chore: seal Design Vision v1 and monorepo scaffold
Archive the differentiated YuXinGu product docs, AI engineering system, design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity over early innovation (see .ai/product/STRATEGY.md). Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
# Playbook: Login / Auth
|
||||
|
||||
## Steps
|
||||
|
||||
1. Cite ADR-0004
|
||||
2. Define Visitor vs User in API behavior (`.ai/domain.md`)
|
||||
3. Issue Bearer token; document in OpenAPI
|
||||
4. Middleware extracts `user_id`
|
||||
5. Persist session/user as designed (Postgres MVP; Redis deferred)
|
||||
6. H5: store token via adapter (`localStorage` key `yxg_token`)
|
||||
7. SDK `getToken` wired
|
||||
8. Tests: invalid token / expired / ownership
|
||||
9. Security review checklist
|
||||
10. Never accept `X-User-Id` alone as auth
|
||||
Reference in New Issue
Block a user