feat(backend): pluggable auth (none/mock/oidc seam)

- authPreHandler(mode) returns Fastify preHandler that sets req.user={id}
- none: uses dev@local
- mock: reads x-mock-user header
- oidc: MVP stub returns 501 + throws
- getUser(req) returns user object

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-27 21:13:26 +02:00
co-authored by Claude Opus 4.8
parent 39eb35116e
commit a58fb19340
2 changed files with 44 additions and 0 deletions
+20
View File
@@ -0,0 +1,20 @@
import type { FastifyRequest, FastifyReply } from "fastify";
export function authPreHandler(mode: "none" | "mock" | "oidc") {
return async (req: FastifyRequest, reply: FastifyReply) => {
if (mode === "none") {
(req as any).user = { id: "dev@local" };
} else if (mode === "mock") {
(req as any).user = {
id: (req.headers["x-mock-user"] as string) ?? "mock",
};
} else {
reply.code(501);
throw new Error("OIDC non configurato (MVP: usa none/mock)");
}
};
}
export function getUser(req: FastifyRequest): { id: string } {
return (req as any).user ?? { id: "dev@local" };
}
+24
View File
@@ -0,0 +1,24 @@
import { test, expect } from "vitest";
import Fastify from "fastify";
import { authPreHandler, getUser } from "../src/auth/auth.js";
test("mode none assegna dev@local", async () => {
const app = Fastify();
app.addHook("preHandler", authPreHandler("none"));
app.get("/me", async (req) => getUser(req));
expect((await app.inject({ method: "GET", url: "/me" })).json()).toEqual({
id: "dev@local",
});
});
test("mode mock legge l'header", async () => {
const app = Fastify();
app.addHook("preHandler", authPreHandler("mock"));
app.get("/me", async (req) => getUser(req));
const res = await app.inject({
method: "GET",
url: "/me",
headers: { "x-mock-user": "alice" },
});
expect(res.json()).toEqual({ id: "alice" });
});