internal/auth/ provides: - TokenStore: 32-byte cryptographically random one-time tokens. Only the SHA-256 hash is persisted (so a DB leak doesn't grant active sessions). Comparison uses subtle.ConstantTimeCompare. Single-use is enforced via UPDATE ... WHERE used_at IS NULL. - Signer: HS256 JWTs with 24h lifetime, jwt.WithValidMethods to reject alg=none and other downgrade attacks. - LogMailer (dev) and SMTPMailer (prod via net/smtp) behind a Mailer interface. - RateLimiter: DB-backed fixed window per email; default 5 per 15 min for the magic-link flow. - Service: orchestrates RequestLogin (auto-creates user on first login, generates token, emails magic link) and Verify (consumes token, updates last_login, issues JWT). - Handlers: POST /auth/login and GET/POST /auth/verify. HandleLogin returns 202 even on validation failure to avoid account enumeration; rate-limit hits surface as 429. Schema additions: magic_tokens (with FK + cascade) and login_attempts. UserStore.SetStoragePath added for completeness. Tests cover: token issue/consume, single-use, expiry, rate limit, JWT round-trip, alg=none rejection, signature tampering, purge, HTTP handlers (login + verify, missing/invalid token paths). Closes #9. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
librenotes
Cloud-native, multi-tenant notes application. A fork of Notesium extended with authentication, per-user data isolation, sync, and PWA support so it can run as a hosted service at librenot.es.
Features
- Markdown notes with bi-directional links (Zettelkasten / evergreen notes)
- Embedded web app — no Electron, no Node runtime, single static binary
- Multi-tenant backend with magic-link authentication (in development)
- Offline-capable PWA with background sync (planned, Phase 4)
Build
Requires Go 1.20 or later.
go build ./cmd/librenotes
This produces a librenotes binary in the current directory. The web
frontend and shell completion are embedded into the binary at compile
time, so no extra files are needed at runtime.
A Makefile with build, test, run, and clean targets is provided
for convenience:
make build
make test
Run
./librenotes web --notes-dir ~/notes
See ./librenotes help for the full command list.
Development setup
A Nix flake provides a reproducible development environment with Go,
build tools, and the project CLIs. Use the plain dev shell for a
non-sandboxed Go toolchain:
nix develop .#dev
Alternatively, build a Docker-based dev environment:
docker build -f Dockerfile.dev -t librenotes-dev .
docker run --rm -it -v "$PWD:/workspace" librenotes-dev
The repository layout follows the standard Go project structure:
cmd/librenotes/ Binary entry point
internal/notesium/ Core notes package (forked from Notesium)
internal/notesium/web/ Embedded frontend assets
The Go module path is git.librete.ch/public/librenotes.
Fork attribution
librenotes is a fork of Notesium by Alon Swartz, used and redistributed under the MIT License. See NOTICE for the upstream commit hash at fork time and instructions for tracking upstream changes.
License
MIT — see LICENSE. Copyright is shared between the original Notesium author and the librenotes contributors.