feat(api): add Better Auth plugin and protected GET /me endpoint
- authPlugin runs preHandler that turns Fastify request headers into a Headers object, calls auth.api.getSession, and decorates request.user / request.session - requireAuth() preHandler short-circuits with 401 when not signed in - New module modules/me with GET /me returning the authenticated user/session - env validates BETTER_AUTH_SECRET (≥32) and BETTER_AUTH_URL — must match web - Restored .js extensions in shared packages so NodeNext-resolution consumers (api) typecheck cleanly; Next webpack now uses extensionAlias to map .js → .ts - Re-enabled NodeNext for packages/auth and packages/db tsconfigs Verified end-to-end: - POST /api/auth/sign-in/email on web returns session cookie - GET /me on api with the cookie returns 200 + user/session - GET /me without the cookie returns 401 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
0139b13fc6
commit
5f17f95d6d
12 files changed
+81
-8
No files matched your search
@@ -5,10 +5,19 @@ const withNextIntl = createNextIntlPlugin('./src/i18n.ts');
|
||||
/** @type {import('next').NextConfig} */
|
||||
const nextConfig = {
|
||||
reactStrictMode: true,
|
||||
transpilePackages: ['@ketopath/auth', '@ketopath/shared', '@ketopath/ui'],
|
||||
transpilePackages: ['@ketopath/auth', '@ketopath/db', '@ketopath/shared', '@ketopath/ui'],
|
||||
experimental: {
|
||||
typedRoutes: true,
|
||||
},
|
||||
webpack(config) {
|
||||
// I package interni usano .js nelle import (NodeNext). Webpack non lo
|
||||
// risolve di default per i file TS: gli diciamo di provare anche .ts/.tsx.
|
||||
config.resolve.extensionAlias = {
|
||||
...config.resolve.extensionAlias,
|
||||
'.js': ['.ts', '.tsx', '.js', '.jsx'],
|
||||
};
|
||||
return config;
|
||||
},
|
||||
};
|
||||
|
||||
export default withNextIntl(nextConfig);
|
||||
Reference in new issue
Block a user