feat(epic2): Implement core authentication and authorization services

- Implement Audit Service (2.5)
  - gRPC server with Record and Query operations
  - Database persistence with audit schema
  - Service registry integration
  - Entry point: cmd/audit-service

- Implement Identity Service (2.2)
  - User CRUD operations
  - Password hashing with argon2id
  - Email verification and password reset flows
  - Entry point: cmd/identity-service
  - Fix package naming conflicts in user_service.go

- Implement Auth Service (2.1)
  - JWT token generation and validation
  - Login, RefreshToken, ValidateToken, Logout RPCs
  - Integration with Identity Service
  - Entry point: cmd/auth-service
  - Note: RefreshToken entity needs Ent generation

- Implement Authz Service (2.3, 2.4)
  - Permission checking and authorization
  - User roles and permissions retrieval
  - RBAC-based authorization
  - Entry point: cmd/authz-service

- Implement gRPC clients for all services
  - Auth, Identity, Authz, and Audit clients
  - Service discovery integration
  - Full gRPC communication

- Add service configurations to config/default.yaml
- Create SUMMARY.md with implementation details and testing instructions
- Fix compilation errors in Identity Service (password package conflicts)
- All services build successfully and tests pass
This commit is contained in:
2025-11-06 20:07:20 +01:00
parent da7a4e3703
commit b1b895e818
91 changed files with 19502 additions and 375 deletions

