Last Updated: 2026-04-28
See PLAN.md for the overall roadmap and feature priorities.
These tasks must be completed before App1 integration.
The marketplace module has types and interfaces defined but lacks concrete implementations.
- Create
identity/ent/schema/listing.go- Product/course listing entity - Create
identity/ent/schema/license.go- License entitlement entity - Create
identity/ent/schema/subscription.go- Subscription entity - Create
identity/ent/schema/seat_assignment.go- Seat assignment entity - Run
go generate ./identity/ent/...to generate Ent code - Add database migrations for new tables
-
Implement
ListingServiceinmarketplace/listing_service.go-
Create(ctx, input)- Create new listing -
Get(ctx, id)- Get listing by ID -
List(ctx, opts)- List with filtering -
Update(ctx, id, input)- Update listing -
Delete(ctx, id)- Delete listing -
Publish(ctx, id)- Publish listing -
Archive(ctx, id)- Archive listing
-
-
Implement
LicenseServiceinmarketplace/license_service.go-
Grant(ctx, input)- Grant license to org -
Revoke(ctx, id)- Revoke license -
Get(ctx, id)- Get license by ID -
ListForOrg(ctx, orgID)- List org's licenses -
AssignSeat(ctx, licenseID, principalID)- Assign seat -
UnassignSeat(ctx, assignmentID)- Remove seat assignment -
GetAvailableSeats(ctx, licenseID)- Check available seats
-
-
Implement
SubscriptionServiceinmarketplace/subscription_service.go-
Create(ctx, input)- Create subscription -
Get(ctx, id)- Get subscription -
Cancel(ctx, id)- Cancel subscription -
UpdateStatus(ctx, id, status)- Update status -
ListForOrg(ctx, orgID)- List org subscriptions
-
- Create
marketplace/stripe/package - Implement
CheckoutServiceinmarketplace/stripe/checkout.go-
CreateCheckoutSession(ctx, input)- Create Stripe Checkout -
CreatePortalSession(ctx, customerID)- Customer portal (deferred)
-
- Implement webhook handlers in
marketplace/stripe/webhooks.go-
HandleCheckoutCompleted- Grant license on purchase -
HandleSubscriptionCreated- Create subscription record -
HandleSubscriptionUpdated- Update subscription status -
HandleSubscriptionDeleted- Handle cancellation -
HandleInvoicePaid- Record payment -
HandleInvoicePaymentFailed- Handle failed payment
-
- Implement Stripe Connect in
marketplace/stripe/connect.go-
CreateConnectAccount(ctx, orgID)- Create seller account -
CreateAccountLink(ctx, accountID)- Onboarding link -
CreatePayout(ctx, accountID, amount)- Trigger payout
-
- Create
marketplace/handlers.gowith Huma handlers-
POST /api/v1/listings- Create listing -
GET /api/v1/listings- List listings -
GET /api/v1/listings/{id}- Get listing -
PATCH /api/v1/listings/{id}- Update listing -
DELETE /api/v1/listings/{id}- Delete listing -
POST /api/v1/listings/{id}/publish- Publish -
POST /api/v1/listings/{id}/archive- Archive -
POST /api/v1/checkout- Create checkout session -
GET /api/v1/licenses- List licenses -
GET /api/v1/licenses/{id}- Get license -
POST /api/v1/licenses/{license_id}/seats- Assign seat -
DELETE /api/v1/licenses/{license_id}/seats/{principal_id}- Unassign seat -
GET /api/v1/licenses/{license_id}/seats- List seats -
POST /api/v1/webhooks/stripe- Stripe webhook endpoint (requires raw body handling)
-
- Add
marketplace/listing_service_test.go - Add
marketplace/license_service_test.go - Add
marketplace/subscription_service_test.go - Add
marketplace/stripe/checkout_test.go - Add
marketplace/stripe/webhooks_test.go - Add
marketplace/handlers_test.go
- Implement Redis storage in
session/ratelimit/redis.go-
NewRedisStorage(client)- Create Redis storage -
Allow(ctx, key, limit, window)- Check and increment -
Reset(ctx, key)- Reset counter -
GetUsage(ctx, key)- Get current usage
-
- Add
session/ratelimit/redis_test.gowith integration tests - Add Redis connection configuration
- Add marketplace metrics to
observability/-
marketplace.checkouts_total- Checkout attempts -
marketplace.purchases_total- Successful purchases -
marketplace.licenses_granted_total- Licenses granted -
marketplace.seats_assigned_total- Seats assigned
-
- Add Stripe webhook metrics
-
marketplace.webhook_received_total- Webhooks received -
marketplace.webhook_processed_total- Webhooks processed -
marketplace.webhook_errors_total- Webhook errors
-
GoDoc coverage analysis identified ~600+ exported items missing documentation comments. This excludes auto-generated ent code (~100+ items) which should not be manually documented.
These are used directly by consumers of the library.
-
Config- Main configuration struct -
ClientConfig- OAuth client configuration -
Duration- Custom duration type for config parsing -
FederationConfig- Federation settings -
TokenConfig- Token generation settings
-
ClaimsFromContext- Extract JWT claims from context -
UserIDFromContext- Extract user ID from context -
OrganizationIDFromContext- Extract org ID from context -
PrincipalIDFromContext- Extract principal ID from context -
RoleFromContext- Extract role from context -
PermissionsFromContext- Extract permissions from context -
HTTPAuth- HTTP authentication middleware -
HTTPAuthOptional- Optional HTTP auth middleware -
RequireRole- Role requirement middleware -
RequirePermission- Permission requirement middleware -
RequireAnyRole- Any role requirement middleware -
RequireAnyPermission- Any permission requirement middleware -
RequirePlatformAdmin- Platform admin requirement -
RequireOrganization- Organization requirement middleware -
ChiAuth- Chi router auth middleware -
ChiAuthOptional- Chi router optional auth -
ChiRequireRole- Chi router role requirement -
RequireAPIKey- API key requirement middleware -
RequireScope- OAuth scope requirement middleware
-
Claims- JWT claims structure -
TokenPair- Access/refresh token pair -
CNFClaim- Confirmation claim for DPoP -
DefaultConfig- Default JWT configuration -
AccessTokenTTL- Access token TTL method -
RefreshTokenTTL- Refresh token TTL method -
GenerateRefreshToken- Refresh token generation -
GenerateTokenPairLegacy- Legacy token pair generation -
WithDPoPBinding- DPoP binding option -
DPoPThumbprint- DPoP thumbprint extraction -
ComputeTokenHash- Token hash computation
-
Authorizer- Main authorizer interface -
OrgAuthorizer- Organization-scoped authorizer -
RelationshipSyncer- Relationship synchronization interface -
ResourceExtractor- Resource ID extraction function type
-
RequireAction- Action requirement middleware -
RequireAllActions- All actions requirement -
RequireAnyAction- Any action requirement -
RequireMembership- Membership requirement -
RequireResourceAction- Resource action requirement -
RequireRole- Role requirement -
WithResourceID- Resource ID injection -
Error- Error handling method
-
BaseSchema- Base SpiceDB schema constant -
ResourceSchema- Resource schema generation -
RegisterPrincipal- Principal registration -
UpdateOrgMembership- Org membership update
-
NewEmbedded- Create embedded auth server -
AuthenticationProvider- Authentication provider interface -
IdentityProvider- Identity provider interface -
OAuthProvider- OAuth provider interface -
OAuthClientStore- OAuth client storage interface -
Identity- Identity type -
Providers- Provider collection -
NewProviders- Create provider collection -
Storage- Storage interface -
MemoryStorage- In-memory storage -
CleanupExpired- Expired token cleanup
-
SessionProvider- Session provider interface -
DefaultSessionProvider- Default session implementation -
AuthorizationSession- Authorization session type -
GetUserClaims- Get user claims from session -
HasConsent- Check consent status -
SaveConsent- Save user consent -
WithUserIDHeader- User ID header option
-
TokenInput- Token request input -
TokenResponse- Token response structure
-
Provider- SCIM provider interface -
Store- SCIM store interface -
ListUsers- List users method -
ListGroups- List groups method -
ToSCIMError- Error conversion -
CompositeAuthorizationHook- Composite auth hook -
RoleBasedAuthorizationHook- Role-based auth hook -
ScopedAuthorizationHook- Scoped auth hook -
PrincipalUserMapper- Principal to user mapping -
EnterpriseExtension- Enterprise SCIM extension -
ServiceProviderConfig- SCIM service provider config -
MultiValue- Multi-value SCIM type
-
HashPassword- Password hashing -
VerifyPassword- Password verification -
NeedsRehash- Check if rehash needed -
DefaultArgon2idParams- Default Argon2id parameters
-
Middleware- RLS middleware type -
DBWithRLS- Database wrapper with RLS -
EntDriver- Ent driver with RLS -
EntHook- Ent hook for RLS -
ContextInjector- Context injection type -
Executor- SQL executor with RLS -
TenantIDFromContext- Get tenant from context -
UserIDFromContext- Get user from context -
