feat(auth): make session duration and password rules configurable
Replace the hardcoded 7-day session lifetime and fixed password complexity rules with registry-backed accessors so they can be tuned from the admin UI without a code change. auth.go: - Drop the SessionDuration const; keep DefaultSessionDuration (7 days) as the fallback used when no registry is wired (e.g. in tests). - AuthHandler gains an optional *database.SettingsRegistry and a sessionDuration() helper that reads the registry, falling back to DefaultSessionDuration. - Cookie MaxAge, JWT exp claim, and ExpiresIn responses now derive from sessionDuration() instead of the package-level SessionDurationSec, so a settings change takes effect on the next login. refresh_token.go: - Refresh-token lifetime follows sessionDuration() via a new refreshTokenTTL() helper (was a separate refreshTokenExpiration const that silently had to be kept in sync with the session duration). password_validator.go: - PasswordValidator now reads min length and the upper/lower/number/ special toggles from the registry at validation time, so rule changes apply immediately. The special-character regex is compiled once and reused (sync.Once). - GetPasswordRequirements() and ValidatePassword() reflect the active configured rules instead of a static list. - Add SetDefaultPasswordSettings() so the package-level default validator (used by echo's struct-tag validator) follows live config. All paths degrade gracefully to the historical defaults when no registry is wired.
This commit is contained in:
+32
-11
@@ -26,14 +26,34 @@ import (
|
||||
)
|
||||
|
||||
const (
|
||||
// Session duration constants
|
||||
// Follows same pattern as refresh_token.go
|
||||
SessionDuration = 7 * 24 * time.Hour // 7 days
|
||||
// DefaultSessionDuration is the fallback session duration used when no
|
||||
// settings registry is wired (matches the historical 7-day value).
|
||||
DefaultSessionDuration = 7 * 24 * time.Hour
|
||||
)
|
||||
|
||||
// SessionDurationSec is the session duration in seconds for use in cookies and API responses
|
||||
// Note: This is computed from SessionDuration to avoid magic numbers
|
||||
var SessionDurationSec = int(SessionDuration.Seconds())
|
||||
// SessionDurationSec is retained for backward compatibility; new code uses the
|
||||
// registry via AuthHandler.sessionDuration().
|
||||
var SessionDurationSec = int(DefaultSessionDuration.Seconds())
|
||||
|
||||
// SetSettings wires the tunable settings registry (optional).
|
||||
func (h *AuthHandler) SetSettings(s *database.SettingsRegistry) { h.settings = s }
|
||||
|
||||
// sessionDuration returns the active session duration from the registry.
|
||||
func (h *AuthHandler) sessionDuration() time.Duration {
|
||||
if h.settings != nil {
|
||||
return h.settings.SessionDuration()
|
||||
}
|
||||
return DefaultSessionDuration
|
||||
}
|
||||
|
||||
// refreshTokenTTL returns the active refresh-token lifetime (shared with the
|
||||
// session duration), with a compiled-default fallback.
|
||||
func (h *AuthHandler) refreshTokenTTL() time.Duration {
|
||||
if h.settings != nil {
|
||||
return h.settings.SessionDuration()
|
||||
}
|
||||
return DefaultSessionDuration
|
||||
}
|
||||
|
||||
var secure = os.Getenv("COOKIE_SECURE")
|
||||
|
||||
@@ -41,6 +61,7 @@ type AuthHandler struct {
|
||||
db *database.Queries
|
||||
jwtKey []byte
|
||||
loginAttemptTracker *middleware.LoginAttemptTracker
|
||||
settings *database.SettingsRegistry
|
||||
}
|
||||
|
||||
func NewAuthHandler(db *database.Queries, jwtSecret string, loginAttemptTracker *middleware.LoginAttemptTracker) *AuthHandler {
|
||||
@@ -265,7 +286,7 @@ func (h *AuthHandler) Register(c *echo.Context) error {
|
||||
HttpOnly: true,
|
||||
Secure: secure == "true", // TODO: Set to true in production with HTTPS
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
MaxAge: SessionDurationSec,
|
||||
MaxAge: int(h.sessionDuration().Seconds()),
|
||||
}
|
||||
c.SetCookie(cookie)
|
||||
|
||||
@@ -298,7 +319,7 @@ window.location.href = '/dashboard';
|
||||
Token: accessToken,
|
||||
RefreshToken: refreshToken,
|
||||
TokenType: "Bearer",
|
||||
ExpiresIn: SessionDurationSec,
|
||||
ExpiresIn: int(h.sessionDuration().Seconds()),
|
||||
User: UserProfile{
|
||||
ID: uuid.UUID(user.ID.Bytes).String(),
|
||||
Email: user.Email,
|
||||
@@ -411,7 +432,7 @@ func (h *AuthHandler) Login(c *echo.Context) error {
|
||||
HttpOnly: true,
|
||||
Secure: secure == "true", // TODO: Set to true in production with HTTPS
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
MaxAge: SessionDurationSec,
|
||||
MaxAge: int(h.sessionDuration().Seconds()),
|
||||
}
|
||||
c.SetCookie(cookie)
|
||||
|
||||
@@ -450,7 +471,7 @@ window.location.href = '%s';
|
||||
Token: accessToken,
|
||||
RefreshToken: refreshToken,
|
||||
TokenType: "Bearer",
|
||||
ExpiresIn: SessionDurationSec,
|
||||
ExpiresIn: int(h.sessionDuration().Seconds()),
|
||||
User: UserProfile{
|
||||
ID: uuid.UUID(user.ID.Bytes).String(),
|
||||
Email: user.Email,
|
||||
@@ -1014,7 +1035,7 @@ func (h *AuthHandler) generateJWTWithAllClaims(userID, userRole, userEmail, user
|
||||
"user_role": userRole,
|
||||
"user_email": userEmail,
|
||||
"user_username": userUsername,
|
||||
"exp": time.Now().Add(SessionDuration).Unix(),
|
||||
"exp": time.Now().Add(h.sessionDuration()).Unix(),
|
||||
"iat": time.Now().Unix(),
|
||||
}
|
||||
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
|
||||
|
||||
Reference in New Issue
Block a user