feat(go-api): implement password-reset flow (issue #15282) (#15293)

## Summary

Ports the Python password-reset flow to Go, adding 4 unauthenticated
endpoints under `/api/v1/auth/password/`:

- `POST /auth/password/forgot/captcha` — generates and returns a PNG
captcha image; stores the plaintext code in Redis (60 s TTL)
- `POST /auth/password/forgot/otp` — verifies captcha, enforces resend
cooldown (60 s), generates HMAC-SHA256-hashed OTP (300 s TTL), sends
plain-text email via SMTP
- `POST /auth/password/forgot/otp/verify` — verifies OTP with attempt
counting (lock after 5 failures for 30 min), sets a
`otp:verified:{email}` flag (300 s TTL) on success
- `POST /auth/password/reset` — checks verified flag, decrypts +
validates passwords, updates user record, auto-logs in (issues JWT,
returns user profile)

Closes #15282
This commit is contained in:
web-dev0521
2026-06-01 19:38:02 -06:00
committed by GitHub
parent 1748723971
commit 1696d4ead6
9 changed files with 1424 additions and 3 deletions

View File

@@ -90,10 +90,24 @@ type ModelConfig struct {
Factory string `mapstructure:"factory"`
}
// OAuthConfig OAuth configuration for a channel
// OAuthConfig OAuth configuration for a channel.
// Mirrors api/apps/auth/__init__.py's OAUTH_CONFIG entries: a Type that
// selects the auth client flavor (oauth2 / oidc / github), plus the
// transport URLs and client credentials. For OIDC the URLs are derived
// from Issuer via the .well-known/openid-configuration document, so they
// may be left blank.
type OAuthConfig struct {
DisplayName string `mapstructure:"display_name"`
Icon string `mapstructure:"icon"`
DisplayName string `mapstructure:"display_name"`
Icon string `mapstructure:"icon"`
Type string `mapstructure:"type"`
ClientID string `mapstructure:"client_id"`
ClientSecret string `mapstructure:"client_secret"`
AuthorizationURL string `mapstructure:"authorization_url"`
TokenURL string `mapstructure:"token_url"`
UserinfoURL string `mapstructure:"userinfo_url"`
RedirectURI string `mapstructure:"redirect_uri"`
Scope string `mapstructure:"scope"`
Issuer string `mapstructure:"issuer"`
}
// ServerConfig server configuration