Files
ketopath/packages/auth/src/env.ts
T
lucianoandClaude Opus 4.7 31eea207ba feat(auth): add @ketopath/auth package wrapping Better Auth
- New workspace packages/auth exporting:
  - auth: Better Auth server instance using Prisma adapter on @ketopath/db
  - makeAuthClient: React client factory parameterised by baseURL
  - readAuthEnv: Zod-validated env reader (BETTER_AUTH_SECRET min 32 chars,
    BETTER_AUTH_URL, optional GOOGLE_CLIENT_ID/SECRET)
- emailAndPassword enabled with min 8 chars, requireEmailVerification: false
  for MVP (re-enable in V1, see ADR 0001)
- Google provider conditionally registered when both env vars are present —
  keeps the package usable before OAuth configuration is delivered
- 7-day sessions, 24h rolling refresh, cookie prefix 'ketopath'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 12:48:51 +02:00

20 lines
700 B
TypeScript

import { z } from 'zod';
// Le env vars sono lette dal processo che importa @ketopath/auth (apps/web,
// apps/api, ecc.). Vengono validate al momento della creazione dell'istanza,
// così errori di configurazione emergono al boot e non a runtime.
const authEnvSchema = z.object({
BETTER_AUTH_SECRET: z
.string()
.min(32, 'BETTER_AUTH_SECRET deve essere lungo almeno 32 caratteri'),
BETTER_AUTH_URL: z.string().url(),
GOOGLE_CLIENT_ID: z.string().optional(),
GOOGLE_CLIENT_SECRET: z.string().optional(),
});
export type AuthEnv = z.infer<typeof authEnvSchema>;
export function readAuthEnv(source: NodeJS.ProcessEnv = process.env): AuthEnv {
return authEnvSchema.parse(source);
}