Skip to content

Feat/shared auth middleware#11

Draft
masaya-osuga wants to merge 3 commits into
mainfrom
feat/shared-auth-middleware
Draft

Feat/shared auth middleware#11
masaya-osuga wants to merge 3 commits into
mainfrom
feat/shared-auth-middleware

Conversation

@masaya-osuga

@masaya-osuga masaya-osuga commented May 10, 2026

Copy link
Copy Markdown
Member

No description provided.

masaya-osuga and others added 3 commits May 10, 2026 15:29
全モジュール共通の認証・認可ユーティリティを internal/shared/auth に新設。
Extract で Bearer (失効チェック付き) と AppCheck を best-effort 検証し、
RequireUserUnlessAllowed で default-deny の保護を行う。
カスタムクレーム検証 (RequireAdmin / RequireAnyClaim) はハンドラから呼ぶ
形で提供。Bearer 検証成功時は AppCheck をスキップする。

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
router に Extract と RequireUserUnlessAllowed を validator の前段で登録。
academic-api は現状すべての endpoint がログイン必須のため allowList は空。
合わせて Firebase 初期化のために signal context を main 冒頭へ移動した。

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant