Replace the hand-rolled JWT auth with Better Auth 1.6.25 httpOnly cookie sessions, validated against the database on every request so revocation, bans and role changes take effect immediately. Backend: - betterAuth.ts wires the Drizzle adapter, magic links, Google sign-in and the admin plugin; auth-schema.ts maps Better Auth's models onto the existing `users` table so user IDs and their foreign keys survive intact. - routes/auth.ts is gone; Better Auth serves the standard endpoints and authExt.ts carries the flows it doesn't cover. - auth.ts shrinks to session resolution and helpers; sessions/revocation in dashboard.ts now read and delete `auth_sessions` rows directly. - Schema adds the Better Auth core + admin columns (email_verified, image, banned, ban_reason, ban_expires), with migrations and tests. - rateLimit.ts resolves client IPs spoof-resistantly: proxy headers are only honoured from loopback/RFC1918 peers plus TRUSTED_PROXIES. - passwordPolicy.ts centralises password validation. - Bump drizzle-orm, drizzle-kit and better-sqlite3 to versions compatible with Better Auth. Frontend: - auth-client.ts plus a reworked AuthContext and api/client.ts move to cookie-based sessions; no more bearer tokens in requests or middleware. photo-api: - Validate Better Auth session cookies against the shared auth_sessions table instead of verifying JWTs; JWT_SECRET is no longer needed for user auth, and PHOTO_VIEW_SECRET now signs gallery view tokens. BETTER_AUTH_SECRET and BETTER_AUTH_URL are required in production; the deprecated JWT_SECRET stays only as the photo-api view-token fallback. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
45 lines
1.6 KiB
JSON
45 lines
1.6 KiB
JSON
{
|
|
"name": "spanglish",
|
|
"version": "1.0.0",
|
|
"private": true,
|
|
"description": "Spanglish - Language Exchange Event Platform",
|
|
"scripts": {
|
|
"dev": "concurrently \"npm run dev:backend\" \"npm run dev:frontend\" \"npm run dev:photos\"",
|
|
"dev:backend": "npm run dev --workspace=backend",
|
|
"dev:frontend": "npm run dev --workspace=frontend",
|
|
"dev:photos": "cd photo-api && go run ./cmd/photo-api",
|
|
"build": "npm run build --workspaces",
|
|
"build:backend": "npm run build --workspace=backend",
|
|
"build:frontend": "npm run build --workspace=frontend",
|
|
"build:photos": "cd photo-api && go build -o bin/photo-api ./cmd/photo-api",
|
|
"test:photos": "cd photo-api && go test ./...",
|
|
"migrate:photos": "cd photo-api && go run ./cmd/photo-api migrate",
|
|
"start": "concurrently \"npm run start:backend\" \"npm run start:frontend\"",
|
|
"start:backend": "npm run start --workspace=backend",
|
|
"start:frontend": "npm run start --workspace=frontend",
|
|
"db:generate": "npm run db:generate --workspace=backend",
|
|
"db:migrate": "npm run db:migrate --workspace=backend",
|
|
"db:studio": "npm run db:studio --workspace=backend",
|
|
"db:export": "npm run db:export --workspace=backend --",
|
|
"db:import": "npm run db:import --workspace=backend --"
|
|
},
|
|
"workspaces": [
|
|
"backend",
|
|
"frontend"
|
|
],
|
|
"devDependencies": {
|
|
"concurrently": "^8.2.2"
|
|
},
|
|
"dependencies": {
|
|
"next": "^16.2.10"
|
|
},
|
|
"allowScripts": {
|
|
"esbuild@0.18.20": true,
|
|
"esbuild@0.25.12": true,
|
|
"esbuild@0.27.2": true,
|
|
"better-sqlite3@12.11.1": true,
|
|
"sharp@0.34.5": true,
|
|
"argon2@0.44.0": true
|
|
}
|
|
}
|