mirror of
https://github.com/bknd-io/bknd/
synced 2026-08-02 16:16:02 +00:00
Compare commits
166 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| f5f591fc4a | |||
| 6bbc922710 | |||
| 959dee013e | |||
| a39e76a440 | |||
| acc10377ca | |||
| 506c7d84cc | |||
| 7ba542c040 | |||
| b784d8611a | |||
| a21d4ad6a7 | |||
| 731b7a7e8d | |||
| e56fc9c368 | |||
| d1aa2da5b1 | |||
| 52fe9aa085 | |||
| 065821d9a5 | |||
| 0fc817382a | |||
| b2872eb196 | |||
| 3d804f5ac5 | |||
| da025efee1 | |||
| ab1fa4c895 | |||
| ebe3bc2ff5 | |||
| f792d8b93e | |||
| 319469f44b | |||
| 1359741e5f | |||
| 8f4de33a76 | |||
| 43dbc856ce | |||
| 5a8f2b4894 | |||
| 2627213de7 | |||
| 36e1bb1867 | |||
| 0cf1d86213 | |||
| 3fac740771 | |||
| 5e5dc62304 | |||
| c1d6384271 | |||
| f2bd04770a | |||
| 41d43126cb | |||
| a39407c9a3 | |||
| 5d6046b149 | |||
| 000f8d20a8 | |||
| 9e7547e787 | |||
| c3ae4a3999 | |||
| 5c3eeb7642 | |||
| a2fa11ccd0 | |||
| fdee39da62 | |||
| 16a3a67634 | |||
| 2b5e1771de | |||
| a16e017e39 | |||
| 079d613b2e | |||
| ff56d616d9 | |||
| 5b3d36c527 | |||
| 2885fea077 | |||
| 5ce22162c3 | |||
| 3f55c0f2c5 | |||
| 21f642161d | |||
| 7912729159 | |||
| d3e87be604 | |||
| ba3d11edab | |||
| 9ec31373e1 | |||
| 70b25a9f9b | |||
| b6717f0237 | |||
| c57f3e8070 | |||
| c2f4f92d1a | |||
| 6eb8525656 | |||
| e2ebb57564 | |||
| 2b7bbc5df0 | |||
| 8766b742c6 | |||
| 3befa43a9e | |||
| a842808464 | |||
| bd1ef8ed57 | |||
| a0019e5500 | |||
| 8ec67a5492 | |||
| 960f7c3fb2 | |||
| 793c214e6d | |||
| 4094004b83 | |||
| 300d86ff7c | |||
| 4c9b662f6f | |||
| a862cfdcf1 | |||
| de62f4e729 | |||
| 7e399830e5 | |||
| ee2ab982df | |||
| 5be55a6fa6 | |||
| 341eb13425 | |||
| 68fbb6e933 | |||
| 8b36985252 | |||
| ff86240b0e | |||
| 40bbdb904f | |||
| a333d537b0 | |||
| 108c108d82 | |||
| 4575d89cfe | |||
| 0ca0828581 | |||
| 07a57ebf67 | |||
| e9f1241ec3 | |||
| 80903d4ffa | |||
| c8290802e9 | |||
| ac6cd4a900 | |||
| a91ddb1ec3 | |||
| ed47c5bf51 | |||
| dbb19a27f4 | |||
| 71a17696eb | |||
| 2dbafebcea | |||
| 84d4635ec3 | |||
| e9c92b6086 | |||
| 5fa7601ad5 | |||
| 2c7054c317 | |||
| 5417aa174e | |||
| 6093f4f46f | |||
| 2178e0ee8b | |||
| be39e8a391 | |||
| b57f362e3a | |||
| e055e477ae | |||
| 422f7893b5 | |||
| 0a50f9850c | |||
| 42f340b189 | |||
| ef41b71921 | |||
| 2847e64b77 | |||
| 28390b0b84 | |||
| 0b58cadbd0 | |||
| 574b37abcd | |||
| 0dbf71e6b5 | |||
| fd1f0f7c54 | |||
| ebad3d15ec | |||
| 2fd5e71574 | |||
| b787837dd2 | |||
| 1fc6e810ae | |||
| 88cc406002 | |||
| 511f639d7a | |||
| 0df17221df | |||
| 347fe0f6ce | |||
| f3c6cd7620 | |||
| 649c465bd0 | |||
| 67604b344a | |||
| aedae8e757 | |||
| 166409fdf4 | |||
| f2aad9caac | |||
| 292e4595ea | |||
| 869031bbfa | |||
| 88e5c06e9d | |||
| cfb4b0e336 | |||
| 2d56b54e0c | |||
| 5d4a77fb10 | |||
| eb0822bbff | |||
| 38902ebcba | |||
| 22e43c2523 | |||
| e68e5792be | |||
| 511c6539fb | |||
| 9070f96571 | |||
| 0347efa592 | |||
| 1b8ce41837 | |||
| 6624927286 | |||
| 803f42a72b | |||
| 7e5c28d621 | |||
| 2f88c2216c | |||
| b89c090f87 | |||
| 5377ac1a41 | |||
| 0e870cda81 | |||
| b784e1c1c4 | |||
| 90f93caff4 | |||
| d6dcfe3acc | |||
| b974fe7ec7 | |||
| 6483ff74bb | |||
| 27e2064f0c | |||
| 5cf91bb35a | |||
| 81533d855a | |||
| 1fdee8435d | |||
| 06d7558c3c | |||
| 7344b1cf3d | |||
| ace9c1b2b9 | |||
| 0629e1bc50 |
@@ -9,6 +9,21 @@ jobs:
|
|||||||
test:
|
test:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
services:
|
||||||
|
postgres:
|
||||||
|
image: postgres:17
|
||||||
|
env:
|
||||||
|
POSTGRES_PASSWORD: postgres
|
||||||
|
POSTGRES_USER: postgres
|
||||||
|
POSTGRES_DB: bknd
|
||||||
|
ports:
|
||||||
|
- 5430:5432
|
||||||
|
options: >-
|
||||||
|
--health-cmd pg_isready
|
||||||
|
--health-interval 10s
|
||||||
|
--health-timeout 5s
|
||||||
|
--health-retries 5
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
@@ -20,11 +35,11 @@ jobs:
|
|||||||
- name: Setup Bun
|
- name: Setup Bun
|
||||||
uses: oven-sh/setup-bun@v1
|
uses: oven-sh/setup-bun@v1
|
||||||
with:
|
with:
|
||||||
bun-version: "1.2.22"
|
bun-version: "1.3.3"
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
working-directory: ./app
|
working-directory: ./app
|
||||||
run: bun install
|
run: bun install #--linker=hoisted
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
working-directory: ./app
|
working-directory: ./app
|
||||||
|
|||||||
+2
-1
@@ -27,7 +27,8 @@ packages/media/.env
|
|||||||
.npmrc
|
.npmrc
|
||||||
/.verdaccio
|
/.verdaccio
|
||||||
.idea
|
.idea
|
||||||
.vscode
|
.vscode/*
|
||||||
|
!.vscode/settings.json
|
||||||
.git_old
|
.git_old
|
||||||
docker/tmp
|
docker/tmp
|
||||||
.debug
|
.debug
|
||||||
|
|||||||
Vendored
+19
@@ -0,0 +1,19 @@
|
|||||||
|
{
|
||||||
|
"typescript.tsdk": "node_modules/typescript/lib",
|
||||||
|
"biome.enabled": true,
|
||||||
|
"editor.defaultFormatter": "biomejs.biome",
|
||||||
|
"editor.codeActionsOnSave": {
|
||||||
|
//"source.organizeImports.biome": "explicit",
|
||||||
|
"source.fixAll.biome": "explicit"
|
||||||
|
},
|
||||||
|
"typescript.preferences.importModuleSpecifier": "non-relative",
|
||||||
|
"typescript.preferences.autoImportFileExcludePatterns": [
|
||||||
|
"**/dist/**",
|
||||||
|
"**/node_modules/**/dist/**",
|
||||||
|
"**/node_modules/**/!(src|lib|esm)/**" // optional, stricter
|
||||||
|
],
|
||||||
|
"typescript.preferences.includePackageJsonAutoImports": "on",
|
||||||
|
"typescript.tsserver.watchOptions": {
|
||||||
|
"excludeDirectories": ["**/dist", "**/node_modules/**/dist"]
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -8,13 +8,17 @@
|
|||||||
</a>
|
</a>
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
bknd simplifies app development by providing a fully functional backend for database management, authentication, media and workflows. Being lightweight and built on Web Standards, it can be deployed nearly anywhere, including running inside your framework of choice. No more deploying multiple separate services!