BypassRLS- Bypass RLS for admin operations -
SetTenant- Set tenant in context -
WithTenant- Transaction with tenant -
WithTenantFromContext- Transaction with context tenant -
RequireTenant- Require tenant middleware -
InjectContext- Inject RLS context -
SetContextFromContext- Set context from existing -
GenerateMigrationSQL- Generate RLS migration SQL -
SystemForgeTables- Tables requiring RLS
-
AsUser- Run as specific user -
WithoutRLS- Run without RLS -
AssertTenantIsolation- Assert tenant isolation
-
Session- BFF session type -
Store- Session store interface -
MemoryStore- In-memory session store -
NeedsRefresh- Check if refresh needed -
GetSessionID- Get session ID from cookie -
OptionalSessionMiddleware- Optional session middleware -
RequireSessionMiddleware- Required session middleware -
OriginMiddleware- Origin validation middleware -
APIProxyMiddleware- API proxy middleware -
RefreshHandler- Token refresh handler -
TokenResponse- BFF token response
-
ProofHeader- DPoP proof header type -
SerializedKeyPair- Serialized key pair -
NewProofClaims- Create proof claims -
ComputeAccessTokenHash- Compute access token hash -
ComputeThumbprint- Compute key thumbprint -
GenerateKeyPair- Generate DPoP key pair -
CreateProof- Create DPoP proof -
ParseProof- Parse DPoP proof -
VerifyTokenBinding- Verify token binding
-
KeyFunc- Rate limit key function type -
LimitResolver- Limit resolver interface -
MemoryStorage- In-memory rate limit storage -
RedisStorage- Redis rate limit storage -
NewRedisStorage- Create Redis storage -
CoreAPIResolver- CoreAPI rate limit resolver -
GetPolicyForRequest- Get policy for request -
ClientKey- Client-based key function -
PrincipalKey- Principal-based key function -
EndpointKey- Endpoint-based key function -
CompositeKey- Composite key function
-
MemoryStateStore- In-memory OAuth state store -
UserInfo- OAuth user info type
-
RateLimits- Rate limits configuration -
MostGranularLimit- Get most granular limit -
MemoryPolicyStore- In-memory policy store -
NewMemoryPolicyStore- Create memory policy store
-
WithLogger- Logger option -
ToContractError- Error conversion -
RequireAuth- Auth requirement middleware -
Middleware- Contract middleware -
RecordAuditEvent- Record audit event -
StartSync- Start provider sync -
SyncLagSeconds- Get sync lag -
MemoryStore- In-memory audit store
-
MarketplaceSchema- Marketplace SpiceDB schema -
MergeSchema- Merge schemas -
SeatsRemaining- Get remaining seats -
SyncLicense- Sync license to SpiceDB -
SyncLicenseRevocation- Sync license revocation -
SyncListing- Sync listing -
SyncSubscription- Sync subscription -
SyncSeatAssignment- Sync seat assignment -
SyncSeatUnassignment- Sync seat unassignment
-
New- Create observability provider -
ConfigFromEnv- Load config from environment -
Middleware- Observability middleware -
SlogHandler- Get slog handler
-
MemoryStore- In-memory feature flag store
-
BaseMixin- Base entity mixin -
UUIDMixin- UUID field mixin -
TimestampMixin- Timestamp fields mixin -
UserBase- User base mixin -
OrganizationBase- Organization base mixin -
MembershipBase- Membership base mixin -
PrincipalMixin- Principal mixin -
HumanMixin- Human entity mixin -
AgentMixin- Agent entity mixin -
ApplicationMixin- Application mixin -
ServicePrincipalMixin- Service principal mixin -
PrincipalMembershipMixin- Principal membership mixin -
OAuthAccountMixin- OAuth account mixin -
RefreshTokenMixin- Refresh token mixin
The following are auto-generated and should NOT be manually documented:
identity/ent/*.go(exceptmixin/andschema/)identity/ent/hook/hook.go- Generated hook typesidentity/ent/privacy/privacy.go- Generated privacy rulesidentity/ent/migrate/- Generated migrationsidentity/ent/internal/- Internal generated code
- Start comment with item name:
// Config holds the main configuration... - Describe purpose, not implementation: Focus on what it does, not how
- Document parameters for functions: Explain each parameter's purpose
- Document return values: Explain what is returned and when errors occur
- Add examples for complex APIs: Use
// Example:blocks where helpful - Cross-reference related items: Use
// See also: OtherTypewhen relevant
// Config holds the main configuration for the CoreAuth server.
