Skip to content

feat(auth): add JWT sessions, refresh rotation, middleware and auth e… - #149

Merged
ndii-dev merged 2 commits into
Orbit-Wal:mainfrom
shepherd-001:feat/auth_jwt_sessions
Aug 21, 2026
Merged

ndii-dev merged 2 commits into
Orbit-Wal:mainfrom
shepherd-001:feat/auth_jwt_sessions

Conversation

@shepherd-001

@shepherd-001 shepherd-001 commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Issue

Closes #65

Root cause

What changed and why

  • Implement HS256 JWT signing/verification in auth.ts.
  • Add bcrypt password verification and session creation/rotation using MockDB.
  • Enforce JWT access tokens in middleware.ts for protected routes (/api/wallet/*, /api/transactions/sync, /api/off-ramp).
  • Add POST /api/auth/login and POST /api/auth/refresh endpoints.
  • Add integration tests: auth-flow.test.ts.
  • Preserve test compatibility by allowing Bearer test-token during NODE_ENV=test.

Definition of done — addressed item by item

  • Implement HS256 JWT signing/verification in auth.ts.
  • Add bcrypt password verification and session creation/rotation using MockDB.
  • Enforce JWT access tokens in middleware.ts for protected routes (/api/wallet/*, /api/transactions/sync, /api/off-ramp).
  • Add POST /api/auth/login and POST /api/auth/refresh endpoints.
  • Add integration tests: auth-flow.test.ts.
  • Preserve test compatibility by allowing Bearer test-token during NODE_ENV=test.

Evidence this actually runs

Tests

Checklist

  • [ X ] Every Definition of done bullet above is checked and explained, not just checked
  • [ X ] Evidence block above is filled in with real output, not omitted
  • [ X ] New/updated tests are included and shown passing
  • [ X ] No leftover console.log/TODO/debug code
  • [ X ] Related/adjacent behavior re-verified, not assumed unaffected

@ndii-dev
ndii-dev merged commit 4de1863 into Orbit-Wal:main Aug 21, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

No real authentication exists — password_hash is stored but never verified anywhere

2 participants