|
bknd simplifies app development by providing a fully functional visual backend for database management, authentication, media and workflows. Being lightweight and built on Web Standards, it can be deployed nearly anywhere, including running inside your framework of choice. No more deploying multiple separate services!
|
||||||
|
|
||||||
|
It's designed to avoid vendor lock-in and architectural limitations. Built exclusively on [WinterTC Minimum Common Web Platform API](https://min-common-api.proposal.wintertc.org/) for universal compatibility, all functionality (data, auth, media, flows) is modular and opt-in, and infrastructure access is adapter-based with direct access to underlying drivers giving you full control without abstractions getting in your way.
|
||||||
|
|
||||||
* **Runtimes**: Node.js 22+, Bun 1.0+, Deno, Browser, Cloudflare Workers/Pages, Vercel, Netlify, AWS Lambda, etc.
|
* **Runtimes**: Node.js 22+, Bun 1.0+, Deno, Browser, Cloudflare Workers/Pages, Vercel, Netlify, AWS Lambda, etc.
|
||||||
* **Databases**:
|
* **Databases**:
|
||||||
* SQLite: LibSQL, Node SQLite, Bun SQLite, Cloudflare D1, Cloudflare Durable Objects SQLite, SQLocal
|
* SQLite: LibSQL, Node SQLite, Bun SQLite, Cloudflare D1, Cloudflare Durable Objects SQLite, SQLocal
|
||||||
* Postgres: Vanilla Postgres, Supabase, Neon, Xata
|
* Postgres: Vanilla Postgres, Supabase, Neon, Xata
|
||||||
* **Frameworks**: React, Next.js, React Router, Astro, Vite, Waku
|
* **Frameworks**: React, Next.js, React Router, Astro, Vite, Waku
|
||||||
* **Storage**: AWS S3, S3-compatible (Tigris, R2, Minio, etc.), Cloudflare R2 (binding), Cloudinary, Filesystem
|
* **Storage**: AWS S3, S3-compatible (Tigris, R2, Minio, etc.), Cloudflare R2 (binding), Cloudinary, Filesystem, Origin Private File System (OPFS)
|
||||||
|
* **Deployment**: Standalone, Docker, Cloudflare Workers, Vercel, Netlify, Deno Deploy, AWS Lambda, Valtown etc.
|
||||||
|
|
||||||
**For documentation and examples, please visit https://docs.bknd.io.**
|
**For documentation and examples, please visit https://docs.bknd.io.**
|
||||||
|
|
||||||
@@ -24,6 +28,18 @@ bknd simplifies app development by providing a fully functional backend for data
|
|||||||
> Please keep in mind that **bknd** is still under active development
|
> Please keep in mind that **bknd** is still under active development
|
||||||
> and therefore full backward compatibility is not guaranteed before reaching v1.0.0.
|
> and therefore full backward compatibility is not guaranteed before reaching v1.0.0.
|
||||||
|
|
||||||
|
## Use Cases
|
||||||
|
|
||||||
|
bknd is a general purpose backend system that implements the primitives almost any backend needs. This way, you can use it for any backend use case, including but not limited to:
|
||||||
|
|
||||||
|
- **Content Management System (CMS)** as Wordpress alternative, hosted separately or embedded in your frontend
|
||||||
|
- **AI Agent Backends** for managing agent state with built-in data persistence, regardless where it is hosted. Optionally communicate over the integrated MCP server.
|
||||||
|
- **SaaS Products** with multi-tenant data isolation (RLS) and user management, with freedom to choose your own database and storage provider
|
||||||
|
- **Prototypes & MVPs** to validate ideas quickly without infrastructure overhead
|
||||||
|
- **API-First Applications** where you need a reliable, type-safe backend without vendor lock-in either with the integrated TypeScript SDK or REST API using OpenAPI
|
||||||
|
- **IoT & Embedded Devices** where minimal footprint matters
|
||||||
|
|
||||||
|
|
||||||
## Size
|
## Size
|
||||||

|

|
||||||

|

|
||||||
@@ -46,13 +62,13 @@ Creating digital products always requires developing both the backend (the logic
|
|||||||
* **Media**: Effortlessly manage and serve all your media files.
|
* **Media**: Effortlessly manage and serve all your media files.
|
||||||
* **Flows**: Design and run workflows with seamless automation. (UI integration coming soon!)
|
* **Flows**: Design and run workflows with seamless automation. (UI integration coming soon!)
