Compare commits

...
Author SHA1 Message Date
gamertan a16283efd7 Add session-bound personal profile editing
verify / verify (push) Successful in 4m35s
2026-09-05 02:37:38 -04:00
gamertan 7c68a3499a Add bounded administrative identity directories
verify / verify (push) Successful in 4m31s
2026-09-05 01:19:57 -04:00
18 changed files with 847 additions and 9 deletions
+28
View File
@@ -2,6 +2,34 @@
# Changelog
## v0.1.0-preview.26 — 2026-09-05
- Add optional self-profile readers and revision-checked username/display-name
writes. Recheck the active session, account and expected revision atomically
with a secret-free audit; preserve immutable user identity and ownership.
- Username edits revoke other sessions but preserve the acting session. A
password-confirmed write can require the exact verified credential hash,
rejecting a concurrent password reset. Applications own reauthentication,
operation-bound passkey approval, CSRF/origin checks and rate/concurrency limits.
- Add explicit SQLite schema 11 for monotonic profile revisions. Existing rows
begin at revision 1; startup with migrations disabled rejects older schemas.
Do not run older writers against schema 11 as a database rollback strategy.
- Email changes are deliberately absent; pending-address verification and mail
delivery are separate work. Test invalid/restricted sessions, collisions,
concurrent/stale edits, audit rollback, restart and schema-10 migration.
## v0.1.0-preview.25 — 2026-09-05
- Add optional, credential-free user and organization directory readers for
application-authorized instance administration. They include inactive/pending
users and personal/archived organizations independently of membership.
- Bound literal searches and stable-ID pagination to at most 200 returned
records. Queries do not load passwords, sessions, recovery material, invitations
or role grants; they grant no authority. Applications must authorize each read.
- Cover pagination, renamed records, literal SQL/wildcard input, Unicode text,
invalid bounds and cancellation. Schema 10 and existing repository contracts
remain unchanged; source exports include the new optional interfaces/readers.
## v0.1.0-preview.24 — 2026-09-05
- Add explicit owner-managed profile and optimistic membership operations.
+3 -3
View File
@@ -17,7 +17,7 @@ router, handlers, HTML, authorization decisions, cache behavior, and
deployment. Adopt one boundary at a time; Go compiles and links only the
packages you import.
> **Public preview:** `v0.1.0-preview.24`. APIs may change before a stable
> **Public preview:** `v0.1.0-preview.26`. APIs may change before a stable
> release. Linux is the maintained release platform.
## Why Web Foundations?
@@ -57,14 +57,14 @@ owns—and, just as importantly, what remains application policy.
Pin the preview in an application module:
```bash
go get gamertan.com/web@v0.1.0-preview.24
go get gamertan.com/web@v0.1.0-preview.26
go mod verify
```
An application may name the first package it intends to adopt:
```bash
go get gamertan.com/web/requestmeta@v0.1.0-preview.24
go get gamertan.com/web/requestmeta@v0.1.0-preview.26
```
The version belongs to the `gamertan.com/web` module. See the
+32
View File
@@ -0,0 +1,32 @@
// SPDX-License-Identifier: MPL-2.0
package auth
import (
"context"
"errors"
)
var ErrDirectoryQuery = errors.New("auth: invalid directory query")
// UserDirectoryQuery requests a bounded instance-wide identity listing. Search
// is literal text, not a query language. AfterID is an exclusive stable-ID cursor;
// Limit defaults to 50 and may not exceed 200.
type UserDirectoryQuery struct {
Search, AfterID string
Limit int
}
type UserDirectoryPage struct {
Users []User
NextID string
}
// UserDirectoryRepository is an optional administrative read capability, not an
// extension of ordinary authentication. Callers MUST authorize instance-wide
// identity access before each call. Results include incomplete/inactive accounts
// but never credentials, session material, recovery codes or permission grants.
// Pagination is a current view, not a snapshot across requests.
type UserDirectoryRepository interface {
UserDirectory(context.Context, UserDirectoryQuery) (UserDirectoryPage, error)
}
+75
View File
@@ -0,0 +1,75 @@
// SPDX-License-Identifier: MPL-2.0
package auth
import (
"context"
"errors"
"strings"
"time"
"unicode"
"unicode/utf8"
)
var (
ErrProfileInput = errors.New("auth: invalid profile change")
ErrProfileAccess = errors.New("auth: profile session is unavailable")
ErrProfileConflict = errors.New("auth: profile changed; reload before editing")
ErrUsernameUnavailable = errors.New("auth: username is unavailable")
)
// OwnProfile contains mutable identity, not credentials or organization roles.
// Revision is independent of timestamps and increases for every profile edit.
type OwnProfile struct {
UserID, Username, Email, DisplayName string
Revision int64
}
// ProfileEdit is a trusted repository command, not an HTTP input model. The
// application must authenticate the session, validate CSRF/origin and rate-limit
// mutations. Username edits additionally require recent reauthentication (and
// any account-specific MFA). For password reauthentication, supply the verified
// hash so a concurrent password reset invalidates the write. After verified
// passkey approval, leave it empty. Do not log or serialize this command.
type ProfileEdit struct {
UserID string
SessionDigest [32]byte
ExpectedRevision int64
Field, Value string
ExpectedPasswordHash string
}
// NormalizeProfileValue validates only supported fields. Email is deliberately
// absent: verified mailbox changes need a separate pending/confirmation flow.
