Some(session) = repo::session::find_active(&state.db, &hash).await? {
|
|
if let Some(user) = repo::user::find_by_id(&state.db, session.user_id).await? {
|
|
return Ok(CurrentUser(user));
|
|
}
|
|
}
|
|
}
|
|
|
|
if let Ok(TypedHeader(Authorization(bearer))) =
|
|
TypedHeader::<Authorization<Bearer>>::from_request_parts(parts, state).await
|
|
{
|
|
let hash = hash_token(bearer.token());
|
|
if let Some(token) = repo::api_token::find_active(&state.db, &hash).await? {
|
|
if let Some(user) = repo::user::find_by_id(&state.db, token.user_id).await? {
|
|
// Fire-and-forget would be ideal but the test harness needs
|
|
// a deterministic write so the touched timestamp shows up
|
|
// when the test inspects state. Synchronous is fine.
|
|
let _ = repo::api_token::touch_last_used(&state.db, token.id).await;
|
|
return Ok(CurrentUser(user));
|
|
}
|
|
}
|
|
}
|
|
|
|
Err(AppError::Unauthenticated)
|
|
}
|
|
}
|