|
||||||
* 🌐 Built on Web Standards for maximum compatibility
|
* 🌐 Built on Web Standards for maximum compatibility
|
||||||
|
* 🛠️ MCP server, client and UI built-in to control your backend
|
||||||
* 🏃♂️ Multiple run modes
|
* 🏃♂️ Multiple run modes
|
||||||
* standalone using the CLI
|
* standalone using the CLI
|
||||||
* using a JavaScript runtime (Node, Bun, workerd)
|
* using a JavaScript runtime (Node, Bun, workerd)
|
||||||
* using a React framework (Next.js, React Router, Astro)
|
* using a React framework (Next.js, React Router, Astro)
|
||||||
* 📦 Official API and React SDK with type-safety
|
* 📦 Official API and React SDK with type-safety
|
||||||
* ⚛️ React elements for auto-configured authentication and media components
|
* ⚛️ React elements for auto-configured authentication and media components
|
||||||
* 🛠️ MCP server, client and UI built-in to control your backend
|
|
||||||
|
|
||||||
## Structure
|
## Structure
|
||||||
The package is mainly split into 4 parts, each serving a specific purpose:
|
The package is mainly split into 4 parts, each serving a specific purpose:
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ VITE_SHOW_ROUTES=
|
|||||||
|
|
||||||
# ===== Test Credentials =====
|
# ===== Test Credentials =====
|
||||||
RESEND_API_KEY=
|
RESEND_API_KEY=
|
||||||
|
PLUNK_API_KEY=
|
||||||
R2_TOKEN=
|
R2_TOKEN=
|
||||||
|
|
||||||
R2_ACCESS_KEY=
|
R2_ACCESS_KEY=
|
||||||
|
|||||||
Vendored
+12
@@ -0,0 +1,12 @@
|
|||||||
|
{
|
||||||
|
"typescript.preferences.includePackageJsonAutoImports": "off",
|
||||||
|
"typescript.suggest.autoImports": true,
|
||||||
|
"typescript.preferences.importModuleSpecifier": "relative",
|
||||||
|
"search.exclude": {
|
||||||
|
"**/dist/**": true,
|
||||||
|
"**/node_modules/**": true
|
||||||
|
},
|
||||||
|
"files.exclude": {
|
||||||
|
"**/dist/**": true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -108,7 +108,7 @@ describe("App tests", async () => {
|
|||||||
expect(Array.from(app.plugins.keys())).toEqual(["test"]);
|
expect(Array.from(app.plugins.keys())).toEqual(["test"]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test.only("drivers", async () => {
|
test("drivers", async () => {
|
||||||
const called: string[] = [];
|
const called: string[] = [];
|
||||||
const app = new App(dummyConnection, undefined, {
|
const app = new App(dummyConnection, undefined, {
|
||||||
drivers: {
|
drivers: {
|
||||||
|
|||||||
@@ -6,13 +6,16 @@ describe("Api", async () => {
|
|||||||
it("should construct without options", () => {
|
it("should construct without options", () => {
|
||||||
const api = new Api();
|
const api = new Api();
|
||||||
expect(api.baseUrl).toBe("http://localhost");
|
expect(api.baseUrl).toBe("http://localhost");
|
||||||
expect(api.isAuthVerified()).toBe(false);
|
|
||||||
|
// verified is true, because no token, user, headers or request given
|
||||||
|
// therefore nothing to check, auth state is verified
|
||||||
|
expect(api.isAuthVerified()).toBe(true);
|
||||||
});
|
});
|
||||||
|
|
||||||
it("should ignore force verify if no claims given", () => {
|
it("should ignore force verify if no claims given", () => {
|
||||||
const api = new Api({ verified: true });
|
const api = new Api({ verified: true });
|
||||||
expect(api.baseUrl).toBe("http://localhost");
|
expect(api.baseUrl).toBe("http://localhost");
|
||||||
expect(api.isAuthVerified()).toBe(false);
|
expect(api.isAuthVerified()).toBe(true);
|
||||||
});
|
});
|
||||||
|
|
||||||
it("should construct from request (token)", async () => {
|
it("should construct from request (token)", async () => {
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ const mockedBackend = new Hono()
|
|||||||
.get("/file/:name", async (c) => {
|
.get("/file/:name", async (c) => {
|
||||||
const { name } = c.req.param();
|
const { name } = c.req.param();
|
||||||
const file = Bun.file(`${assetsPath}/${name}`);
|
const file = Bun.file(`${assetsPath}/${name}`);
|
||||||
return new Response(file, {
|
return new Response(new File([await file.bytes()], name, { type: file.type }), {
|
||||||
headers: {
|
headers: {
|
||||||
"Content-Type": file.type,
|
"Content-Type": file.type,
|
||||||
"Content-Length": file.size.toString(),
|
"Content-Length": file.size.toString(),
|
||||||
@@ -67,7 +67,7 @@ describe("MediaApi", () => {
|
|||||||
const res = await mockedBackend.request("/api/media/file/" + name);
|
const res = await mockedBackend.request("/api/media/file/" + name);
|
||||||
await Bun.write(path, res);
|
await Bun.write(path, res);
|
||||||
|
|
||||||
const file = await Bun.file(path);
|
const file = Bun.file(path);
|
||||||
expect(file.size).toBeGreaterThan(0);
|
expect(file.size).toBeGreaterThan(0);
|
||||||
expect(file.type).toBe("image/png");
|
expect(file.type).toBe("image/png");
|
||||||
await file.delete();
|
await file.delete();
|
||||||
@@ -154,15 +154,12 @@ describe("MediaApi", () => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// upload via readable from bun
|
// upload via readable from bun
|
||||||
await matches(await api.upload(file.stream(), { filename: "readable.png" }), "readable.png");
|
await matches(api.upload(file.stream(), { filename: "readable.png" }), "readable.png");
|
||||||
|
|
||||||
// upload via readable from response
|
// upload via readable from response
|
||||||
{
|
{
|
||||||
const response = (await mockedBackend.request(url)) as Response;
|
const response = (await mockedBackend.request(url)) as Response;
|
||||||
await matches(
|
await matches(api.upload(response.body!, { filename: "readable.png" }), "readable.png");
|
||||||
await api.upload(response.body!, { filename: "readable.png" }),
|
|
||||||
"readable.png",
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,8 +1,12 @@
|
|||||||
import { describe, expect, mock, test } from "bun:test";
|
import { describe, expect, mock, test, beforeAll, afterAll } from "bun:test";
|
||||||
import { createApp as internalCreateApp, type CreateAppConfig } from "bknd";
|
import { createApp as internalCreateApp, type CreateAppConfig } from "bknd";
|
||||||
import { getDummyConnection } from "../../__test__/helper";
|
import { getDummyConnection } from "../../__test__/helper";
|
||||||
import { ModuleManager } from "modules/ModuleManager";
|
import { ModuleManager } from "modules/ModuleManager";
|
||||||
import { em, entity, text } from "data/prototype";
|
import { em, entity, text } from "data/prototype";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
async function createApp(config: CreateAppConfig = {}) {
|
async function createApp(config: CreateAppConfig = {}) {
|
||||||
const app = internalCreateApp({
|
const app = internalCreateApp({
|
||||||
|
|||||||
@@ -201,7 +201,10 @@ describe("mcp auth", async () => {
|
|||||||
},
|
},
|
||||||
return_config: true,
|
return_config: true,
|
||||||
});
|
});
|
||||||
expect(addGuestRole.config.guest.permissions).toEqual(["read", "write"]);
|
expect(addGuestRole.config.guest.permissions.map((p) => p.permission)).toEqual([
|
||||||
|
"read",
|
||||||
|
"write",
|
||||||
|
]);
|
||||||
|
|
||||||
// update role
|
// update role
|
||||||
await tool(server, "config_auth_roles_update", {
|
await tool(server, "config_auth_roles_update", {
|
||||||
@@ -210,13 +213,15 @@ describe("mcp auth", async () => {
|
|||||||
permissions: ["read"],
|
permissions: ["read"],
