feat : 6 astra improve it
CI / Verify and audit (push) Successful in 2m33s
CI / Build, scan and deploy immutable images (push) Failing after 1m29s

This commit is contained in:
2026-09-22 18:28:18 +07:00 Unverified
parent 88afa8e947
commit 87e6bcd96f
56 changed files with 1351 additions and 511 deletions
+18 -24
View File
@@ -5,6 +5,7 @@ import { drizzleAdapter } from "better-auth/adapters/drizzle";
import { nextCookies } from "better-auth/next-js";
import { admin, captcha } from "better-auth/plugins";
import { headers } from "next/headers";
import { cache } from "react";
import { getDb } from "@/db";
import {
@@ -15,6 +16,8 @@ import {
} from "@/db/schema";
import { isAuthorizedAdmin, type SessionUserLike } from "./authorization";
import { HttpError } from "@/lib/security/http";
import { consumeRateLimit } from "@/lib/security/rate-limit";
function required(name: string): string {
const value = process.env[name];
@@ -50,16 +53,20 @@ function createAuth() {
emailAndPassword: {
enabled: true,
disableSignUp: true,
minPasswordLength: 8,
minPasswordLength: 12,
maxPasswordLength: 128,
},
databaseHooks: {
user: {
create: {
before: async () => ({ data: { emailVerified: true } }),
},
advanced: {
ipAddress: {
ipAddressHeaders: process.env.TRUSTED_CLIENT_IP_HEADER
? [process.env.TRUSTED_CLIENT_IP_HEADER] : [],
},
},
rateLimit: {
enabled: true,
customStorage: { consume: (key, rule) => consumeRateLimit(`auth:${key}`, rule) },
customRules: { "/sign-in/email": { window: 60, max: 10 } },
},
plugins: [
...(process.env.NODE_ENV === "development" ? [] : [
captcha({
@@ -68,7 +75,7 @@ function createAuth() {
endpoints: ["/sign-in/email"],
}),
]),
admin({ defaultRole: "admin" }),
admin({ defaultRole: "user" }),
nextCookies(),
],
});
@@ -87,20 +94,7 @@ export interface AdminSession {
session: { id: string };
}
export async function getAdminSession(): Promise<AdminSession | null> {
if (process.env.BUZZ_DEMO_MODE === "true") {
return {
user: {
id: "demo-admin",
email: "[email protected]",
emailVerified: true,
role: "admin",
name: "Demo Admin",
},
session: { id: "demo-session" },
};
}
export const getAdminSession = cache(async (): Promise<AdminSession | null> => {
// Public pages can be prerendered without the runtime auth secret. In that
// case the header simply omits the admin link; auth routes still fail loudly
// through getAuth() when authentication is actually used.
@@ -117,11 +111,11 @@ export async function getAdminSession(): Promise<AdminSession | null> {
user: session.user,
session: { id: session.session.id },
};
}
});
export class AdminAuthorizationError extends Error {
export class AdminAuthorizationError extends HttpError {
constructor() {
super("Admin authorization required.");
super(401, "unauthorized");
this.name = "AdminAuthorizationError";
}
}