refactor(10.2-01): nest framework packages under modules

- Move remaining beach packages and embedded admin assets\n- Rewrite framework, example, build, and gate paths
This commit is contained in:
Jakub Zych
2026-09-28 02:21:02 +02:00
parent ac1f6d14f4
commit 5e50b166ef
277 changed files with 303 additions and 303 deletions

View File

@@ -0,0 +1,61 @@
package bouncer
import (
"context"
"time"
)
type userKey struct{}
// Principal is the authenticated identity stored on the request context.
// PreferredLocale empty means no override. TokensValidAfter zero means no cutoff.
// IsSuperuser and PermissionGrants are set only for backend-admin principals.
// A grant ending in ".*" matches permission codes by prefix.
type Principal struct {
ID uint
MustChangePassword bool
PreferredLocale string
TokensValidAfter time.Time
Backend bool `json:"-"`
IsSuperuser bool `json:"-"`
PermissionGrants map[string]bool `json:"-"`
}
// WithUser stores the verified principal on ctx.
func WithUser(ctx context.Context, user *Principal) context.Context {
if ctx == nil {
ctx = context.Background()
}
return context.WithValue(ctx, userKey{}, user)
}
// User returns the verified principal from ctx.
func User(ctx context.Context) (*Principal, bool) {
if ctx == nil {
return nil, false
}
u, ok := ctx.Value(userKey{}).(*Principal)
return u, ok && u != nil
}
type credentialKey struct{}
// WithCredential stores the resolved credential (e.g. *ApiToken) on ctx.
func WithCredential(ctx context.Context, cred any) context.Context {
if ctx == nil {
ctx = context.Background()
}
return context.WithValue(ctx, credentialKey{}, cred)
}
// Credential returns the resolved credential from ctx.
func Credential(ctx context.Context) (any, bool) {
if ctx == nil {
return nil, false
}
c := ctx.Value(credentialKey{})
if c == nil {
return nil, false
}
return c, true
}