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
expect(app.toJSON().auth.roles?.guest?.permissions).toEqual(["read"]);
|
expect(app.toJSON().auth.roles?.guest?.permissions?.map((p) => p.permission)).toEqual([
|
||||||
|
"read",
|
||||||
|
]);
|
||||||
|
|
||||||
// get role
|
// get role
|
||||||
const getGuestRole = await tool(server, "config_auth_roles_get", {
|
const getGuestRole = await tool(server, "config_auth_roles_get", {
|
||||||
key: "guest",
|
key: "guest",
|
||||||
});
|
});
|
||||||
expect(getGuestRole.value.permissions).toEqual(["read"]);
|
expect(getGuestRole.value.permissions.map((p) => p.permission)).toEqual(["read"]);
|
||||||
|
|
||||||
// remove role
|
// remove role
|
||||||
await tool(server, "config_auth_roles_remove", {
|
await tool(server, "config_auth_roles_remove", {
|
||||||
|
|||||||
@@ -1,7 +1,11 @@
|
|||||||
import { AppEvents } from "App";
|
import { AppEvents } from "App";
|
||||||
import { describe, test, expect, beforeAll, mock } from "bun:test";
|
import { describe, test, expect, beforeAll, mock, afterAll } from "bun:test";
|
||||||
import { type App, createApp, createMcpToolCaller } from "core/test/utils";
|
import { type App, createApp, createMcpToolCaller } from "core/test/utils";
|
||||||
import type { McpServer } from "bknd/utils";
|
import type { McpServer } from "bknd/utils";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* - [x] system_config
|
* - [x] system_config
|
||||||
|
|||||||
@@ -0,0 +1,42 @@
|
|||||||
|
import { describe, expect, test } from "bun:test";
|
||||||
|
import { code, hybrid } from "modes";
|
||||||
|
|
||||||
|
describe("modes", () => {
|
||||||
|
describe("code", () => {
|
||||||
|
test("verify base configuration", async () => {
|
||||||
|
const c = code({}) as any;
|
||||||
|
const config = await c.app?.({} as any);
|
||||||
|
expect(Object.keys(config)).toEqual(["options"]);
|
||||||
|
expect(config.options.mode).toEqual("code");
|
||||||
|
expect(config.options.plugins).toEqual([]);
|
||||||
|
expect(config.options.manager.skipValidation).toEqual(false);
|
||||||
|
expect(config.options.manager.onModulesBuilt).toBeDefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("keeps overrides", async () => {
|
||||||
|
const c = code({
|
||||||
|
connection: {
|
||||||
|
url: ":memory:",
|
||||||
|
},
|
||||||
|
}) as any;
|
||||||
|
const config = await c.app?.({} as any);
|
||||||
|
expect(config.connection.url).toEqual(":memory:");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("hybrid", () => {
|
||||||
|
test("fails if no reader is provided", () => {
|
||||||
|
// @ts-ignore
|
||||||
|
expect(hybrid({} as any).app?.({} as any)).rejects.toThrow(/reader/);
|
||||||
|
});
|
||||||
|
test("verify base configuration", async () => {
|
||||||
|
const c = hybrid({ reader: async () => ({}) }) as any;
|
||||||
|
const config = await c.app?.({} as any);
|
||||||
|
expect(Object.keys(config)).toEqual(["reader", "beforeBuild", "config", "options"]);
|
||||||
|
expect(config.options.mode).toEqual("db");
|
||||||
|
expect(config.options.plugins).toEqual([]);
|
||||||
|
expect(config.options.manager.skipValidation).toEqual(false);
|
||||||
|
expect(config.options.manager.onModulesBuilt).toBeDefined();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -76,7 +76,7 @@ describe("repros", async () => {
|
|||||||
expect(app.em.entities.map((e) => e.name)).toEqual(["media", "test"]);
|
expect(app.em.entities.map((e) => e.name)).toEqual(["media", "test"]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test.only("verify inversedBy", async () => {
|
test("verify inversedBy", async () => {
|
||||||
const schema = proto.em(
|
const schema = proto.em(
|
||||||
{
|
{
|
||||||
products: proto.entity("products", {
|
products: proto.entity("products", {
|
||||||
|
|||||||
@@ -1,3 +1,41 @@
|
|||||||
|
import { Authenticator } from "auth/authenticate/Authenticator";
|
||||||
import { describe, expect, test } from "bun:test";
|
import { describe, expect, test } from "bun:test";
|
||||||
|
|
||||||
describe("Authenticator", async () => {});
|
describe("Authenticator", async () => {
|
||||||
|
test("should return auth cookie headers", async () => {
|
||||||
|
const auth = new Authenticator({}, null as any, {
|
||||||
|
jwt: {
|
||||||
|
secret: "secret",
|
||||||
|
fields: [],
|
||||||
|
},
|
||||||
|
cookie: {
|
||||||
|
sameSite: "strict",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const headers = await auth.getAuthCookieHeader("token");
|
||||||
|
const cookie = headers.get("Set-Cookie");
|
||||||
|
expect(cookie).toStartWith("auth=");
|
||||||
|
expect(cookie).toEndWith("HttpOnly; Secure; SameSite=Strict");
|
||||||
|
|
||||||
|
// now expect it to be removed
|
||||||
|
const headers2 = await auth.removeAuthCookieHeader(headers);
|
||||||
|
const cookie2 = headers2.get("Set-Cookie");
|
||||||
|
expect(cookie2).toStartWith("auth=; Max-Age=0; Path=/; Expires=");
|
||||||
|
expect(cookie2).toEndWith("HttpOnly; Secure; SameSite=Strict");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("should return auth cookie string", async () => {
|
||||||
|
const auth = new Authenticator({}, null as any, {
|
||||||
|
jwt: {
|
||||||
|
secret: "secret",
|
||||||
|
fields: [],
|
||||||
|
},
|
||||||
|
cookie: {
|
||||||
|
sameSite: "strict",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const cookie = await auth.unsafeGetAuthCookie("token");
|
||||||
|
expect(cookie).toStartWith("auth=");
|
||||||
|
expect(cookie).toEndWith("HttpOnly; Secure; SameSite=Strict");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|||||||
@@ -1,9 +1,35 @@
|
|||||||
import { describe, expect, test } from "bun:test";
|
import { describe, expect, test, beforeAll, afterAll } from "bun:test";
|
||||||
import { Guard } from "../../../src/auth/authorize/Guard";
|
import { Guard, type GuardConfig } from "auth/authorize/Guard";
|
||||||
|
import { Permission } from "auth/authorize/Permission";
|
||||||
|
import { Role, type RoleSchema } from "auth/authorize/Role";
|
||||||
|
import { objectTransform, s } from "bknd/utils";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
|
function createGuard(
|
||||||
|
permissionNames: string[],
|
||||||
|
roles?: Record<string, Omit<RoleSchema, "name">>,
|
||||||
|
config?: GuardConfig,
|
||||||
|
) {
|
||||||
|
const _roles = roles
|
||||||
|
? objectTransform(roles, ({ permissions = [], is_default, implicit_allow }, name) => {
|
||||||
|
return Role.create(name, { permissions, is_default, implicit_allow });
|
||||||
|
})
|
||||||
|
: {};
|
||||||
|
const _permissions = permissionNames.map((name) => new Permission(name));
|
||||||
|
return new Guard(_permissions, Object.values(_roles), config);
|
||||||
|
}
|
||||||
|
|
||||||
describe("authorize", () => {
|
describe("authorize", () => {
|
||||||
|
const read = new Permission("read", {
|
||||||
|
filterable: true,
|
||||||
|
});
|
||||||
|
const write = new Permission("write");
|
||||||
|
|
||||||
test("basic", async () => {
|
test("basic", async () => {
|
||||||
const guard = Guard.create(
|
const guard = createGuard(
|
||||||
["read", "write"],
|
["read", "write"],
|
||||||
{
|
{
|
||||||
admin: {
|
admin: {
|
||||||
@@ -16,14 +42,14 @@ describe("authorize", () => {
|
|||||||
role: "admin",
|
role: "admin",
|
||||||
};
|
};
|
||||||
|
|
||||||
expect(guard.granted("read", user)).toBe(true);
|
