mengstack-api/internal/modules/auth/.spec/module.md
MengStack Dev df809f1045
Some checks failed
CI / Build & Test (push) Failing after 1m31s
feat: user CRUD API + dashboard stats + kernel infrastructure
- Add user management endpoints (list/create/get/update/delete) with pagination and search
- Add dashboard stats endpoint with tenant/user/online counts and growth metrics
- Add tenant resolver middleware for multi-tenant request scoping
- Add i18n kernel with zh/en message files and AcceptLanguage middleware
- Add WebSocket hub/handler for real-time communication
- Add job scheduler kernel with cron support
- Add plugin sandbox for isolated execution
- Add storage kernel (local filesystem)
- Add event bus kernel for pub/sub
- Add cache kernel abstraction
- Add database migration runner and version upgrade checker
- Add rate limiting middleware with Redis backend
- Add SQL migrations for rbac, audit_logs, settings, notifications, examples
- Extend user repository with list/delete/count operations
- Register all module routes with tenant resolver
2026-10-03 03:42:58 +08:00

47 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Auth 模块规范
## 模块边界
auth 模块负责用户身份认证:注册、登录、登出、JWT 签发与刷新。
**属于本模块:** 用户实体、密码哈希、JWT 令牌、登录/注册流程
**不属于本模块:** 角色权限(→ rbac)、组织架构(→ org)、审计记录(→ audit)
## 文件职责
| 文件 | 层 | 职责 |
|------|---|------|
| `domain/user.go` | 领域 | User 实体定义,零外部依赖 |
| `domain/dto.go` | 领域 | RegisterRequest/LoginRequest 等 DTO |
| `domain/repository.go` | 领域 | UserRepository 接口定义 |
| `application/service.go` | 应用 | 业务编排:注册/登录/刷新 |
| `application/jwt.go` | 应用 | JWT 签发/验证/刷新逻辑 |
| `infrastructure/user_repo.go` | 基础设施 | GORM 实现 UserRepository |
| `infrastructure/migrate.go` | 基础设施 | AutoMigrate 注册(开发用) |
| `interfaces/handler.go` | 接口 | HTTP Handler,参数校验 |
| `interfaces/routes.go` | 接口 | 路由注册 |
## 接口约定
```
POST /api/v1/auth/register → 注册(email/username/password)
POST /api/v1/auth/login → 登录(返回 access_token + refresh_token)
POST /api/v1/auth/refresh → 刷新令牌(需 refresh_token)
POST /api/v1/auth/logout → 登出(需认证)
GET /api/v1/auth/me → 获取当前用户信息
```
## 边界案例
- 同租户 email 唯一约束 → 重复注册返回 ErrDuplicate
- 密码错误次数过多 → 账户锁定(预留,当前未实现锁定策略)
- Refresh Token 过期 → 返回 ErrTokenExpired,客户端需重新登录
- 跨租户访问 → Repository 层强制 tenant_id 条件,不可能越界
## 禁止
- domain/ 禁止 import gorm、http、redis
- 禁止在 Handler 层写业务逻辑
- 禁止明文存储密码
- 禁止在日志中打印密码或 token