P0: tc-auth local sessions, tc-api P0 endpoints, teamclaw-server binary

- tc-auth: argon2id passwords, hashed opaque bearer tokens in auth_sessions
  (migration 0002), anti-enumeration login errors, redacted token Debug
- tc-api: axum router with /healthz, /api/auth/login|logout, /api/user/me,
  /api/team/{claws,credits,permissions}; Authed bearer extractor + RBAC
  permission derivation; integration-tested over real TCP vs real Postgres
- teamclaw-server: config -> pool -> self-migrate -> serve

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-09 22:30:33 -05:00
co-authored by Claude Fable 5
parent 0afb359183
commit c4349bf292
25 changed files with 1257 additions and 0 deletions
+25
View File
@@ -0,0 +1,25 @@
[package]
name = "tc-auth"
version = "0.1.0"
edition.workspace = true
rust-version.workspace = true
license.workspace = true
publish.workspace = true
[dependencies]
argon2 = "0.5"
base64 = "0.22"
rand_core = { version = "0.6", features = ["getrandom"] }
sha2 = "0.10"
sqlx = { workspace = true }
tc-db = { path = "../tc-db" }
tc-domain = { path = "../tc-domain" }
thiserror = { workspace = true }
time = { workspace = true }
[dev-dependencies]
tc-testkit = { path = "../tc-testkit" }
tokio = { workspace = true }
[lints]
workspace = true