Password handling and lockout
Used bcrypt for password hashing and implemented account lockout after five failed attempts.
GO / AUTHENTICATION ENGINEERING
A command-line registration and login system with layered authentication and an explicit session lifecycle.
Architecture overview
THE BUILD
Built a Dockerized Go authentication system using Cobra and PostgreSQL through pgx. The project covers user registration, login, password security, multi-factor authentication, and session management.
Used bcrypt for password hashing and implemented account lockout after five failed attempts.
Added Google Authenticator-compatible TOTP MFA, including enrollment coverage in unit tests.
Implemented configurable session expiration, session-token revocation, and hashed session-token storage.
Wrote unit tests covering password hashing, account lockout, session expiration, token storage, and TOTP enrollment.
This is a portfolio project focused on Go authentication and tested session behavior.