P1 items #6 (JWT expiry) and #7 (refresh/logout routes) were already delivered
in the P0 pass. This commit covers the two remaining P1 items:
#9 — Replace dangerous handler-level .unwrap() calls (13 sites):
* handlers/users.rs: 5x ObjectId::parse_str(&claims.sub).unwrap() in
get_profile/update_profile/delete_account/get_settings/update_settings now
return 401 on a malformed subject instead of panicking (matches the guard
already used in change_password).
* handlers/auth.rs: the login user.id.ok_or_else(..).unwrap() was a latent
panic bug — the crafted 500 response was discarded. Now returns the clean
500 via match.
* handlers/health_stats.rs: 6x state.health_stats_repo.as_ref().unwrap() now
return 503 SERVICE_UNAVAILABLE if the feature is unconfigured, mirroring the
interactions.rs pattern.
* Left untouched: 14 test/boot-time unwraps and 7 infallible ones (header
literal parsing, infallible TryFrom). The 3 borderline model-layer
inserted_id unwraps are flagged for later.
#8 — Rewrite the broken integration tests against a real test DB:
* Split the crate into bin+lib: new src/lib.rs + src/app.rs (build_app), with
main.rs now a thin entrypoint. Tests build the exact production router
in-process instead of hitting a live server on a hardcoded port.
* tests/common/mod.rs: helpers that connect to Mongo, build a fresh AppState
against a unique per-process DB (normogen_test_<uuid>), and tear it down.
A 1s connectivity probe makes tests skip gracefully when Mongo is absent, so
'cargo test' stays green without Mongo — CI runs them for real.
* Rewrote tests/auth_tests.rs and tests/medication_tests.rs with the ACTUAL
API contracts (POST /register {email,username,password}; response has token
+ refresh_token, not access_token; register returns 201). Covers register,
login (right/wrong password), auth enforcement, refresh rotation + reuse
detection, logout, and password-change invalidating old tokens.
* Added a 'test' CI job with a mongo:7 service container running
cargo test --all-targets.
* Synced scripts/test-ci-locally.sh: fixed the stale -D warnings (CI is
non-strict) and the reverted 'Docker Buildx' claims; added unit + integration
test steps with a Mongo skip note.
Verified: cargo fmt --check clean, build + clippy --all-targets clean.
Full 'cargo test': 18 unit + 9 auth + 4 medication = 31 passed, 0 failed
(integration tests skip cleanly when MongoDB is unreachable).
Address the four P0 security items from the project review:
* token_version validation (#1): the JWT middleware now rejects access tokens
whose token_version claim is stale (e.g. issued before a password change).
A short-TTL (30s) in-memory cache (TokenVersionCache) avoids a Mongo lookup
per request; credential changes invalidate the cache immediately on the
handling instance.
* Fail-fast config (#2): add APP_ENVIRONMENT (development|production). In
production the server refuses to boot unless JWT_SECRET and ENCRYPTION_KEY
are set to non-default values; development keeps the insecure defaults with
a warning.
* Real client IP in audit logs (#4): new client_ip middleware resolves the
originating IP (X-Forwarded-For > X-Real-IP > ConnectInfo socket) and
exposes it via a ClientIp extractor. All five hardcoded "0.0.0.0" audit
calls are replaced, and the missing PasswordChanged audit event is added to
change_password. axum::serve now uses into_make_service_with_connect_info.
* Refresh token persistence (#5): refresh tokens are now stored hashed in
MongoDB (RefreshTokenRepository) instead of an in-memory map lost on restart.
Added /api/auth/refresh (with rotation + token_version check) and
/api/auth/logout routes; register/login return a refresh_token; password
change/recovery revoke all of a user's refresh tokens. JwtService now honors
JwtConfig expiries instead of hardcoding 15min/30d, and the dead in-memory
refresh store is removed.
Also: wire up DatabaseInitializer (was never called), fix the refresh_tokens
index to tokenHash + add an expiresAt TTL index, add sha2 dep.
Rate limiting (#3) is deferred per scope; the stub remains.
Verified: cargo fmt --check clean, cargo build/clippy --all-targets clean,
18 unit tests pass (9 new). Integration tests (tests/*) still need a live
server — fixing them is tracked as P1.
BREAKING CHANGE: AuthResponse now includes a refresh_token field.
- Remove old Cargo.lock with incompatible dependency versions
- Run 'cargo update' to regenerate with compatible versions
- Fixes 'time-macros-0.2.27' parsing error in CI
- Clippy now passes cleanly with no warnings
- Dependencies updated to latest compatible versions