feat : use guide login only [no ci]

This commit is contained in:
2026-10-06 18:41:28 +07:00 Unverified
parent 1339dd43e6
commit 3c8f60433a
28 changed files with 50 additions and 783 deletions
+11 -11
View File
@@ -1,13 +1,11 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
const session = vi.fn();
const handler = vi.fn(async () => Response.json({ passed: true }));
vi.mock("server-only", () => ({}));
vi.mock("better-auth/next-js", () => ({ toNextJsHandler: () => ({ GET: handler }) }));
vi.mock("@/lib/auth/server", () => ({
getAuth: () => ({ api: { getSession: session }, handler }),
isSudlohOidcEnabled: () => true,
getAuth: () => ({ handler }),
}));
const { GET, POST } = await import("./route");
@@ -15,11 +13,9 @@ const { GET, POST } = await import("./route");
beforeEach(() => {
vi.clearAllMocks();
process.env.BETTER_AUTH_URL = "https://guide.sudloh.com";
process.env.SUDLOH_OIDC_ONLY = "true";
session.mockResolvedValue({ user: { id: "user-1" }, session: { id: "session-1" } });
});
describe("Better Auth Sudloh boundary", () => {
describe("Better Auth route", () => {
it("lets Better Auth serve the local browser session", async () => {
const response = await GET(new Request("https://guide.sudloh.com/api/auth/get-session"));
expect(response.status).toBe(200);
@@ -27,11 +23,6 @@ describe("Better Auth Sudloh boundary", () => {
expect(handler).toHaveBeenCalledOnce();
});
it("permits the OIDC callback", async () => {
const callback = await GET(new Request("https://guide.sudloh.com/api/auth/callback/sudloh?code=code"));
expect(callback.status).toBe(200);
});
it("passes mutations to Better Auth for local session checks", async () => {
const response = await POST(new Request("https://guide.sudloh.com/api/auth/admin/create-user", {
method: "POST", headers: { Origin: "https://guide.sudloh.com", "Content-Type": "application/json" },
@@ -40,4 +31,13 @@ describe("Better Auth Sudloh boundary", () => {
expect(response.status).toBe(200);
expect(handler).toHaveBeenCalledOnce();
});
it("passes local profile changes to Better Auth", async () => {
const response = await POST(new Request("https://guide.sudloh.com/api/auth/change-email", {
method: "POST", headers: { Origin: "https://guide.sudloh.com", "Content-Type": "application/json" },
body: JSON.stringify({ newEmail: "[email protected]" }),
}));
expect(response.status).toBe(200);
expect(handler).toHaveBeenCalledOnce();
});
});
+1 -16
View File
@@ -1,9 +1,5 @@
import { toNextJsHandler } from "better-auth/next-js";
import { and, eq } from "drizzle-orm";
import { getAuth, isSudlohOidcEnabled } from "@/lib/auth/server";
import { getDb } from "@/db";
import { accounts } from "@/db/schema";
import { getAuth } from "@/lib/auth/server";
import { errorResponse, HttpError, readJson, requireSameOrigin } from "@/lib/security/http";
const handlers = toNextJsHandler((request) => getAuth().handler(request));
@@ -17,17 +13,6 @@ async function mutate(request: Request) {
requireSameOrigin(request);
const input = await readJson(request.clone());
const path = new URL(request.url).pathname;
if (["/update-user", "/change-email"].some((endpoint) => path.endsWith(endpoint))) {
if (isSudlohOidcEnabled() && process.env.SUDLOH_OIDC_ONLY === "true")
throw new HttpError(403, "manage-profile-at-sudloh");
const session = await getAuth().api.getSession({ headers: request.headers });
if (session) {
const [linked] = await getDb().select({ id: accounts.id }).from(accounts).where(and(
eq(accounts.userId, session.user.id), eq(accounts.providerId, "sudloh"),
)).limit(1);
if (linked) throw new HttpError(403, "manage-profile-at-sudloh");
}
}
if (["/admin/create-user", "/admin/set-user-password"].some((endpoint) => path.endsWith(endpoint))) {
const password = input && typeof input === "object" && "password" in input ? input.password : undefined;
const newPassword = input && typeof input === "object" && "newPassword" in input ? input.newPassword : undefined;