barsa 2266167467 Enhance JWT handling and authentication flow
- Introduced support for previous JWT secrets in the environment configuration to facilitate key rotation.
- Refactored the JoseJwtService to manage multiple signing and verification keys, improving security during token validation.
- Updated the AuthTokenService to include family identifiers for refresh tokens, enhancing session management and security.
- Modified the PasswordWorkflowService and SignupWorkflowService to return session metadata instead of token strings, aligning with security best practices.
- Improved error handling and token revocation logic in the TokenBlacklistService and AuthTokenService to prevent replay attacks.
- Updated documentation to reflect changes in the authentication architecture and security model.
2025-12-12 15:29:58 +09:00
..
2025-08-22 17:02:49 +09:00

Portal Structure Overview

This app follows a feature-first architecture with a consolidated lib for shared utilities.

Structure:

src/
  app/           # Next.js App Router
  components/    # Design system (ui, layout, common)
  features/      # Feature modules (auth, billing, subscriptions, ...)
  lib/           # Core utils and services (api, query, env, utils, types)
  providers/     # App-wide providers (e.g., QueryProvider)
  styles/        # Global styles

Key changes:

  • Merged former core/ and shared/ into lib/.
  • Moved components/providers/query-provider.tsx to providers/query-provider.tsx.
  • Introduced path aliases: @/lib/*, @/providers/*.

Migration tips:

  • Prefer importing from @/lib/... going forward.
  • All @/shared/* or @/core/* imports have been removed; use @/lib/*.