docs(adr): adopt Better Auth, replacing Clerk

Reasons (full ADR in docs/decisions/0001-auth-provider.md):
- KetoPath targets EU users with Art. 9 GDPR data; Clerk on US infra
  raises Schrems II concerns
- Free, self-hostable, stays in our Postgres
- TypeScript-first, fits Next.js + Fastify + Prisma stack

CLAUDE.md updated:
- Tech stack: Better Auth on EU Postgres
- "Cosa NON fare mai": no manual password hashing
- References: Better Auth docs link

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
lucianoandClaude Opus 4.7 committed 2026-04-29 12:44:21 +02:00
1 parent 72d47da453
commit e9f1a55a5b
2 files changed
+78 -3

No files matched your search

+3 -3
View File
@@ -26,7 +26,7 @@ Il documento di prodotto completo è in `docs/PRD_KetoPath.docx`. Quando devi pr
**Backend**
- Node.js + Fastify + TypeScript
- Prisma come ORM
- Auth gestita via Clerk (no roll-your-own)
- Auth gestita via Better Auth, self-hostata su Postgres EU (vedi `docs/decisions/0001-auth-provider.md`)
**Database & infrastruttura**
- PostgreSQL 15+ come DB principale
@@ -156,7 +156,7 @@ pnpm test:e2e # Playwright
## Cosa NON fare mai
- Salvare password in chiaro (Clerk gestisce auth, non implementarla a mano).
- Salvare password in chiaro o reimplementare l'hashing manualmente (Better Auth gestisce hashing scrypt, sessioni e flussi OAuth — non riscriverli).
- Loggare dati di salute fuori dal DB cifrato.
- Usare `eval()` o `new Function()` con input utente.
- Disabilitare feature di sicurezza (CSP, CORS, rate limiting) per "comodità di sviluppo".
@@ -199,7 +199,7 @@ Queste decisioni non sono ancora finalizzate. Se le tocchi, aprire un ADR in `do
- PRD completo: `docs/PRD_KetoPath.docx`
- Documentazione Next.js: https://nextjs.org/docs
- Documentazione Prisma: https://www.prisma.io/docs
- Documentazione Clerk: https://clerk.com/docs
- Documentazione Better Auth: https://better-auth.com/docs
- shadcn/ui: https://ui.shadcn.com
- GDPR e dati sanitari: https://www.garanteprivacy.it/