mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-01 17:53:18 +00:00
fix(api): do not default DEV_AUTH_BYPASS outside local migrate
This commit is contained in:
parent
c0ad22e3a7
commit
280014e89d
3 changed files with 22 additions and 6 deletions
|
|
@ -2,15 +2,12 @@ import { migrate } from "drizzle-orm/node-postgres/migrator";
|
|||
import path from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { closeDb, createDb } from "./client.js";
|
||||
import { loadEnv } from "../env.js";
|
||||
import { loadEnv, withLocalDevAuthBypass } from "../env.js";
|
||||
|
||||
const __dirname = path.dirname(fileURLToPath(import.meta.url));
|
||||
|
||||
async function main(): Promise<void> {
|
||||
const env = loadEnv({
|
||||
...process.env,
|
||||
DEV_AUTH_BYPASS: process.env.DEV_AUTH_BYPASS ?? "true",
|
||||
});
|
||||
const env = loadEnv(withLocalDevAuthBypass());
|
||||
|
||||
if (env.databaseDriver !== "postgres") {
|
||||
throw new Error("db:migrate currently supports DATABASE_DRIVER=postgres only.");
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
import { describe, expect, it } from "vitest";
|
||||
import { loadEnv } from "./env.js";
|
||||
import { loadEnv, withLocalDevAuthBypass } from "./env.js";
|
||||
|
||||
describe("loadEnv", () => {
|
||||
it("allows DEV_AUTH_BYPASS in development", () => {
|
||||
|
|
@ -49,6 +49,18 @@ describe("loadEnv", () => {
|
|||
).toThrow(/DEV_AUTH_BYPASS/);
|
||||
});
|
||||
|
||||
it("defaults DEV_AUTH_BYPASS only for local node envs", () => {
|
||||
expect(withLocalDevAuthBypass({ NODE_ENV: "development" }).DEV_AUTH_BYPASS).toBe("true");
|
||||
expect(withLocalDevAuthBypass({ NODE_ENV: "test" }).DEV_AUTH_BYPASS).toBe("true");
|
||||
expect(withLocalDevAuthBypass({ NODE_ENV: "production" }).DEV_AUTH_BYPASS).toBeUndefined();
|
||||
expect(
|
||||
withLocalDevAuthBypass({ NODE_ENV: "production", DEV_AUTH_BYPASS: "false" }).DEV_AUTH_BYPASS,
|
||||
).toBe("false");
|
||||
expect(() => loadEnv(withLocalDevAuthBypass({ NODE_ENV: "production" }))).toThrow(
|
||||
/COGNITO_ISSUER/,
|
||||
);
|
||||
});
|
||||
|
||||
it("requires Cognito config when bypass is off", () => {
|
||||
expect(() =>
|
||||
loadEnv({
|
||||
|
|
|
|||
|
|
@ -10,6 +10,13 @@ export function isUserRole(value: string): value is UserRole {
|
|||
|
||||
const LOCAL_NODE_ENVS = new Set(["development", "test"]);
|
||||
|
||||
export function withLocalDevAuthBypass(env: NodeJS.ProcessEnv = process.env): NodeJS.ProcessEnv {
|
||||
if (env.DEV_AUTH_BYPASS !== undefined) return env;
|
||||
const nodeEnv = env.NODE_ENV ?? "development";
|
||||
if (!LOCAL_NODE_ENVS.has(nodeEnv)) return env;
|
||||
return { ...env, DEV_AUTH_BYPASS: "true" };
|
||||
}
|
||||
|
||||
export type ApiEnv = {
|
||||
nodeEnv: string;
|
||||
stage: string;
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue