Replace the hand-rolled JWT auth with Better Auth 1.6.25 httpOnly cookie sessions, validated against the database on every request so revocation, bans and role changes take effect immediately. Backend: - betterAuth.ts wires the Drizzle adapter, magic links, Google sign-in and the admin plugin; auth-schema.ts maps Better Auth's models onto the existing `users` table so user IDs and their foreign keys survive intact. - routes/auth.ts is gone; Better Auth serves the standard endpoints and authExt.ts carries the flows it doesn't cover. - auth.ts shrinks to session resolution and helpers; sessions/revocation in dashboard.ts now read and delete `auth_sessions` rows directly. - Schema adds the Better Auth core + admin columns (email_verified, image, banned, ban_reason, ban_expires), with migrations and tests. - rateLimit.ts resolves client IPs spoof-resistantly: proxy headers are only honoured from loopback/RFC1918 peers plus TRUSTED_PROXIES. - passwordPolicy.ts centralises password validation. - Bump drizzle-orm, drizzle-kit and better-sqlite3 to versions compatible with Better Auth. Frontend: - auth-client.ts plus a reworked AuthContext and api/client.ts move to cookie-based sessions; no more bearer tokens in requests or middleware. photo-api: - Validate Better Auth session cookies against the shared auth_sessions table instead of verifying JWTs; JWT_SECRET is no longer needed for user auth, and PHOTO_VIEW_SECRET now signs gallery view tokens. BETTER_AUTH_SECRET and BETTER_AUTH_URL are required in production; the deprecated JWT_SECRET stays only as the photo-api view-token fallback. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
37 lines
1.3 KiB
TypeScript
37 lines
1.3 KiB
TypeScript
import { fetchApi, API_BASE } from './client';
|
|
import type { Media } from './types';
|
|
|
|
export const mediaApi = {
|
|
getAll: (relatedType?: string, relatedId?: string) => {
|
|
const params = new URLSearchParams();
|
|
if (relatedType) params.set('relatedType', relatedType);
|
|
if (relatedId) params.set('relatedId', relatedId);
|
|
const query = params.toString();
|
|
return fetchApi<{ media: Media[] }>(`/api/media${query ? `?${query}` : ''}`);
|
|
},
|
|
|
|
upload: async (file: File, relatedId?: string, relatedType?: string) => {
|
|
const formData = new FormData();
|
|
formData.append('file', file);
|
|
if (relatedId) formData.append('relatedId', relatedId);
|
|
if (relatedType) formData.append('relatedType', relatedType);
|
|
|
|
// Auth rides on the session cookie
|
|
const res = await fetch(`${API_BASE}/api/media/upload`, {
|
|
method: 'POST',
|
|
credentials: API_BASE ? 'include' : 'same-origin',
|
|
body: formData,
|
|
});
|
|
|
|
if (!res.ok) {
|
|
const errorData = await res.json().catch(() => ({ error: 'Upload failed' }));
|
|
throw new Error(errorData.error || 'Upload failed');
|
|
}
|
|
|
|
return res.json() as Promise<{ media: Media; url: string }>;
|
|
},
|
|
|
|
delete: (id: string) =>
|
|
fetchApi<{ message: string }>(`/api/media/${id}`, { method: 'DELETE' }),
|
|
};
|