chore(identity): wire staging identity operations

This commit is contained in:
Jesse_Chen
2026-07-21 17:52:25 +08:00
parent aae8cb5c21
commit 20f5a6c1d1
14 changed files with 311 additions and 22 deletions
+4 -3
View File
@@ -3,7 +3,8 @@ import { Pool } from "pg";
import { buildAuthOptions, type AdminUserAuthorizer } from "./auth-factory.ts";
import {
readIdentityConfig,
isSelfHostedIdentityEnabled,
readSelfHostedIdentityConfig,
type SelfHostedIdentityConfig,
} from "./config.ts";
import type { EmailOtpSender } from "./contracts.ts";
@@ -110,10 +111,10 @@ const identityGlobal = globalThis as typeof globalThis & {
export function getIdentityAuthServices(
env: NodeJS.ProcessEnv = process.env,
): IdentityAuthServices {
const config = readIdentityConfig(env);
if (config.provider !== "self-hosted") {
if (!isSelfHostedIdentityEnabled(env)) {
throw new Error("self-hosted identity is not enabled");
}
const config = readSelfHostedIdentityConfig(env);
identityGlobal.jyotishaIdentityAuth ??= createIdentityAuthServices(config);
return identityGlobal.jyotishaIdentityAuth;
+29 -9
View File
@@ -19,6 +19,16 @@ export type IdentityConfig =
| SupabaseIdentityConfig
| SelfHostedIdentityConfig;
export function isSelfHostedIdentityEnabled(
env: IdentityEnvironment,
): boolean {
const value = env.SELF_HOSTED_IDENTITY_ENABLED?.trim() || "false";
if (value !== "true" && value !== "false") {
throw new Error("SELF_HOSTED_IDENTITY_ENABLED must be true or false");
}
return value === "true";
}
function required(env: IdentityEnvironment, key: string): string {
const value = env[key]?.trim();
if (!value) throw new Error(`${key} is required`);
@@ -81,15 +91,9 @@ function readSender(env: IdentityEnvironment): string {
return value;
}
export function readIdentityConfig(
export function readSelfHostedIdentityConfig(
env: IdentityEnvironment,
): IdentityConfig {
const provider = env.AUTH_PROVIDER?.trim() || "supabase";
if (provider === "supabase") return { provider };
if (provider !== "self-hosted") {
throw new Error("AUTH_PROVIDER must be supabase or self-hosted");
}
): SelfHostedIdentityConfig {
const userOrigin = readOrigin(env, "AUTH_USER_ORIGIN");
const adminOrigin = readOrigin(env, "AUTH_ADMIN_ORIGIN");
if (userOrigin === adminOrigin) {
@@ -103,7 +107,7 @@ export function readIdentityConfig(
}
return {
provider,
provider: "self-hosted",
databaseUrl: readPostgresUrl(env),
userOrigin,
adminOrigin,
@@ -113,3 +117,19 @@ export function readIdentityConfig(
resendFrom: readSender(env),
};
}
export function readIdentityConfig(
env: IdentityEnvironment,
): IdentityConfig {
const provider = env.AUTH_PROVIDER?.trim() || "supabase";
if (provider === "supabase") return { provider };
if (provider !== "self-hosted") {
throw new Error("AUTH_PROVIDER must be supabase or self-hosted");
}
if (!isSelfHostedIdentityEnabled(env)) {
throw new Error(
"SELF_HOSTED_IDENTITY_ENABLED must be true when AUTH_PROVIDER is self-hosted",
);
}
return readSelfHostedIdentityConfig(env);
}