Files
mercadodevida/work/current.md
rikrdo 75293f39bc feat(identity): F-005 register/login/logout with argon2 sessions and rate limiting
- Hexagonal identity module: domain ports, use cases, argon2id hasher, pg repos
- Migration 002_identity: identity_users + identity_sessions (token hash only)
- Opaque 512-bit session tokens; DB stores SHA-256 hash; 7-day TTL in SQL
- Cookie HttpOnly + Secure (COOKIE_SECURE, default true) + SameSite=Lax
- LoginRateLimiter: 10 failures -> 429 + Retry-After, 15-min cooldown
- Anti-enumeration: identical generic 401 + dummy-hash timing equalization
- buildApp gains optional pool/cookieSecure; foundation-only app preserved
- 47 unit + 14 integration tests; live smoke covers all acceptance criteria
2026-08-14 22:58:32 +02:00

954 B

Current work

  • Active feature: none (idle)
  • Last closed: F-005 — Identity: register, login, sessions
  • Next suggested: F-006 — Users: profile, addresses, RBAC (depends on F-005, satisfied)
  • Runtime status: reset via scripts/agent_status.py
  • verify.sh: green at close

F-005 closure notes

  • Identity module hexagonal: domain/application/infrastructure/api under src/modules/identity
  • Sessions server-side: cookie carries opaque 512-bit token; identity_sessions stores only SHA-256 hash
  • argon2id (OWASP params) behind PasswordHasher port; timing equalized 401 (no enumeration)
  • Rate limit: 10 consecutive failures per email -> 429 + Retry-After (15 min cooldown), in-memory behind interface
  • Cookie: HttpOnly + Secure (COOKIE_SECURE, default true) + SameSite=Lax
  • Migration 002_identity reversible; integration suite updated for full revert (count:0)
  • Gates: reviewer/security/qa APPROVED. Commits include specs, artifacts, code, docs.