feat: protect write endpoints with JWT auth (story #08)

Add bcrypt user file auth, JWT middleware on all write routes, Pinia
authStore with localStorage persistence, login view with redirect
support, and v-if guards on all CRUD controls and admin nav link.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-19 11:18:42 +02:00
co-authored by Claude Sonnet 4.6
parent 649c9687ac
commit 1b381d9385
32 changed files with 895 additions and 56 deletions
+16
View File
@@ -9,11 +9,15 @@ import (
type Config struct {
DatabaseURL string
Port string
UsersFile string
JWTSecret string
}
// Load reads configuration from environment variables.
// DATABASE_URL is required (no silent default — fails fast if missing).
// PORT defaults to "3000".
// USERS_FILE defaults to "users.env".
// JWT_SECRET is required.
func Load() *Config {
dbURL := os.Getenv("DATABASE_URL")
if dbURL == "" {
@@ -21,13 +25,25 @@ func Load() *Config {
"Copy .env.example to .env and set the correct value.")
}
jwtSecret := os.Getenv("JWT_SECRET")
if jwtSecret == "" {
log.Fatal("JWT_SECRET environment variable is required but not set.")
}
port := os.Getenv("PORT")
if port == "" {
port = "3000"
}
usersFile := os.Getenv("USERS_FILE")
if usersFile == "" {
usersFile = "users.env"
}
return &Config{
DatabaseURL: dbURL,
Port: port,
UsersFile: usersFile,
JWTSecret: jwtSecret,
}
}