bbe0757ab6
Implement complete refresh token flow for improved security: - Short-lived access tokens (configurable, default 1h) - Long-lived refresh tokens (configurable, default 7d) - Automatic token rotation on refresh - Token revocation for proper logout Domain layer: - Add RefreshToken entity with validation and revocation - Add RefreshTokenRepository interface Application layer: - Add RefreshTokenHandler for token refresh operations - Add RevokeTokenHandler for single token revocation - Add RevokeAllTokensHandler for user-wide revocation Infrastructure layer: - Implement SQLite RefreshTokenRepository - Add refresh_tokens table migration with indexes - Add parseDuration helper for flexible time configuration HTTP layer: - Add POST /api/v1/auth/refresh endpoint - Add POST /api/v1/auth/logout endpoint - Update login/register to return refresh tokens - Improve Swagger documentation with clear descriptions Configuration: - Update .env.example with secure token expiry defaults - Add support for minute/hour/day duration formats Tests: - Fix test suite to work with new signatures - All existing tests passing
86 lines
2.2 KiB
Go
86 lines
2.2 KiB
Go
package sqlite
|
|
|
|
import (
|
|
"database/sql"
|
|
)
|
|
|
|
func RunMigrations(db *sql.DB) error {
|
|
migrations := []string{
|
|
createUsersTable,
|
|
createHabitsTable,
|
|
createHabitEntriesTable,
|
|
createRefreshTokensTable,
|
|
createIndexes,
|
|
}
|
|
|
|
for _, migration := range migrations {
|
|
if _, err := db.Exec(migration); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
const createUsersTable = `
|
|
CREATE TABLE IF NOT EXISTS users (
|
|
id TEXT PRIMARY KEY,
|
|
email TEXT UNIQUE NOT NULL,
|
|
password_hash TEXT NOT NULL,
|
|
timezone TEXT DEFAULT 'UTC',
|
|
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
|
updated_at DATETIME DEFAULT CURRENT_TIMESTAMP
|
|
);
|
|
`
|
|
|
|
const createHabitsTable = `
|
|
CREATE TABLE IF NOT EXISTS habits (
|
|
id TEXT PRIMARY KEY,
|
|
user_id TEXT NOT NULL,
|
|
name TEXT NOT NULL,
|
|
description TEXT,
|
|
type TEXT CHECK(type IN ('BOOLEAN', 'COUNTER', 'VALUE')),
|
|
frequency TEXT CHECK(frequency IN ('DAILY', 'WEEKLY', 'MONTHLY')),
|
|
specific_days TEXT,
|
|
specific_dates TEXT,
|
|
carry_over BOOLEAN DEFAULT 0,
|
|
is_negative BOOLEAN DEFAULT 0,
|
|
target_value REAL,
|
|
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
|
archived_at DATETIME,
|
|
FOREIGN KEY (user_id) REFERENCES users(id) ON DELETE CASCADE
|
|
);
|
|
`
|
|
|
|
const createHabitEntriesTable = `
|
|
CREATE TABLE IF NOT EXISTS habit_entries (
|
|
id TEXT PRIMARY KEY,
|
|
habit_id TEXT NOT NULL,
|
|
scheduled_date DATE NOT NULL,
|
|
completed_at DATETIME NOT NULL,
|
|
value REAL,
|
|
FOREIGN KEY (habit_id) REFERENCES habits(id) ON DELETE CASCADE,
|
|
UNIQUE(habit_id, scheduled_date)
|
|
);
|
|
`
|
|
|
|
const createRefreshTokensTable = `
|
|
CREATE TABLE IF NOT EXISTS refresh_tokens (
|
|
id TEXT PRIMARY KEY,
|
|
user_id TEXT NOT NULL,
|
|
token TEXT UNIQUE NOT NULL,
|
|
expires_at DATETIME NOT NULL,
|
|
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
|
revoked_at DATETIME,
|
|
FOREIGN KEY (user_id) REFERENCES users(id) ON DELETE CASCADE
|
|
);
|
|
`
|
|
|
|
const createIndexes = `
|
|
CREATE INDEX IF NOT EXISTS idx_habits_user ON habits(user_id);
|
|
CREATE INDEX IF NOT EXISTS idx_habits_active ON habits(user_id, archived_at);
|
|
CREATE INDEX IF NOT EXISTS idx_entries_habit ON habit_entries(habit_id);
|
|
CREATE INDEX IF NOT EXISTS idx_entries_scheduled ON habit_entries(scheduled_date);
|
|
CREATE INDEX IF NOT EXISTS idx_refresh_tokens_user ON refresh_tokens(user_id);
|
|
CREATE INDEX IF NOT EXISTS idx_refresh_tokens_token ON refresh_tokens(token);
|
|
`
|