Files
david bbe0757ab6
CI/CD Pipeline / Test (push) Has been cancelled
CI/CD Pipeline / Lint (push) Has been cancelled
CI/CD Pipeline / Build and Push Docker Image (push) Has been cancelled
Add refresh token authentication system
Implement complete refresh token flow for improved security:
- Short-lived access tokens (configurable, default 1h)
- Long-lived refresh tokens (configurable, default 7d)
- Automatic token rotation on refresh
- Token revocation for proper logout

Domain layer:
- Add RefreshToken entity with validation and revocation
- Add RefreshTokenRepository interface

Application layer:
- Add RefreshTokenHandler for token refresh operations
- Add RevokeTokenHandler for single token revocation
- Add RevokeAllTokensHandler for user-wide revocation

Infrastructure layer:
- Implement SQLite RefreshTokenRepository
- Add refresh_tokens table migration with indexes
- Add parseDuration helper for flexible time configuration

HTTP layer:
- Add POST /api/v1/auth/refresh endpoint
- Add POST /api/v1/auth/logout endpoint
- Update login/register to return refresh tokens
- Improve Swagger documentation with clear descriptions

Configuration:
- Update .env.example with secure token expiry defaults
- Add support for minute/hour/day duration formats

Tests:
- Fix test suite to work with new signatures
- All existing tests passing
2025-11-27 09:57:54 +01:00

31 lines
683 B
Go

package commands
import (
"context"
"apocapoc-api/internal/domain/repositories"
"apocapoc-api/internal/shared/errors"
)
type RevokeAllTokensCommand struct {
UserID string
}
type RevokeAllTokensHandler struct {
refreshTokenRepo repositories.RefreshTokenRepository
}
func NewRevokeAllTokensHandler(refreshTokenRepo repositories.RefreshTokenRepository) *RevokeAllTokensHandler {
return &RevokeAllTokensHandler{
refreshTokenRepo: refreshTokenRepo,
}
}
func (h *RevokeAllTokensHandler) Handle(ctx context.Context, cmd RevokeAllTokensCommand) error {
if cmd.UserID == "" {
return errors.ErrInvalidInput
}
return h.refreshTokenRepo.RevokeAllByUserID(ctx, cmd.UserID)
}