mirror of
https://github.com/yusufipk/OpenFrame.git
synced 2026-09-11 17:46:06 +00:00
feat(auth): implement OAuth login with Google and GitHub, add Prisma adapter for user management
This commit is contained in:
@@ -0,0 +1,257 @@
|
|||||||
|
'use client';
|
||||||
|
|
||||||
|
import { useState, useEffect, Suspense } from 'react';
|
||||||
|
import Link from 'next/link';
|
||||||
|
import { useRouter, useSearchParams } from 'next/navigation';
|
||||||
|
import { Loader2 } from 'lucide-react';
|
||||||
|
import { Button } from '@/components/ui/button';
|
||||||
|
import { Card, CardContent, CardDescription, CardHeader, CardTitle } from '@/components/ui/card';
|
||||||
|
import { Input } from '@/components/ui/input';
|
||||||
|
import { Label } from '@/components/ui/label';
|
||||||
|
import { signIn } from 'next-auth/react';
|
||||||
|
|
||||||
|
function getSafeCallbackUrl(value: string | null): string {
|
||||||
|
if (!value) return '/dashboard';
|
||||||
|
try {
|
||||||
|
const baseOrigin = typeof window === 'undefined' ? 'http://localhost' : window.location.origin;
|
||||||
|
const parsed = new URL(value, baseOrigin);
|
||||||
|
if (parsed.origin !== baseOrigin) return '/dashboard';
|
||||||
|
return `${parsed.pathname}${parsed.search}${parsed.hash}`;
|
||||||
|
} catch {
|
||||||
|
return '/dashboard';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const ERROR_MESSAGES: Record<string, string> = {
|
||||||
|
RegistrationClosed: 'Sign-up is currently invite-only. Contact an administrator.',
|
||||||
|
// Generic message — avoid confirming whether a credentials account exists for this email
|
||||||
|
OAuthAccountNotLinked: 'Sign-in failed. Please try a different method or contact support.',
|
||||||
|
OAuthCallbackError: 'OAuth sign-in failed. Please try again.',
|
||||||
|
OAuthEmailNotVerified: 'Your OAuth account email is not verified. Please verify it with your provider and try again.',
|
||||||
|
Default: 'Something went wrong. Please try again.',
|
||||||
|
};
|
||||||
|
|
||||||
|
interface LoginFormInnerProps {
|
||||||
|
googleEnabled: boolean;
|
||||||
|
githubEnabled: boolean;
|
||||||
|
}
|
||||||
|
|
||||||
|
function LoginFormInner({ googleEnabled, githubEnabled }: LoginFormInnerProps) {
|
||||||
|
const router = useRouter();
|
||||||
|
const searchParams = useSearchParams();
|
||||||
|
const [isLoading, setIsLoading] = useState(false);
|
||||||
|
const [oauthLoading, setOauthLoading] = useState<string | null>(null);
|
||||||
|
const [error, setError] = useState('');
|
||||||
|
const [email, setEmail] = useState('');
|
||||||
|
const [password, setPassword] = useState('');
|
||||||
|
const [showSuccess, setShowSuccess] = useState(false);
|
||||||
|
const callbackUrl = getSafeCallbackUrl(searchParams.get('callbackUrl'));
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (searchParams.get('registered') === 'true') {
|
||||||
|
setShowSuccess(true);
|
||||||
|
}
|
||||||
|
const errorCode = searchParams.get('error');
|
||||||
|
if (errorCode) {
|
||||||
|
setError(ERROR_MESSAGES[errorCode] ?? ERROR_MESSAGES.Default);
|
||||||
|
}
|
||||||
|
}, [searchParams]);
|
||||||
|
|
||||||
|
const handleEmailLogin = async (e: React.FormEvent) => {
|
||||||
|
e.preventDefault();
|
||||||
|
setIsLoading(true);
|
||||||
|
setError('');
|
||||||
|
|
||||||
|
try {
|
||||||
|
const result = await signIn('credentials', {
|
||||||
|
email,
|
||||||
|
password,
|
||||||
|
redirect: false,
|
||||||
|
callbackUrl,
|
||||||
|
});
|
||||||
|
|
||||||
|
if (result?.error) {
|
||||||
|
setError('Invalid email or password');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const destination = getSafeCallbackUrl(result?.url || callbackUrl);
|
||||||
|
router.push(destination);
|
||||||
|
router.refresh();
|
||||||
|
} catch {
|
||||||
|
setError('Something went wrong. Please try again.');
|
||||||
|
} finally {
|
||||||
|
setIsLoading(false);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const handleOAuthLogin = async (provider: string) => {
|
||||||
|
setOauthLoading(provider);
|
||||||
|
setError('');
|
||||||
|
await signIn(provider, { callbackUrl });
|
||||||
|
};
|
||||||
|
|
||||||
|
const hasOAuth = googleEnabled || githubEnabled;
|
||||||
|
const anyLoading = isLoading || oauthLoading !== null;
|
||||||
|
|
||||||
|
return (
|
||||||
|
<Card>
|
||||||
|
<CardHeader className="text-center">
|
||||||
|
<CardTitle>Welcome back</CardTitle>
|
||||||
|
<CardDescription>Sign in to your account to continue</CardDescription>
|
||||||
|
</CardHeader>
|
||||||
|
<CardContent>
|
||||||
|
{showSuccess && (
|
||||||
|
<div className="p-3 rounded-md bg-green-500/10 text-green-600 text-sm mb-4">
|
||||||
|
Account created successfully! Please sign in.
