feat(auth): add local login and CSRF-protected sessions

This commit is contained in:
2026-08-16 23:23:55 +02:00
parent 8477a69a29
commit 29bfb41363
10 changed files with 1062 additions and 35 deletions
+21 -4
View File
@@ -1,6 +1,23 @@
import { buildApp } from "./app.js";
import { buildApp, type AppWithAuthSessionStore } from "./app.js";
import { loadConfig } from "./config.js";
const config = loadConfig(process.env);
const app = buildApp(config);
app.listen({ port: config.port, host: config.host })
.then((addr) => console.log(`backend listening on ${addr}`));
const app = buildApp(config) as AppWithAuthSessionStore;
async function start(): Promise<void> {
const sessions = app.thothiiAuthSessionStore;
if (sessions) {
await sessions.prune();
const interval = setInterval(() => {
void sessions.prune().catch(() => app.log.warn({ component: "auth-session-prune" }, "auth session pruning failed"));
}, 15 * 60 * 1000);
interval.unref();
app.addHook("onClose", async () => clearInterval(interval));
}
const address = await app.listen({ port: config.port, host: config.host });
console.log(`backend listening on ${address}`);
}
void start().catch(() => {
console.error("backend startup failed");
process.exitCode = 1;
});