func NormalizeProfileValue(field, value string) (string, error) {
value = strings.TrimSpace(value)
switch field {
case "username":
if !identifierPattern.MatchString(value) {
return "", ErrProfileInput
}
case "display_name":
if value == "" || len(value) > 128 || !utf8.ValidString(value) {
return "", ErrProfileInput
}
for _, r := range value {
if unicode.IsControl(r) {
return "", ErrProfileInput
}
}
default:
return "", ErrProfileInput
}
return value, nil
}
// OwnProfileRepository is optional; no change to the authentication Repository
// interface is required. It derives access from the current session, never from
// a site-wide administrator flag. Implementations atomically recheck identity,
// session and revision, mutate one field, and append the audit. Username edits
// revoke other sessions but preserve the acting session. They never reassign
// stable IDs, memberships, passkeys, billing identities or historical records.
type OwnProfileRepository interface {
OwnProfile(context.Context, [32]byte, time.Time) (OwnProfile, error)
UpdateOwnProfile(context.Context, ProfileEdit, AuditEvent) (OwnProfile, error)
}
+43
View File
@@ -0,0 +1,43 @@
// SPDX-License-Identifier: MPL-2.0
package auth
import "testing"
func TestNormalizeProfileValue(t *testing.T) {
for _, value := range []struct{ field, value, want string }{
{"username", " Reader.One ", "Reader.One"}, {"display_name", " Émilie ★ ", "Émilie ★"},
} {
got, err := NormalizeProfileValue(value.field, value.value)
if err != nil || got != value.want {
t.Fatalf("normalization: %q %v", got, err)
}
}
for _, value := range []struct{ field, value string }{
{"email", "new@example.test"}, {"role", "owner"}, {"username", "a"}, {"username", "foo@bar"},
{"display_name", ""}, {"display_name", "hello\x00world"}, {"display_name", "hello\nworld"}, {"display_name", string([]byte{0xff})},
} {
if _, err := NormalizeProfileValue(value.field, value.value); err == nil {
t.Fatalf("invalid field accepted: %s", value.field)
}
}
}
func FuzzProfileValue(f *testing.F) {
f.Add("username", "reader.one")
f.Add("display_name", "Émilie")
f.Add("email", "a@example.test")
f.Fuzz(func(t *testing.T, field, value string) {
normal, err := NormalizeProfileValue(field, value)
if err != nil {
return
}
if len(normal) == 0 || len(normal) > 128 {
t.Fatal("unbounded value")
}
again, err := NormalizeProfileValue(field, normal)
if err != nil || again != normal {
t.Fatal("unstable normalization")
}
})
}
+95
View File
@@ -0,0 +1,95 @@
// SPDX-License-Identifier: MPL-2.0
package authsqlite
import (
"context"
"strings"
"time"
"gamertan.com/web/auth"
"gamertan.com/web/organizations"
)
var _ auth.UserDirectoryRepository = (*Store)(nil)
var _ organizations.DirectoryRepository = (*Store)(nil)
// UserDirectory is an administrative read; the adapter cannot infer application
// authorization. Search covers ID, username, email and display name. SQLite LIKE
// folds ASCII case; non-ASCII display-name text matches with its original case.
func (store *Store) UserDirectory(ctx context.Context, query auth.UserDirectoryQuery) (auth.UserDirectoryPage, error) {
pattern, limit, valid := directoryQuery(query.Search, query.AfterID, query.Limit)
if !valid {
return auth.UserDirectoryPage{}, auth.ErrDirectoryQuery
}
rows, err := store.db.QueryContext(ctx, `SELECT id,username,email,display_name,status,password_change_required,registration_pending,created_at,updated_at
FROM gwf_users WHERE id>? AND (?='' OR id=? OR username_normalized LIKE ? ESCAPE '\' OR email_normalized LIKE ? ESCAPE '\' OR display_name LIKE ? ESCAPE '\')
ORDER BY id LIMIT ?`, query.AfterID, strings.TrimSpace(query.Search), strings.TrimSpace(query.Search), strings.ToLower(pattern), strings.ToLower(pattern), pattern, limit+1)
if err != nil {
return auth.UserDirectoryPage{}, err
}
defer rows.Close()
page := auth.UserDirectoryPage{Users: make([]auth.User, 0, limit)}
for rows.Next() {
user, err := scanPasskeyUser(rows)
if err != nil {
return auth.UserDirectoryPage{}, err
}
page.Users = append(page.Users, user)
}
if err = rows.Err(); err != nil {
return auth.UserDirectoryPage{}, err
}
if len(page.Users) > limit {
page.Users = page.Users[:limit]
page.NextID = page.Users[limit-1].ID
}
return page, nil
}
// OrganizationDirectory reads all personal/business and active/archived records.
// It does not join membership, grant access, or choose a merchant. Search covers
// exact ID and literal slug/name text using SQLite's ASCII case folding.
