mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-07 08:08:52 +00:00
fix(api): do not default DEV_AUTH_BYPASS outside local migrate
This commit is contained in:
parent
c0ad22e3a7
commit
280014e89d
3 changed files with 22 additions and 6 deletions
|
|
@ -2,15 +2,12 @@ import { migrate } from "drizzle-orm/node-postgres/migrator";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import { fileURLToPath } from "node:url";
|
import { fileURLToPath } from "node:url";
|
||||||
import { closeDb, createDb } from "./client.js";
|
import { closeDb, createDb } from "./client.js";
|
||||||
import { loadEnv } from "../env.js";
|
import { loadEnv, withLocalDevAuthBypass } from "../env.js";
|
||||||
|
|
||||||
const __dirname = path.dirname(fileURLToPath(import.meta.url));
|
const __dirname = path.dirname(fileURLToPath(import.meta.url));
|
||||||
|
|
||||||
async function main(): Promise<void> {
|
async function main(): Promise<void> {
|
||||||
const env = loadEnv({
|
const env = loadEnv(withLocalDevAuthBypass());
|
||||||
...process.env,
|
|
||||||
DEV_AUTH_BYPASS: process.env.DEV_AUTH_BYPASS ?? "true",
|
|
||||||
});
|
|
||||||
|
|
||||||
if (env.databaseDriver !== "postgres") {
|
if (env.databaseDriver !== "postgres") {
|
||||||
throw new Error("db:migrate currently supports DATABASE_DRIVER=postgres only.");
|
throw new Error("db:migrate currently supports DATABASE_DRIVER=postgres only.");
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,5 @@
|
||||||
import { describe, expect, it } from "vitest";
|
import { describe, expect, it } from "vitest";
|
||||||
import { loadEnv } from "./env.js";
|
import { loadEnv, withLocalDevAuthBypass } from "./env.js";
|
||||||
|
|
||||||
describe("loadEnv", () => {
|
describe("loadEnv", () => {
|
||||||
it("allows DEV_AUTH_BYPASS in development", () => {
|
it("allows DEV_AUTH_BYPASS in development", () => {
|
||||||
|
|
@ -49,6 +49,18 @@ describe("loadEnv", () => {
|
||||||
).toThrow(/DEV_AUTH_BYPASS/);
|
).toThrow(/DEV_AUTH_BYPASS/);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("defaults DEV_AUTH_BYPASS only for local node envs", () => {
|
||||||
|
expect(withLocalDevAuthBypass({ NODE_ENV: "development" }).DEV_AUTH_BYPASS).toBe("true");
|
||||||
|
expect(withLocalDevAuthBypass({ NODE_ENV: "test" }).DEV_AUTH_BYPASS).toBe("true");
|
||||||
|
expect(withLocalDevAuthBypass({ NODE_ENV: "production" }).DEV_AUTH_BYPASS).toBeUndefined();
|
||||||
|
expect(
|
||||||
|
withLocalDevAuthBypass({ NODE_ENV: "production", DEV_AUTH_BYPASS: "false" }).DEV_AUTH_BYPASS,
|
||||||
|
).toBe("false");
|
||||||
|
expect(() => loadEnv(withLocalDevAuthBypass({ NODE_ENV: "production" }))).toThrow(
|
||||||
|
/COGNITO_ISSUER/,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
it("requires Cognito config when bypass is off", () => {
|
it("requires Cognito config when bypass is off", () => {
|
||||||
expect(() =>
|
expect(() =>
|
||||||
loadEnv({
|
loadEnv({
|
||||||
|
|
|
||||||
|
|
@ -10,6 +10,13 @@ export function isUserRole(value: string): value is UserRole {
|
||||||
|
|
||||||
const LOCAL_NODE_ENVS = new Set(["development", "test"]);
|
const LOCAL_NODE_ENVS = new Set(["development", "test"]);
|
||||||
|
|
||||||
|
export function withLocalDevAuthBypass(env: NodeJS.ProcessEnv = process.env): NodeJS.ProcessEnv {
|
||||||
|
if (env.DEV_AUTH_BYPASS !== undefined) return env;
|
||||||
|
const nodeEnv = env.NODE_ENV ?? "development";
|
||||||
|
if (!LOCAL_NODE_ENVS.has(nodeEnv)) return env;
|
||||||
|
return { ...env, DEV_AUTH_BYPASS: "true" };
|
||||||
|
}
|
||||||
|
|
||||||
export type ApiEnv = {
|
export type ApiEnv = {
|
||||||
nodeEnv: string;
|
nodeEnv: string;
|
||||||
stage: string;
|
stage: string;
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue