feat(auth): replace Google login with credentials
This commit is contained in:
+38
-5
@@ -13,7 +13,12 @@ import {
|
||||
verifications,
|
||||
} from "@/db/schema";
|
||||
|
||||
import { isAuthorizedAdmin, type SessionUserLike } from "./authorization";
|
||||
import {
|
||||
isAllowedAdminRegistration,
|
||||
isAuthorizedAdmin,
|
||||
isConfiguredAdminEmail,
|
||||
type SessionUserLike,
|
||||
} from "./authorization";
|
||||
|
||||
function required(name: string): string {
|
||||
const value = process.env[name];
|
||||
@@ -22,6 +27,8 @@ function required(name: string): string {
|
||||
}
|
||||
|
||||
function createAuth() {
|
||||
const adminEmail = required("ADMIN_EMAIL");
|
||||
|
||||
return betterAuth({
|
||||
appName: "Buzz Sheet",
|
||||
database: drizzleAdapter(getDb(), {
|
||||
@@ -36,10 +43,36 @@ function createAuth() {
|
||||
}),
|
||||
baseURL: required("BETTER_AUTH_URL"),
|
||||
secret: required("BETTER_AUTH_SECRET"),
|
||||
socialProviders: {
|
||||
google: {
|
||||
clientId: required("GOOGLE_CLIENT_ID"),
|
||||
clientSecret: required("GOOGLE_CLIENT_SECRET"),
|
||||
emailAndPassword: {
|
||||
enabled: true,
|
||||
minPasswordLength: 8,
|
||||
maxPasswordLength: 128,
|
||||
},
|
||||
user: {
|
||||
validateUserInfo: async ({ user, source }) => {
|
||||
if (
|
||||
!isAllowedAdminRegistration(
|
||||
user.email,
|
||||
source.method,
|
||||
adminEmail,
|
||||
)
|
||||
) {
|
||||
return {
|
||||
error: "ADMIN_REGISTRATION_FORBIDDEN",
|
||||
errorDescription:
|
||||
"Registration is limited to the configured administrator.",
|
||||
};
|
||||
}
|
||||
},
|
||||
},
|
||||
databaseHooks: {
|
||||
user: {
|
||||
create: {
|
||||
before: async (user) => {
|
||||
if (!isConfiguredAdminEmail(user.email, adminEmail)) return false;
|
||||
return { data: { emailVerified: true } };
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
plugins: [nextCookies()],
|
||||
|
||||
Reference in New Issue
Block a user