feat(auth): setup/login/logout, argon2id, sessions, login rate limit
This commit is contained in:
23
server/src/app.ts
Normal file
23
server/src/app.ts
Normal file
@@ -0,0 +1,23 @@
|
||||
import { Hono } from "hono";
|
||||
import { getCookie } from "hono/cookie";
|
||||
import type { Db } from "./db";
|
||||
import { authRoutes, isAuthenticated } from "./routes/auth";
|
||||
|
||||
export type Deps = { db: Db; key: Buffer };
|
||||
const PUBLIC = new Set(["/api/health", "/api/me", "/api/setup", "/api/login"]);
|
||||
|
||||
export function createApp(deps: Deps) {
|
||||
const app = new Hono();
|
||||
app.get("/api/health", (c) => c.json({ ok: true }));
|
||||
app.use("/api/*", async (c, next) => {
|
||||
if (PUBLIC.has(c.req.path)) return next();
|
||||
if (!(await isAuthenticated(deps.db, getCookie(c, "helios_session")))) {
|
||||
return c.json({ error: "unauthenticated" }, 401);
|
||||
}
|
||||
return next();
|
||||
});
|
||||
app.route("/api", authRoutes({ db: deps.db }));
|
||||
// Later route groups (settings, connectors, chat) mount here.
|
||||
app.get("/api/settings", (c) => c.json({ error: "not implemented" }, 501)); // replaced in Task 5
|
||||
return app;
|
||||
}
|
||||
Reference in New Issue
Block a user