Files
API/vitest.config.ts
T
Paddy 7aac07a013 Add admin identity module: better-auth, per-app permissions, invitations
Introduces src/models/admin/, a dedicated identity and permissions module on
its own nachklang_admin database, and the shared authenticator that feedback
and tickets will move onto in the cutover step. Nothing swaps over yet:
feedback.auth.ts and tickets.auth.ts still authenticate against the legacy
calendar sessions, so production behaviour is unchanged.

- better-auth 1.7 mounted at /admin/auth/*, sessions as httpOnly cookies
  scoped to .nachklang.art so one sign-in covers every *.nachklang.art app.
- Accounts are invite-only: public sign-up is disabled, and the invitations
  plugin is the only code that creates users. Tokens are stored as SHA-256
  hashes and travel in the request body, never in a URL.
- Per-app permissions in user_app_permissions; requireAppAccess(app) queries
  the database on every request (no cookie cache) so disabling a user or
  revoking a session takes effect immediately.
- ADMIN_BOOTSTRAP_EMAIL guarantees a way in on an empty database, idempotently
  and without crashing the API if the database is unreachable at boot.
- Guards prevent an admin from removing their own admin permission, disabling
  themselves, or stripping the last active admin.

The admin pool uses the callback-style mysql2, not mysql2/promise: Kysely's
MysqlDialect drives the pool with callbacks, and the promise wrapper ignores
them, so every query hangs silently. Only the integration tests caught this.

Schema in sql/admin/001_init.sql, derived from getAuthTables() on the
installed better-auth rather than the published CLI, which lags the library
and omits account.issuer.

app.ts is split into src/app.factory.ts so the integration tests drive the
real middleware order rather than a copy of it.

Tests: 131 unit, plus 41 integration tests against a throwaway MariaDB
started by test/integration/setup.ts (docker or podman).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 18:03:08 +02:00

29 lines
909 B
TypeScript

import {defineConfig} from 'vitest/config';
export default defineConfig({
test: {
include: ['test/**/*.test.ts'],
// The integration suite needs a Docker MariaDB and runs separately via
// npm run test:integration (vitest.integration.config.ts).
exclude: ['test/integration/**'],
environment: 'node',
// feedback.ratelimit throws at import time without a salt (see
// test/feedback/ratelimit.salt-guard.test.ts). Set one here so the suite
// passes on a clean checkout without a local .env; the salt-guard test
// deletes it explicitly before exercising the missing-salt path.
env: {
FEEDBACK_IP_SALT: 'vitest-salt'
},
reporters: [
'default',
['vitest-sonar-reporter', {outputFile: 'testResults/sonar-report.xml'}]
],
coverage: {
provider: 'v8',
reporter: ['text-summary', 'lcov'],
reportsDirectory: 'coverage',
include: ['app.ts', 'src/**/*.ts']
}
}
});