// It includes settings for OAuth clients, token generation, and federation.
type Config struct {
// Clients defines the OAuth 2.0 clients that can authenticate.
Clients []ClientConfig `json:"clients" yaml:"clients"`
// Token configures access and refresh token generation.
Token TokenConfig `json:"token" yaml:"token"`
// Federation configures cross-application identity federation.
Federation FederationConfig `json:"federation" yaml:"federation"`
}
// HTTPAuth returns middleware that requires a valid JWT in the Authorization header.
// It extracts claims and adds them to the request context.
// Returns 401 Unauthorized if the token is missing or invalid.
// Returns 403 Forbidden if the token is expired.
//
// See also: HTTPAuthOptional, ClaimsFromContext
func HTTPAuth(jwtService *jwt.Service) func(http.Handler) http.Handler- Create
identity/mfa/package - Create
identity/mfa/totp.go-
GenerateSecret()- Generate TOTP secret -
GenerateQRCode(secret, issuer, account)- QR code for authenticator apps -
ValidateCode(secret, code)- Validate 6-digit code -
ValidateCodeWithWindow(secret, code, window)- Allow time drift
-
- Create
identity/mfa/recovery.go-
GenerateRecoveryCodes(count)- Generate backup codes -
HashRecoveryCode(code)- Hash for storage -
ValidateRecoveryCode(hash, code)- Validate and mark used
-
- Create
identity/ent/schema/mfa_enrollment.go- User relationship
- Secret (encrypted)
- Verified timestamp
- Recovery codes (hashed)
- Create
identity/mfa/enrollment.go-
StartEnrollment(userID)- Begin MFA setup -
VerifyEnrollment(userID, code)- Complete setup -
Unenroll(userID)- Remove MFA -
GetEnrollmentStatus(userID)- Check MFA status
-
- Create
identity/mfa/handlers.go-
POST /api/v1/mfa/enroll- Start enrollment -
POST /api/v1/mfa/verify- Verify enrollment -
POST /api/v1/mfa/challenge- Request MFA challenge -
POST /api/v1/mfa/validate- Validate MFA code -
DELETE /api/v1/mfa- Unenroll
-
- Create
session/middleware/mfa.go-
RequireMFA()- Require MFA for route -
MFAVerifiedFromContext(ctx)- Check MFA status in context -
SetMFAVerified(ctx)- Mark session as MFA verified
-
- Update JWT claims to include MFA verification status
- Add MFA requirement to sensitive operations
- Create
identity/mfa/totp_test.go - Create
identity/mfa/recovery_test.go - Create
identity/mfa/enrollment_test.go - Create
session/middleware/mfa_test.go
- Create
identity/security/lockout.go-
RecordFailure(identifier)- Track failed login -
IsLocked(identifier)- Check lockout status -
RecordSuccess(identifier)- Clear on success -
GetStatus(identifier)- Get remaining lockout time -
CheckAndRecord(identifier, success)- Combined check and record
-
- Create
identity/security/lockout_redis.go- Redis-backed storage for distributed deployments
- Create
identity/security/lockout_test.go(9 tests passing) - Configuration options:
- MaxAttempts - Max attempts before lockout
- LockoutDuration - How long account stays locked
- AttemptWindow - Time window for counting attempts
- Create
identity/ent/schema/login_attempt.go(optional, for persistence) - Add lockout check to authentication flow (integration)
- Create
session/invalidation/invalidation.go-
InvalidateAllSessions(userID)- Logout all devices -
InvalidateSession(sessionID)- Logout specific session -
ListSessions(userID)- List user's sessions -
InvalidateDeviceSessions(userID, deviceID)- Logout specific device -
InvalidateOtherSessions(userID, currentSessionID)- Logout other devices -
CreateSession(userID, opts...)- Create tracked session -
ValidateSession(sessionID)- Validate and update LastActiveAt -
RefreshSession(sessionID)- Extend session expiration
-
- Create
session/invalidation/store_memory.go- In-memory session storage
- Create
session/invalidation/store_redis.go- Redis-backed session storage for distributed deployments
- Session struct with:
- Session ID
- UserID
- DeviceID, DeviceInfo
- IPAddress
- LastActiveAt, CreatedAt, ExpiresAt
- Metadata map
- Create
session/invalidation/invalidation_test.go(15 tests passing) - MaxSessionsPerUser enforcement
