- authPlugin runs preHandler that turns Fastify request headers into a Headers object, calls auth.api.getSession, and decorates request.user / request.session - requireAuth() preHandler short-circuits with 401 when not signed in - New module modules/me with GET /me returning the authenticated user/session - env validates BETTER_AUTH_SECRET (≥32) and BETTER_AUTH_URL — must match web - Restored .js extensions in shared packages so NodeNext-resolution consumers (api) typecheck cleanly; Next webpack now uses extensionAlias to map .js → .ts - Re-enabled NodeNext for packages/auth and packages/db tsconfigs Verified end-to-end: - POST /api/auth/sign-in/email on web returns session cookie - GET /me on api with the cookie returns 200 + user/session - GET /me without the cookie returns 401 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
34 lines
875 B
JSON
34 lines
875 B
JSON
{
|
|
"name": "@ketopath/api",
|
|
"version": "0.0.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"dev": "tsx watch --env-file=.env src/server.ts",
|
|
"build": "tsc",
|
|
"start": "node dist/server.js",
|
|
"typecheck": "tsc --noEmit",
|
|
"lint": "eslint src --max-warnings=0"
|
|
},
|
|
"dependencies": {
|
|
"@fastify/cors": "^9.0.1",
|
|
"@fastify/helmet": "^11.1.1",
|
|
"@fastify/rate-limit": "^9.1.0",
|
|
"@fastify/sensible": "^5.6.0",
|
|
"@ketopath/auth": "workspace:*",
|
|
"@ketopath/db": "workspace:*",
|
|
"@ketopath/shared": "workspace:*",
|
|
"better-auth": "^1.0.21",
|
|
"fastify": "^4.28.1",
|
|
"fastify-plugin": "^4.5.1",
|
|
"zod": "^3.23.8"
|
|
},
|
|
"devDependencies": {
|
|
"@ketopath/eslint-config": "workspace:*",
|
|
"@ketopath/tsconfig": "workspace:*",
|
|
"@types/node": "^20.12.7",
|
|
"pino-pretty": "^11.2.1",
|
|
"tsx": "^4.16.2"
|
|
}
|
|
}
|