7aac07a013
Introduces src/models/admin/, a dedicated identity and permissions module on its own nachklang_admin database, and the shared authenticator that feedback and tickets will move onto in the cutover step. Nothing swaps over yet: feedback.auth.ts and tickets.auth.ts still authenticate against the legacy calendar sessions, so production behaviour is unchanged. - better-auth 1.7 mounted at /admin/auth/*, sessions as httpOnly cookies scoped to .nachklang.art so one sign-in covers every *.nachklang.art app. - Accounts are invite-only: public sign-up is disabled, and the invitations plugin is the only code that creates users. Tokens are stored as SHA-256 hashes and travel in the request body, never in a URL. - Per-app permissions in user_app_permissions; requireAppAccess(app) queries the database on every request (no cookie cache) so disabling a user or revoking a session takes effect immediately. - ADMIN_BOOTSTRAP_EMAIL guarantees a way in on an empty database, idempotently and without crashing the API if the database is unreachable at boot. - Guards prevent an admin from removing their own admin permission, disabling themselves, or stripping the last active admin. The admin pool uses the callback-style mysql2, not mysql2/promise: Kysely's MysqlDialect drives the pool with callbacks, and the promise wrapper ignores them, so every query hangs silently. Only the integration tests caught this. Schema in sql/admin/001_init.sql, derived from getAuthTables() on the installed better-auth rather than the published CLI, which lags the library and omits account.issuer. app.ts is split into src/app.factory.ts so the integration tests drive the real middleware order rather than a copy of it. Tests: 131 unit, plus 41 integration tests against a throwaway MariaDB started by test/integration/setup.ts (docker or podman). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
32 lines
1.2 KiB
YAML
32 lines
1.2 KiB
YAML
# Manual alternative for bringing up the admin tests' database by hand.
|
|
#
|
|
# `npm run test:integration` does NOT use this file: test/integration/setup.ts
|
|
# starts the container directly, because `podman compose` needs a separate
|
|
# compose provider that neither podman nor docker ships, and one container needs
|
|
# no orchestration. Keep the two in step, or delete this file if nobody uses it.
|
|
#
|
|
# Port 3307 and a throwaway data directory on purpose: it must never collide
|
|
# with, or outlive, the dev database from docker-compose.dev.yml.
|
|
services:
|
|
mariadb-test:
|
|
image: mariadb:11
|
|
environment:
|
|
MARIADB_ROOT_PASSWORD: roottestpassword
|
|
MARIADB_DATABASE: nachklang_admin
|
|
MARIADB_USER: nachklang
|
|
MARIADB_PASSWORD: testpassword
|
|
ports:
|
|
- "3307:3306"
|
|
tmpfs:
|
|
- /var/lib/mysql
|
|
volumes:
|
|
# Applied by the entrypoint on first boot, against MARIADB_DATABASE.
|
|
# This is the very migration production runs, so a mistake in it fails
|
|
# the test run rather than the deploy.
|
|
- ./sql/admin/001_init.sql:/docker-entrypoint-initdb.d/001_init.sql:ro
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 2s
|
|
timeout: 5s
|
|
retries: 30
|