feat(03-01): add ServeMux groups, JWT verifier, and serve command

Named middleware resolves at boot, HS256 tokens are pinned with required
exp/sub, and both binaries expose a signal-aware serve command.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 20:04:13 +02:00
parent d0d845052b
commit 4ee4c4a2fc
18 changed files with 976 additions and 12 deletions

28
bouncer/context.go Normal file
View File

@@ -0,0 +1,28 @@
package bouncer
import "context"
type userKey struct{}
// Principal is the authenticated identity stored on the request context.
type Principal struct {
ID uint
MustChangePassword bool
}
// WithUser stores the verified principal on ctx.
func WithUser(ctx context.Context, user *Principal) context.Context {
if ctx == nil {
ctx = context.Background()
}
return context.WithValue(ctx, userKey{}, user)
}
// User returns the verified principal from ctx.
func User(ctx context.Context) (*Principal, bool) {
if ctx == nil {
return nil, false
}
u, ok := ctx.Value(userKey{}).(*Principal)
return u, ok && u != nil
}