Feat v0.6.9 cookie fix roadmap (#44)
Co-authored-by: Jeffrey Smith <jasafpro@gmail.com> Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #44.
This commit is contained in:
56
CHANGELOG.md
56
CHANGELOG.md
@@ -2,6 +2,62 @@
|
||||
|
||||
All notable changes to Armature are documented here.
|
||||
|
||||
## v0.6.9 — Session Lifetime Config
|
||||
|
||||
Admin-configurable session durations, "keep me logged in" opt-in, and
|
||||
optional idle timeout. Completes the auth hardening started in v0.6.8.
|
||||
|
||||
### Added
|
||||
|
||||
- **Admin session settings**: `session.access_token_ttl` (default 15m,
|
||||
clamp 5m–60m) and `session.refresh_token_ttl` (default 7d, clamp
|
||||
1h–90d) stored in `global_settings`. New `LoadSessionConfig()` helper
|
||||
reads and clamps values with `parseDurationString()` supporting `m`,
|
||||
`h`, `d` suffixes.
|
||||
- **"Keep me logged in" checkbox**: Login form opt-in. Checked = full
|
||||
`refresh_token_ttl`. Unchecked = capped at 24h. Cookie `max-age`
|
||||
tracks whichever lifetime was chosen. `keep_login` flag stored on
|
||||
refresh token row.
|
||||
- **Config-driven token generation**: `generateTokens()` reads TTLs from
|
||||
`global_settings` instead of hardcoded `15*time.Minute` /
|
||||
`7*24*time.Hour`. Response includes `expires_in` and
|
||||
`refresh_expires_in` (seconds) so the client schedules refresh
|
||||
correctly.
|
||||
- **Idle timeout (optional)**: Admin-toggleable (default off). Server
|
||||
checks `last_activity_at` on refresh-token row; rejects if gap exceeds
|
||||
`session.idle_timeout`. Client SDK pings `POST /api/v1/auth/activity`
|
||||
on click/keydown (debounced, max 1/min).
|
||||
- **Admin Settings > Session section**: Dropdowns for access TTL, refresh
|
||||
TTL, and idle timeout with toggle.
|
||||
- **7 new tests**: Duration parsing, clamping (low/high), defaults,
|
||||
invalid values, empty idle timeout.
|
||||
|
||||
### Changed
|
||||
|
||||
- `CreateRefreshToken` store method now accepts `keepLogin bool`
|
||||
parameter; both Postgres and SQLite implementations updated.
|
||||
- `GetRefreshTokenInfo` returns `RefreshTokenInfo` struct with
|
||||
`UserID`, `KeepLogin`, `LastActivityAt` for idle-timeout decisions.
|
||||
- SDK `auth.login()` accepts optional third `keepLogin` parameter;
|
||||
cookie max-age derived from server `refresh_expires_in` response.
|
||||
- SDK boots activity tracking after successful auth boot.
|
||||
|
||||
## v0.6.8 — Cookie Fix + UI Hardening Roadmap
|
||||
|
||||
### Fixed
|
||||
|
||||
- **Session cookie max-age bug**: `arm_token` cookie was set to 15 min
|
||||
(matching access token) while refresh token lasted 7 days. Cookie now
|
||||
matches refresh token lifetime so Go SSR middleware can serve page
|
||||
shells while JS refreshes the access token client-side.
|
||||
|
||||
### Added
|
||||
|
||||
- **ROADMAP-UI.md**: Detailed UI hardening roadmap (v0.6.9–v0.6.15)
|
||||
covering session config, viewport foundation, CSS deduplication,
|
||||
extension CSS isolation, responsive layout, visual polish, and
|
||||
automated usability survey gate.
|
||||
|
||||
## v0.6.7 — Native mTLS
|
||||
|
||||
End-to-end mutual TLS without a reverse proxy. Targets systemd+podman
|
||||
|
||||
Reference in New Issue
Block a user