forked from EduCraft/curriculum-project-hub
12628c9233
- scaffold hub/database-admin as SvelteKit 2 + Svelte 5 static SPA
with aurora/glass visual style (paths.base='/database')
- add lib/{api,session,org}.ts + Aurora.svelte component
- add routes: root redirect, /admin login page, /dashboard (OWNER/ADMIN only)
- backend: replace server-rendered HTML routes with /database/config JSON endpoint
- add hub/src/database/static.ts to serve SPA under /database/*
- wire registerDatabaseSpa into plugin.ts
- exempt /database/* from silo rate-limit (same treatment as /admin/*)
- add database:dev + database:build npm scripts; update deploy scripts
- update hub/src/database/README.md
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
51 lines
1.9 KiB
TypeScript
51 lines
1.9 KiB
TypeScript
/**
|
|
* Registers the `/database/*` HTTP surface onto the Fastify app.
|
|
*
|
|
* Single public entry point (mirrors src/admin/plugin.ts). hub.ts calls
|
|
* registerDatabasePlugin() so the routes are recognized at startup.
|
|
*
|
|
* Register AFTER registerAdminPlugin: it relies on the @fastify/cookie parser
|
|
* and the /auth/feishu/* login routes that the admin plugin adds.
|
|
*
|
|
* The dev login bypass is self-contained in THIS module: the flag is read here
|
|
* (not threaded from hub.ts) and only ever enables the `/database/dev-login`
|
|
* route below. Double-gated: NODE_ENV must not be production AND
|
|
* HUB_DEV_LOGIN_BYPASS must be truthy. Production always requires real Feishu
|
|
* OAuth.
|
|
*/
|
|
import type { FastifyInstance } from "fastify";
|
|
import type { PrismaClient } from "@prisma/client";
|
|
import { registerDatabaseRoutes } from "./routes/databaseRoutes.js";
|
|
import { registerDatabaseSpa } from "./static.js";
|
|
|
|
export interface DatabasePluginConfig {
|
|
readonly prisma: PrismaClient;
|
|
readonly sessionSecret: string;
|
|
readonly siloOrganizationSlug: string;
|
|
}
|
|
|
|
const FALSY = new Set(["", "0", "false", "no", "off"]);
|
|
|
|
export async function registerDatabasePlugin(
|
|
app: FastifyInstance,
|
|
config: DatabasePluginConfig,
|
|
): Promise<void> {
|
|
const allowDevLoginBypass =
|
|
process.env["NODE_ENV"] !== "production" &&
|
|
!FALSY.has((process.env["HUB_DEV_LOGIN_BYPASS"] ?? "").trim().toLowerCase());
|
|
if (allowDevLoginBypass) {
|
|
app.log.warn("DEV login bypass enabled: /database/dev-login mints a session without Feishu OAuth");
|
|
}
|
|
|
|
await registerDatabaseRoutes(app, {
|
|
prisma: config.prisma,
|
|
sessionSecret: config.sessionSecret,
|
|
siloOrganizationSlug: config.siloOrganizationSlug,
|
|
allowDevLoginBypass,
|
|
});
|
|
|
|
// SPA shell + fallback, registered after the concrete /database/* routes above
|
|
// so the /database/* wildcard does not shadow them.
|
|
await registerDatabaseSpa(app);
|
|
}
|