Lenso Auth Module
First-party Lenso auth modules and isolated Console UI artifacts.
crates/auth: Rust linked auth module.crates/auth-anonymous: Rust anonymous auth provider module.crates/auth-device: Rust linked auth device policy module.crates/auth-github: Rust GitHub OAuth provider module.crates/auth-google: Rust Google OAuth/OIDC provider module.crates/auth-oauth: Rust OAuth client substrate module.crates/auth-oidc: Rust OIDC provider module.crates/auth-password: Rust password credential module and identifier/password provider.auth-phone: first-party phone provider with SMS OTP flows and phone password routes backed byauth-password(crates/auth-phone).packages/auth-console: isolated sessions and users Console UI artifact.packages/auth-device-console: isolated device-policy Console UI artifact.packages/auth-provider-console: isolated provider Console UI artifact.
Packages
- Rust:
lenso-module-auth - Rust:
lenso-module-auth-anonymous - Rust:
lenso-module-auth-device - Rust:
lenso-module-auth-github - Rust:
lenso-module-auth-google - Rust:
lenso-module-auth-oauth - Rust:
lenso-module-auth-oidc - Rust:
lenso-module-auth-password - Rust:
lenso-module-auth-phone
Redis Session Cache
lenso-module-auth resolves session tokens from Postgres by default. Hosts that
want Redis-backed session lookup should:
- Depend on
lenso-module-authwithfeatures = ["redis"]. - Set
REDIS_URLfor the host process. - Set runtime config
auth.session_cachetoredis.
The runtime config key is module-owned and defaults to database. When it is
set to redis, the host must provide a Redis connection; otherwise Lenso fails
startup validation with a clear configuration error. Cached session keys use the
auth:sessions: prefix and expire at the lower of the session expiry and the
host's cache TTL.
Generated Lenso hosts can apply the matching descriptor profile with:
JWT Secret
lenso-module-auth-password prefers the host's module-local
LENSO_MODULE_AUTH_PASSWORD__JWT_SECRET value for JWT signing. Runtime config
auth-password.jwt_secret remains a fallback for existing installs.
Development
The Console UI workspaces are private build inputs. Their outputs are bound to
the owning Module Release and have no independent npm identity or version. They
use @lenso/console-bridge for the sandboxed host protocol.