feat(auth): add @ketopath/auth package wrapping Better Auth
- New workspace packages/auth exporting:
- auth: Better Auth server instance using Prisma adapter on @ketopath/db
- makeAuthClient: React client factory parameterised by baseURL
- readAuthEnv: Zod-validated env reader (BETTER_AUTH_SECRET min 32 chars,
BETTER_AUTH_URL, optional GOOGLE_CLIENT_ID/SECRET)
- emailAndPassword enabled with min 8 chars, requireEmailVerification: false
for MVP (re-enable in V1, see ADR 0001)
- Google provider conditionally registered when both env vars are present —
keeps the package usable before OAuth configuration is delivered
- 7-day sessions, 24h rolling refresh, cookie prefix 'ketopath'
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
79d4943c00
commit
31eea207ba
9 files changed
+110
-1
No files matched your search
@@ -0,0 +1,19 @@
|
||||
import { z } from 'zod';
|
||||
|
||||
// Le env vars sono lette dal processo che importa @ketopath/auth (apps/web,
|
||||
// apps/api, ecc.). Vengono validate al momento della creazione dell'istanza,
|
||||
// così errori di configurazione emergono al boot e non a runtime.
|
||||
const authEnvSchema = z.object({
|
||||
BETTER_AUTH_SECRET: z
|
||||
.string()
|
||||
.min(32, 'BETTER_AUTH_SECRET deve essere lungo almeno 32 caratteri'),
|
||||
BETTER_AUTH_URL: z.string().url(),
|
||||
GOOGLE_CLIENT_ID: z.string().optional(),
|
||||
GOOGLE_CLIENT_SECRET: z.string().optional(),
|
||||
});
|
||||
|
||||
export type AuthEnv = z.infer<typeof authEnvSchema>;
|
||||
|
||||
export function readAuthEnv(source: NodeJS.ProcessEnv = process.env): AuthEnv {
|
||||
return authEnvSchema.parse(source);
|
||||
}
|
||||
Reference in new issue
Block a user