Files
MichilisandClaude Opus 5 733d2459df Migrate authentication to Better Auth
Replace the hand-rolled JWT auth with Better Auth 1.6.25 httpOnly cookie
sessions, validated against the database on every request so revocation,
bans and role changes take effect immediately.

Backend:
- betterAuth.ts wires the Drizzle adapter, magic links, Google sign-in and
  the admin plugin; auth-schema.ts maps Better Auth's models onto the
  existing `users` table so user IDs and their foreign keys survive intact.
- routes/auth.ts is gone; Better Auth serves the standard endpoints and
  authExt.ts carries the flows it doesn't cover.
- auth.ts shrinks to session resolution and helpers; sessions/revocation in
  dashboard.ts now read and delete `auth_sessions` rows directly.
- Schema adds the Better Auth core + admin columns (email_verified, image,
  banned, ban_reason, ban_expires), with migrations and tests.
- rateLimit.ts resolves client IPs spoof-resistantly: proxy headers are only
  honoured from loopback/RFC1918 peers plus TRUSTED_PROXIES.
- passwordPolicy.ts centralises password validation.
- Bump drizzle-orm, drizzle-kit and better-sqlite3 to versions compatible
  with Better Auth.

Frontend:
- auth-client.ts plus a reworked AuthContext and api/client.ts move to
  cookie-based sessions; no more bearer tokens in requests or middleware.

photo-api:
- Validate Better Auth session cookies against the shared auth_sessions
  table instead of verifying JWTs; JWT_SECRET is no longer needed for user
  auth, and PHOTO_VIEW_SECRET now signs gallery view tokens.

BETTER_AUTH_SECRET and BETTER_AUTH_URL are required in production; the
deprecated JWT_SECRET stays only as the photo-api view-token fallback.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 19:07:04 +00:00

50 lines
2.0 KiB
Bash

# Spanglish photo-api configuration
# Copy to .env — the service loads it on start (systemd also passes it via
# EnvironmentFile). This service has its own .env; nothing is shared with
# backend/.env except the VALUES of JWT_SECRET and DATABASE_URL.
# Port (dev default 3003; the systemd unit overrides to 3020 in production)
PORT=3003
# Database — the SAME database the backend uses. photo-api owns only the
# photos_* tables (created by `photo-api migrate`) and reads users/events/
# tickets/payments for auth and access checks.
# DB_TYPE must match the backend's engine: postgres | sqlite
DB_TYPE=postgres
DATABASE_URL=postgresql://spanglish:password@localhost:5432/spanglish_db
# For sqlite instead:
# DB_TYPE=sqlite
# DATABASE_URL=../backend/data/spanglish.db
# Secret for gallery image view tokens (HMAC). Any strong random value; does
# not need to match any backend secret. Rotating it invalidates outstanding
# image URLs for at most ~1 hour (they are re-minted per page load).
PHOTO_VIEW_SECRET=8b69468724b730dddecba3d04717cf44e6dc5b808773e7e60156d38875f0f6cd
# DEPRECATED: fallback for PHOTO_VIEW_SECRET during the Better Auth migration
# (user auth now validates Better Auth sessions from the shared database, not
# JWTs). Set PHOTO_VIEW_SECRET and remove this.
JWT_SECRET=
# Public site origin, used to build share links and allow dev CORS
FRONTEND_URL=https://spanglishcommunity.com
# Photo storage. Local disk by default; setting BOTH S3_ENDPOINT and
# S3_BUCKET switches to S3 (same convention as the backend's media storage).
# Use a photos-specific bucket — do not reuse the backend's media bucket.
STORAGE_PATH=./data/photos
#S3_ENDPOINT=
#S3_REGION=auto
#S3_BUCKET=spanglish-photos
#S3_ACCESS_KEY_ID=
#S3_SECRET_ACCESS_KEY=
#S3_FORCE_PATH_STYLE=true
# Upload and processing tuning
MAX_UPLOAD_MB=50
WORKER_CONCURRENCY=2
# HEIC conversion shells out to a host-installed CLI (autodetects `vips`
# then `heif-convert`; Debian: apt install libvips-tools). Set to override.
#HEIC_CONVERTER=