View File

@@ -43,6 +43,66 @@ func (_u *UserUpdate) SetNillableEmail(v *string) *UserUpdate {
return _u
}
// SetUsername sets the "username" field.
func (_u *UserUpdate) SetUsername(v string) *UserUpdate {
_u.mutation.SetUsername(v)
return _u
}
// SetNillableUsername sets the "username" field if the given value is not nil.
func (_u *UserUpdate) SetNillableUsername(v *string) *UserUpdate {
if v != nil {
_u.SetUsername(*v)
}
return _u
}
// ClearUsername clears the value of the "username" field.
func (_u *UserUpdate) ClearUsername() *UserUpdate {
_u.mutation.ClearUsername()
return _u
}
// SetFirstName sets the "first_name" field.
func (_u *UserUpdate) SetFirstName(v string) *UserUpdate {
_u.mutation.SetFirstName(v)
return _u
}
// SetNillableFirstName sets the "first_name" field if the given value is not nil.
func (_u *UserUpdate) SetNillableFirstName(v *string) *UserUpdate {
if v != nil {
_u.SetFirstName(*v)
}
return _u
}
// ClearFirstName clears the value of the "first_name" field.
func (_u *UserUpdate) ClearFirstName() *UserUpdate {
_u.mutation.ClearFirstName()
return _u
}
// SetLastName sets the "last_name" field.
func (_u *UserUpdate) SetLastName(v string) *UserUpdate {
_u.mutation.SetLastName(v)
return _u
}
// SetNillableLastName sets the "last_name" field if the given value is not nil.
func (_u *UserUpdate) SetNillableLastName(v *string) *UserUpdate {
if v != nil {
_u.SetLastName(*v)
}
return _u
}
// ClearLastName clears the value of the "last_name" field.
func (_u *UserUpdate) ClearLastName() *UserUpdate {
_u.mutation.ClearLastName()
return _u
}
// SetPasswordHash sets the "password_hash" field.
func (_u *UserUpdate) SetPasswordHash(v string) *UserUpdate {
_u.mutation.SetPasswordHash(v)
@@ -71,6 +131,66 @@ func (_u *UserUpdate) SetNillableVerified(v *bool) *UserUpdate {
return _u
}
// SetEmailVerificationToken sets the "email_verification_token" field.
func (_u *UserUpdate) SetEmailVerificationToken(v string) *UserUpdate {
_u.mutation.SetEmailVerificationToken(v)
return _u
}
// SetNillableEmailVerificationToken sets the "email_verification_token" field if the given value is not nil.
func (_u *UserUpdate) SetNillableEmailVerificationToken(v *string) *UserUpdate {
if v != nil {
_u.SetEmailVerificationToken(*v)
}
return _u
}
// ClearEmailVerificationToken clears the value of the "email_verification_token" field.
func (_u *UserUpdate) ClearEmailVerificationToken() *UserUpdate {
_u.mutation.ClearEmailVerificationToken()
return _u
}
// SetPasswordResetToken sets the "password_reset_token" field.
func (_u *UserUpdate) SetPasswordResetToken(v string) *UserUpdate {
_u.mutation.SetPasswordResetToken(v)
return _u
}
// SetNillablePasswordResetToken sets the "password_reset_token" field if the given value is not nil.
func (_u *UserUpdate) SetNillablePasswordResetToken(v *string) *UserUpdate {
if v != nil {
_u.SetPasswordResetToken(*v)
}
return _u
}
// ClearPasswordResetToken clears the value of the "password_reset_token" field.
func (_u *UserUpdate) ClearPasswordResetToken() *UserUpdate {
_u.mutation.ClearPasswordResetToken()
return _u
}
// SetPasswordResetExpiresAt sets the "password_reset_expires_at" field.
func (_u *UserUpdate) SetPasswordResetExpiresAt(v time.Time) *UserUpdate {
_u.mutation.SetPasswordResetExpiresAt(v)
return _u
}
// SetNillablePasswordResetExpiresAt sets the "password_reset_expires_at" field if the given value is not nil.
func (_u *UserUpdate) SetNillablePasswordResetExpiresAt(v *time.Time) *UserUpdate {
if v != nil {
_u.SetPasswordResetExpiresAt(*v)
}
return _u
}
// ClearPasswordResetExpiresAt clears the value of the "password_reset_expires_at" field.
func (_u *UserUpdate) ClearPasswordResetExpiresAt() *UserUpdate {
_u.mutation.ClearPasswordResetExpiresAt()
return _u
}
// SetUpdatedAt sets the "updated_at" field.
func (_u *UserUpdate) SetUpdatedAt(v time.Time) *UserUpdate {
_u.mutation.SetUpdatedAt(v)
@@ -184,12 +304,48 @@ func (_u *UserUpdate) sqlSave(ctx context.Context) (_node int, err error) {
if value, ok := _u.mutation.Email(); ok {
_spec.SetField(user.FieldEmail, field.TypeString, value)
}
if value, ok := _u.mutation.Username(); ok {
_spec.SetField(user.FieldUsername, field.TypeString, value)
}
if _u.mutation.UsernameCleared() {
_spec.ClearField(user.FieldUsername, field.TypeString)
}
if value, ok := _u.mutation.FirstName(); ok {
_spec.SetField(user.FieldFirstName, field.TypeString, value)
}
if _u.mutation.FirstNameCleared() {
_spec.ClearField(user.FieldFirstName, field.TypeString)
}
if value, ok := _u.mutation.LastName(); ok {
_spec.SetField(user.FieldLastName, field.TypeString, value)
}
if _u.mutation.LastNameCleared() {
_spec.ClearField(user.FieldLastName, field.TypeString)
}
if value, ok := _u.mutation.PasswordHash(); ok {
_spec.SetField(user.FieldPasswordHash, field.TypeString, value)
}
if value, ok := _u.mutation.Verified(); ok {
_spec.SetField(user.FieldVerified, field.TypeBool, value)
}
if value, ok := _u.mutation.EmailVerificationToken(); ok {
_spec.SetField(user.FieldEmailVerificationToken, field.TypeString, value)
}
if _u.mutation.EmailVerificationTokenCleared() {
_spec.ClearField(user.FieldEmailVerificationToken, field.TypeString)
}
if value, ok := _u.mutation.PasswordResetToken(); ok {
_spec.SetField(user.FieldPasswordResetToken, field.TypeString, value)
}
if _u.mutation.PasswordResetTokenCleared() {
_spec.ClearField(user.FieldPasswordResetToken, field.TypeString)
}
if value, ok := _u.mutation.PasswordResetExpiresAt(); ok {
_spec.SetField(user.FieldPasswordResetExpiresAt, field.TypeTime, value)
}
if _u.mutation.PasswordResetExpiresAtCleared() {
_spec.ClearField(user.FieldPasswordResetExpiresAt, field.TypeTime)
}
if value, ok := _u.mutation.UpdatedAt(); ok {
_spec.SetField(user.FieldUpdatedAt, field.TypeTime, value)
}
