approvedcompleteApache-2.0

Auth service on CoreLedger + hiqlite rate limiting

004-auth-core

The authentication core, re-based from template-encore apps/api onto enrahitu's own substrate: stateless RS256 JWT access tokens in httpOnly cookies, rotated DB-backed refresh tokens, CSRF double-submit, roles, and audit records on CoreLedger; login rate limiting on hiqlite counters. Drivers are pluggable: mock (dev) here, rauthy OIDC in spec 005 (which owns backend/auth/rauthy.ts inside this spec's directory claim).

Establishes
  • backend/auth/ (directory)
  • backend/lib/ (directory)
  • scripts/generate-keys.ts
Sections
  • 004: Auth core
  • 1. Purpose
  • 2. Territory
  • 3. Behavior
  • 4. Out of scope
  • 5. Phase A seam (amended by spec 021, 2026-07-20)
Source
specs/004-auth-core/spec.md @ dc4c9237e12aas of 2026-07-21 ยท shard 01e5f3f3948a