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{error && (
|
||||||
|
<div className="p-3 rounded-md bg-destructive/10 text-destructive text-sm mb-4">
|
||||||
|
{error}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{/* OAuth Buttons */}
|
||||||
|
{hasOAuth && (
|
||||||
|
<div className="space-y-2 mb-4">
|
||||||
|
{googleEnabled && (
|
||||||
|
<Button
|
||||||
|
type="button"
|
||||||
|
variant="outline"
|
||||||
|
className="w-full"
|
||||||
|
disabled={anyLoading}
|
||||||
|
onClick={() => handleOAuthLogin('google')}
|
||||||
|
>
|
||||||
|
{oauthLoading === 'google' ? (
|
||||||
|
<Loader2 className="h-4 w-4 mr-2 animate-spin" />
|
||||||
|
) : (
|
||||||
|
<svg className="h-4 w-4 mr-2" viewBox="0 0 24 24" aria-hidden="true">
|
||||||
|
<path
|
||||||
|
d="M22.56 12.25c0-.78-.07-1.53-.2-2.25H12v4.26h5.92c-.26 1.37-1.04 2.53-2.21 3.31v2.77h3.57c2.08-1.92 3.28-4.74 3.28-8.09z"
|
||||||
|
fill="#4285F4"
|
||||||
|
/>
|
||||||
|
<path
|
||||||
|
d="M12 23c2.97 0 5.46-.98 7.28-2.66l-3.57-2.77c-.98.66-2.23 1.06-3.71 1.06-2.86 0-5.29-1.93-6.16-4.53H2.18v2.84C3.99 20.53 7.7 23 12 23z"
|
||||||
|
fill="#34A853"
|
||||||
|
/>
|
||||||
|
<path
|
||||||
|
d="M5.84 14.09c-.22-.66-.35-1.36-.35-2.09s.13-1.43.35-2.09V7.07H2.18C1.43 8.55 1 10.22 1 12s.43 3.45 1.18 4.93l2.85-2.22.81-.62z"
|
||||||
|
fill="#FBBC05"
|
||||||
|
/>
|
||||||
|
<path
|
||||||
|
d="M12 5.38c1.62 0 3.06.56 4.21 1.64l3.15-3.15C17.45 2.09 14.97 1 12 1 7.7 1 3.99 3.47 2.18 7.07l3.66 2.84c.87-2.6 3.3-4.53 6.16-4.53z"
|
||||||
|
fill="#EA4335"
|
||||||
|
/>
|
||||||
|
</svg>
|
||||||
|
)}
|
||||||
|
Continue with Google
|
||||||
|
</Button>
|
||||||
|
)}
|
||||||
|
{githubEnabled && (
|
||||||
|
<Button
|
||||||
|
type="button"
|
||||||
|
variant="outline"
|
||||||
|
className="w-full"
|
||||||
|
disabled={anyLoading}
|
||||||
|
onClick={() => handleOAuthLogin('github')}
|
||||||
|
>
|
||||||
|
{oauthLoading === 'github' ? (
|
||||||
|
<Loader2 className="h-4 w-4 mr-2 animate-spin" />
|
||||||
|
) : (
|
||||||
|
<svg className="h-4 w-4 mr-2" viewBox="0 0 24 24" aria-hidden="true" fill="currentColor">
|
||||||
|
<path d="M12 2C6.477 2 2 6.484 2 12.017c0 4.425 2.865 8.18 6.839 9.504.5.092.682-.217.682-.483 0-.237-.008-.868-.013-1.703-2.782.605-3.369-1.343-3.369-1.343-.454-1.158-1.11-1.466-1.11-1.466-.908-.62.069-.608.069-.608 1.003.07 1.531 1.032 1.531 1.032.892 1.53 2.341 1.088 2.91.832.092-.647.35-1.088.636-1.338-2.22-.253-4.555-1.113-4.555-4.951 0-1.093.39-1.988 1.029-2.688-.103-.253-.446-1.272.098-2.65 0 0 .84-.27 2.75 1.026A9.564 9.564 0 0112 6.844c.85.004 1.705.115 2.504.337 1.909-1.296 2.747-1.027 2.747-1.027.546 1.379.202 2.398.1 2.651.64.7 1.028 1.595 1.028 2.688 0 3.848-2.339 4.695-4.566 4.943.359.309.678.92.678 1.855 0 1.338-.012 2.419-.012 2.747 0 .268.18.58.688.482A10.019 10.019 0 0022 12.017C22 6.484 17.522 2 12 2z" />
|
||||||
|
</svg>
|
||||||
|
)}
|
||||||
|
Continue with GitHub
|
||||||
|
</Button>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{/* Divider */}
|
||||||
|
{hasOAuth && (
|
||||||
|