func (store *Store) OrganizationDirectory(ctx context.Context, query organizations.DirectoryQuery) (organizations.DirectoryPage, error) {
pattern, limit, valid := directoryQuery(query.Search, query.AfterID, query.Limit)
if !valid {
return organizations.DirectoryPage{}, organizations.ErrDirectoryQuery
}
rows, err := store.db.QueryContext(ctx, `SELECT id,slug,name,status,personal,revision,created_at,updated_at
FROM gwf_organizations WHERE id>? AND (?='' OR id=? OR slug LIKE ? ESCAPE '\' OR name LIKE ? ESCAPE '\')
ORDER BY id LIMIT ?`, query.AfterID, strings.TrimSpace(query.Search), strings.TrimSpace(query.Search), pattern, pattern, limit+1)
if err != nil {
return organizations.DirectoryPage{}, err
}
defer rows.Close()
page := organizations.DirectoryPage{Organizations: make([]organizations.Organization, 0, limit)}
for rows.Next() {
var value organizations.Organization
var created, updated int64
if err = rows.Scan(&value.ID, &value.Slug, &value.Name, &value.Status, &value.Personal, &value.Revision, &created, &updated); err != nil {
return organizations.DirectoryPage{}, err
}
value.CreatedAt, value.UpdatedAt = time.Unix(created, 0).UTC(), time.Unix(updated, 0).UTC()
page.Organizations = append(page.Organizations, value)
}
if err = rows.Err(); err != nil {
return organizations.DirectoryPage{}, err
}
if len(page.Organizations) > limit {
page.Organizations = page.Organizations[:limit]
page.NextID = page.Organizations[limit-1].ID
}
return page, nil
}
func directoryQuery(search, after string, limit int) (string, int, bool) {
if !text(search, 128, true) || after != "" && !opaqueID(after) || limit < 0 || limit > 200 {
return "", 0, false
}
if limit == 0 {
limit = 50
}
// Wildcards and the escape character are literal user text, never operators.
pattern := "%" + strings.NewReplacer(`\`, `\\`, `%`, `\%`, `_`, `\_`).Replace(strings.TrimSpace(search)) + "%"
return pattern, limit, true
}
+146
View File
@@ -0,0 +1,146 @@
// SPDX-License-Identifier: MPL-2.0
package authsqlite
import (
"context"
"encoding/json"
"errors"
"fmt"
"path/filepath"
"strings"
"testing"
"gamertan.com/web/auth"
"gamertan.com/web/organizations"
)
func TestInstanceDirectoriesAreBoundedCredentialFreeAndIndependentOfMembership(t *testing.T) {
store, err := Open(filepath.Join(t.TempDir(), "directory.sqlite"))
if err != nil {
t.Fatal(err)
}
defer store.Close()
ctx := t.Context()
for index := 0; index < 205; index++ {
id := fmt.Sprintf("record-%03d", index)
status := []string{"active", "suspended", "disabled"}[index%3]
_, err = store.db.ExecContext(ctx, `INSERT INTO gwf_users(id,username,username_normalized,email,email_normalized,display_name,status,password_change_required,registration_pending,created_at,updated_at) VALUES(?,?,?,?,?,?,?,?,?,1,1)`, id, id, id, id+"@example.test", id+"@example.test", "Person "+id, status, index%2, index%5 == 0)
if err != nil {
t.Fatal(err)
}
_, err = store.db.ExecContext(ctx, `INSERT INTO gwf_organizations(id,slug,name,personal,status,revision,created_at,updated_at) VALUES(?,?,?,?,?,1,1,1)`, id, id, "Business "+id, index%2, []string{"active", "archived"}[index%2])
if err != nil {
t.Fatal(err)
}
}
users, err := store.UserDirectory(ctx, auth.UserDirectoryQuery{})
if err != nil || len(users.Users) != 50 || users.NextID != "record-049" {
t.Fatalf("default users: %d %q %v", len(users.Users), users.NextID, err)
}
if !users.Users[0].RegistrationPending || users.Users[1].Status != "suspended" || !users.Users[1].PasswordChangeRequired || users.Users[2].Status != "disabled" {
t.Fatal("administrative account states were hidden")
}
encoded, _ := json.Marshal(users)
for _, secret := range []string{"password_hash", "Session", "Digest", "Credential", "Recovery"} {
if strings.Contains(string(encoded), secret) {
t.Fatalf("directory leaked credential field %s", secret)
}
}
for _, size := range []int{1, 50, 200} {
userAfter, orgAfter, count := "", "", 0
for {
users, err := store.UserDirectory(ctx, auth.UserDirectoryQuery{AfterID: userAfter, Limit: size})
if err != nil {
t.Fatal(err)
}
orgs, err := store.OrganizationDirectory(ctx, organizations.DirectoryQuery{AfterID: orgAfter, Limit: size})
if err != nil {
t.Fatal(err)
}
if len(users.Users) != len(orgs.Organizations) || len(users.Users) > size {
t.Fatal("invalid page bound")
}
for index, user := range users.Users {
want := fmt.Sprintf("record-%03d", count)
if user.ID != want || orgs.Organizations[index].ID != want {
t.Fatalf("pagination skipped/duplicated %s", want)
}
count++
}
if users.NextID == "" || orgs.NextID == "" {
if users.NextID != orgs.NextID || count != 205 {
t.Fatalf("early end: %d", count)
}
break
}
userAfter, orgAfter = users.NextID, orgs.NextID
}
}
orgs, err := store.OrganizationDirectory(ctx, organizations.DirectoryQuery{Limit: 2})
if err != nil || orgs.Organizations[0].Personal || !orgs.Organizations[1].Personal || orgs.Organizations[1].Status != "archived" {
t.Fatal("personal/archived organizations omitted")
}
// A display-name change cannot move a record behind a stable-ID cursor.
if _, err = store.db.Exec(`UPDATE gwf_users SET display_name='AAA' WHERE id='record-050'`); err != nil {
t.Fatal(err)
}
next, err := store.UserDirectory(ctx, auth.UserDirectoryQuery{AfterID: "record-049", Limit: 1})
if err != nil || next.Users[0].ID != "record-050" {
t.Fatal("name change disturbed cursor")
}
}
func TestInstanceDirectoryLiteralSearchValidationAndCancellation(t *testing.T) {
store, err := Open(filepath.Join(t.TempDir(), "directory.sqlite"))
if err != nil {
t.Fatal(err)
}
defer store.Close()
_, err = store.db.Exec(`INSERT INTO gwf_users(id,username,username_normalized,email,email_normalized,display_name,status,created_at,updated_at) VALUES('person-001','Alice','alice','Alice@example.test','alice@example.test','Élodie 50%_\ works','active',1,1)`)
if err != nil {
t.Fatal(err)
}
_, err = store.db.Exec(`INSERT INTO gwf_organizations(id,slug,name,personal,status,revision,created_at,updated_at) VALUES('company-001','alice-company','Élodie 50%_\ works',0,'active',1,1,1)`)
if err != nil {
t.Fatal(err)
}
for _, search := range []string{"", " ALICE ", "example.test", "person-001", "Élodie", `50%_\`} {
page, err := store.UserDirectory(t.Context(), auth.UserDirectoryQuery{Search: search})
if err != nil || len(page.Users) != 1 || page.NextID != "" {
t.Errorf("user literal search %q: %#v %v", search, page, err)
}
}
for _, search := range []string{"", "ALICE", "company-001", "Élodie", `50%_\`} {
page, err := store.OrganizationDirectory(t.Context(), organizations.DirectoryQuery{Search: search})
if err != nil || len(page.Organizations) != 1 || page.NextID != "" {
t.Errorf("organization literal search %q: %#v %v", search, page, err)
}
}
for _, search := range []string{"absent", "%' OR 1=1 --", "%_%", "\\_%"} {
users, err := store.UserDirectory(t.Context(), auth.UserDirectoryQuery{Search: search})
if err != nil || users.Users == nil || len(users.Users) != 0 {
t.Errorf("nonliteral user search %q", search)
}
orgs, err := store.OrganizationDirectory(t.Context(), organizations.DirectoryQuery{Search: search})
if err != nil || orgs.Organizations == nil || len(orgs.Organizations) != 0 {
t.Errorf("nonliteral org search %q", search)
}
}
for _, query := range []auth.UserDirectoryQuery{{Search: strings.Repeat("a", 129)}, {Search: "bad\x00value"}, {Search: "bad\nvalue"}, {Search: "\xff"}, {AfterID: "bad/id"}, {AfterID: strings.Repeat("a", 129)}, {Limit: -1}, {Limit: 201}} {
if _, err := store.UserDirectory(t.Context(), query); !errors.Is(err, auth.ErrDirectoryQuery) {
t.Errorf("invalid user query accepted: %#v %v", query, err)
}
if _, err := store.OrganizationDirectory(t.Context(), organizations.DirectoryQuery{Search: query.Search, AfterID: query.AfterID, Limit: query.Limit}); !errors.Is(err, organizations.ErrDirectoryQuery) {
t.Errorf("invalid org query accepted: %#v %v", query, err)
}
}
ctx, cancel := context.WithCancel(t.Context())
cancel()
if _, err = store.UserDirectory(ctx, auth.UserDirectoryQuery{}); !errors.Is(err, context.Canceled) {
t.Fatalf("user cancellation: %v", err)
}
if _, err = store.OrganizationDirectory(ctx, organizations.DirectoryQuery{}); !errors.Is(err, context.Canceled) {
t.Fatalf("organization cancellation: %v", err)
}
}
+101
View File
@@ -0,0 +1,101 @@
// SPDX-License-Identifier: MPL-2.0
package authsqlite
import (
"context"
"database/sql"
"errors"
"math"
"time"
"gamertan.com/web/auth"
"modernc.org/sqlite"
)
var _ auth.OwnProfileRepository = (*Store)(nil)
const ownProfileQuery = `SELECT u.id,u.username,u.email,u.display_name,u.profile_revision
FROM gwf_users u JOIN gwf_auth_sessions s ON s.user_id=u.id
WHERE s.token_hash=? AND s.expires_at>? AND u.status='active'
AND u.registration_pending=0 AND u.password_change_required=0`
func scanOwnProfile(row interface{ Scan(...any) error }) (auth.OwnProfile, error) {
var profile auth.OwnProfile
err := row.Scan(&profile.UserID, &profile.Username, &profile.Email, &profile.DisplayName, &profile.Revision)
if errors.Is(err, sql.ErrNoRows) {
return auth.OwnProfile{}, auth.ErrProfileAccess
}
return profile, err
}
func (store *Store) OwnProfile(ctx context.Context, session [32]byte, now time.Time) (auth.OwnProfile, error) {
if zeroDigest(session) || now.IsZero() {
return auth.OwnProfile{}, auth.ErrProfileAccess
}
return scanOwnProfile(store.db.QueryRowContext(ctx, ownProfileQuery, session[:], now.Unix()))
}
func (store *Store) UpdateOwnProfile(ctx context.Context, change auth.ProfileEdit, audit auth.AuditEvent) (auth.OwnProfile, error) {
value, err := auth.NormalizeProfileValue(change.Field, change.Value)
if err != nil || !opaqueID(change.UserID) || zeroDigest(change.SessionDigest) || change.ExpectedRevision < 1 || change.ExpectedRevision == math.MaxInt64 ||
!validAuditEvent(audit) || audit.ActorUserID != change.UserID || audit.ResourceType != "user" || audit.ResourceID != change.UserID || audit.Action != "auth.profile."+change.Field ||
change.ExpectedPasswordHash != "" && (change.Field != "username" || len(change.ExpectedPasswordHash) > 1024) {
return auth.OwnProfile{}, auth.ErrProfileInput
}
tx, err := store.db.BeginTx(ctx, nil)
if err != nil {
return auth.OwnProfile{}, err
}
defer tx.Rollback()
// This first statement takes the writer lock and tests the real current
// session/account/revision together. No read-before-write lock upgrade race.
