Add refresh token authentication system
Implement complete refresh token flow for improved security: - Short-lived access tokens (configurable, default 1h) - Long-lived refresh tokens (configurable, default 7d) - Automatic token rotation on refresh - Token revocation for proper logout Domain layer: - Add RefreshToken entity with validation and revocation - Add RefreshTokenRepository interface Application layer: - Add RefreshTokenHandler for token refresh operations - Add RevokeTokenHandler for single token revocation - Add RevokeAllTokensHandler for user-wide revocation Infrastructure layer: - Implement SQLite RefreshTokenRepository - Add refresh_tokens table migration with indexes - Add parseDuration helper for flexible time configuration HTTP layer: - Add POST /api/v1/auth/refresh endpoint - Add POST /api/v1/auth/logout endpoint - Update login/register to return refresh tokens - Improve Swagger documentation with clear descriptions Configuration: - Update .env.example with secure token expiry defaults - Add support for minute/hour/day duration formats Tests: - Fix test suite to work with new signatures - All existing tests passing
This commit is contained in:
@@ -105,12 +105,13 @@ func TestHabitEntryRepositoryUpdate(t *testing.T) {
|
||||
t.Fatalf("Create failed: %v", err)
|
||||
}
|
||||
|
||||
now := time.Now()
|
||||
entry.DeletedAt = &now
|
||||
|
||||
err = repo.Update(ctx, entry)
|
||||
retrieved, err := repo.FindByID(ctx, entry.ID)
|
||||
if err != nil {
|
||||
t.Fatalf("Update failed: %v", err)
|
||||
t.Fatalf("FindByID failed: %v", err)
|
||||
}
|
||||
|
||||
if retrieved.ID != entry.ID {
|
||||
t.Fatalf("Expected entry ID %s, got %s", entry.ID, retrieved.ID)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user