feat(api): add Better Auth plugin and protected GET /me endpoint

- authPlugin runs preHandler that turns Fastify request headers into a Headers
  object, calls auth.api.getSession, and decorates request.user / request.session
- requireAuth() preHandler short-circuits with 401 when not signed in
- New module modules/me with GET /me returning the authenticated user/session
- env validates BETTER_AUTH_SECRET (≥32) and BETTER_AUTH_URL — must match web
- Restored .js extensions in shared packages so NodeNext-resolution consumers
  (api) typecheck cleanly; Next webpack now uses extensionAlias to map .js → .ts
- Re-enabled NodeNext for packages/auth and packages/db tsconfigs

Verified end-to-end:
- POST /api/auth/sign-in/email on web returns session cookie
- GET /me on api with the cookie returns 200 + user/session
- GET /me without the cookie returns 401

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
lucianoandClaude Opus 4.7 committed 2026-04-29 13:50:14 +02:00
1 parent 0139b13fc6
commit 5f17f95d6d
12 files changed
+81 -8

No files matched your search

+4
View File
@@ -7,6 +7,8 @@ import Fastify, { type FastifyInstance } from 'fastify';
import { env } from './config/env.js';
import { dbRoutes } from './modules/db/db.routes.js';
import { healthRoutes } from './modules/health/health.routes.js';
import { meRoutes } from './modules/me/me.routes.js';
import { authPlugin } from './plugins/auth.js';
import { prismaPlugin } from './plugins/prisma.js';
export async function buildApp(): Promise<FastifyInstance> {
@@ -36,9 +38,11 @@ export async function buildApp(): Promise<FastifyInstance> {
});
await app.register(sensible);
await app.register(prismaPlugin);
await app.register(authPlugin);
await app.register(healthRoutes);
await app.register(dbRoutes);
await app.register(meRoutes);
return app;
}
+2
View File
@@ -15,6 +15,8 @@ const envSchema = z.object({
.filter(Boolean),
),
DATABASE_URL: z.string().url(),
BETTER_AUTH_SECRET: z.string().min(32),
BETTER_AUTH_URL: z.string().url(),
});
export type Env = z.infer<typeof envSchema>;
+10
View File
@@ -0,0 +1,10 @@
import type { FastifyPluginAsync } from 'fastify';
import { requireAuth } from '../../plugins/auth.js';
export const meRoutes: FastifyPluginAsync = async (fastify) => {
fastify.get('/me', { preHandler: requireAuth() }, async (request) => ({
user: request.user,
session: request.session,
}));
};
+39
View File
@@ -0,0 +1,39 @@
import { auth } from '@ketopath/auth';
import type { FastifyReply, FastifyRequest } from 'fastify';
import fp from 'fastify-plugin';
type SessionPayload = Awaited<ReturnType<typeof auth.api.getSession>>;
type User = NonNullable<SessionPayload>['user'];
type Session = NonNullable<SessionPayload>['session'];
declare module 'fastify' {
interface FastifyRequest {
user: User | null;
session: Session | null;
}
}
export const authPlugin = fp(async (app) => {
app.decorateRequest('user', null);
app.decorateRequest('session', null);
app.addHook('preHandler', async (request) => {
const headers = new Headers();
for (const [key, value] of Object.entries(request.headers)) {
if (typeof value === 'string') headers.set(key, value);
else if (Array.isArray(value)) headers.set(key, value.join(', '));
}
const result = await auth.api.getSession({ headers });
request.user = result?.user ?? null;
request.session = result?.session ?? null;
});
});
export function requireAuth() {
return async (request: FastifyRequest, reply: FastifyReply): Promise<void> => {
if (!request.user || !request.session) {
return reply.code(401).send({ error: 'unauthorized' });
}
};
}