<div className="relative mb-4">
|
||||||
|
<div className="absolute inset-0 flex items-center">
|
||||||
|
<span className="w-full border-t" />
|
||||||
|
</div>
|
||||||
|
<div className="relative flex justify-center text-xs uppercase">
|
||||||
|
<span className="bg-card px-2 text-muted-foreground">or continue with email</span>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{/* Email Form */}
|
||||||
|
<form onSubmit={handleEmailLogin} className="space-y-4">
|
||||||
|
<div className="space-y-2">
|
||||||
|
<Label htmlFor="email">Email</Label>
|
||||||
|
<Input
|
||||||
|
id="email"
|
||||||
|
type="email"
|
||||||
|
placeholder="[email protected]"
|
||||||
|
value={email}
|
||||||
|
onChange={(e) => {
|
||||||
|
setEmail(e.target.value);
|
||||||
|
setError('');
|
||||||
|
}}
|
||||||
|
required
|
||||||
|
disabled={anyLoading}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<div className="space-y-2">
|
||||||
|
<Label htmlFor="password">Password</Label>
|
||||||
|
<Input
|
||||||
|
id="password"
|
||||||
|
type="password"
|
||||||
|
placeholder="••••••••"
|
||||||
|
value={password}
|
||||||
|
onChange={(e) => {
|
||||||
|
setPassword(e.target.value);
|
||||||
|
setError('');
|
||||||
|
}}
|
||||||
|
required
|
||||||
|
disabled={anyLoading}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<Button type="submit" className="w-full" disabled={anyLoading}>
|
||||||
|
{isLoading && <Loader2 className="h-4 w-4 mr-2 animate-spin" />}
|
||||||
|
Sign in
|
||||||
|
</Button>
|
||||||
|
</form>
|
||||||
|
|
||||||
|
<p className="text-center text-sm text-muted-foreground mt-6">
|
||||||
|
Don't have an account?{' '}
|
||||||
|
<Link href="/register" className="text-primary hover:underline">
|
||||||
|
Sign up
|
||||||
|
</Link>
|
||||||
|
</p>
|
||||||
|
</CardContent>
|
||||||
|
</Card>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function LoginFormSkeleton() {
|
||||||
|
return (
|
||||||
|
<Card>
|
||||||
|
<CardHeader className="text-center">
|
||||||
|
<CardTitle>Welcome back</CardTitle>
|
||||||
|
<CardDescription>Sign in to your account to continue</CardDescription>
|
||||||
|
</CardHeader>
|
||||||
|
<CardContent className="space-y-4">
|
||||||
|
<div className="h-10 bg-muted animate-pulse rounded-md" />
|
||||||
|
<div className="h-10 bg-muted animate-pulse rounded-md" />
|
||||||
|
<div className="h-10 bg-primary/20 animate-pulse rounded-md" />
|
||||||
|
</CardContent>
|
||||||
|
</Card>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function LoginForm({ googleEnabled, githubEnabled }: LoginFormInnerProps) {
|
||||||
|
return (
|
||||||
|
<Suspense fallback={<LoginFormSkeleton />}>
|
||||||
|
<LoginFormInner googleEnabled={googleEnabled} githubEnabled={githubEnabled} />
|
||||||
|
</Suspense>
|
||||||
|
);
|
||||||
|
}
|
||||||
+12
-156
@@ -1,161 +1,16 @@
|
|||||||
'use client';
|
|
||||||
|
|
||||||
import { useState, useEffect, Suspense } from 'react';
|
|
||||||
import Link from 'next/link';
|
import Link from 'next/link';
|
||||||
import { useRouter, useSearchParams } from 'next/navigation';
