feat(03-01): add ServeMux groups, JWT verifier, and serve command
Named middleware resolves at boot, HS256 tokens are pinned with required exp/sub, and both binaries expose a signal-aware serve command. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
28
bouncer/context.go
Normal file
28
bouncer/context.go
Normal file
@@ -0,0 +1,28 @@
|
||||
package bouncer
|
||||
|
||||
import "context"
|
||||
|
||||
type userKey struct{}
|
||||
|
||||
// Principal is the authenticated identity stored on the request context.
|
||||
type Principal struct {
|
||||
ID uint
|
||||
MustChangePassword bool
|
||||
}
|
||||
|
||||
// WithUser stores the verified principal on ctx.
|
||||
func WithUser(ctx context.Context, user *Principal) context.Context {
|
||||
if ctx == nil {
|
||||
ctx = context.Background()
|
||||
}
|
||||
return context.WithValue(ctx, userKey{}, user)
|
||||
}
|
||||
|
||||
// User returns the verified principal from ctx.
|
||||
func User(ctx context.Context) (*Principal, bool) {
|
||||
if ctx == nil {
|
||||
return nil, false
|
||||
}
|
||||
u, ok := ctx.Value(userKey{}).(*Principal)
|
||||
return u, ok && u != nil
|
||||
}
|
||||
Reference in New Issue
Block a user