feat(10-01): harden the admin cookie session and prefix boot guards

- refresh and logout read the Bearer header first, then the summer_admin
  cookie; a cookie refresh rotates the cookie without a token in the body and
  logout always expires the cookie
- backend.cookie_secure (default true) may drop Secure outside production only
- activation rejects controller vendor segments api, assets, login, settings
- BuildRouter rejects non-cabana routes at or under the admin prefix
- SPA single-flights refresh on 401, replays once, and refreshes proactively
  at 80 percent of expires_in; dist rebuilt
- scripts/check-admin-dist.sh rebuilds the SPA and fails on dist drift
- tests: TestPhase10CookieAuth, TestPhase10CSRF, TestPhase10Prefix,
  TestPhase10AdminPrefixCollision, boardwalk serving and header tests
This commit is contained in:
Jakub Zych
2026-09-27 15:34:19 +02:00
parent 5f9353841b
commit dafdb18234
15 changed files with 1283 additions and 18 deletions

26
scripts/check-admin-dist.sh Executable file
View File

@@ -0,0 +1,26 @@
#!/usr/bin/env bash
# Drift gate for the committed admin SPA build (D-04). Rebuilds admin/ from
# the committed lockfile into a temporary directory and fails when the result
# differs from boardwalk/dist, the tree the Go binary embeds. After changing
# the SPA, rebuild with `npm --prefix admin run build` and commit the result.
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$ROOT"
if [[ ! -d admin/node_modules ]]; then
npm --prefix admin ci
fi
npm --prefix admin run typecheck
TMP="$(mktemp -d)"
trap 'rm -rf "$TMP"' EXIT
(cd admin && node_modules/.bin/vite build --outDir "$TMP/dist" --emptyOutDir --logLevel warn)
if ! diff -r "$TMP/dist" boardwalk/dist; then
echo "check-admin-dist: boardwalk/dist is stale; run npm --prefix admin run build and commit boardwalk/dist" >&2
exit 1
fi
echo "check-admin-dist: boardwalk/dist matches a fresh build"