|
import { Video } from 'lucide-react';
|
||||||
import { Video, Loader2 } from 'lucide-react';
|
import { LoginForm, LoginFormSkeleton } from './login-form';
|
||||||
import { Button } from '@/components/ui/button';
|
import { Suspense } from 'react';
|
||||||
import { Card, CardContent, CardDescription, CardHeader, CardTitle } from '@/components/ui/card';
|
|
||||||
import { Input } from '@/components/ui/input';
|
|
||||||
import { Label } from '@/components/ui/label';
|
|
||||||
import { signIn } from 'next-auth/react';
|
|
||||||
|
|
||||||
function getSafeCallbackUrl(value: string | null): string {
|
|
||||||
if (!value) return '/dashboard';
|
|
||||||
try {
|
|
||||||
const baseOrigin = typeof window === 'undefined' ? 'http://localhost' : window.location.origin;
|
|
||||||
const parsed = new URL(value, baseOrigin);
|
|
||||||
if (parsed.origin !== baseOrigin) return '/dashboard';
|
|
||||||
return `${parsed.pathname}${parsed.search}${parsed.hash}`;
|
|
||||||
} catch {
|
|
||||||
return '/dashboard';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function LoginForm() {
|
|
||||||
const router = useRouter();
|
|
||||||
const searchParams = useSearchParams();
|
|
||||||
const [isLoading, setIsLoading] = useState(false);
|
|
||||||
const [error, setError] = useState('');
|
|
||||||
const [email, setEmail] = useState('');
|
|
||||||
const [password, setPassword] = useState('');
|
|
||||||
const [showSuccess, setShowSuccess] = useState(false);
|
|
||||||
const callbackUrl = getSafeCallbackUrl(searchParams.get('callbackUrl'));
|
|
||||||
|
|
||||||
useEffect(() => {
|
|
||||||
if (searchParams.get('registered') === 'true') {
|
|
||||||
setShowSuccess(true);
|
|
||||||
}
|
|
||||||
}, [searchParams]);
|
|
||||||
|
|
||||||
const handleEmailLogin = async (e: React.FormEvent) => {
|
|
||||||
e.preventDefault();
|
|
||||||
setIsLoading(true);
|
|
||||||
setError('');
|
|
||||||
|
|
||||||
try {
|
|
||||||
const result = await signIn('credentials', {
|
|
||||||
email,
|
|
||||||
password,
|
|
||||||
redirect: false,
|
|
||||||
callbackUrl,
|
|
||||||
});
|
|
||||||
|
|
||||||
if (result?.error) {
|
|
||||||
setError('Invalid email or password');
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
const destination = getSafeCallbackUrl(result?.url || callbackUrl);
|
|
||||||
router.push(destination);
|
|
||||||
router.refresh();
|
|
||||||
} catch {
|
|
||||||
setError('Something went wrong. Please try again.');
|
|
||||||
} finally {
|
|
||||||
setIsLoading(false);
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
return (
|
|
||||||
<Card>
|
|
||||||
<CardHeader className="text-center">
|
|
||||||
<CardTitle>Welcome back</CardTitle>
|
|
||||||
<CardDescription>
|
|
||||||
Sign in to your account to continue
|
|
||||||
</CardDescription>
|
|
||||||
</CardHeader>
|
|
||||||
<CardContent>
|
|
||||||
{showSuccess && (
|
|
||||||
<div className="p-3 rounded-md bg-green-500/10 text-green-600 text-sm mb-4">
|
|
||||||
Account created successfully! Please sign in.