set := `display_name=?`
args := []any{value}
if change.Field == "username" {
set = `username=?,username_normalized=?`
args = append(args, normalize(value))
}
args = append(args, audit.CreatedAt.Unix(), change.UserID, change.ExpectedRevision, change.SessionDigest[:], audit.CreatedAt.Unix(), change.ExpectedPasswordHash, change.ExpectedPasswordHash)
result, err := tx.ExecContext(ctx, `UPDATE gwf_users SET `+set+`,profile_revision=profile_revision+1,updated_at=MAX(updated_at,?)
WHERE id=? AND profile_revision=? AND status='active' AND registration_pending=0 AND password_change_required=0
AND EXISTS (SELECT 1 FROM gwf_auth_sessions WHERE user_id=gwf_users.id AND token_hash=? AND expires_at>?)
AND (?='' OR EXISTS (SELECT 1 FROM gwf_password_credentials WHERE user_id=gwf_users.id AND password_hash=?))`, args...)
if err != nil {
var constraint *sqlite.Error
if errors.As(err, &constraint) && constraint.Code() == 2067 {
return auth.OwnProfile{}, auth.ErrUsernameUnavailable
}
return auth.OwnProfile{}, err
}
changed, err := result.RowsAffected()
if err != nil {
return auth.OwnProfile{}, err
}
if changed != 1 {
profile, err := scanOwnProfile(tx.QueryRowContext(ctx, ownProfileQuery, change.SessionDigest[:], audit.CreatedAt.Unix()))
if err != nil {
return auth.OwnProfile{}, err
}
if profile.UserID != change.UserID {
return auth.OwnProfile{}, auth.ErrProfileAccess
}
return auth.OwnProfile{}, auth.ErrProfileConflict
}
if change.Field == "username" {
if _, err = tx.ExecContext(ctx, `DELETE FROM gwf_auth_sessions WHERE user_id=? AND token_hash<>?`, change.UserID, change.SessionDigest[:]); err != nil {
return auth.OwnProfile{}, err
}
}
if err = appendAudit(ctx, tx, audit); err != nil {
return auth.OwnProfile{}, err
}
profile, err := scanOwnProfile(tx.QueryRowContext(ctx, ownProfileQuery, change.SessionDigest[:], audit.CreatedAt.Unix()))
if err != nil {
return auth.OwnProfile{}, err
}
if err = tx.Commit(); err != nil {
return auth.OwnProfile{}, err
}
return profile, nil
}
+212
View File
@@ -0,0 +1,212 @@
// SPDX-License-Identifier: MPL-2.0
package authsqlite
import (
"crypto/sha256"
"errors"
"path/filepath"
"sync"
"testing"
"time"
"gamertan.com/web/auth"
)
type profileFixture struct {
store *Store
path string
now time.Time
user auth.User
session, other auth.Session
}
func newProfileFixture(t *testing.T) profileFixture {
t.Helper()
path := filepath.Join(t.TempDir(), "identity.sqlite")
store, err := Open(path)
if err != nil {
t.Fatal(err)
}
t.Cleanup(func() { store.Close() })
now := time.Now().UTC().Truncate(time.Second)
user := auth.User{ID: "profile-user", Username: "profile.reader", Email: "profile@example.test", DisplayName: "Profile Reader", Status: "active", CreatedAt: now, UpdatedAt: now}
if err = store.CreateUser(t.Context(), user, "fixture-hash"); err != nil {
t.Fatal(err)
}
session := auth.Session{UserID: user.ID, Digest: sha256.Sum256([]byte("acting-session")), CreatedAt: now, LastSeenAt: now, ExpiresAt: now.Add(time.Hour)}
other := session
other.Digest = sha256.Sum256([]byte("other-session"))
for _, s := range []auth.Session{session, other} {
if err = store.CreateSession(t.Context(), s); err != nil {
t.Fatal(err)
}
}
return profileFixture{store, path, now, user, session, other}
}
func (f profileFixture) change(field, value string, revision int64) (auth.ProfileEdit, auth.AuditEvent) {
return auth.ProfileEdit{UserID: f.user.ID, SessionDigest: f.session.Digest, ExpectedRevision: revision, Field: field, Value: value},
auth.AuditEvent{ID: "profile-audit-" + field, ActorUserID: f.user.ID, Action: "auth.profile." + field, ResourceType: "user", ResourceID: f.user.ID, Summary: "Own profile field changed", CreatedAt: f.now}
}
func TestOwnProfileStableIdentityAndSessionPolicy(t *testing.T) {
f := newProfileFixture(t)
initial, err := f.store.OwnProfile(t.Context(), f.session.Digest, f.now)
if err != nil || initial.Revision != 1 {
t.Fatalf("initial revision: %d %v", initial.Revision, err)
}
change, audit := f.change("display_name", " Émilie ★ ", 1)
updated, err := f.store.UpdateOwnProfile(t.Context(), change, audit)
if err != nil || updated.DisplayName != "Émilie ★" || updated.Revision != 2 || updated.UserID != initial.UserID || updated.Username != initial.Username || updated.Email != initial.Email {
t.Fatalf("display update: %+v %v", updated, err)
}
if _, err = f.store.OwnProfile(t.Context(), f.other.Digest, f.now); err != nil {
t.Fatal("display edit revoked session", err)
}
if _, err = f.store.UpdateOwnProfile(t.Context(), change, audit); !errors.Is(err, auth.ErrProfileConflict) {
t.Fatalf("stale: %v", err)
}
change, audit = f.change("username", "new.reader", 2)
change.ExpectedPasswordHash = "fixture-hash"
updated, err = f.store.UpdateOwnProfile(t.Context(), change, audit)
if err != nil || updated.Username != "new.reader" || updated.Revision != 3 || updated.UserID != initial.UserID || updated.Email != initial.Email {
t.Fatalf("username update: %+v %v", updated, err)
}
if _, err = f.store.OwnProfile(t.Context(), f.other.Digest, f.now); !errors.Is(err, auth.ErrProfileAccess) {
t.Fatalf("other session survived: %v", err)
}
user, hash, err := f.store.CredentialByIdentifier(t.Context(), "NEW.READER")
if err != nil || user.ID != initial.UserID || hash != "fixture-hash" {
t.Fatal("credential identity changed", err)
}
var count int
if err = f.store.db.QueryRow(`SELECT count(*) FROM gwf_audit_events WHERE actor_user_id=? AND resource_id=?`, f.user.ID, f.user.ID).Scan(&count); err != nil || count != 2 {
t.Fatalf("audits: %d %v", count, err)
}
reopened, err := OpenWithOptions(f.path, OpenOptions{Migrate: false})
if err != nil {
t.Fatal(err)
}
defer reopened.Close()
if recovered, err := reopened.OwnProfile(t.Context(), f.session.Digest, f.now); err != nil || recovered != updated {
t.Fatalf("restart: %+v %v", recovered, err)
}
}
func TestOwnProfileAuthorizationAndRollback(t *testing.T) {
for _, test := range []struct{ name, sql string }{
{"revoked-session", `DELETE FROM gwf_auth_sessions`},
{"expired-session", `UPDATE gwf_auth_sessions SET expires_at=1`},
{"suspended", `UPDATE gwf_users SET status='suspended'`},
{"disabled", `UPDATE gwf_users SET status='disabled'`},
{"registration-pending", `UPDATE gwf_users SET registration_pending=1`},
{"password-change", `UPDATE gwf_users SET password_change_required=1`},
} {
t.Run(test.name, func(t *testing.T) {
f := newProfileFixture(t)
if _, err := f.store.db.Exec(test.sql); err != nil {
t.Fatal(err)
}
change, audit := f.change("display_name", "not allowed", 1)
if _, err := f.store.UpdateOwnProfile(t.Context(), change, audit); !errors.Is(err, auth.ErrProfileAccess) {
t.Fatalf("access: %v", err)
}
})
}
f := newProfileFixture(t)
change, audit := f.change("username", "new.reader", 1)
change.UserID = "another-user"
audit.ActorUserID = change.UserID
audit.ResourceID = change.UserID
if _, err := f.store.UpdateOwnProfile(t.Context(), change, audit); !errors.Is(err, auth.ErrProfileAccess) {
t.Fatalf("foreign user: %v", err)
}
change, audit = f.change("username", "new.reader", 1)
change.ExpectedPasswordHash = "old-verified-hash"
if _, err := f.store.UpdateOwnProfile(t.Context(), change, audit); !errors.Is(err, auth.ErrProfileConflict) {
t.Fatalf("changed password: %v", err)
}
change.ExpectedPasswordHash = "fixture-hash"
if err := f.store.AppendAudit(t.Context(), audit); err != nil {
t.Fatal(err)
}
if _, err := f.store.UpdateOwnProfile(t.Context(), change, audit); err == nil {
t.Fatal("duplicate audit accepted")
}
if profile, err := f.store.OwnProfile(t.Context(), f.session.Digest, f.now); err != nil || profile.Revision != 1 || profile.Username != f.user.Username {
t.Fatalf("rollback: %+v %v", profile, err)
}
if _, err := f.store.OwnProfile(t.Context(), f.other.Digest, f.now); err != nil {
t.Fatal("audit failure revoked session", err)
}
}
func TestOwnProfileUniquenessConcurrencyAndMigration(t *testing.T) {
f := newProfileFixture(t)
otherUser := f.user
otherUser.ID = "another-user"
otherUser.Username = "another.reader"
otherUser.Email = "another@example.test"
if err := f.store.CreateUser(t.Context(), otherUser, "fixture-hash"); err != nil {
t.Fatal(err)
}
change, audit := f.change("username", "ANOTHER.READER", 1)
if _, err := f.store.UpdateOwnProfile(t.Context(), change, audit); !errors.Is(err, auth.ErrUsernameUnavailable) {
t.Fatalf("unique name: %v", err)
}
second, err := OpenWithOptions(f.path, OpenOptions{Migrate: false})
if err != nil {
t.Fatal(err)
}
defer second.Close()
var wg sync.WaitGroup
results := make(chan error, 2)
for _, store := range []*Store{f.store, second} {
wg.Add(1)
go func(store *Store) {
defer wg.Done()
change, audit := f.change("display_name", "New Name", 1)
_, err := store.UpdateOwnProfile(t.Context(), change, audit)
results <- err
}(store)
}
wg.Wait()
close(results)
success, conflict := 0, 0
for err := range results {
if err == nil {
success++
} else if errors.Is(err, auth.ErrProfileConflict) {
conflict++
} else {
t.Fatal(err)
}
}
if success != 1 || conflict != 1 {
t.Fatalf("concurrent writes: %d successes, %d conflicts", success, conflict)
}
// Recreate the actual previous schema without rewriting its identity rows.
