From 3eb04b1a2bdf9e53231fe862cfd76327371a9741 Mon Sep 17 00:00:00 2001 From: gramanas Date: Sat, 12 Sep 2026 11:24:17 +0300 Subject: Initial multi-tenant blog host Go + Postgres application serving a management dashboard on the base domain and one public blog per subdomain. Markdown posts organised in pages, form-based theme customisation, image uploads stored in Postgres, JWT cookie sessions with CSRF, superadmin user management, RSS feeds. Docker/compose deployment and a Makefile-driven dev environment with seed data. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/auth/jwt.go | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 internal/auth/jwt.go (limited to 'internal/auth/jwt.go') diff --git a/internal/auth/jwt.go b/internal/auth/jwt.go new file mode 100644 index 0000000..a7fb52a --- /dev/null +++ b/internal/auth/jwt.go @@ -0,0 +1,41 @@ +package auth + +import ( + "errors" + "time" + + "github.com/golang-jwt/jwt/v5" +) + +const SessionTTL = 7 * 24 * time.Hour + +type Claims struct { + jwt.RegisteredClaims + UserID int64 `json:"uid"` + TokenVersion int `json:"ver"` +} + +func IssueToken(secret []byte, userID int64, tokenVersion int, now time.Time) (string, error) { + c := Claims{ + RegisteredClaims: jwt.RegisteredClaims{ + IssuedAt: jwt.NewNumericDate(now), + ExpiresAt: jwt.NewNumericDate(now.Add(SessionTTL)), + }, + UserID: userID, + TokenVersion: tokenVersion, + } + return jwt.NewWithClaims(jwt.SigningMethodHS256, c).SignedString(secret) +} + +func ParseToken(secret []byte, tok string) (*Claims, error) { + var c Claims + _, err := jwt.ParseWithClaims(tok, &c, func(t *jwt.Token) (any, error) { return secret, nil }, + jwt.WithValidMethods([]string{"HS256"}), jwt.WithExpirationRequired()) + if err != nil { + return nil, err + } + if c.UserID == 0 { + return nil, errors.New("missing uid") + } + return &c, nil +} -- cgit v1.2.3