|
|
||||||
</div>
|
|
||||||
)}
|
|
||||||
|
|
||||||
{/* Email Form */}
|
|
||||||
<form onSubmit={handleEmailLogin} className="space-y-4">
|
|
||||||
<div className="space-y-2">
|
|
||||||
<Label htmlFor="email">Email</Label>
|
|
||||||
<Input
|
|
||||||
id="email"
|
|
||||||
type="email"
|
|
||||||
placeholder="[email protected]"
|
|
||||||
value={email}
|
|
||||||
onChange={(e) => {
|
|
||||||
setEmail(e.target.value);
|
|
||||||
setError('');
|
|
||||||
}}
|
|
||||||
required
|
|
||||||
disabled={isLoading}
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<div className="space-y-2">
|
|
||||||
<Label htmlFor="password">Password</Label>
|
|
||||||
<Input
|
|
||||||
id="password"
|
|
||||||
type="password"
|
|
||||||
placeholder="••••••••"
|
|
||||||
value={password}
|
|
||||||
onChange={(e) => {
|
|
||||||
setPassword(e.target.value);
|
|
||||||
setError('');
|
|
||||||
}}
|
|
||||||
required
|
|
||||||
disabled={isLoading}
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
{error && (
|
|
||||||
<div className="p-3 rounded-md bg-destructive/10 text-destructive text-sm">
|
|
||||||
{error}
|
|
||||||
</div>
|
|
||||||
)}
|
|
||||||
|
|
||||||
<Button type="submit" className="w-full" disabled={isLoading}>
|
|
||||||
{isLoading && <Loader2 className="h-4 w-4 mr-2 animate-spin" />}
|
|
||||||
Sign in
|
|
||||||
</Button>
|
|
||||||
</form>
|
|
||||||
|
|
||||||
<p className="text-center text-sm text-muted-foreground mt-6">
|
|
||||||
Don't have an account?{' '}
|
|
||||||
<Link href="/register" className="text-primary hover:underline">
|
|
||||||
Sign up
|
|
||||||
</Link>
|
|
||||||
</p>
|
|
||||||
</CardContent>
|
|
||||||
</Card>
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function LoginFormSkeleton() {
|
|
||||||
return (
|
|
||||||
<Card>
|
|
||||||
<CardHeader className="text-center">
|
|
||||||
<CardTitle>Welcome back</CardTitle>
|
|
||||||
<CardDescription>
|
|
||||||
Sign in to your account to continue
|
|
||||||
</CardDescription>
|
|
||||||
</CardHeader>
|
|
||||||
<CardContent className="space-y-4">
|
|
||||||
<div className="h-10 bg-muted animate-pulse rounded-md" />
|
|
||||||
<div className="h-10 bg-muted animate-pulse rounded-md" />
|
|
||||||
<div className="h-10 bg-primary/20 animate-pulse rounded-md" />
|
|
||||||
</CardContent>
|
|
||||||
</Card>
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
export default function LoginPage() {
|
export default function LoginPage() {
|
||||||
|
const googleEnabled = Boolean(
|
||||||
|
process.env.GOOGLE_CLIENT_ID && process.env.GOOGLE_CLIENT_SECRET,
|
||||||
|
);
|
||||||
|
const githubEnabled = Boolean(
|
||||||
|
process.env.GITHUB_CLIENT_ID && process.env.GITHUB_CLIENT_SECRET,
|
||||||
|
);
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="min-h-screen flex items-center justify-center p-4 bg-background">
|
<div className="min-h-screen flex items-center justify-center p-4 bg-background">
|
||||||
<div className="w-full max-w-md">
|
<div className="w-full max-w-md">
|
||||||
@@ -166,7 +21,7 @@ export default function LoginPage() {
|
|||||||
</Link>
|
</Link>
|
||||||
|
|
||||||
<Suspense fallback={<LoginFormSkeleton />}>
|
<Suspense fallback={<LoginFormSkeleton />}>
|
||||||
<LoginForm />
|
<LoginForm googleEnabled={googleEnabled} githubEnabled={githubEnabled} />
|
||||||
</Suspense>
|
</Suspense>
|
||||||
|
|
||||||
