lenso-module-auth 0.1.7

First-party auth anchor module for the Lenso backend framework.
Documentation

Lenso Auth Module

First-party Lenso auth modules and Runtime Console surface.

  • crates/auth: Rust linked auth module.
  • crates/auth-anonymous: Rust anonymous auth provider module.
  • crates/auth-device: Rust linked auth device policy module.
  • crates/auth-github: Rust GitHub OAuth provider module.
  • crates/auth-google: Rust Google OAuth/OIDC provider module.
  • crates/auth-oauth: Rust OAuth client substrate module.
  • crates/auth-oidc: Rust OIDC provider module.
  • crates/auth-password: Rust password credential module and identifier/password provider.
  • auth-phone: first-party phone provider with SMS OTP flows and phone password routes backed by auth-password (crates/auth-phone).
  • packages/auth-console: Runtime Console surface loaded as a runtime bundle.

Packages

  • Rust: lenso-module-auth
  • Rust: lenso-module-auth-anonymous
  • Rust: lenso-module-auth-device
  • Rust: lenso-module-auth-github
  • Rust: lenso-module-auth-google
  • Rust: lenso-module-auth-oauth
  • Rust: lenso-module-auth-oidc
  • Rust: lenso-module-auth-password
  • Rust: lenso-module-auth-phone
  • npm: @lenso/auth-console

Redis Session Cache

lenso-module-auth resolves session tokens from Postgres by default. Hosts that want Redis-backed session lookup should:

  1. Depend on lenso-module-auth with features = ["redis"].
  2. Set REDIS_URL for the host process.
  3. Set runtime config auth.session_cache to redis.

The runtime config key is module-owned and defaults to database. When it is set to redis, the host must provide a Redis connection; otherwise Lenso fails startup validation with a clear configuration error. Cached session keys use the auth:sessions: prefix and expire at the lower of the session expiry and the host's cache TTL.

Generated Lenso hosts can apply the matching descriptor profile with:

lenso module install auth --profile redis-session-cache

JWT Secret

lenso-module-auth-password prefers the host's module-local LENSO_MODULE_AUTH_PASSWORD__JWT_SECRET value for JWT signing. Runtime config auth-password.jwt_secret remains a fallback for existing installs.

Development

cargo test --locked -p lenso-module-auth -p lenso-module-auth-anonymous -p lenso-module-auth-device -p lenso-module-auth-github -p lenso-module-auth-google -p lenso-module-auth-oauth -p lenso-module-auth-oidc -p lenso-module-auth-password -p lenso-module-auth-phone
pnpm install --frozen-lockfile
pnpm check

The console package treats @lenso/runtime-console-api as a peer dependency. Local development resolves it from the sibling lenso-runtime-console repository.