Switches from the planned Auth.js v5 to better-auth 1.7.1. The plan assumed the blocker would be schema fit; it is not. @auth/drizzle-adapter accepts our tables verbatim. What rules Auth.js out is that credentials providers hardcode JWT and never call adapter.createSession, and the config assertion that would catch it only fires when EVERY provider is credentials — so adding Google suppresses the warning and the app ships silently broken. Phone OTP with database sessions is not reachable there without hand-building the whole OTP security layer. Also corrects a premise: better-auth's drizzle-orm peer is declared OPTIONAL, so no 0.38 -> 0.45 upgrade is forced. Verified on 0.38.4. - auth schema rewritten to better-auth 1.7.1's own getSchema() output: sessions/accounts/verifications reshaped, emailVerified and phoneVerified are BOOLEAN (a timestamptz there fails 100% of signups), accounts.issuer added, phone_otps dropped. Ban state now comes from the admin plugin rather than a second bannedAt column. - Session resolution is one file. Everything downstream is written against our own Session type, so the provider stays swappable. - Ban enforcement lives in the resolver because Session carries no ban field and protectedProcedure promises a non-banned user. - Phone OTP sign-in, Google, role selection, tRPC user router. - Synthetic emails for phone-first users, with isSyntheticEmail() gating every future send. Pros must supply a real address; clients need not. - Duplicate-account detection, since both signup routes stay open and nothing correlates a phone to a Google identity. Detects only — merging accounts that carry reviews and payments needs its own tooling. - SMS sender refuses to fall back to console logging in production. - declaration:false for the app, which is the actual fix for the TS2742 wall from better-auth's transitive zod under pnpm. Verified against a live server: OTP sent, code verified, uuid PK honoured, database session written, and an authenticated tRPC call resolved. A signed-in stranger gets NOT_FOUND on another client's deck; anonymous gets UNAUTHORIZED. 124 tests passing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
44 lines
1.5 KiB
TypeScript
44 lines
1.5 KiB
TypeScript
import { describe, expect, it } from 'vitest';
|
|
import {
|
|
isContactableEmail,
|
|
isSyntheticEmail,
|
|
phoneFromSyntheticEmail,
|
|
syntheticEmailFor,
|
|
} from '../src/email';
|
|
|
|
describe('synthetic emails', () => {
|
|
it('mints an address from a phone number', () => {
|
|
expect(syntheticEmailFor('+34600123456')).toBe('+34600123456@phone.linkder.local');
|
|
});
|
|
|
|
it('recognises its own output', () => {
|
|
expect(isSyntheticEmail(syntheticEmailFor('+34600123456'))).toBe(true);
|
|
});
|
|
|
|
it('treats a real address as contactable', () => {
|
|
expect(isSyntheticEmail('marc@gmail.com')).toBe(false);
|
|
expect(isContactableEmail('marc@gmail.com')).toBe(true);
|
|
});
|
|
|
|
it('treats null and empty as not contactable rather than throwing', () => {
|
|
expect(isSyntheticEmail(null)).toBe(true);
|
|
expect(isSyntheticEmail(undefined)).toBe(true);
|
|
expect(isSyntheticEmail('')).toBe(true);
|
|
expect(isContactableEmail(null)).toBe(false);
|
|
});
|
|
|
|
it('is case insensitive — a bounce is a bounce whatever the casing', () => {
|
|
expect(isSyntheticEmail('+34600123456@PHONE.LINKDER.LOCAL')).toBe(true);
|
|
});
|
|
|
|
it('does not match a lookalike domain', () => {
|
|
expect(isSyntheticEmail('someone@phone.linkder.local.evil.com')).toBe(false);
|
|
expect(isSyntheticEmail('someone@notphone.linkder.local')).toBe(false);
|
|
});
|
|
|
|
it('recovers the phone number for support tooling', () => {
|
|
expect(phoneFromSyntheticEmail('+34600123456@phone.linkder.local')).toBe('+34600123456');
|
|
expect(phoneFromSyntheticEmail('marc@gmail.com')).toBeNull();
|
|
});
|
|
});
|