auth
Shared session, password-hashing, and TOTP primitives consumed by both
customer_accounts and admin_users. One of the two singular module
folders permitted by the naming conventions (alongside example).
What it owns
- Sessions —
session-service.tspersists session rows in Postgres with a Redis cache layer for hot reads; cookies signed via@fastify/cookie. - Password hashing —
password-hasher.tswraps argon2id; defaults are tuned for the target hardware (see the Hardware & system requirements section ofREADME.mdat the repository root). - TOTP — the platform's
kernel/crypto/totpwrapsotpauth+ a backup-code pool. - Fastify plugin —
plugin.tsparses the session cookie and attachesrequest.actor = { kind, id, ... }plusrequest.adminActor. - Route guards —
requireAdmin(permission?),requireAdminAny(codes)andrequireCustomer, provided as ports frombackend.tsand resolved by every module that gates a route. They were Fastify decorators on the plugin once; they were turned into ports so production and the test harness run the same implementation instead of one each.
No HTTP routes of its own
auth is a primitive module — login/logout/2FA endpoints belong to the
customer-facing customer_accounts and admin-facing admin_users
modules.
Extension points
- Session storage —
session-serviceis constructed with(em, redis); alternative caches plug in here. - Custom actor kinds — extend the
request.actordiscriminated union and update therequireXpre-handlers; existing callers keep working because the routes only use therequireXfactory they already consume.