libretechandClaude Opus 4.7 6c2e33a3af Implement email magic-link authentication
internal/auth/ provides:
- TokenStore: 32-byte cryptographically random one-time tokens.
  Only the SHA-256 hash is persisted (so a DB leak doesn't grant
  active sessions). Comparison uses subtle.ConstantTimeCompare.
  Single-use is enforced via UPDATE ... WHERE used_at IS NULL.
- Signer: HS256 JWTs with 24h lifetime, jwt.WithValidMethods to
  reject alg=none and other downgrade attacks.
- LogMailer (dev) and SMTPMailer (prod via net/smtp) behind a
  Mailer interface.
- RateLimiter: DB-backed fixed window per email; default 5 per
  15 min for the magic-link flow.
- Service: orchestrates RequestLogin (auto-creates user on first
  login, generates token, emails magic link) and Verify (consumes
  token, updates last_login, issues JWT).
- Handlers: POST /auth/login and GET/POST /auth/verify.
  HandleLogin returns 202 even on validation failure to avoid
  account enumeration; rate-limit hits surface as 429.

Schema additions: magic_tokens (with FK + cascade) and
login_attempts. UserStore.SetStoragePath added for completeness.

Tests cover: token issue/consume, single-use, expiry, rate limit,
JWT round-trip, alg=none rejection, signature tampering, purge,
HTTP handlers (login + verify, missing/invalid token paths).

Closes #9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 22:16:25 +02:00
2026-04-28 21:58:59 +02:00
2026-04-28 21:58:59 +02:00
2026-04-28 21:58:59 +02:00

librenotes

CI

Cloud-native, multi-tenant notes application. A fork of Notesium extended with authentication, per-user data isolation, sync, and PWA support so it can run as a hosted service at librenot.es.

Features

  • Markdown notes with bi-directional links (Zettelkasten / evergreen notes)
  • Embedded web app — no Electron, no Node runtime, single static binary
  • Multi-tenant backend with magic-link authentication (in development)
  • Offline-capable PWA with background sync (planned, Phase 4)

Build

Requires Go 1.20 or later.

go build ./cmd/librenotes

This produces a librenotes binary in the current directory. The web frontend and shell completion are embedded into the binary at compile time, so no extra files are needed at runtime.

A Makefile with build, test, run, and clean targets is provided for convenience:

make build
make test

Run

./librenotes web --notes-dir ~/notes

See ./librenotes help for the full command list.

Development setup

A Nix flake provides a reproducible development environment with Go, build tools, and the project CLIs. Use the plain dev shell for a non-sandboxed Go toolchain:

nix develop .#dev

Alternatively, build a Docker-based dev environment:

docker build -f Dockerfile.dev -t librenotes-dev .
docker run --rm -it -v "$PWD:/workspace" librenotes-dev

The repository layout follows the standard Go project structure:

cmd/librenotes/      Binary entry point
internal/notesium/   Core notes package (forked from Notesium)
internal/notesium/web/   Embedded frontend assets

The Go module path is git.librete.ch/public/librenotes.

Fork attribution

librenotes is a fork of Notesium by Alon Swartz, used and redistributed under the MIT License. See NOTICE for the upstream commit hash at fork time and instructions for tracking upstream changes.

License

MIT — see LICENSE. Copyright is shared between the original Notesium author and the librenotes contributors.

S
Description
No description provided
Readme MIT
987 KiB
2026-04-29 01:30:06 +02:00
Languages
JavaScript 51.3%
Go 33.8%
HTML 8%
Shell 2.9%
CSS 2.4%
Other 1.6%