expect(guard.granted(read, user)).toBeUndefined();
|
||||||
expect(guard.granted("write", user)).toBe(true);
|
expect(guard.granted(write, user)).toBeUndefined();
|
||||||
|
|
||||||
expect(() => guard.granted("something")).toThrow();
|
expect(() => guard.granted(new Permission("something"), {})).toThrow();
|
||||||
});
|
});
|
||||||
|
|
||||||
test("with default", async () => {
|
test("with default", async () => {
|
||||||
const guard = Guard.create(
|
const guard = createGuard(
|
||||||
["read", "write"],
|
["read", "write"],
|
||||||
{
|
{
|
||||||
admin: {
|
admin: {
|
||||||
@@ -37,26 +63,26 @@ describe("authorize", () => {
|
|||||||
{ enabled: true },
|
{ enabled: true },
|
||||||
);
|
);
|
||||||
|
|
||||||
expect(guard.granted("read")).toBe(true);
|
expect(guard.granted(read, {})).toBeUndefined();
|
||||||
expect(guard.granted("write")).toBe(false);
|
expect(() => guard.granted(write, {})).toThrow();
|
||||||
|
|
||||||
const user = {
|
const user = {
|
||||||
role: "admin",
|
role: "admin",
|
||||||
};
|
};
|
||||||
|
|
||||||
expect(guard.granted("read", user)).toBe(true);
|
expect(guard.granted(read, user)).toBeUndefined();
|
||||||
expect(guard.granted("write", user)).toBe(true);
|
expect(guard.granted(write, user)).toBeUndefined();
|
||||||
});
|
});
|
||||||
|
|
||||||
test("guard implicit allow", async () => {
|
test("guard implicit allow", async () => {
|
||||||
const guard = Guard.create([], {}, { enabled: false });
|
const guard = createGuard([], {}, { enabled: false });
|
||||||
|
|
||||||
expect(guard.granted("read")).toBe(true);
|
expect(guard.granted(read, {})).toBeUndefined();
|
||||||
expect(guard.granted("write")).toBe(true);
|
expect(guard.granted(write, {})).toBeUndefined();
|
||||||
});
|
});
|
||||||
|
|
||||||
test("role implicit allow", async () => {
|
test("role implicit allow", async () => {
|
||||||
const guard = Guard.create(["read", "write"], {
|
const guard = createGuard(["read", "write"], {
|
||||||
admin: {
|
admin: {
|
||||||
implicit_allow: true,
|
implicit_allow: true,
|
||||||
},
|
},
|
||||||
@@ -66,12 +92,12 @@ describe("authorize", () => {
|
|||||||
role: "admin",
|
role: "admin",
|
||||||
};
|
};
|
||||||
|
|
||||||
expect(guard.granted("read", user)).toBe(true);
|
expect(guard.granted(read, user)).toBeUndefined();
|
||||||
expect(guard.granted("write", user)).toBe(true);
|
expect(guard.granted(write, user)).toBeUndefined();
|
||||||
});
|
});
|
||||||
|
|
||||||
test("guard with guest role implicit allow", async () => {
|
test("guard with guest role implicit allow", async () => {
|
||||||
const guard = Guard.create(["read", "write"], {
|
const guard = createGuard(["read", "write"], {
|
||||||
guest: {
|
guest: {
|
||||||
implicit_allow: true,
|
implicit_allow: true,
|
||||||
is_default: true,
|
is_default: true,
|
||||||
@@ -79,7 +105,143 @@ describe("authorize", () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
expect(guard.getUserRole()?.name).toBe("guest");
|
expect(guard.getUserRole()?.name).toBe("guest");
|
||||||
expect(guard.granted("read")).toBe(true);
|
expect(guard.granted(read, {})).toBeUndefined();
|
||||||
expect(guard.granted("write")).toBe(true);
|
expect(guard.granted(write, {})).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("cases", () => {
|
||||||
|
test("guest none, member deny if user.enabled is false", () => {
|
||||||
|
const guard = createGuard(
|
||||||
|
["read"],
|
||||||
|
{
|
||||||
|
guest: {
|
||||||
|
is_default: true,
|
||||||
|
},
|
||||||
|
member: {
|
||||||
|
permissions: [
|
||||||
|
{
|
||||||
|
permission: "read",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
condition: {},
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
type: "member",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
condition: {
|
||||||
|
"user.enabled": false,
|
||||||
|
},
|
||||||
|
effect: "deny",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{ enabled: true },
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(() => guard.granted(read, { role: "guest" })).toThrow();
|
||||||
|
|
||||||
|
// member is allowed, because default role permission effect is allow
|
||||||
|
// and no deny policy is met
|
||||||
|
expect(guard.granted(read, { role: "member" })).toBeUndefined();
|
||||||
|
|
||||||
|
// member is allowed, because deny policy is not met
|
||||||
|
expect(guard.granted(read, { role: "member", enabled: true })).toBeUndefined();
|
||||||
|
|
||||||
|
// member is denied, because deny policy is met
|
||||||
|
expect(() => guard.granted(read, { role: "member", enabled: false })).toThrow();
|
||||||
|
|
||||||
|
// get the filter for member role
|
||||||
|
expect(guard.filters(read, { role: "member" }).filter).toEqual({
|
||||||
|
type: "member",
|
||||||
|
});
|
||||||
|
|
||||||
|
// get filter for guest
|
||||||
|
expect(guard.filters(read, {}).filter).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("guest should only read posts that are public", () => {
|
||||||
|
const read = new Permission(
|
||||||
|
"read",
|
||||||
|
{
|
||||||
|
// make this permission filterable
|
||||||
|
// without this, `filter` policies have no effect
|
||||||
|
filterable: true,
|
||||||
|
},
|
||||||
|
// expect the context to match this schema
|
||||||
|
// otherwise exit with 500 to ensure proper policy checking
|
||||||
|
s.object({
|
||||||
|
entity: s.string(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const guard = createGuard(
|
||||||
|
["read"],
|
||||||
|
{
|
||||||
|
guest: {
|
||||||
|
// this permission is applied if no (or invalid) role is provided
|
||||||
|
is_default: true,
|
||||||
|
permissions: [
|
||||||
|
{
|
||||||
|
permission: "read",
|
||||||
|
// effect deny means only having this permission, doesn't guarantee access
|
||||||
|
effect: "deny",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
// only if this condition is met
|
||||||
|
condition: {
|
||||||
|
entity: {
|
||||||
|
$in: ["posts"],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
// the effect is allow
|
||||||
|
effect: "allow",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
condition: {
|
||||||
|
entity: "posts",
|
||||||
|
},
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
public: true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
// members should be allowed to read all
|
||||||
|
member: {
|
||||||
|
permissions: [
|
||||||
|
{
|
||||||
|
permission: "read",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{ enabled: true },
|
||||||
|
);
|
||||||
|
|
||||||
|
// guest can only read posts
|
||||||
|
expect(guard.granted(read, {}, { entity: "posts" })).toBeUndefined();
|
||||||
|
expect(() => guard.granted(read, {}, { entity: "users" })).toThrow();
|
||||||
|
|
||||||
|
// and guests can only read public posts
|
||||||
|
expect(guard.filters(read, {}, { entity: "posts" }).filter).toEqual({
|
||||||
|
public: true,
|
||||||
|
});
|
||||||
|
|
||||||
|
// member can read posts and users
|
||||||
|
expect(guard.granted(read, { role: "member" }, { entity: "posts" })).toBeUndefined();
|
||||||
|
expect(guard.granted(read, { role: "member" }, { entity: "users" })).toBeUndefined();
|
||||||
|
|
||||||
|
// member should not have a filter
|
||||||
|
expect(
|
||||||
|
guard.filters(read, { role: "member" }, { entity: "posts" }).filter,
|
||||||
|
).toBeUndefined();
|
||||||
