Step 2 of the build order. The admin mints an invite link, the recipient
registers with it, and from then on has a session.
- The invite is spent in the same transaction that creates the account, so a
failed signup leaves the code usable
- Sessions are idle timeouts, 24h or 30 days with remember me, read from a
cookie or a bearer header, extended at most once a minute
- Ban is a reversible toggle that drops the member's live sessions
- No password minimum; login is rate limited instead, 10 failures per email
in 15 minutes, cleared by a correct password
- Invite codes render as links carrying ?code=, which the register form
prefills; PUBLIC_URL makes them pasteable from the loopback admin panel
Tests cover invite spending, the idle timeout, ban, and the rate limiter.
Step 1 of the build order in docs/decisions.md. Boots, applies migrations
before serving, and serves a health check and an empty admin page.
- 001_init.sql is the full schema from docs/spec.md, including the check
constraints and indexes the old app lacked
- The startup sweep fails submissions left mid-conversion by a restart; an
in-process goroutine dies with the process and those rows would otherwise
say converting forever
- Admin is Basic Auth from env on its own listener, fatal at startup when
ADMIN_PASSWORD is unset