Archive the differentiated YuXinGu product docs, AI engineering system, design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity over early innovation (see .ai/product/STRATEGY.md). Co-authored-by: Cursor <cursoragent@cursor.com>
20 lines
432 B
Markdown
20 lines
432 B
Markdown
# ADR-0004 JWT (or opaque Bearer) for auth
|
|
|
|
## Status
|
|
|
|
Accepted (direction)
|
|
|
|
## Decision
|
|
|
|
Clients send `Authorization: Bearer <token>`. Prefer JWT for stateless MVP; server may later move to opaque tokens + session store via new ADR.
|
|
|
|
## Reason
|
|
|
|
1. Works for H5 and future mini-program
|
|
2. Simple middleware story
|
|
|
|
## Never
|
|
|
|
Never invent parallel auth headers (`X-User-Id` as sole auth).
|
|
Never trust client-only “isVip” flags.
|