phase-0: foundation, both apps boot end to end
Monorepo (pnpm workspaces) with two deployable apps and three pure packages. apps/api (Hono on Node): Zod validated env that fails fast and names the problem, Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable migrations covering the whole SPEC section 5 schema, Better Auth with the four roles and seeded demo accounts, localized error envelope, /healthz and /readyz, graceful SIGTERM drain. Dialect specific SQL is confined to the two factories. apps/web (Next.js App Router): locale routed shell in es and en with a language switcher, sign in screen, and a runtime /api proxy so the browser only ever sees one origin and cookies stay first party. packages/i18n ships both catalogs complete; es is generated from COPY.md and a test re-derives it from the document on every run so it cannot drift. packages/contracts holds the Zod schemas and the typed client the web app uses. Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck and lint clean, migrate and seed from a clean database, sign in through the proxy with CSRF rejection of foreign origins. Not verified here: docker compose. This user has no access to the docker socket. RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and no tax rule, check digit or deadline was invented. See DECISIONS.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
import type { NextRequest } from 'next/server';
|
||||
|
||||
/**
|
||||
* Single origin proxy: the browser only ever talks to the web origin, and everything
|
||||
* under /api is forwarded to the API container. Cookies stay first party, so there is
|
||||
* no CORS anywhere in v1.
|
||||
*
|
||||
* SPEC-GAP: SPEC.md section 2 specifies Next rewrites for this. Next bakes rewrite
|
||||
* destinations into the build manifest, which would make API_INTERNAL_URL a build time
|
||||
* value and stop one image from running in both compose and k8s. A route handler reads
|
||||
* it per request instead, which is what "all configuration via .env" requires.
|
||||
*/
|
||||
|
||||
export const dynamic = 'force-dynamic';
|
||||
|
||||
/** Set by the proxy or the runtime, never forwarded verbatim. */
|
||||
const STRIPPED_REQUEST_HEADERS = new Set([
|
||||
'host',
|
||||
'connection',
|
||||
'content-length',
|
||||
'transfer-encoding',
|
||||
'accept-encoding',
|
||||
]);
|
||||
|
||||
const STRIPPED_RESPONSE_HEADERS = new Set(['content-encoding', 'content-length', 'transfer-encoding']);
|
||||
|
||||
function apiBaseUrl(): string {
|
||||
return (process.env['API_INTERNAL_URL'] ?? 'http://localhost:4000').replace(/\/$/, '');
|
||||
}
|
||||
|
||||
async function proxy(request: NextRequest): Promise<Response> {
|
||||
const incoming = new URL(request.url);
|
||||
const target = `${apiBaseUrl()}${incoming.pathname}${incoming.search}`;
|
||||
|
||||
const headers = new Headers();
|
||||
request.headers.forEach((value, key) => {
|
||||
if (!STRIPPED_REQUEST_HEADERS.has(key.toLowerCase())) headers.set(key, value);
|
||||
});
|
||||
|
||||
const hasBody = request.method !== 'GET' && request.method !== 'HEAD';
|
||||
const upstream = await fetch(target, {
|
||||
method: request.method,
|
||||
headers,
|
||||
redirect: 'manual',
|
||||
...(hasBody ? { body: request.body, duplex: 'half' } : {}),
|
||||
} as RequestInit & { duplex?: 'half' });
|
||||
|
||||
const responseHeaders = new Headers();
|
||||
upstream.headers.forEach((value, key) => {
|
||||
const name = key.toLowerCase();
|
||||
if (name === 'set-cookie') return;
|
||||
if (!STRIPPED_RESPONSE_HEADERS.has(name)) responseHeaders.set(key, value);
|
||||
});
|
||||
// Session and CSRF cookies arrive as several Set-Cookie headers and must stay separate.
|
||||
for (const cookie of upstream.headers.getSetCookie()) {
|
||||
responseHeaders.append('set-cookie', cookie);
|
||||
}
|
||||
|
||||
return new Response(upstream.body, { status: upstream.status, headers: responseHeaders });
|
||||
}
|
||||
|
||||
export const GET = proxy;
|
||||
export const POST = proxy;
|
||||
export const PUT = proxy;
|
||||
export const PATCH = proxy;
|
||||
export const DELETE = proxy;
|
||||
export const HEAD = proxy;
|
||||
export const OPTIONS = proxy;
|
||||
Reference in New Issue
Block a user