feat(auth): setup/login/logout, argon2id, sessions, login rate limit

This commit is contained in:
marcuspaico
2026-08-17 14:11:00 -07:00
parent 3c796da649
commit 0b8e897e31
5 changed files with 162 additions and 3 deletions

23
server/src/app.ts Normal file
View File

@@ -0,0 +1,23 @@
import { Hono } from "hono";
import { getCookie } from "hono/cookie";
import type { Db } from "./db";
import { authRoutes, isAuthenticated } from "./routes/auth";
export type Deps = { db: Db; key: Buffer };
const PUBLIC = new Set(["/api/health", "/api/me", "/api/setup", "/api/login"]);
export function createApp(deps: Deps) {
const app = new Hono();
app.get("/api/health", (c) => c.json({ ok: true }));
app.use("/api/*", async (c, next) => {
if (PUBLIC.has(c.req.path)) return next();
if (!(await isAuthenticated(deps.db, getCookie(c, "helios_session")))) {
return c.json({ error: "unauthenticated" }, 401);
}
return next();
});
app.route("/api", authRoutes({ db: deps.db }));
// Later route groups (settings, connectors, chat) mount here.
app.get("/api/settings", (c) => c.json({ error: "not implemented" }, 501)); // replaced in Task 5
return app;
}