feat(09-01): implement separate-admin genre list tracer

- Audience-aware mint, verify, refresh, and backend guard keep frontend tokens compatible
- Cabana mounts raw admin login, list schema, and record list behind admin.jwt.secret
- Framework migration seeds Winter backend users and developer/publisher roles
This commit is contained in:
Jakub Zych
2026-09-24 17:17:19 +02:00
parent 01d3871510
commit dfa00f7e3a
13 changed files with 1178 additions and 13 deletions

View File

@@ -9,11 +9,15 @@ type userKey struct{}
// Principal is the authenticated identity stored on the request context.
// PreferredLocale empty means no override. TokensValidAfter zero means no cutoff.
// IsSuperuser and PermissionGrants are set only for backend-admin principals.
// A grant ending in ".*" matches permission codes by prefix.
type Principal struct {
ID uint
MustChangePassword bool
PreferredLocale string
TokensValidAfter time.Time
IsSuperuser bool `json:"-"`
PermissionGrants map[string]bool `json:"-"`
}
// WithUser stores the verified principal on ctx.