@@ -272,6 +428,66 @@ func (_u *UserUpdateOne) SetNillableEmail(v *string) *UserUpdateOne {
return _u
}
// SetUsername sets the "username" field.
func (_u *UserUpdateOne) SetUsername(v string) *UserUpdateOne {
_u.mutation.SetUsername(v)
return _u
}
// SetNillableUsername sets the "username" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillableUsername(v *string) *UserUpdateOne {
if v != nil {
_u.SetUsername(*v)
}
return _u
}
// ClearUsername clears the value of the "username" field.
func (_u *UserUpdateOne) ClearUsername() *UserUpdateOne {
_u.mutation.ClearUsername()
return _u
}
// SetFirstName sets the "first_name" field.
func (_u *UserUpdateOne) SetFirstName(v string) *UserUpdateOne {
_u.mutation.SetFirstName(v)
return _u
}
// SetNillableFirstName sets the "first_name" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillableFirstName(v *string) *UserUpdateOne {
if v != nil {
_u.SetFirstName(*v)
}
return _u
}
// ClearFirstName clears the value of the "first_name" field.
func (_u *UserUpdateOne) ClearFirstName() *UserUpdateOne {
_u.mutation.ClearFirstName()
return _u
}
// SetLastName sets the "last_name" field.
func (_u *UserUpdateOne) SetLastName(v string) *UserUpdateOne {
_u.mutation.SetLastName(v)
return _u
}
// SetNillableLastName sets the "last_name" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillableLastName(v *string) *UserUpdateOne {
if v != nil {
_u.SetLastName(*v)
}
return _u
}
// ClearLastName clears the value of the "last_name" field.
func (_u *UserUpdateOne) ClearLastName() *UserUpdateOne {
_u.mutation.ClearLastName()
return _u
}
// SetPasswordHash sets the "password_hash" field.
func (_u *UserUpdateOne) SetPasswordHash(v string) *UserUpdateOne {
_u.mutation.SetPasswordHash(v)
@@ -300,6 +516,66 @@ func (_u *UserUpdateOne) SetNillableVerified(v *bool) *UserUpdateOne {
return _u
}
// SetEmailVerificationToken sets the "email_verification_token" field.
func (_u *UserUpdateOne) SetEmailVerificationToken(v string) *UserUpdateOne {
_u.mutation.SetEmailVerificationToken(v)
return _u
}
// SetNillableEmailVerificationToken sets the "email_verification_token" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillableEmailVerificationToken(v *string) *UserUpdateOne {
if v != nil {
_u.SetEmailVerificationToken(*v)
}
return _u
}
// ClearEmailVerificationToken clears the value of the "email_verification_token" field.
func (_u *UserUpdateOne) ClearEmailVerificationToken() *UserUpdateOne {
_u.mutation.ClearEmailVerificationToken()
return _u
}
// SetPasswordResetToken sets the "password_reset_token" field.
func (_u *UserUpdateOne) SetPasswordResetToken(v string) *UserUpdateOne {
_u.mutation.SetPasswordResetToken(v)
return _u
}
// SetNillablePasswordResetToken sets the "password_reset_token" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillablePasswordResetToken(v *string) *UserUpdateOne {
if v != nil {
_u.SetPasswordResetToken(*v)
}
return _u
}
// ClearPasswordResetToken clears the value of the "password_reset_token" field.
func (_u *UserUpdateOne) ClearPasswordResetToken() *UserUpdateOne {
_u.mutation.ClearPasswordResetToken()
return _u
}
// SetPasswordResetExpiresAt sets the "password_reset_expires_at" field.
func (_u *UserUpdateOne) SetPasswordResetExpiresAt(v time.Time) *UserUpdateOne {
_u.mutation.SetPasswordResetExpiresAt(v)
return _u
}
// SetNillablePasswordResetExpiresAt sets the "password_reset_expires_at" field if the given value is not nil.
func (_u *UserUpdateOne) SetNillablePasswordResetExpiresAt(v *time.Time) *UserUpdateOne {
if v != nil {
_u.SetPasswordResetExpiresAt(*v)
}
return _u
}
// ClearPasswordResetExpiresAt clears the value of the "password_reset_expires_at" field.
func (_u *UserUpdateOne) ClearPasswordResetExpiresAt() *UserUpdateOne {
_u.mutation.ClearPasswordResetExpiresAt()
return _u
}
// SetUpdatedAt sets the "updated_at" field.
func (_u *UserUpdateOne) SetUpdatedAt(v time.Time) *UserUpdateOne {
_u.mutation.SetUpdatedAt(v)
@@ -443,12 +719,48 @@ func (_u *UserUpdateOne) sqlSave(ctx context.Context) (_node *User, err error) {
if value, ok := _u.mutation.Email(); ok {
_spec.SetField(user.FieldEmail, field.TypeString, value)
}
if value, ok := _u.mutation.Username(); ok {
_spec.SetField(user.FieldUsername, field.TypeString, value)
}
if _u.mutation.UsernameCleared() {
_spec.ClearField(user.FieldUsername, field.TypeString)
}
if value, ok := _u.mutation.FirstName(); ok {
_spec.SetField(user.FieldFirstName, field.TypeString, value)
}
if _u.mutation.FirstNameCleared() {
_spec.ClearField(user.FieldFirstName, field.TypeString)
}
if value, ok := _u.mutation.LastName(); ok {
_spec.SetField(user.FieldLastName, field.TypeString, value)
}
if _u.mutation.LastNameCleared() {
_spec.ClearField(user.FieldLastName, field.TypeString)
}
if value, ok := _u.mutation.PasswordHash(); ok {
_spec.SetField(user.FieldPasswordHash, field.TypeString, value)
}
if value, ok := _u.mutation.Verified(); ok {
_spec.SetField(user.FieldVerified, field.TypeBool, value)
}
if value, ok := _u.mutation.EmailVerificationToken(); ok {
_spec.SetField(user.FieldEmailVerificationToken, field.TypeString, value)
}
if _u.mutation.EmailVerificationTokenCleared() {
_spec.ClearField(user.FieldEmailVerificationToken, field.TypeString)
}
if value, ok := _u.mutation.PasswordResetToken(); ok {
_spec.SetField(user.FieldPasswordResetToken, field.TypeString, value)
}
if _u.mutation.PasswordResetTokenCleared() {
_spec.ClearField(user.FieldPasswordResetToken, field.TypeString)
}
if value, ok := _u.mutation.PasswordResetExpiresAt(); ok {
_spec.SetField(user.FieldPasswordResetExpiresAt, field.TypeTime, value)
}
if _u.mutation.PasswordResetExpiresAtCleared() {
_spec.ClearField(user.FieldPasswordResetExpiresAt, field.TypeTime)
}
if value, ok := _u.mutation.UpdatedAt(); ok {
_spec.SetField(user.FieldUpdatedAt, field.TypeTime, value)
}