phase-0: foundation, both apps boot end to end
Monorepo (pnpm workspaces) with two deployable apps and three pure packages. apps/api (Hono on Node): Zod validated env that fails fast and names the problem, Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable migrations covering the whole SPEC section 5 schema, Better Auth with the four roles and seeded demo accounts, localized error envelope, /healthz and /readyz, graceful SIGTERM drain. Dialect specific SQL is confined to the two factories. apps/web (Next.js App Router): locale routed shell in es and en with a language switcher, sign in screen, and a runtime /api proxy so the browser only ever sees one origin and cookies stay first party. packages/i18n ships both catalogs complete; es is generated from COPY.md and a test re-derives it from the document on every run so it cannot drift. packages/contracts holds the Zod schemas and the typed client the web app uses. Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck and lint clean, migrate and seed from a clean database, sign in through the proxy with CSRF rejection of foreign origins. Not verified here: docker compose. This user has no access to the docker socket. RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and no tax rule, check digit or deadline was invented. See DECISIONS.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
import { createAuth } from '../auth/options';
|
||||
import { createDb } from '../db/index';
|
||||
import { migrateToLatest } from '../db/migrator';
|
||||
import { seed } from '../db/seed';
|
||||
import { createApp, type AppHandle } from '../http/app';
|
||||
import type { AppDeps } from '../http/context';
|
||||
import { type Env, parseEnv } from '../lib/env';
|
||||
|
||||
export const TEST_ENV: Record<string, string> = {
|
||||
NODE_ENV: 'test',
|
||||
DATABASE_URL: 'sqlite::memory:',
|
||||
BETTER_AUTH_SECRET: 'test-secret-that-is-long-enough-32chars',
|
||||
BETTER_AUTH_URL: 'http://localhost:3000',
|
||||
APP_PUBLIC_URL: 'http://localhost:3000',
|
||||
};
|
||||
|
||||
export interface Harness extends AppHandle {
|
||||
deps: AppDeps;
|
||||
env: Env;
|
||||
close: () => Promise<void>;
|
||||
/** Signs in a seeded account and returns the cookie header for later requests. */
|
||||
signIn: (email: string, password: string) => Promise<string>;
|
||||
}
|
||||
|
||||
export async function createHarness(overrides: Record<string, string> = {}): Promise<Harness> {
|
||||
const parsed = parseEnv({ ...TEST_ENV, ...overrides });
|
||||
if (!parsed.ok || !parsed.env) throw new Error(parsed.message);
|
||||
const env = parsed.env;
|
||||
|
||||
const handle = createDb(env.DATABASE_URL);
|
||||
await migrateToLatest(handle, env);
|
||||
|
||||
const auth = createAuth({ db: handle.db, dialect: handle.dialect, env, sendOtp: async () => undefined });
|
||||
await seed(handle, auth);
|
||||
|
||||
const deps: AppDeps = { env, handle, auth };
|
||||
const appHandle = createApp(deps);
|
||||
|
||||
return {
|
||||
...appHandle,
|
||||
deps,
|
||||
env,
|
||||
close: () => handle.close(),
|
||||
signIn: async (email, password) => {
|
||||
const response = await appHandle.app.request('/api/auth/sign-in/email', {
|
||||
method: 'POST',
|
||||
headers: { 'content-type': 'application/json' },
|
||||
body: JSON.stringify({ email, password }),
|
||||
});
|
||||
if (!response.ok) throw new Error(`sign in failed: ${response.status} ${await response.text()}`);
|
||||
const cookie = response.headers.get('set-cookie');
|
||||
if (!cookie) throw new Error('sign in returned no cookie');
|
||||
return cookie.split(';')[0] ?? '';
|
||||
},
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user