Files
vmall/openspec/changes/archive/2026-09-17-foundation-auth/proposal.md
T

946 B

Proposal: foundation-auth

Why

VMall needs a working backend skeleton and an identity layer before any commerce feature: users, roles (platform_admin / shop_owner / shop_staff / customer), and JWT-based auth that gates every protected endpoint.

What changes

  • Rust axum API skeleton: config, structured errors, health/readiness endpoints, sqlx migrations on boot, Redis connection manager.
  • Users table with argon2 password hashes; shops table (needed for role scoping).
  • Auth endpoints: register (customer), login, me.
  • JWT issuance/validation middleware; role-guard helpers (require_role, shop-scoping for shop roles).
  • Seed: one platform admin account.

Non-goals

  • OAuth / social login, refresh tokens, password reset flows.
  • Fine-grained permission tables beyond the four roles.

Capabilities

  • auth: registration, login, token issuance, current-user lookup.
  • rbac: role model and enforcement on protected routes.