refactor: centralize auth system across all modules

All modules now use the main IAM JWT (ACCESS_TOKEN_SECRET) for authentication,
removing three separate auth systems (hackathon Supabase, hackathon JWT, QR JWT).

Changes:
- hackathon: replace HackathonJwtService with decode_access_token() from imphnen-libs
  - remove entire src/auth/ (Supabase signup/login/GitHub/forgot-reset)
  - remove common/hackathon_jwt.rs, common/supabase_client.rs
  - remove Supabase from HackathonConfig (JWT, GitHub OAuth, Supabase anon/service keys)
  - replace Supabase Storage with MinioService from imphnen-libs
  - all route jwt params removed; hackathon_router takes MinioService instead
- qr: replace QrJwtService with decode_access_token() from imphnen-libs
  - remove entire src/auth/ (register/login/Google OAuth/refresh)
  - remove common/qr_jwt.rs, src/config.rs
  - qr_auth_middleware now lazy-upserts users into QR DB on first access
  - qr_router(pool) — no config needed
- gateway: create MinioService once and pass to hackathon_router; qr_router simplified

Users now register/login via /v1/auth/* and use the same JWT for all endpoints.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
maulanasdqn
2026-04-02 16:33:02 +07:00
co-authored by Claude Sonnet 4.6
parent 4bba182ea3
commit 2ae43b3bcc
47 changed files with 78 additions and 1139 deletions
@@ -4,11 +4,10 @@ use std::sync::Arc;
use crate::teams::application::team_service::TeamServiceImpl;
use crate::teams::domain::service::TeamService;
use crate::teams::infrastructure::persistence::PostgresTeamRepository;
use crate::common::hackathon_jwt::HackathonJwtService;
use crate::middleware::hackathon_auth::hackathon_auth_middleware;
use super::handlers::*;
pub fn build_team_routes(pool: Arc<PgPool>, jwt: Arc<HackathonJwtService>) -> Router {
pub fn build_team_routes(pool: Arc<PgPool>) -> Router {
let repo = Arc::new(PostgresTeamRepository::new(pool.clone()));
let service: Arc<dyn TeamService> = Arc::new(TeamServiceImpl::new(repo));
@@ -25,7 +24,6 @@ pub fn build_team_routes(pool: Arc<PgPool>, jwt: Arc<HackathonJwtService>) -> Ro
.route("/teams/:team_id/members/:member_id", delete(remove_member_handler))
.layer(Extension(service))
.layer(Extension(pool.clone()))
.layer(Extension(jwt))
.layer(from_fn(hackathon_auth_middleware));
Router::new().merge(public).merge(protected)