- Create
identity/ent/schema/user_session.go(optional, for persistence) - Add session tracking to JWT issuance (integration)
- Add session validation to JWT middleware (integration)
- Create
identity/security/anomaly.go-
DetectAnomalousLogin(userID, ip, userAgent)- Check for anomalies -
RecordLogin(userID, ip, userAgent, location)- Track login patterns -
GetLoginHistory(userID)- Get recent logins
-
- Detection rules:
- New device/browser
- New location
- Impossible travel
- Unusual time of day
- Alert actions:
- Email notification
- Require MFA
- Block login
- Create
session/ratelimit/redis.go-
NewRedisStorage(client, opts)- Create Redis storage -
Allow(ctx, key, limit)- Check and increment (sliding window) -
Reset(ctx, key)- Reset counter - Lua script for atomic sliding window operations
-
- Create
session/ratelimit/memory.go- In-memory storage for single-instance deployments
- Create
session/ratelimit/ratelimit.go- Storage interface
- Limiter with middleware
- StaticResolver and TieredResolver
- Observability integration
- Create
session/ratelimit/ratelimit_test.go - Add Redis connection configuration (RedisConfig)
- Support cluster mode (UniversalClient)
- Add connection pooling options
- Create
featureflags/stores/redis.go-
NewRedisStore(client, opts)- Create Redis store -
Get(ctx, key)- Get flag value -
Set(ctx, key, value)- Set flag value -
Delete(ctx, key)- Delete flag -
List(ctx, prefix)- List flags -
Watch(ctx, key)- Watch for changes
-
- Create
featureflags/stores/redis_test.go - Add pub/sub for real-time updates
- Add TTL support for temporary flags
- Create
webhook/package - Create
webhook/config.go- Webhook configuration struct
- Retry policy options
- Signature algorithm options
- Create
identity/ent/schema/webhook.go- URL
- Secret (encrypted)
- Events subscribed
- Active flag
- Organization relationship
- Create
identity/ent/schema/webhook_delivery.go- Webhook relationship
- Event type
- Payload
- Status code
- Attempts
- Delivered timestamp
- Create
webhook/dispatcher.go-
Dispatch(ctx, event)- Queue event for delivery -
DispatchSync(ctx, event)- Synchronous delivery -
GetDeliveryStatus(deliveryID)- Check delivery status -
RetryDelivery(deliveryID)- Manual retry
-
- Create
webhook/worker.go- Background worker for async delivery
- Exponential backoff retry
- Dead letter queue handling
- Create
webhook/signature.go-
Sign(payload, secret)- Generate HMAC signature -
Verify(payload, signature, secret)- Verify signature - Support SHA-256 and SHA-512
-
- Create
webhook/handlers.go-
POST /api/v1/webhooks- Create webhook -
GET /api/v1/webhooks- List webhooks -
GET /api/v1/webhooks/{id}- Get webhook -
PATCH /api/v1/webhooks/{id}- Update webhook -
DELETE /api/v1/webhooks/{id}- Delete webhook -
POST /api/v1/webhooks/{id}/test- Send test event -
GET /api/v1/webhooks/{id}/deliveries- List deliveries -
POST /api/v1/webhooks/{id}/deliveries/{delivery_id}/retry- Retry delivery
-
- Create
webhook/dispatcher_test.go - Create
webhook/signature_test.go - Create
webhook/handlers_test.go - Integration tests with mock server
- Create
productgraph/correlation.go - Implement
CorrelationMiddleware - Implement
SessionIDFromContext - Implement
RequestIDFromContext - Implement
UserIDFromContext - Create
productgraph/correlation_test.go
- Create
productgraph/config.go - Create
productgraph/event.go - Create
productgraph/client.go - Implement async batching
- Create
productgraph/client_test.go
- Create
productgraph/middleware.go - Implement
RequestTrackerMiddleware - Implement
ChainMiddleware - Create
productgraph/middleware_test.go
- Create
observability/productgraph.go - Add
SetProductGraphmethod - Add
SetProductGraphFromEnvmethod - Update
Shutdownto close ProductGraph
- Create
productgraph/journey.go-
StartJourney(ctx, journeyID, name)- Start journey -
CompleteJourney(ctx, journeyID)- Complete journey -
AbandonJourney(ctx, journeyID, reason)- Abandon journey
-
- Add journey context propagation
- Create
