feat(users): add admin-granted verified badge for trusted contributors

- migration 0002: users.verified boolean, default false
- verified rides in the JWT (role + verified claims)
- POST /users/{id}/verify + /unverify, admin-only (403 otherwise)
- Issue now takes the whole user so trust claims travel in the token
- unit + integration + admin-flow tests
This commit is contained in:
Efremenko Arhip
2026-07-26 19:10:01 +03:00
parent 0c1f5f06d4
commit c6a66747eb
20 changed files with 429 additions and 51 deletions
+13 -8
View File
@@ -5,17 +5,19 @@ import (
"time"
"github.com/golang-jwt/jwt/v5"
"github.com/google/uuid"
"github.com/emil28092005/SciMesh/users/internal/domain"
)
// Claims is the payload of a signed token. Subject (from RegisteredClaims) is
// the user id — it becomes the coordinator's jobs.owner_id; Role drives
// authorization. Both services verify this token locally with the shared HS256
// secret, so no runtime call back to the userservice is ever needed.
// authorization; Verified tells the coordinator whether this user's workers are
// trusted (results accepted without quorum). Both services verify this token
// locally with the shared HS256 secret, so no runtime call back to the
// userservice is ever needed.
type Claims struct {
Role domain.Role `json:"role"`
Role domain.Role `json:"role"`
Verified bool `json:"verified"`
jwt.RegisteredClaims
}
@@ -35,13 +37,16 @@ func NewIssuer(secret string, ttl time.Duration, now func() time.Time) Issuer {
return Issuer{secret: []byte(secret), ttl: ttl, now: now}
}
// Issue returns a signed token for the user, valid for the configured TTL.
func (i Issuer) Issue(userID uuid.UUID, role domain.Role) (string, error) {
// Issue returns a signed token for the user, valid for the configured TTL. It
// takes the whole user so every trust-bearing field (role, verified) travels in
// the token, keeping the two services from needing a runtime lookup.
func (i Issuer) Issue(u *domain.User) (string, error) {
now := i.now()
claims := Claims{
Role: role,
Role: u.Role,
Verified: u.Verified,
RegisteredClaims: jwt.RegisteredClaims{
Subject: userID.String(),
Subject: u.ID.String(),
IssuedAt: jwt.NewNumericDate(now),
ExpiresAt: jwt.NewNumericDate(now.Add(i.ttl)),
},
+6 -3
View File
@@ -16,7 +16,7 @@ func TestIssueVerifyRoundTrip(t *testing.T) {
iss := NewIssuer(testSecret, time.Hour, nil)
id := uuid.New()
token, err := iss.Issue(id, domain.RoleAdmin)
token, err := iss.Issue(&domain.User{ID: id, Role: domain.RoleAdmin, Verified: true})
if err != nil {
t.Fatalf("issue: %v", err)
}
@@ -31,12 +31,15 @@ func TestIssueVerifyRoundTrip(t *testing.T) {
if claims.Role != domain.RoleAdmin {
t.Errorf("role = %q, want admin", claims.Role)
}
if !claims.Verified {
t.Error("verified claim not carried in token")
}
}
func TestVerifyRejectsExpired(t *testing.T) {
// Negative TTL: the token is already expired when issued.
iss := NewIssuer(testSecret, -time.Minute, nil)
token, _ := iss.Issue(uuid.New(), domain.RoleUser)
token, _ := iss.Issue(&domain.User{ID: uuid.New(), Role: domain.RoleUser})
if _, err := iss.Verify(token); err == nil {
t.Error("expired token accepted")
@@ -44,7 +47,7 @@ func TestVerifyRejectsExpired(t *testing.T) {
}
func TestVerifyRejectsWrongSecret(t *testing.T) {
token, _ := NewIssuer(testSecret, time.Hour, nil).Issue(uuid.New(), domain.RoleUser)
token, _ := NewIssuer(testSecret, time.Hour, nil).Issue(&domain.User{ID: uuid.New(), Role: domain.RoleUser})
other := NewIssuer("another-secret-also-32-bytes-long!!!", time.Hour, nil)
if _, err := other.Verify(token); err == nil {