mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
* chore(auth): upgrade better-auth 1.3.12 → 1.6.11 * chore(auth): address Greptile review — broaden change-email type + migration newline * fix(auth): correct oneTimeToken expiresIn unit (minutes, not seconds) Better-auth's oneTimeToken expiresIn is in minutes (multiplied by 60_000ms internally). Sim's existing 24*60*60 evaluated to ~60 days of token lifetime instead of the intended 24 hours. Tokens are one-time-use and typically consumed within seconds of generation (Socket.IO handshake), so this tightens an unused security window without affecting UX.
37 lines
1.1 KiB
TypeScript
37 lines
1.1 KiB
TypeScript
import { db } from '@sim/db'
|
|
import * as schema from '@sim/db/schema'
|
|
import { betterAuth } from 'better-auth'
|
|
import { drizzleAdapter } from 'better-auth/adapters/drizzle'
|
|
import { oneTimeToken } from 'better-auth/plugins'
|
|
|
|
export interface VerifyAuthOptions {
|
|
/** Better Auth shared secret. Must match the apps/sim Better Auth secret. */
|
|
secret: string
|
|
/** Public-facing Better Auth URL (usually same as NEXT_PUBLIC_APP_URL). */
|
|
baseURL: string
|
|
}
|
|
|
|
/**
|
|
* Minimal Better Auth instance used by services that only need to verify
|
|
* one-time tokens issued by the main app. Shares the Better Auth DB schema
|
|
* (`verification` table) and secret with the main app, so tokens issued by
|
|
* `apps/sim`'s full auth config are accepted here.
|
|
*/
|
|
export function createVerifyAuth(options: VerifyAuthOptions) {
|
|
return betterAuth({
|
|
baseURL: options.baseURL,
|
|
secret: options.secret,
|
|
database: drizzleAdapter(db, {
|
|
provider: 'pg',
|
|
schema,
|
|
}),
|
|
plugins: [
|
|
oneTimeToken({
|
|
expiresIn: 24 * 60,
|
|
}),
|
|
],
|
|
})
|
|
}
|
|
|
|
export type VerifyAuth = ReturnType<typeof createVerifyAuth>
|