if _, err = f.store.db.Exec(`ALTER TABLE gwf_users DROP COLUMN profile_revision`); err != nil {
t.Fatal(err)
}
if _, err = f.store.db.Exec(`DELETE FROM gamertan_web_migrations WHERE version=11`); err != nil {
t.Fatal(err)
}
if version, err := f.store.CurrentSchema(t.Context()); err != nil || version != 10 {
t.Fatalf("prior schema: %d %v", version, err)
}
if err = f.store.RequireCurrentSchema(t.Context()); err == nil {
t.Fatal("startup accepted old schema")
}
if err = f.store.Migrate(t.Context()); err != nil {
t.Fatal(err)
}
profile, err := f.store.OwnProfile(t.Context(), f.session.Digest, f.now)
if err != nil || profile.UserID != f.user.ID || profile.Email != f.user.Email || profile.DisplayName != "New Name" || profile.Revision != 1 {
t.Fatalf("migration: %+v %v", profile, err)
}
if err = f.store.Migrate(t.Context()); err != nil {
t.Fatal("idempotent migration", err)
}
}
+2 -1
View File
@@ -351,7 +351,8 @@ func TestRoleInvitationMigrationPreservesLegacyAndRequiresExplicitMigration(t *t
// Reconstruct the previous invitation schema in this disposable database.
if _, err = f.store.db.Exec(`ALTER TABLE gwf_organization_invitations DROP COLUMN direct_roles_json;
ALTER TABLE gwf_organization_invitations DROP COLUMN required_owner_role;
DELETE FROM gamertan_web_migrations WHERE version=10`); err != nil {
ALTER TABLE gwf_users DROP COLUMN profile_revision;
DELETE FROM gamertan_web_migrations WHERE version>=10`); err != nil {
t.Fatal(err)
}
if err = f.store.RequireCurrentSchema(t.Context()); err == nil {
+5 -1
View File
@@ -77,7 +77,7 @@ func OpenWithOptions(path string, options OpenOptions) (*Store, error) {
return store, nil
}
const SchemaVersion = 10
const SchemaVersion = 11
func (store *Store) CurrentSchema(ctx context.Context) (int, error) {
var exists int
@@ -179,6 +179,7 @@ func (store *Store) Migrate(ctx context.Context) error {
table, column, definition string
}{
{"gwf_users", "registration_pending", `INTEGER NOT NULL DEFAULT 0 CHECK(registration_pending IN (0,1))`},
{"gwf_users", "profile_revision", `INTEGER NOT NULL DEFAULT 1 CHECK(profile_revision > 0)`},
{"gwf_organizations", "status", `TEXT NOT NULL DEFAULT 'active' CHECK(status IN ('active','archived'))`},
{"gwf_organizations", "revision", `INTEGER NOT NULL DEFAULT 1 CHECK(revision > 0)`},
{"gwf_organizations", "updated_at", `INTEGER NOT NULL DEFAULT 0`},
@@ -244,6 +245,9 @@ func (store *Store) Migrate(ctx context.Context) error {
if _, err = tx.ExecContext(ctx, `INSERT OR IGNORE INTO gamertan_web_migrations(version,applied_at) VALUES(10,?)`, time.Now().UTC().Unix()); err != nil {
return err
}
if _, err = tx.ExecContext(ctx, `INSERT OR IGNORE INTO gamertan_web_migrations(version,applied_at) VALUES(11,?)`, time.Now().UTC().Unix()); err != nil {
return err
}
return tx.Commit()
}
+23
View File
@@ -21,3 +21,26 @@ template. Its private evidence, persistent bans, account data, route policy,
operator exclusions, synchronization, and publishing workflow remain
application-owned. Useful pressure from that migration may improve a general
interface, but it may not smuggle EQL-specific policy into this module.
## Optional personal-profile editing
`auth.OwnProfileRepository` supports a narrow self-service boundary independently
of instance-directory authorization. Load the profile using the current session
digest; derive the target from that result. Normalize one username or display
name using `auth.NormalizeProfileValue`. Never decode an HTTP body directly into
`auth.ProfileEdit`, which carries trusted identity and credential-check state.
Require CSRF/origin validation for browser writes and rate-limit credential work.
For username changes, verify the current password (supply its hash as
`ExpectedPasswordHash`) or consume an exact operation-bound passkey approval;
enforce any additional authentication policy your application requires. Include
the session, user, value and expected profile revision in the passkey binding.
The SQLite transaction rechecks session/account/revision and any verified hash,
updates one field, revokes other sessions for username edits, and appends audit.
Do not log the command or include secret material in its audit.
Schema 11 adds `profile_revision` without changing stable identity keys. Run an
explicit migration before starting an adopter with automatic migration disabled.
Keep the pre-migration backup; adjacent older binaries are not approved writers
for the migrated schema. Email-change enrollment/confirmation is not implemented
by this interface and must not be simulated with an unverified direct update.
+21 -2
View File
@@ -8,6 +8,25 @@ application concern belongs in the shared module.
## Gamertan accounts and commerce
- Personal identity editing is not instance administration. `OwnProfileRepository`
derives self-access from the active session; `ProfileEdit` is a trusted internal
command, never a browser request model. SQLite schema 11 adds a monotonic
revision because timestamps alone cannot distinguish two edits in one second.
