Archive the differentiated YuXinGu product docs, AI engineering system, design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity over early innovation (see .ai/product/STRATEGY.md). Co-authored-by: Cursor <cursoragent@cursor.com>
15 lines
462 B
Markdown
15 lines
462 B
Markdown
# Playbook: Login / Auth
|
|
|
|
## Steps
|
|
|
|
1. Cite ADR-0004
|
|
2. Define Visitor vs User in API behavior (`.ai/domain.md`)
|
|
3. Issue Bearer token; document in OpenAPI
|
|
4. Middleware extracts `user_id`
|
|
5. Persist session/user as designed (Postgres MVP; Redis deferred)
|
|
6. H5: store token via adapter (`localStorage` key `yxg_token`)
|
|
7. SDK `getToken` wired
|
|
8. Tests: invalid token / expired / ownership
|
|
9. Security review checklist
|
|
10. Never accept `X-User-Id` alone as auth
|