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -0,0 +1,327 @@
|
|||||||
|
import { describe, it, expect, beforeAll, afterAll } from "bun:test";
|
||||||
|
import { createApp } from "core/test/utils";
|
||||||
|
import type { CreateAppConfig } from "App";
|
||||||
|
import * as proto from "data/prototype";
|
||||||
|
import { mergeObject } from "core/utils/objects";
|
||||||
|
import type { App, DB } from "bknd";
|
||||||
|
import type { CreateUserPayload } from "auth/AppAuth";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
|
async function makeApp(config: Partial<CreateAppConfig["config"]> = {}) {
|
||||||
|
const app = createApp({
|
||||||
|
config: mergeObject(
|
||||||
|
{
|
||||||
|
data: proto
|
||||||
|
.em(
|
||||||
|
{
|
||||||
|
users: proto.systemEntity("users", {}),
|
||||||
|
posts: proto.entity("posts", {
|
||||||
|
title: proto.text(),
|
||||||
|
content: proto.text(),
|
||||||
|
}),
|
||||||
|
comments: proto.entity("comments", {
|
||||||
|
content: proto.text(),
|
||||||
|
}),
|
||||||
|
},
|
||||||
|
({ relation }, { users, posts, comments }) => {
|
||||||
|
relation(posts).manyToOne(users);
|
||||||
|
relation(comments).manyToOne(posts);
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.toJSON(),
|
||||||
|
auth: {
|
||||||
|
enabled: true,
|
||||||
|
jwt: {
|
||||||
|
secret: "secret",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
config,
|
||||||
|
),
|
||||||
|
});
|
||||||
|
await app.build();
|
||||||
|
|
||||||
|
return app;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function createUsers(app: App, users: CreateUserPayload[]) {
|
||||||
|
return Promise.all(
|
||||||
|
users.map(async (user) => {
|
||||||
|
return await app.createUser(user);
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function loadFixtures(app: App, fixtures: Record<string, any[]> = {}) {
|
||||||
|
const results = {} as any;
|
||||||
|
for (const [entity, data] of Object.entries(fixtures)) {
|
||||||
|
results[entity] = await app.em
|
||||||
|
.mutator(entity as any)
|
||||||
|
.insertMany(data)
|
||||||
|
.then((result) => result.data);
|
||||||
|
}
|
||||||
|
return results;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("data permissions", async () => {
|
||||||
|
const app = await makeApp({
|
||||||
|
server: {
|
||||||
|
mcp: {
|
||||||
|
enabled: true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
auth: {
|
||||||
|
guard: {
|
||||||
|
enabled: true,
|
||||||
|
},
|
||||||
|
roles: {
|
||||||
|
guest: {
|
||||||
|
is_default: true,
|
||||||
|
permissions: [
|
||||||
|
{
|
||||||
|
permission: "system.access.api",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
permission: "data.entity.read",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
condition: {
|
||||||
|
entity: "posts",
|
||||||
|
},
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
users_id: { $isnull: 1 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
permission: "data.entity.create",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
condition: {
|
||||||
|
entity: "posts",
|
||||||
|
},
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
users_id: { $isnull: 1 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
permission: "data.entity.update",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
condition: {
|
||||||
|
entity: "posts",
|
||||||
|
},
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
users_id: { $isnull: 1 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
permission: "data.entity.delete",
|
||||||
|
policies: [
|
||||||
|
{
|
||||||
|
condition: { entity: "posts" },
|
||||||
|
},
|
||||||
|
{
|
||||||
|
condition: { entity: "posts" },
|
||||||
|
effect: "filter",
|
||||||
|
filter: {
|
||||||
|
users_id: { $isnull: 1 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const users = [
|
||||||
|
{ email: "foo@example.com", password: "password" },
|
||||||
|
{ email: "bar@example.com", password: "password" },
|
||||||
|
];
|
||||||
|
const fixtures = {
|
||||||
|
posts: [
|
||||||
|
{ content: "post 1", users_id: 1 },
|
||||||
|
{ content: "post 2", users_id: 2 },
|
||||||
|
{ content: "post 3", users_id: null },
|
||||||
|
],
|
||||||
|
comments: [
|
||||||
|
{ content: "comment 1", posts_id: 1 },
|
||||||
|
{ content: "comment 2", posts_id: 2 },
|
||||||
|
{ content: "comment 3", posts_id: 3 },
|
||||||
|
],
|
||||||
|
};
|
||||||
|
await createUsers(app, users);
|
||||||
|
const results = await loadFixtures(app, fixtures);
|
||||||
|
|
||||||
|
describe("http", async () => {
|
||||||
|
it("read many", async () => {
|
||||||
|
// many only includes posts with users_id is null
|
||||||
|
const res = await app.server.request("/api/data/entity/posts");
|
||||||
|
const data = await res.json().then((r: any) => r.data);
|
||||||
|
expect(data).toEqual([results.posts[2]]);
|
||||||
|
|
||||||
|
// same with /query
|
||||||
|
{
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/query", {
|
||||||
|
method: "POST",
|
||||||
|
});
|
||||||
|
const data = await res.json().then((r: any) => r.data);
|
||||||
|
expect(data).toEqual([results.posts[2]]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("read one", async () => {
|
||||||
|
// one only includes posts with users_id is null
|
||||||
|
{
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/1");
|
||||||
|
const data = await res.json().then((r: any) => r.data);
|
||||||
|
expect(res.status).toBe(404);
|
||||||
|
expect(data).toBeUndefined();
|
||||||
|
}
|
||||||
|
|
||||||
|
// read one by allowed id
|
||||||
|
{
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/3");
|
||||||
|
const data = await res.json().then((r: any) => r.data);
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(data).toEqual(results.posts[2]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("read many by reference", async () => {
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/1/comments");
|
||||||
|
const data = await res.json().then((r: any) => r.data);
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(data).toEqual(results.comments.filter((c: any) => c.posts_id === 1));
|
||||||
|
});
|
||||||
|
|
||||||
|
it("mutation create one", async () => {
|
||||||
|
// not allowed
|
||||||
|
{
|
||||||
|
const res = await app.server.request("/api/data/entity/posts", {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({ content: "post 4" }),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(403);
|
||||||
|
}
|
||||||
|
// allowed
|
||||||
|
{
|
||||||
|
const res = await app.server.request("/api/data/entity/posts", {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({ content: "post 4", users_id: null }),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(201);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("mutation update one", async () => {
|
||||||
|
// update one: not allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/1", {
|
||||||
|
method: "PATCH",
|
||||||
|
body: JSON.stringify({ content: "post 4" }),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(403);
|
||||||
|
|
||||||
|
{
|
||||||
|
// update one: allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/3", {
|
||||||
|
method: "PATCH",
|
||||||
|
body: JSON.stringify({ content: "post 3 (updated)" }),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(await res.json().then((r: any) => r.data.content)).toBe("post 3 (updated)");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("mutation update many", async () => {