<p className="text-center text-xs text-muted-foreground mt-4">
|
<p className="text-center text-xs text-muted-foreground mt-4">
|
||||||
@@ -176,3 +31,4 @@ export default function LoginPage() {
|
|||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@
|
|||||||
"": {
|
"": {
|
||||||
"name": "openframe",
|
"name": "openframe",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
"@auth/prisma-adapter": "^2.11.1",
|
||||||
"@aws-sdk/client-s3": "^3.985.0",
|
"@aws-sdk/client-s3": "^3.985.0",
|
||||||
"@prisma/adapter-pg": "^7.3.0",
|
"@prisma/adapter-pg": "^7.3.0",
|
||||||
"@prisma/client": "^7.3.0",
|
"@prisma/client": "^7.3.0",
|
||||||
@@ -57,7 +58,9 @@
|
|||||||
|
|
||||||
"@antfu/ni": ["@antfu/[email protected]", "", { "dependencies": { "ansis": "^4.0.0", "fzf": "^0.5.2", "package-manager-detector": "^1.3.0", "tinyexec": "^1.0.1" }, "bin": { "na": "bin/na.mjs", "ni": "bin/ni.mjs", "nr": "bin/nr.mjs", "nci": "bin/nci.mjs", "nlx": "bin/nlx.mjs", "nun": "bin/nun.mjs", "nup": "bin/nup.mjs" } }, "sha512-9q/yCljni37pkMr4sPrI3G4jqdIk074+iukc5aFJl7kmDCCsiJrbZ6zKxnES1Gwg+i9RcDZwvktl23puGslmvA=="],
|
"@antfu/ni": ["@antfu/[email protected]", "", { "dependencies": { "ansis": "^4.0.0", "fzf": "^0.5.2", "package-manager-detector": "^1.3.0", "tinyexec": "^1.0.1" }, "bin": { "na": "bin/na.mjs", "ni": "bin/ni.mjs", "nr": "bin/nr.mjs", "nci": "bin/nci.mjs", "nlx": "bin/nlx.mjs", "nun": "bin/nun.mjs", "nup": "bin/nup.mjs" } }, "sha512-9q/yCljni37pkMr4sPrI3G4jqdIk074+iukc5aFJl7kmDCCsiJrbZ6zKxnES1Gwg+i9RcDZwvktl23puGslmvA=="],
|
||||||
|
|
||||||
"@auth/core": ["@auth/[email protected].0", "", { "dependencies": { "@panva/hkdf": "^1.2.1", "jose": "^6.0.6", "oauth4webapi": "^3.3.0", "preact": "10.24.3", "preact-render-to-string": "6.5.11" }, "peerDependencies": { "@simplewebauthn/browser": "^9.0.1", "@simplewebauthn/server": "^9.0.2", "nodemailer": "^6.8.0" }, "optionalPeers": ["@simplewebauthn/browser", "@simplewebauthn/server", "nodemailer"] }, "sha512-Wd7mHPQ/8zy6Qj7f4T46vg3aoor8fskJm6g2Zyj064oQ3+p0xNZXAV60ww0hY+MbTesfu29kK14Zk5d5JTazXQ=="],
|
"@auth/core": ["@auth/[email protected].1", "", { "dependencies": { "@panva/hkdf": "^1.2.1", "jose": "^6.0.6", "oauth4webapi": "^3.3.0", "preact": "10.24.3", "preact-render-to-string": "6.5.11" }, "peerDependencies": { "@simplewebauthn/browser": "^9.0.1", "@simplewebauthn/server": "^9.0.2", "nodemailer": "^7.0.7" }, "optionalPeers": ["@simplewebauthn/browser", "@simplewebauthn/server", "nodemailer"] }, "sha512-t9cJ2zNYAdWMacGRMT6+r4xr1uybIdmYa49calBPeTqwgAFPV/88ac9TEvCR85pvATiSPt8VaNf+Gt24JIT/uw=="],
|
||||||
|
|
||||||
|
"@auth/prisma-adapter": ["@auth/[email protected]", "", { "dependencies": { "@auth/core": "0.41.1" }, "peerDependencies": { "@prisma/client": ">=2.26.0 || >=3 || >=4 || >=5 || >=6" } }, "sha512-Ke7DXP0Fy0Mlmjz/ZJLXwQash2UkA4621xCM0rMtEczr1kppLc/njCbUkHkIQ/PnmILjqSPEKeTjDPsYruvkug=="],
|
||||||
|
|
||||||
"@aws-crypto/crc32": ["@aws-crypto/[email protected]", "", { "dependencies": { "@aws-crypto/util": "^5.2.0", "@aws-sdk/types": "^3.222.0", "tslib": "^2.6.2" } }, "sha512-nLbCWqQNgUiwwtFsen1AdzAtvuLRsQS8rYgMuxCrdKf9kOssamGLuPwyTY9wyYblNr9+1XM8v6zoDTPPSIeANg=="],
|
"@aws-crypto/crc32": ["@aws-crypto/[email protected]", "", { "dependencies": { "@aws-crypto/util": "^5.2.0", "@aws-sdk/types": "^3.222.0", "tslib": "^2.6.2" } }, "sha512-nLbCWqQNgUiwwtFsen1AdzAtvuLRsQS8rYgMuxCrdKf9kOssamGLuPwyTY9wyYblNr9+1XM8v6zoDTPPSIeANg=="],
