Add admin identity module: better-auth, per-app permissions, invitations
Introduces src/models/admin/, a dedicated identity and permissions module on its own nachklang_admin database, and the shared authenticator that feedback and tickets will move onto in the cutover step. Nothing swaps over yet: feedback.auth.ts and tickets.auth.ts still authenticate against the legacy calendar sessions, so production behaviour is unchanged. - better-auth 1.7 mounted at /admin/auth/*, sessions as httpOnly cookies scoped to .nachklang.art so one sign-in covers every *.nachklang.art app. - Accounts are invite-only: public sign-up is disabled, and the invitations plugin is the only code that creates users. Tokens are stored as SHA-256 hashes and travel in the request body, never in a URL. - Per-app permissions in user_app_permissions; requireAppAccess(app) queries the database on every request (no cookie cache) so disabling a user or revoking a session takes effect immediately. - ADMIN_BOOTSTRAP_EMAIL guarantees a way in on an empty database, idempotently and without crashing the API if the database is unreachable at boot. - Guards prevent an admin from removing their own admin permission, disabling themselves, or stripping the last active admin. The admin pool uses the callback-style mysql2, not mysql2/promise: Kysely's MysqlDialect drives the pool with callbacks, and the promise wrapper ignores them, so every query hangs silently. Only the integration tests caught this. Schema in sql/admin/001_init.sql, derived from getAuthTables() on the installed better-auth rather than the published CLI, which lags the library and omits account.issuer. app.ts is split into src/app.factory.ts so the integration tests drive the real middleware order rather than a copy of it. Tests: 131 unit, plus 41 integration tests against a throwaway MariaDB started by test/integration/setup.ts (docker or podman). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
import {defineConfig} from 'vitest/config';
|
||||
|
||||
/**
|
||||
* The admin module's integration tests. Separate from vitest.config.ts because
|
||||
* these need Docker: they run against a real MariaDB (see
|
||||
* docker-compose.test.yml) rather than mocks, which is the only way to catch
|
||||
* the Kysely/MariaDB dialect and cookie-attribute problems this module can have.
|
||||
*
|
||||
* Run with: npm run test:integration
|
||||
*/
|
||||
export default defineConfig({
|
||||
test: {
|
||||
include: ['test/integration/**/*.test.ts'],
|
||||
environment: 'node',
|
||||
globalSetup: ['test/integration/setup.ts'],
|
||||
// One database, shared state: parallel files would fight over the same
|
||||
// user and invitation rows.
|
||||
fileParallelism: false,
|
||||
testTimeout: 30_000,
|
||||
hookTimeout: 180_000,
|
||||
env: {
|
||||
NODE_ENV: 'test',
|
||||
FEEDBACK_IP_SALT: 'vitest-salt',
|
||||
DB_HOST: '127.0.0.1',
|
||||
DB_PORT: '3307',
|
||||
DB_USER: 'nachklang',
|
||||
DB_PASSWORD: 'testpassword',
|
||||
ADMIN_DB: 'nachklang_admin',
|
||||
API_BASE_URL: 'http://localhost:3000',
|
||||
ADMIN_APP_URL: 'http://localhost:3002',
|
||||
APP_ORIGINS: 'http://localhost:3001',
|
||||
BETTER_AUTH_SECRET: 'integration-test-secret-not-used-anywhere-else',
|
||||
PASSKEY_RP_ID: 'localhost',
|
||||
ADMIN_BOOTSTRAP_EMAIL: 'boot@nachklang.art',
|
||||
SALESFORCE_ENABLED: 'false'
|
||||
}
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user