* Add signup/login (profile creation + JWT auth) API: - POST /auth/signup — creates a house + user_profile (transactional), hashes the password with argon2, sets a JWT in an httpOnly cookie - POST /auth/login — verifies credentials (generic 401 for both wrong email and wrong password, doesn't leak which), sets the cookie - POST /auth/logout — clears the cookie - GET /auth/me — current profile, behind requireAuth middleware - requireAuth verifies the JWT and re-checks tokenVersion against the DB, so a stateless JWT can still be invalidated (password change / logout-everywhere, not built yet but the field is in place) Schema: user_profiles gets password_hash + token_version (not in the original spec doc — required for auth). New migration, with COMMENT ON for the new columns per the established pattern. Decisions from the auth planning discussion: JWT in httpOnly cookie (not server-side sessions), first profile created also creates its house, argon2 for hashing. argon2 pinned to 0.31.2 (not ^, deliberately): 0.45.1 segfaults at runtime on this Windows machine — reproduced consistently across bash (sandboxed and unsandboxed) and PowerShell, while 0.31.2 works fine with the same API. Documented in the README as a trap for future upgrades, since `tsc`/`prisma generate` succeeding doesn't catch a runtime native-binding crash. Tests: Mocha (unit-style, apps/api/test/auth.test.ts) and a Cucumber feature (apps/api/features/auth.feature) covering the full signup → authenticated flow, duplicate email, wrong password. Both share test-support/reset-db.ts (TRUNCATE ... CASCADE) to start each test/scenario from a clean slate. Test-only argon2 cost parameters (NODE_ENV=test) keep the suite fast — argon2's real cost is deliberately expensive, which made hashing dozens of times per run slow and occasionally timeout-flaky at default cost. CI: added a Postgres service container to lint-and-test (previously none — tests didn't touch a real DB), runs `prisma migrate deploy` before the test steps. Verified end-to-end manually against the dev server (curl): signup, duplicate email (409), wrong password (401), valid login (200), validation errors (400), /me with and without cookie, logout (204) — all behave as intended. Full suite (lint, mocha, cucumber, build) run multiple times locally with no flakiness after the timeout/cost fixes. * Fix CI: generate Prisma Client via postinstall CI failed with "@prisma/client did not initialize yet" — pnpm install never ran `prisma generate`, and `prisma migrate deploy` (unlike `migrate dev`) doesn't do it either. Worked locally only because prior `prisma migrate dev` runs had already generated the client as a side effect. Adding a postinstall script fixes it for CI and for anyone cloning the repo fresh and running plain `pnpm install`.
42 lines
1.1 KiB
JSON
42 lines
1.1 KiB
JSON
{
|
|
"name": "api",
|
|
"version": "0.0.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"dev": "tsx watch src/server.ts",
|
|
"build": "tsc -p tsconfig.json",
|
|
"start": "node dist/server.js",
|
|
"test": "cross-env NODE_ENV=test mocha",
|
|
"test:bdd": "cross-env NODE_ENV=test NODE_OPTIONS=--import=tsx cucumber-js",
|
|
"prisma:generate": "prisma generate",
|
|
"prisma:migrate": "prisma migrate dev",
|
|
"postinstall": "prisma generate"
|
|
},
|
|
"dependencies": {
|
|
"@prisma/client": "^5.22.0",
|
|
"argon2": "0.31.2",
|
|
"cookie-parser": "^1.4.7",
|
|
"cors": "^2.8.6",
|
|
"dotenv": "^16.4.5",
|
|
"express": "^4.21.1",
|
|
"jsonwebtoken": "^9.0.3",
|
|
"zod": "^3.23.8"
|
|
},
|
|
"devDependencies": {
|
|
"@cucumber/cucumber": "^13.2.1",
|
|
"@types/cookie-parser": "^1.4.10",
|
|
"@types/cors": "^2.8.19",
|
|
"@types/express": "^4.17.21",
|
|
"@types/jsonwebtoken": "^9.0.10",
|
|
"@types/node": "^22.9.0",
|
|
"@types/supertest": "^6.0.2",
|
|
"chai": "^5.1.2",
|
|
"cross-env": "^10.1.0",
|
|
"mocha": "^10.8.2",
|
|
"prisma": "^5.22.0",
|
|
"supertest": "^7.0.0",
|
|
"tsx": "^4.19.2",
|
|
"typescript": "^5.7.2"
|
|
}
|
|
}
|