Files
digital-psychology/.ai/playbooks/login.md
T
jackyu66gitandCursor 2fb1dfee14 chore: seal Design Vision v1 and monorepo scaffold
Archive the differentiated YuXinGu product docs, AI engineering system,
design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity
over early innovation (see .ai/product/STRATEGY.md).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:00:44 +08:00

462 B

Playbook: Login / Auth

Steps

  1. Cite ADR-0004
  2. Define Visitor vs User in API behavior (.ai/domain.md)
  3. Issue Bearer token; document in OpenAPI
  4. Middleware extracts user_id
  5. Persist session/user as designed (Postgres MVP; Redis deferred)
  6. H5: store token via adapter (localStorage key yxg_token)
  7. SDK getToken wired
  8. Tests: invalid token / expired / ownership
  9. Security review checklist
  10. Never accept X-User-Id alone as auth