feat(auth): replace Google login with credentials
CI / Verify (push) Successful in 1m6s
CI / Build immutable images and deploy (push) Has been skipped

This commit is contained in:
2026-08-29 07:54:15 +00:00 Unverified
parent c5a3fed1f0
commit 659a57fb4a
12 changed files with 413 additions and 57 deletions
+4 -4
View File
@@ -96,7 +96,7 @@ The admin uses a visual Notion-style block editor with forms, cards, drag-and-dr
- Cache validated public page snapshots by their page and data-source version vector. Use an external Redis-backed Next.js remote cache and tag handler so both application replicas share cache state and invalidations. Keep admin routes dynamic.
- Write cache invalidation and SSE work to a transactional outbox with the content mutation. A retrying worker invalidates affected page, directory, and data-source tags only after the database commit, then publishes typed Redis events.
- Provide Redis-backed, invalidation-only SSE streams for public pages, the character directory, and authenticated admin sessions. Events carry only opaque IDs and versions; clients refetch authoritative state on connection, reconnection, or notification. Send 90-second heartbeats, close streams after 30 minutes so clients reconnect, and disable Traefik response buffering. SSE is never a source of correctness and never carries page content.
- Authenticate through Google using Better Auth. Permit admin access only when the verified Google email equals `ADMIN_EMAIL`; repeat authorization checks in every mutation, media, and administrative endpoint.
- Authenticate with Better Auth email and password. Permit registration and admin access only when the credential account email exactly equals `ADMIN_EMAIL`; use a temporary `/register` bootstrap page and repeat authorization checks in every mutation, media, and administrative endpoint.
- Upload PNG, JPEG, WebP, and GIF assets up to 20 MB through short-lived presigned requests. Serve them through same-origin `/media/[id]` responses. Allow public access only while an asset is referenced by a currently visible snapshot; otherwise require admin authentication. Retain objects while referenced by either current content or retained revisions.
- Applying a template clones independent pages, blocks, and data sources. Later template edits affect only future applications.
- Do not provide custom HTML, JavaScript, TypeScript, React, CSS, code blocks that execute, external scripts, arbitrary npm packages, or network-capable extensions.
@@ -135,8 +135,8 @@ flowchart LR
- Implement internally in four gates:
1. Database model, immutable data-source versions, revisions, transactional outbox, formula engine, and workbook-derived fixtures.
2. Public renderer, templates, and responsive shadcn admin editor.
3. Google authentication, reference-aware S3 media handling, Redis-backed caching and SSE, and conflict recovery.
4. Production builds, browser tests, Docker, migrations, Kubernetes, and CI.
3. Better Auth email/password authentication, reference-aware S3 media handling, Redis-backed caching and SSE, and conflict recovery.
4. Production builds, HTTP and integration tests, Docker, migrations, Kubernetes, and CI.
- Release to production once all four gates pass.
- During the public/editor gate, initialize shadcn with the `base-nova` preset before adding components. Add only the official components required by the implemented surface, and review generated component source and Base UI composition after each addition.
- Implement and commit each completed feature separately. Do not accumulate the project into one large commit.
@@ -167,7 +167,7 @@ flowchart LR
- Verify those 379 formulas with deterministic decimal results, then separately test precedence, subtraction, multiplication, percentages, unary signs, blank and missing references, cycles, dependency-propagated failures, rounding, and division by zero.
- Test block validation, schema migration, unknown-block fallback, templates, custom slugs, redirects, public notes, visibility, ordering, and revision restore.
- Test autosave debounce, serialization, transient retries, concurrent conflicts, checkpoint coalescing, named revisions, 30-day expiry, global data-source dependency updates, historical version pinning, “use latest,” and media retention.
- Test Google admin restrictions and authorization on every write/media endpoint.
- Test email/password registration restrictions and authorization on every write/media endpoint.
- Test upload limits, file validation, failed upload recovery, and same-origin media delivery.
- Test cached public snapshots and immediate dependency-aware invalidation following accepted autosaves.
- Test SSE authorization, public-event privacy, heartbeat, reconnection and authoritative refetch, duplicate or missed notifications, and directory/page/admin topics.