|
||||||
|
// update many: not allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts", {
|
||||||
|
method: "PATCH",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
},
|
||||||
|
body: JSON.stringify({
|
||||||
|
update: { content: "post 4" },
|
||||||
|
where: { users_id: { $isnull: 0 } },
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(200); // because filtered
|
||||||
|
const _data = await res.json().then((r: any) => r.data.map((p: any) => p.users_id));
|
||||||
|
expect(_data.every((u: any) => u === null)).toBe(true);
|
||||||
|
|
||||||
|
// verify
|
||||||
|
const data = await app.em
|
||||||
|
.repo("posts")
|
||||||
|
.findMany({ select: ["content", "users_id"] })
|
||||||
|
.then((r) => r.data);
|
||||||
|
|
||||||
|
// expect non null users_id to not have content "post 4"
|
||||||
|
expect(
|
||||||
|
data.filter((p: any) => p.users_id !== null).every((p: any) => p.content !== "post 4"),
|
||||||
|
).toBe(true);
|
||||||
|
// expect null users_id to have content "post 4"
|
||||||
|
expect(
|
||||||
|
data.filter((p: any) => p.users_id === null).every((p: any) => p.content === "post 4"),
|
||||||
|
).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
const count = async () => {
|
||||||
|
const {
|
||||||
|
data: { count: _count },
|
||||||
|
} = await app.em.repo("posts").count();
|
||||||
|
return _count;
|
||||||
|
};
|
||||||
|
it("mutation delete one", async () => {
|
||||||
|
const initial = await count();
|
||||||
|
|
||||||
|
// delete one: not allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/1", {
|
||||||
|
method: "DELETE",
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(403);
|
||||||
|
expect(await count()).toBe(initial);
|
||||||
|
|
||||||
|
{
|
||||||
|
// delete one: allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts/3", {
|
||||||
|
method: "DELETE",
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(await count()).toBe(initial - 1);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("mutation delete many", async () => {
|
||||||
|
// delete many: not allowed
|
||||||
|
const res = await app.server.request("/api/data/entity/posts", {
|
||||||
|
method: "DELETE",
|
||||||
|
headers: {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
},
|
||||||
|
body: JSON.stringify({
|
||||||
|
where: {},
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
|
||||||
|
// only deleted posts with users_id is null
|
||||||
|
const remaining = await app.em
|
||||||
|
.repo("posts")
|
||||||
|
.findMany()
|
||||||
|
.then((r) => r.data);
|
||||||
|
expect(remaining.every((p: any) => p.users_id !== null)).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
import { describe, test, expect, beforeAll, afterAll } from "bun:test";
|
||||||
|
import { createAuthTestApp } from "./shared";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
import { em, entity, text } from "data/prototype";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
|
const schema = em(
|
||||||
|
{
|
||||||
|
posts: entity("posts", {
|
||||||
|
title: text(),
|
||||||
|
content: text(),
|
||||||
|
}),
|
||||||
|
comments: entity("comments", {
|
||||||
|
content: text(),
|
||||||
|
}),
|
||||||
|
},
|
||||||
|
({ relation }, { posts, comments }) => {
|
||||||
|
relation(posts).manyToOne(comments);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
describe("DataController (auth)", () => {
|
||||||
|
test("reading schema.json", async () => {
|
||||||
|
const { request } = await createAuthTestApp(
|
||||||
|
{
|
||||||
|
permission: ["system.access.api", "data.entity.read", "system.schema.read"],
|
||||||
|
request: new Request("http://localhost/api/data/schema.json"),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
config: { data: schema.toJSON() },
|
||||||
|
},
|
||||||
|
);
|
||||||
|
expect((await request.guest()).status).toBe(403);
|
||||||
|
expect((await request.member()).status).toBe(403);
|
||||||
|
expect((await request.authorized()).status).toBe(200);
|
||||||
|
expect((await request.admin()).status).toBe(200);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
import { describe, test, expect, beforeAll, afterAll } from "bun:test";
|
||||||
|
import { createAuthTestApp } from "./shared";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
|
describe("SystemController (auth)", () => {
|
||||||
|
test("reading info", async () => {
|
||||||
|
const { request } = await createAuthTestApp({
|
||||||
|
permission: ["system.access.api", "system.info"],
|
||||||
|
request: new Request("http://localhost/api/system/info"),
|
||||||
|
});
|
||||||
|
expect((await request.guest()).status).toBe(403);
|
||||||
|
expect((await request.member()).status).toBe(403);
|
||||||
|
expect((await request.authorized()).status).toBe(200);
|
||||||
|
expect((await request.admin()).status).toBe(200);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("reading permissions", async () => {
|
||||||
|
const { request } = await createAuthTestApp({
|
||||||
|
permission: ["system.access.api", "system.schema.read"],
|
||||||
|
request: new Request("http://localhost/api/system/permissions"),
|
||||||
|
});
|
||||||
|
expect((await request.guest()).status).toBe(403);
|
||||||
|
expect((await request.member()).status).toBe(403);
|
||||||
|
expect((await request.authorized()).status).toBe(200);
|
||||||
|
expect((await request.admin()).status).toBe(200);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("access openapi", async () => {
|
||||||
|
const { request } = await createAuthTestApp({
|
||||||
|
permission: ["system.access.api", "system.openapi"],
|
||||||
|
request: new Request("http://localhost/api/system/openapi.json"),
|
||||||
|
});
|
||||||
|
expect((await request.guest()).status).toBe(403);
|
||||||
|
expect((await request.member()).status).toBe(403);
|
||||||
|
expect((await request.authorized()).status).toBe(200);
|
||||||
|
expect((await request.admin()).status).toBe(200);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,171 @@
|
|||||||
|
import { createApp } from "core/test/utils";
|
||||||
|
import type { CreateAppConfig } from "App";
|
||||||
|
import type { RoleSchema } from "auth/authorize/Role";
|
||||||
|
import { isPlainObject } from "core/utils";
|
||||||
|
|
||||||
|
export type AuthTestConfig = {
|
||||||
|
guest?: RoleSchema;
|
||||||
|
member?: RoleSchema;
|
||||||
|
authorized?: RoleSchema;
|
||||||
|
};
|
||||||
|
|
||||||
|
export async function createAuthTestApp(
|
||||||
|
testConfig: {
|
||||||
|
permission: AuthTestConfig | string | string[];
|
||||||
|
request: Request;
|
||||||
|
},
|
||||||
|
config: Partial<CreateAppConfig> = {},
|
||||||
|
) {
|
||||||
|
let member: RoleSchema | undefined;
|
||||||
|
let authorized: RoleSchema | undefined;
|
||||||
|
let guest: RoleSchema | undefined;
|
||||||
|
if (isPlainObject(testConfig.permission)) {
|
||||||
|
if (testConfig.permission.guest)
|
||||||
|
guest = {
|
||||||
|
...testConfig.permission.guest,
|
||||||
|
is_default: true,
|
||||||
|
};
|
||||||
|
if (testConfig.permission.member) member = testConfig.permission.member;
|
||||||
|
if (testConfig.permission.authorized) authorized = testConfig.permission.authorized;
|
||||||
|
} else {
|
||||||
|
member = {
|
||||||
|
permissions: [],
|
||||||
|
};
|
||||||
|
authorized = {
|
||||||
|