Session/account/revision checks, mutation and audit share one write transaction.
Username edits invalidate other sessions without changing immutable IDs,
memberships, credentials, orders or provider billing identities. A password
proof binds the verified hash into that transaction; passkey proofs must bind
the exact user/session/field/value/revision before calling it. The application
chooses account-specific reauthentication and owns its credential-work limits.
Email requires a separate verified change protocol, not another accepted field.
- Instance operators need all-user/all-organization directories, not a staff
roster or implicit membership in every business. Optional bounded readers now
expose identity/profile records without credentials, independent of membership.
The application must authorize each call through an explicit instance scope;
these readers intentionally contain no Gamertan-specific roles or UI policy.
Stable-ID cursors and literal searches are covered against pagination gaps,
renamed profiles, inactive/personal records and wildcard/query injection.
- Customer profile and membership editing requires current ownership for every
write, not just changes involving another owner. The existing generic methods
intentionally permit application-authorized delegated administrators, so an
@@ -40,8 +59,8 @@ application concern belongs in the shared module.
policy; there is no new database schema or commerce dependency in Foundations.
- The account email remains required and unique. Gamertan uses normalized
email as the canonical login identifier and keeps username as a stable public
identity. Until a mail package exists, the application must not describe an
email as the canonical login identifier; the immutable user ID, not the editable
username, owns account relationships. Until a mail package exists, it must not describe an
address as verified merely because it was entered during registration.
- Password authentication is sufficient for an ordinary customer base
session. Privileged application actions use an exact operation binding with
+1 -1
View File
@@ -26,7 +26,7 @@ The packages are ordinary Go imports. Pin the current preview and verify its
module checksum:
```bash
go get gamertan.com/web/requestmeta@v0.1.0-preview.24
go get gamertan.com/web/requestmeta@v0.1.0-preview.26
go mod verify
```
+1 -1
View File
@@ -18,7 +18,7 @@ import "gamertan.com/web/requestmeta"
and request the containing module at an exact version:
```bash
go get gamertan.com/web/requestmeta@v0.1.0-preview.24
go get gamertan.com/web/requestmeta@v0.1.0-preview.25
```
Only imported packages are compiled and linked. The packages nevertheless
+19
View File
@@ -40,6 +40,25 @@ never accept the owner-role policy or actor identity from submitted fields.
## Creating an organization with an owner
For instance-wide administrative directories, the optional
`auth.UserDirectoryRepository` and `organizations.DirectoryRepository` readers
on `authsqlite.Store` list all identities/organizations, not just memberships.
**Authorize an explicit instance-read capability before every call.** These are
not customer self-service or public directory APIs; they deliberately include
incomplete/inactive accounts and personal/archived organizations without exposing
credentials, recovery material or invitations. Merchant classification remains
application policy. Reading never creates a membership or grants a role.
Both queries accept literal `Search` (up to 128 bytes), exclusive `AfterID`, and
`Limit` (default 50, maximum 200). An empty `NextID` ends the result. Preserve the
search when following a cursor; reset it when changing the search. IDs give stable
ordering despite renamed profiles, but pages are current views rather than a
multi-request snapshot. New records sorting before a cursor appear on a fresh
listing. SQLite search folds ASCII case; non-ASCII display-name text matches with
its original case. Wildcards and SQL fragments are always literal search text.
These optional readers do not change the required authentication/organization
repository contracts or schema 10.
For an existing authenticated user creating a business, use
`CreateOwnedOrganization` with `OwnerRole` configured when constructing the
service. Seed that role first. This commits the organization, active membership,
+32
View File
@@ -0,0 +1,32 @@
// SPDX-License-Identifier: MPL-2.0
package organizations
import (
"context"
"errors"
)
var ErrDirectoryQuery = errors.New("organizations: invalid directory query")
// DirectoryQuery searches all organizations independently of membership.
// Search is literal text. AfterID is an exclusive stable-ID cursor. Limit
// defaults to 50 and may not exceed 200.
type DirectoryQuery struct {
Search, AfterID string
Limit int
}
type DirectoryPage struct {
Organizations []Organization
NextID string
}
// DirectoryRepository is an optional administrative read capability. The caller
// MUST authorize instance-wide organization access. Personal and archived records
// are included; no membership is granted and no invitations or secrets are read.
// The application classifies its configured merchant organization. Pagination is
// a current view, not a snapshot across requests.
type DirectoryRepository interface {
OrganizationDirectory(context.Context, DirectoryQuery) (DirectoryPage, error)
}
+8
View File
@@ -29,6 +29,9 @@ analytics/fuzz_test.go
analytics/geo.go
auth/auth.go
auth/context.go
auth/directory.go
auth/profile.go
auth/profile_test.go
auth/password.go
auth/password_test.go
authrecovery/recovery.go
@@ -41,6 +44,10 @@ authhttp/passkey.go
authhttp/passkey_test.go
authsqlite/store.go
authsqlite/store_test.go
authsqlite/directory.go
authsqlite/directory_test.go
authsqlite/profile.go
authsqlite/profile_test.go
authsqlite/account.go
authsqlite/account_test.go
authsqlite/access.go
@@ -91,6 +98,7 @@ requestmeta/requestmeta_test.go
organizations/organizations.go
organizations/organizations_test.go
organizations/owned.go
organizations/directory.go
organizations/owned_test.go
organizations/role_invitations.go
organizations/role_invitations_test.go