feat(users): add admin-granted verified badge for trusted contributors

- migration 0002: users.verified boolean, default false
- verified rides in the JWT (role + verified claims)
- POST /users/{id}/verify + /unverify, admin-only (403 otherwise)
- Issue now takes the whole user so trust claims travel in the token
- unit + integration + admin-flow tests
This commit is contained in:
Efremenko Arhip
2026-07-26 19:10:01 +03:00
parent 0c1f5f06d4
commit c6a66747eb
20 changed files with 429 additions and 51 deletions
+6 -2
View File
@@ -22,6 +22,9 @@ type UserRepository interface {
GetByEmail(ctx context.Context, email string) (*domain.User, error)
// GetByID returns the user with id, or ErrUserNotFound.
GetByID(ctx context.Context, id uuid.UUID) (*domain.User, error)
// SetVerified toggles the verified flag, returning ErrUserNotFound if no
// such user exists.
SetVerified(ctx context.Context, id uuid.UUID, verified bool) error
}
// PasswordHasher hashes and verifies passwords. The bcrypt adapter satisfies it.
@@ -30,9 +33,10 @@ type PasswordHasher interface {
Compare(hash, password string) error
}
// TokenIssuer mints a signed access token for an authenticated user.
// TokenIssuer mints a signed access token for an authenticated user. It takes
// the whole user so trust-bearing claims (role, verified) travel in the token.
type TokenIssuer interface {
Issue(userID uuid.UUID, role domain.Role) (string, error)
Issue(u *domain.User) (string, error)
}
// Clock reads the current time; a fake one makes tests deterministic.