|
||||||
|
|
||||||
@@ -1971,6 +1974,8 @@
|
|||||||
|
|
||||||
"next/postcss": ["[email protected]", "", { "dependencies": { "nanoid": "^3.3.6", "picocolors": "^1.0.0", "source-map-js": "^1.0.2" } }, "sha512-PS08Iboia9mts/2ygV3eLpY5ghnUcfLV/EXTOW1E2qYxJKGGBUtNjN76FYHnMs36RmARn41bC0AZmn+rR0OVpQ=="],
|
"next/postcss": ["[email protected]", "", { "dependencies": { "nanoid": "^3.3.6", "picocolors": "^1.0.0", "source-map-js": "^1.0.2" } }, "sha512-PS08Iboia9mts/2ygV3eLpY5ghnUcfLV/EXTOW1E2qYxJKGGBUtNjN76FYHnMs36RmARn41bC0AZmn+rR0OVpQ=="],
|
||||||
|
|
||||||
|
"next-auth/@auth/core": ["@auth/[email protected]", "", { "dependencies": { "@panva/hkdf": "^1.2.1", "jose": "^6.0.6", "oauth4webapi": "^3.3.0", "preact": "10.24.3", "preact-render-to-string": "6.5.11" }, "peerDependencies": { "@simplewebauthn/browser": "^9.0.1", "@simplewebauthn/server": "^9.0.2", "nodemailer": "^6.8.0" }, "optionalPeers": ["@simplewebauthn/browser", "@simplewebauthn/server", "nodemailer"] }, "sha512-Wd7mHPQ/8zy6Qj7f4T46vg3aoor8fskJm6g2Zyj064oQ3+p0xNZXAV60ww0hY+MbTesfu29kK14Zk5d5JTazXQ=="],
|
||||||
|
|
||||||
"npm-run-path/path-key": ["[email protected]", "", {}, "sha512-haREypq7xkM7ErfgIyA0z+Bj4AGKlMSdlQE2jvJo6huWD1EdkKYV+G/T4nq0YEF2vgTT8kqMFKo1uHn950r4SQ=="],
|
"npm-run-path/path-key": ["[email protected]", "", {}, "sha512-haREypq7xkM7ErfgIyA0z+Bj4AGKlMSdlQE2jvJo6huWD1EdkKYV+G/T4nq0YEF2vgTT8kqMFKo1uHn950r4SQ=="],
|
||||||
|
|
||||||
"nypm/citty": ["[email protected]", "", {}, "sha512-8csy5IBFI2ex2hTVpaHN2j+LNE199AgiI7y4dMintrr8i0lQiFn+0AWMZrWdHKIgMOer65f8IThysYhoReqjWA=="],
|
"nypm/citty": ["[email protected]", "", {}, "sha512-8csy5IBFI2ex2hTVpaHN2j+LNE199AgiI7y4dMintrr8i0lQiFn+0AWMZrWdHKIgMOer65f8IThysYhoReqjWA=="],
|
||||||
|
|||||||
+45
-2
@@ -1,17 +1,22 @@
|
|||||||
import NextAuth from 'next-auth';
|
import NextAuth from 'next-auth';
|
||||||
import Credentials from 'next-auth/providers/credentials';
|
import Credentials from 'next-auth/providers/credentials';
|
||||||
|
import Google from 'next-auth/providers/google';
|
||||||
|
import GitHub from 'next-auth/providers/github';
|
||||||
|
import { PrismaAdapter } from '@auth/prisma-adapter';
|
||||||
import bcrypt from 'bcryptjs';
|
import bcrypt from 'bcryptjs';
|
||||||
import { db } from '@/lib/db';
|
import { db } from '@/lib/db';
|
||||||
import { ProjectMemberRole, WorkspaceMemberRole } from '@prisma/client';
|
import { ProjectMemberRole, WorkspaceMemberRole } from '@prisma/client';
|
||||||
import { hasBillingAccess } from '@/lib/billing';
|
import { hasBillingAccess } from '@/lib/billing';
|
||||||
|
import { isInviteCodeRequired } from '@/lib/feature-flags';
|
||||||
|
|
||||||
// Dummy hash for timing-safe comparison when user doesn't exist
|
// Dummy hash for timing-safe comparison when user doesn't exist
|
||||||
// This prevents user enumeration via timing attacks
|
// This prevents user enumeration via timing attacks
|
||||||
const DUMMY_HASH = '$2a$12$000000000000000000000uGG3k3xK2CVTxXrT7VW2sGd1XrY6Ky';
|
const DUMMY_HASH = '$2a$12$000000000000000000000uGG3k3xK2CVTxXrT7VW2sGd1XrY6Ky';
|
||||||
|
|
||||||
export const { handlers, signIn, signOut, auth } = NextAuth({
|
export const { handlers, signIn, signOut, auth } = NextAuth({
|
||||||
// Note: We don't use PrismaAdapter with Credentials + JWT strategy
|
// PrismaAdapter handles OAuth account linking and user creation in DB.
|
||||||
// The adapter is for OAuth providers that need to store accounts/sessions in DB
|
// JWT strategy is still used for sessions (no DB sessions table needed).
|
||||||
|
adapter: PrismaAdapter(db),
|
||||||
providers: [
|
providers: [
|
||||||
Credentials({
|
Credentials({
|
||||||
name: 'credentials',
|
name: 'credentials',
|
||||||
@@ -50,6 +55,18 @@ export const { handlers, signIn, signOut, auth } = NextAuth({
|
|||||||
};
|
};
|
||||||
},
|
},
|
||||||
}),
|
}),
|
||||||
|
...(process.env.GOOGLE_CLIENT_ID && process.env.GOOGLE_CLIENT_SECRET
|
||||||
|
? [Google({ clientId: process.env.GOOGLE_CLIENT_ID, clientSecret: process.env.GOOGLE_CLIENT_SECRET })]
|
||||||
|
: []),
|
||||||
|
...(process.env.GITHUB_CLIENT_ID && process.env.GITHUB_CLIENT_SECRET
|
||||||
|
? [{
|
||||||
|
...GitHub({ clientId: process.env.GITHUB_CLIENT_ID, clientSecret: process.env.GITHUB_CLIENT_SECRET }),
|
||||||
|
// GitHub sends iss=https://github.com/login/oauth in callbacks (RFC 9207).
|
||||||
|
// Auth.js v5 beta defaults to "https://authjs.dev" for OAuth providers, causing
|
||||||
|
// a mismatch. Setting the correct issuer here fixes the CallbackRouteError.
|
||||||
|
issuer: 'https://github.com/login/oauth',
|
||||||
|
}]
|
||||||
|
: []),
|
||||||
],
|
],
|
||||||
session: {
|
session: {
|
||||||
strategy: 'jwt',
|
strategy: 'jwt',
|
||||||
@@ -60,6 +77,32 @@ export const { handlers, signIn, signOut, auth } = NextAuth({
|
|||||||
signOut: '/signout',
|
signOut: '/signout',
|
||||||
},
|
},
|
||||||
callbacks: {
|
callbacks: {
|
||||||
|
async signIn({ account, profile }) {
|
||||||
|
// Credentials sign-in is handled by the authorize() function above
|
||||||
|
if (account?.provider === 'credentials') return true;
|
||||||
|
|
||||||
|
// Reject OAuth sign-ins where the provider email is not verified.
|
||||||
|
// Google always sets email_verified: true. GitHub does not guarantee it.
|
||||||
|
if (profile && profile.email_verified === false) {
|
||||||
|
return '/login?error=OAuthEmailNotVerified';
|
||||||
|
}
|
||||||
|
|
||||||
|
// OAuth sign-in: allow existing OAuth accounts regardless of invite setting
|
||||||
|
if (account?.providerAccountId && account?.provider) {
|
||||||
|
const existingAccount = await db.account.findUnique({
|
||||||
|
where: { provider_providerAccountId: { provider: account.provider, providerAccountId: account.providerAccountId } },
|
||||||
|
select: { id: true },
|
||||||
|
});
|
||||||
|
if (existingAccount) return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// New OAuth user: block when invite-only mode is active
|
||||||
|
if (isInviteCodeRequired()) {
|
||||||
|
return '/login?error=RegistrationClosed';
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
},
|
||||||
async session({ session, token }) {
|
async session({ session, token }) {
|
||||||
if (token.sub && session.user) {
|
if (token.sub && session.user) {
|
||||||
session.user.id = token.sub;
|
session.user.id = token.sub;
|
||||||
|
|||||||
@@ -24,6 +24,7 @@
|
|||||||
"bunny:cleanup-orphans": "bun run scripts/bunny-orphan-cleanup.ts"
|
"bunny:cleanup-orphans": "bun run scripts/bunny-orphan-cleanup.ts"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
"@auth/prisma-adapter": "^2.11.1",
|
||||||
"@aws-sdk/client-s3": "^3.985.0",
|
"@aws-sdk/client-s3": "^3.985.0",
|
||||||
"@prisma/adapter-pg": "^7.3.0",
|
"@prisma/adapter-pg": "^7.3.0",
|
||||||
"@prisma/client": "^7.3.0",
|
"@prisma/client": "^7.3.0",
|
||||||
|
|||||||
Reference in New Issue
Block a user