identity/gdpr/export.go-
ExportUserData(ctx, userID)- Export all user data -
ExportToJSON(data)- JSON format -
ExportToCSV(data)- CSV format
-
- Define exportable data types:
- User profile
- Organization memberships
- OAuth accounts
- API keys (metadata only)
- Audit logs
- Sessions
- Create
identity/gdpr/export_test.go
- Create
identity/gdpr/deletion.go-
DeleteUserData(ctx, userID)- Delete all user data -
ScheduleDeletion(ctx, userID, when)- Schedule deletion -
CancelDeletion(ctx, userID)- Cancel scheduled deletion -
AnonymizeUser(ctx, userID)- Anonymize instead of delete
-
- Cascade delete:
- User record
- Memberships
- OAuth accounts
- API keys
- Sessions
- MFA enrollments
- Create
identity/gdpr/deletion_test.go
- Create
contract/audit/search.go-
Search(ctx, query)- Search audit logs -
Export(ctx, query, format)- Export search results
-
- Query options:
- Date range
- Actor (user/service)
- Action type
- Resource type
- Organization
- Create
contract/audit/search_test.go
- Create
identity/admin/impersonation.go-
StartImpersonation(ctx, adminID, targetUserID)- Start impersonation -
EndImpersonation(ctx)- End impersonation -
IsImpersonating(ctx)- Check impersonation status -
GetRealUser(ctx)- Get actual admin user
-
- Create impersonation token type
- Add impersonation claims to JWT
- Audit log all impersonation actions
- Create
identity/admin/impersonation_test.go
- Create
identity/admin/bulk.go-
BulkImportUsers(ctx, users)- Import users from CSV/JSON -
BulkExportUsers(ctx, query)- Export users -
BulkUpdateUsers(ctx, query, updates)- Bulk update -
BulkDeleteUsers(ctx, userIDs)- Bulk delete
-
- Create
identity/admin/bulk_test.go - Add progress tracking for large operations
- Add dry-run mode
- Create
notification/package - Create
notification/email.go-
Send(ctx, to, template, data)- Send email -
SendBulk(ctx, recipients, template, data)- Bulk send
-
- Create
notification/templates/- Welcome email
- Password reset
- Email verification
- MFA enrollment
- Suspicious login alert
- Subscription confirmation
- Provider support:
- SMTP
- SendGrid
- AWS SES
- Mailgun
- Create
identity/apikey/rotation.go-
ScheduleRotation(ctx, keyID, interval)- Schedule rotation -
Rotate(ctx, keyID)- Rotate key immediately -
GetRotationSchedule(ctx, keyID)- Get schedule
-
- Create
identity/apikey/quota.go-
SetQuota(ctx, keyID, quota)- Set rate limit -
GetUsage(ctx, keyID)- Get current usage -
ResetUsage(ctx, keyID)- Reset usage counter
-
- Create
identity/apikey/metering.go-
RecordCall(ctx, keyID)- Record API call -
GetUsageReport(ctx, keyID, period)- Usage report
-
- Create
identity/saml/package - Create
identity/saml/provider.go-
NewSAMLProvider(config)- Create provider -
GenerateMetadata()- SP metadata -
HandleAssertion(ctx, assertion)- Process SAML response
-
- Create
identity/saml/handlers.go-
GET /saml/metadata- Service provider metadata -
POST /saml/acs- Assertion consumer service -
GET /saml/login- Initiate SSO
-
- Create
identity/oidc/provider.go-
NewOIDCProvider(config)- Create provider -
HandleCallback(ctx, code)- Handle callback -
RefreshToken(ctx, token)- Refresh token
-
- Support multiple IdPs per organization
- Create
identity/webauthn/package - Create
identity/webauthn/registration.go-
BeginRegistration(ctx, userID)- Start registration -
FinishRegistration(ctx, userID, response)- Complete registration
-
- Create
identity/webauthn/authentication.go-
BeginAuthentication(ctx, userID)- Start authentication -
FinishAuthentication(ctx, userID, response)- Verify
-
- P0: Critical path, blocks release
- P1: High priority, should have for production
- P2: Medium priority, important for enterprise
- P3: Future consideration
- MFA/2FA support
- Webhook system
- GDPR compliance helpers
- Admin impersonation
- Marketplace module (Phase 1-4)
- ProductGraph correlation and client
- Request tracking middleware
- Observability integration
- Redis rate limiting backend
- Account lockout (brute-force protection)
- Session invalidation (logout all devices)