mirror of
https://github.com/djdevin/recflare.git
synced 2026-09-08 22:51:30 -07:00
1.4 KiB
1.4 KiB
auth
Auth Worker served on the auth subdomain. A Hono app handling authentication.
Binding-dependent behavior (database queries) is stubbed for now — no real
KV/D1/DO bindings yet.
Routes
| Method | Path | Description |
|---|---|---|
| GET | /eac/challenge |
EAC challenge, served as text |
| GET | /cachedlogin/forplatformid/:platform/:id |
Cached logins (stubbed → []) |
| POST | /connect/token |
OAuth token endpoint, issues a JWT |
| GET | /role/developer/:id |
Developer role lookup (TODO) |
Signing key
Tokens are signed HS256 with the JWT_SECRET binding (see src/jwt.ts). It's a
Cloudflare secret in deployed environments and read from .dev.vars locally
(gitignored) — never committed. "keep_vars": true in wrangler.jsonc keeps
deploys from clearing it.
Set the deployed secret once (persists across deploys):
bunx wrangler secret put JWT_SECRET
Notes / TODO
/eac/challengecontent is inlined insrc/auth.app.ts(Workers have no filesystem) — replaceEAC_CHALLENGEwith the real challenge text./cachedlogin/...and theRoomInstancecleanup in/connect/tokenneed a DB binding to be implemented./role/developer/:idis a stub (// TODO: implement).