M1: authentication with better-auth, verified end to end

Switches from the planned Auth.js v5 to better-auth 1.7.1. The plan
assumed the blocker would be schema fit; it is not. @auth/drizzle-adapter
accepts our tables verbatim. What rules Auth.js out is that credentials
providers hardcode JWT and never call adapter.createSession, and the
config assertion that would catch it only fires when EVERY provider is
credentials — so adding Google suppresses the warning and the app ships
silently broken. Phone OTP with database sessions is not reachable there
without hand-building the whole OTP security layer.

Also corrects a premise: better-auth's drizzle-orm peer is declared
OPTIONAL, so no 0.38 -> 0.45 upgrade is forced. Verified on 0.38.4.

- auth schema rewritten to better-auth 1.7.1's own getSchema() output:
  sessions/accounts/verifications reshaped, emailVerified and
  phoneVerified are BOOLEAN (a timestamptz there fails 100% of signups),
  accounts.issuer added, phone_otps dropped. Ban state now comes from the
  admin plugin rather than a second bannedAt column.
- Session resolution is one file. Everything downstream is written
  against our own Session type, so the provider stays swappable.
- Ban enforcement lives in the resolver because Session carries no ban
  field and protectedProcedure promises a non-banned user.
- Phone OTP sign-in, Google, role selection, tRPC user router.
- Synthetic emails for phone-first users, with isSyntheticEmail() gating
  every future send. Pros must supply a real address; clients need not.
- Duplicate-account detection, since both signup routes stay open and
  nothing correlates a phone to a Google identity. Detects only — merging
  accounts that carry reviews and payments needs its own tooling.
- SMS sender refuses to fall back to console logging in production.
- declaration:false for the app, which is the actual fix for the TS2742
  wall from better-auth's transitive zod under pnpm.

Verified against a live server: OTP sent, code verified, uuid PK honoured,
database session written, and an authenticated tRPC call resolved. A
signed-in stranger gets NOT_FOUND on another client's deck; anonymous
gets UNAUTHORIZED.

124 tests passing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
serfowi
2026-08-20 14:40:23 -04:00
co-authored by Claude Opus 5
parent 66dd4ac942
commit cebeda7f4c
32 changed files with 1873 additions and 397 deletions
+39
View File
@@ -0,0 +1,39 @@
/**
* Phone-first signup still has to put something in `users.email` — better-auth
* requires it to be present and unique. We mint a synthetic address on a domain
* we control and never deliver to.
*
* For a plumber-and-electrician marketplace this will be MOST client accounts,
* so every outbound-mail path must check `isSyntheticEmail` first. Sending to
* one is not merely useless: it is a bounce against our sending reputation, and
* at volume that costs us delivery to the addresses that are real.
*
* Pros are required to supply a genuine address during onboarding — they need
* payout statements, tax records and dispute notices. Clients may never have one
* and are served over SMS instead.
*/
export const SYNTHETIC_EMAIL_DOMAIN = 'phone.linkder.local';
export function syntheticEmailFor(phoneE164: string): string {
return `${phoneE164}@${SYNTHETIC_EMAIL_DOMAIN}`;
}
export function isSyntheticEmail(email: string | null | undefined): boolean {
if (!email) return true; // nothing to send to is, for our purposes, the same thing
return email.toLowerCase().endsWith(`@${SYNTHETIC_EMAIL_DOMAIN}`);
}
/** True when we can actually put a message in front of this person by email. */
export function isContactableEmail(email: string | null | undefined): email is string {
return !isSyntheticEmail(email);
}
/**
* Recover the phone number a synthetic address was minted from.
* Useful in support tooling; returns null for a real address.
*/
export function phoneFromSyntheticEmail(email: string): string | null {
if (!isSyntheticEmail(email)) return null;
const [local] = email.split('@');
return local && local.startsWith('+') ? local : null;
}
+1
View File
@@ -4,3 +4,4 @@ export * from './state-machines';
export * from './ranking';
export * from './cancellation';
export * from './schemas';
export * from './email';
+43
View File
@@ -0,0 +1,43 @@
import { describe, expect, it } from 'vitest';
import {
isContactableEmail,
isSyntheticEmail,
phoneFromSyntheticEmail,
syntheticEmailFor,
} from '../src/email';
describe('synthetic emails', () => {
it('mints an address from a phone number', () => {
expect(syntheticEmailFor('+34600123456')).toBe('+34600123456@phone.linkder.local');
});
it('recognises its own output', () => {
expect(isSyntheticEmail(syntheticEmailFor('+34600123456'))).toBe(true);
});
it('treats a real address as contactable', () => {
expect(isSyntheticEmail('marc@gmail.com')).toBe(false);
expect(isContactableEmail('marc@gmail.com')).toBe(true);
});
it('treats null and empty as not contactable rather than throwing', () => {
expect(isSyntheticEmail(null)).toBe(true);
expect(isSyntheticEmail(undefined)).toBe(true);
expect(isSyntheticEmail('')).toBe(true);
expect(isContactableEmail(null)).toBe(false);
});
it('is case insensitive — a bounce is a bounce whatever the casing', () => {
expect(isSyntheticEmail('+34600123456@PHONE.LINKDER.LOCAL')).toBe(true);
});
it('does not match a lookalike domain', () => {
expect(isSyntheticEmail('someone@phone.linkder.local.evil.com')).toBe(false);
expect(isSyntheticEmail('someone@notphone.linkder.local')).toBe(false);
});
it('recovers the phone number for support tooling', () => {
expect(phoneFromSyntheticEmail('+34600123456@phone.linkder.local')).toBe('+34600123456');
expect(phoneFromSyntheticEmail('marc@gmail.com')).toBeNull();
});
});