feat(coordinator): UI login/register via userservice (cookie session)
When JWT_SECRET + USERSERVICE_URL are set, the operator UI authenticates through userservice login/registration instead of the static UI_AUTH_TOKEN: - /ui/login, /ui/register, /ui/logout pages proxy to the userservice - successful login stores the JWT in an httpOnly, /ui-scoped cookie - withUISession verifies the cookie locally and stamps the requester - unset -> falls back to basic auth, so the team's existing flow is unchanged Tests cover the session gate, cookie set/clear, and the login/register proxy.
This commit is contained in:
@@ -110,7 +110,7 @@ func run() error {
|
||||
|
||||
// pool.Ping backs /health: readiness means the database answers, not just
|
||||
// that the process is alive.
|
||||
api := httptransport.NewServer(useCases, log, cfg.RequestTimeout, cfg.HeartbeatInterval, cfg.MaxUploadBytes, cfg.JWTSecret, pool.Ping)
|
||||
api := httptransport.NewServer(useCases, log, cfg.RequestTimeout, cfg.HeartbeatInterval, cfg.MaxUploadBytes, cfg.JWTSecret, cfg.UserserviceURL, pool.Ping)
|
||||
err = infra.RunServer(ctx, log, cfg.Addr, api.Handler(cfg.Token, cfg.UIToken))
|
||||
|
||||
// Shutdown order matters, and defers alone cannot express it (they run
|
||||
|
||||
Reference in New Issue
Block a user