auth-yes/tasks/new/2026-0825.01.jul.story.arch.monolith-decomposition-roadmap-1845.ph6.md

1.9 KiB

TASK METADATA

  • Target Files: server/auth-session.ts, server/forward_auth.ts, server/session_resolver.ts, ui/mod.ts, ui/db_queries.ts, ui/auth_checks.ts, server/main.test.ts
  • Core Objective: Phase 6 (Core Logic Refactoring): Separate database queries and admin authorization checks from pure SSR page routing in ui/mod.ts, and decouple ForwardAuth ingress handling from session caching/resolution in server/auth-session.ts.
  • Dependencies: tasks/new/2026-0825.01.jul.story.arch.monolith-decomposition-roadmap-1845.md
  • Additional Important Notes: Must maintain fast-path microsecond Valkey caching, zero-dependency SDK compatibility, and pass all quality gates.

2. Architectural Considerations & Risks

  • Risks:
    • Introducing latency in ForwardAuth validation if session resolution dependencies are decoupled improperly.
    • Circular import dependencies between Hono routing and session resolver modules.
  • Alternatives:
    • Leaving logic combined; rejected to ensure clear layer separation between edge ingress and data store resolution.

3. Proposed Implementation

  1. Decompose server/auth-session.ts:
    • server/forward_auth.ts: Extract Traefik ForwardAuth header parsing, dynamic bypass evaluation (is_public, bypass_paths), and upstream identity injection.
    • server/session_resolver.ts: Extract multi-cookie iteration, Valkey L1/L2 cache resolution, and PostgreSQL fallback queries.
  2. Decompose ui/mod.ts:
    • ui/db_queries.ts: Extract raw SQL queries for loading apps, roles, grants, invites, and audit logs.
    • ui/auth_checks.ts: Extract admin authorization and session verification middleware.
    • ui/mod.ts: Retain purely as clean SSR route mounting.
  3. Quality Gates & Validation:
    • Run deno fmt, deno task lint, deno task check.
    • Run deno test --allow-all to ensure all routes and test suites pass cleanly.