refactor: centralize auth system across all modules

All modules now use the main IAM JWT (ACCESS_TOKEN_SECRET) for authentication,
removing three separate auth systems (hackathon Supabase, hackathon JWT, QR JWT).

Changes:
- hackathon: replace HackathonJwtService with decode_access_token() from imphnen-libs
  - remove entire src/auth/ (Supabase signup/login/GitHub/forgot-reset)
  - remove common/hackathon_jwt.rs, common/supabase_client.rs
  - remove Supabase from HackathonConfig (JWT, GitHub OAuth, Supabase anon/service keys)
  - replace Supabase Storage with MinioService from imphnen-libs
  - all route jwt params removed; hackathon_router takes MinioService instead
- qr: replace QrJwtService with decode_access_token() from imphnen-libs
  - remove entire src/auth/ (register/login/Google OAuth/refresh)
  - remove common/qr_jwt.rs, src/config.rs
  - qr_auth_middleware now lazy-upserts users into QR DB on first access
  - qr_router(pool) — no config needed
- gateway: create MinioService once and pass to hackathon_router; qr_router simplified

Users now register/login via /v1/auth/* and use the same JWT for all endpoints.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
maulanasdqn
2026-04-02 16:33:02 +07:00
co-authored by Claude Sonnet 4.6
parent 4bba182ea3
commit 2ae43b3bcc
47 changed files with 78 additions and 1139 deletions
+10 -20
View File
@@ -2,7 +2,6 @@ pub mod config;
pub mod common;
pub mod middleware;
pub mod admin;
pub mod auth;
pub mod certificates;
pub mod chat;
pub mod storage;
@@ -14,7 +13,6 @@ pub mod join_requests;
pub mod winners;
pub use admin::hackathon_admin_routes;
pub use auth::hackathon_auth_routes;
pub use certificates::hackathon_certificates_routes;
pub use chat::build_chat_routes;
pub use storage::hackathon_storage_routes;
@@ -29,28 +27,20 @@ pub use config::HackathonConfig;
use axum::Router;
use sea_orm::DatabaseConnection;
use std::sync::Arc;
use common::{hackathon_jwt::HackathonJwtService, supabase_client::SupabaseClient};
use imphnen_libs::MinioService;
pub fn hackathon_router(db: DatabaseConnection, config: Arc<HackathonConfig>) -> Router {
pub fn hackathon_router(db: DatabaseConnection, _config: Arc<HackathonConfig>, minio: Arc<MinioService>) -> Router {
let pool = Arc::new(db.get_postgres_connection_pool().clone());
let jwt = Arc::new(HackathonJwtService::new(&config.jwt_secret, config.jwt_expiry_hours));
let supabase = Arc::new(SupabaseClient::new(
config.supabase_url.clone(),
config.supabase_anon_key.clone(),
config.supabase_service_role_key.clone(),
config.storage_bucket.clone(),
));
Router::new()
.merge(hackathon_auth_routes(pool.clone(), jwt.clone(), supabase.clone(), config.clone()))
.merge(hackathon_users_routes(pool.clone(), jwt.clone()))
.merge(build_team_routes(pool.clone(), jwt.clone()))
.merge(build_invitation_routes(pool.clone(), jwt.clone()))
.merge(build_join_request_routes(pool.clone(), jwt.clone()))
.merge(build_chat_routes(pool.clone(), jwt.clone()))
.merge(hackathon_submissions_routes(pool.clone(), jwt.clone()))
.merge(hackathon_storage_routes(pool.clone(), jwt.clone(), supabase))
.merge(hackathon_users_routes(pool.clone()))
.merge(build_team_routes(pool.clone()))
.merge(build_invitation_routes(pool.clone()))
.merge(build_join_request_routes(pool.clone()))
.merge(build_chat_routes(pool.clone()))
.merge(hackathon_submissions_routes(pool.clone()))
.merge(hackathon_storage_routes(pool.clone(), minio))
.merge(hackathon_certificates_routes(pool.clone()))
.merge(hackathon_winners_routes(pool.clone()))
.merge(hackathon_admin_routes(pool, jwt))
.merge(hackathon_admin_routes(pool))
}