Better auth

This commit is contained in:
2025-10-17 10:34:57 +02:00
parent 6868894a1b
commit 4876b57389
6 changed files with 186 additions and 119 deletions
+22 -33
View File
@@ -5,10 +5,10 @@ import { supabase } from "../supa";
/**
* POST /api/user
* Register new user
* Body: { name, username, email, password }
* Body: { username, email, password }
*/
export async function POST(req: NextRequest) {
const { name, username, email, password } = await req.json();
const { username, email, password } = await req.json();
if (!email || !password || !username)
return NextResponse.json(
@@ -28,29 +28,35 @@ export async function POST(req: NextRequest) {
{ status: StatusCodes.CONFLICT }
);
const { data: authData, error: authError } =
await supabase.auth.admin.createUser({
email,
password,
email_confirm: true,
user_metadata: { name, username },
});
const { data: authData, error: authError } = await supabase.auth.signUp({
email,
password,
});
if (authError)
return NextResponse.json(
{ message: authError.message },
{ status: StatusCodes.BAD_REQUEST }
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
);
if (!authData.user)
return NextResponse.json(
{ message: "User is null" },
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
);
await supabase.from("profiles").insert({
id: authData.user.id,
name,
username,
display_name: username,
avatar_url: "",
node_address: "",
});
return NextResponse.json({
message: "ok",
user_id: authData.user.id,
message: "User registered. Please check your email to verify your account.",
user_id: authData.user?.id,
email_sent: true,
});
}
@@ -61,30 +67,14 @@ export async function POST(req: NextRequest) {
*/
export async function GET(req: NextRequest) {
const params = new URL(req.url).searchParams;
const [username, password] = [params.get("username"), params.get("password")];
const [email, password] = [params.get("email"), params.get("password")];
if (!username || !password)
if (!email || !password)
return NextResponse.json(
{ message: "Params username and password are required" },
{ message: "Params email and password are required" },
{ status: StatusCodes.BAD_REQUEST }
);
let email = username;
if (!username.includes("@")) {
const { data } = await supabase
.from("profiles")
.select("email")
.eq("email", username)
.maybeSingle();
email = data?.email;
}
if (!email)
return NextResponse.json(
{ message: "Invalid username" },
{ status: StatusCodes.UNAUTHORIZED }
);
const { data, error } = await supabase.auth.signInWithPassword({
email,
password,
@@ -104,7 +94,6 @@ export async function GET(req: NextRequest) {
user_id: session?.user?.id,
});
// Optionally set cookie
res.cookies.set("token", session?.access_token ?? "", { httpOnly: true });
return res;
+40
View File
@@ -0,0 +1,40 @@
import { NextRequest, NextResponse } from "next/server";
import { supabase } from "../supa";
import { StatusCodes } from "http-status-codes";
export async function GET(req: NextRequest) {
const email = req.nextUrl.searchParams.get("email");
const password = req.nextUrl.searchParams.get("password");
if (!email || !password)
return NextResponse.json(
{ message: "Missing email or password" },
{ status: StatusCodes.BAD_REQUEST }
);
const { data, error } = await supabase.auth.signInWithPassword({
email,
password,
});
if (error)
return NextResponse.json(
{ message: error.message },
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
);
if (!data)
return NextResponse.json(
{ verified: false, message: "User not found" },
{ status: StatusCodes.NOT_FOUND }
);
const res = NextResponse.json({
verified: !!data.user.email_confirmed_at,
user_id: data.user.id,
access_token: data.session.access_token,
refresh_token: data.session.refresh_token,
});
return res;
}