approvedcompleteApache-2.0
Auth service on CoreLedger + hiqlite rate limiting
004-auth-core
The authentication core, re-based from template-encore apps/api onto enrahitu's own substrate: stateless RS256 JWT access tokens in httpOnly cookies, rotated DB-backed refresh tokens, CSRF double-submit, roles, and audit records on CoreLedger; login rate limiting on hiqlite counters. Drivers are pluggable: mock (dev) here, rauthy OIDC in spec 005 (which owns backend/auth/rauthy.ts inside this spec's directory claim).
- Depends on
- Establishes
- backend/auth/ (directory)
- backend/lib/ (directory)
- scripts/generate-keys.ts
- Sections
- 004: Auth core
- 1. Purpose
- 2. Territory
- 3. Behavior
- 4. Out of scope
- 5. Phase A seam (amended by spec 021, 2026-07-20)
- Source
- specs/004-auth-core/spec.md @ dc4c9237e12aas of 2026-07-21 ยท shard 01e5f3f3948a