- authPlugin runs preHandler that turns Fastify request headers into a Headers object, calls auth.api.getSession, and decorates request.user / request.session - requireAuth() preHandler short-circuits with 401 when not signed in - New module modules/me with GET /me returning the authenticated user/session - env validates BETTER_AUTH_SECRET (≥32) and BETTER_AUTH_URL — must match web - Restored .js extensions in shared packages so NodeNext-resolution consumers (api) typecheck cleanly; Next webpack now uses extensionAlias to map .js → .ts - Re-enabled NodeNext for packages/auth and packages/db tsconfigs Verified end-to-end: - POST /api/auth/sign-in/email on web returns session cookie - GET /me on api with the cookie returns 200 + user/session - GET /me without the cookie returns 401 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
49 lines
1.4 KiB
TypeScript
49 lines
1.4 KiB
TypeScript
import cors from '@fastify/cors';
|
|
import helmet from '@fastify/helmet';
|
|
import rateLimit from '@fastify/rate-limit';
|
|
import sensible from '@fastify/sensible';
|
|
import Fastify, { type FastifyInstance } from 'fastify';
|
|
|
|
import { env } from './config/env.js';
|
|
import { dbRoutes } from './modules/db/db.routes.js';
|
|
import { healthRoutes } from './modules/health/health.routes.js';
|
|
import { meRoutes } from './modules/me/me.routes.js';
|
|
import { authPlugin } from './plugins/auth.js';
|
|
import { prismaPlugin } from './plugins/prisma.js';
|
|
|
|
export async function buildApp(): Promise<FastifyInstance> {
|
|
const app = Fastify({
|
|
logger: {
|
|
level: env.LOG_LEVEL,
|
|
...(env.NODE_ENV === 'development'
|
|
? {
|
|
transport: {
|
|
target: 'pino-pretty',
|
|
options: { translateTime: 'HH:MM:ss', ignore: 'pid,hostname' },
|
|
},
|
|
}
|
|
: {}),
|
|
},
|
|
disableRequestLogging: env.NODE_ENV === 'production',
|
|
});
|
|
|
|
await app.register(helmet, { global: true });
|
|
await app.register(cors, {
|
|
origin: env.CORS_ORIGINS,
|
|
credentials: true,
|
|
});
|
|
await app.register(rateLimit, {
|
|
max: 100,
|
|
timeWindow: '1 minute',
|
|
});
|
|
await app.register(sensible);
|
|
await app.register(prismaPlugin);
|
|
await app.register(authPlugin);
|
|
|
|
await app.register(healthRoutes);
|
|
await app.register(dbRoutes);
|
|
await app.register(meRoutes);
|
|
|
|
return app;
|
|
}
|