koan_server/auth/mod.rs
1//! Authentication layer for the koan server.
2//!
3//! When `auth_enabled = true`:
4//! - All GraphQL/Subsonic requests must carry a valid JWT in `Authorization: Bearer <token>`
5//! - Auth routes (/auth/login, /auth/refresh, /auth/logout) are always accessible
6//!
7//! When `auth_enabled = false` (opt-in, not the default):
8//! - All requests are treated as admin — no auth required. Same behavior as before this feature.
9
10pub mod middleware;
11pub mod password;
12pub mod routes;
13
14use koan_core::auth::Role;
15
16/// Authenticated user context injected into request extensions and GraphQL context.
17#[derive(Debug, Clone)]
18pub struct AuthUser {
19 pub user_id: i64,
20 pub username: String,
21 pub role: Role,
22}
23
24impl AuthUser {
25 /// Anonymous admin user for when auth is disabled.
26 pub fn anonymous_admin() -> Self {
27 Self {
28 user_id: 0,
29 username: "anonymous".into(),
30 role: Role::Admin,
31 }
32 }
33}