permissions: Array.isArray(testConfig.permission)
|
||||||
|
? testConfig.permission
|
||||||
|
: [testConfig.permission],
|
||||||
|
};
|
||||||
|
guest = {
|
||||||
|
permissions: [],
|
||||||
|
is_default: true,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
console.log("authorized", authorized);
|
||||||
|
|
||||||
|
const app = createApp({
|
||||||
|
...config,
|
||||||
|
config: {
|
||||||
|
...config.config,
|
||||||
|
auth: {
|
||||||
|
...config.config?.auth,
|
||||||
|
enabled: true,
|
||||||
|
guard: {
|
||||||
|
enabled: true,
|
||||||
|
...config.config?.auth?.guard,
|
||||||
|
},
|
||||||
|
jwt: {
|
||||||
|
...config.config?.auth?.jwt,
|
||||||
|
secret: "secret",
|
||||||
|
},
|
||||||
|
roles: {
|
||||||
|
...config.config?.auth?.roles,
|
||||||
|
guest,
|
||||||
|
member,
|
||||||
|
authorized,
|
||||||
|
admin: {
|
||||||
|
implicit_allow: true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
await app.build();
|
||||||
|
|
||||||
|
const users = {
|
||||||
|
guest: null,
|
||||||
|
member: await app.createUser({
|
||||||
|
email: "member@test.com",
|
||||||
|
password: "12345678",
|
||||||
|
role: "member",
|
||||||
|
}),
|
||||||
|
authorized: await app.createUser({
|
||||||
|
email: "authorized@test.com",
|
||||||
|
password: "12345678",
|
||||||
|
role: "authorized",
|
||||||
|
}),
|
||||||
|
admin: await app.createUser({
|
||||||
|
email: "admin@test.com",
|
||||||
|
password: "12345678",
|
||||||
|
role: "admin",
|
||||||
|
}),
|
||||||
|
} as const;
|
||||||
|
|
||||||
|
const tokens = {} as Record<keyof typeof users, string>;
|
||||||
|
for (const [key, user] of Object.entries(users)) {
|
||||||
|
if (user) {
|
||||||
|
tokens[key as keyof typeof users] = await app.module.auth.authenticator.jwt(user);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function makeRequest(user: keyof typeof users, input: string, init: RequestInit = {}) {
|
||||||
|
const headers = new Headers(init.headers ?? {});
|
||||||
|
if (user in tokens) {
|
||||||
|
headers.set("Authorization", `Bearer ${tokens[user as keyof typeof tokens]}`);
|
||||||
|
}
|
||||||
|
const res = await app.server.request(input, {
|
||||||
|
...init,
|
||||||
|
headers,
|
||||||
|
});
|
||||||
|
|
||||||
|
let data: any;
|
||||||
|
if (res.headers.get("Content-Type")?.startsWith("application/json")) {
|
||||||
|
data = await res.json();
|
||||||
|
} else if (res.headers.get("Content-Type")?.startsWith("text/")) {
|
||||||
|
data = await res.text();
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
status: res.status,
|
||||||
|
ok: res.ok,
|
||||||
|
headers: Object.fromEntries(res.headers.entries()),
|
||||||
|
data,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
const requestFn = new Proxy(
|
||||||
|
{},
|
||||||
|
{
|
||||||
|
get(_, prop: keyof typeof users) {
|
||||||
|
return async (input: string, init: RequestInit = {}) => {
|
||||||
|
return makeRequest(prop, input, init);
|
||||||
|
};
|
||||||
|
},
|
||||||
|
},
|
||||||
|
) as {
|
||||||
|
[K in keyof typeof users]: (
|
||||||
|
input: string,
|
||||||
|
init?: RequestInit,
|
||||||
|
) => Promise<{
|
||||||
|
status: number;
|
||||||
|
ok: boolean;
|
||||||
|
headers: Record<string, string>;
|
||||||
|
data: any;
|
||||||
|
}>;
|
||||||
|
};
|
||||||
|
|
||||||
|
const request = new Proxy(
|
||||||
|
{},
|
||||||
|
{
|
||||||
|
get(_, prop: keyof typeof users) {
|
||||||
|
return async () => {
|
||||||
|
return makeRequest(prop, testConfig.request.url, {
|
||||||
|
headers: testConfig.request.headers,
|
||||||
|
method: testConfig.request.method,
|
||||||
|
body: testConfig.request.body,
|
||||||
|
});
|
||||||
|
};
|
||||||
|
},
|
||||||
|
},
|
||||||
|
) as {
|
||||||
|
[K in keyof typeof users]: () => Promise<{
|
||||||
|
status: number;
|
||||||
|
ok: boolean;
|
||||||
|
headers: Record<string, string>;
|
||||||
|
data: any;
|
||||||
|
}>;
|
||||||
|
};
|
||||||
|
|
||||||
|
return { app, users, request, requestFn };
|
||||||
|
}
|
||||||
@@ -0,0 +1,543 @@
|
|||||||
|
import { describe, it, expect } from "bun:test";
|
||||||
|
import { s } from "bknd/utils";
|
||||||
|
import { Permission } from "auth/authorize/Permission";
|
||||||
|
import { Policy } from "auth/authorize/Policy";
|
||||||
|
import { Hono } from "hono";
|
||||||
|
import { getPermissionRoutes, permission } from "auth/middlewares/permission.middleware";
|
||||||
|
import { auth } from "auth/middlewares/auth.middleware";
|
||||||
|
import { Guard, mergeFilters, type GuardConfig } from "auth/authorize/Guard";
|
||||||
|
import { Role, RolePermission } from "auth/authorize/Role";
|
||||||
|
import { Exception } from "bknd";
|
||||||
|
import { convert } from "core/object/query/object-query";
|
||||||
|
|
||||||
|
describe("Permission", () => {
|
||||||
|
it("works with minimal schema", () => {
|
||||||
|
expect(() => new Permission("test")).not.toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("parses context", () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test3",
|
||||||
|
{
|
||||||
|
filterable: true,
|
||||||
|
},
|
||||||
|
s.object({
|
||||||
|
a: s.string(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => p.parseContext({ a: [] })).toThrow();
|
||||||
|
expect(p.parseContext({ a: "test" })).toEqual({ a: "test" });
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(p.parseContext({ a: 1 })).toEqual({ a: "1" });
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("Policy", () => {
|
||||||
|
it("works with minimal schema", () => {
|
||||||
|
expect(() => new Policy().toJSON()).not.toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("checks condition", () => {
|
||||||
|
const p = new Policy({
|
||||||
|
condition: {
|
||||||
|
a: 1,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(p.meetsCondition({ a: 1 })).toBe(true);
|
||||||
|
expect(p.meetsCondition({ a: 2 })).toBe(false);
|
||||||
|
expect(p.meetsCondition({ a: 1, b: 1 })).toBe(true);
|
||||||
|
expect(p.meetsCondition({})).toBe(false);
|
||||||
|
|
||||||
|
const p2 = new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $gt: 1 },
|
||||||
|
$or: {
|
||||||
|
b: { $lt: 2 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(p2.meetsCondition({ a: 2 })).toBe(true);
|
||||||
|
expect(p2.meetsCondition({ a: 1 })).toBe(false);
|
||||||
|
expect(p2.meetsCondition({ a: 1, b: 1 })).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("filters", () => {
|
||||||
|
const p = new Policy({
|
||||||
|
filter: {
|
||||||
|
age: { $gt: 18 },
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const subjects = [{ age: 19 }, { age: 17 }, { age: 12 }];
|
||||||
|
|
||||||
|
expect(p.getFiltered(subjects)).toEqual([{ age: 19 }]);
|
||||||
|
|
||||||
|
expect(p.meetsFilter({ age: 19 })).toBe(true);
|
||||||
|
expect(p.meetsFilter({ age: 17 })).toBe(false);
|
||||||
|
expect(p.meetsFilter({ age: 12 })).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("replaces placeholders", () => {
|
||||||
|
const p = new Policy({
|
||||||
|
condition: {
|
||||||
|
a: "@auth.username",
|
||||||
|
},
|
||||||
|
filter: {
|
||||||
|
a: "@auth.username",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const vars = { auth: { username: "test" } };
|
||||||
|
|
||||||
|
expect(p.meetsCondition({ a: "test" }, vars)).toBe(true);
|
||||||
|
expect(p.meetsCondition({ a: "test2" }, vars)).toBe(false);
|
||||||
|
expect(p.meetsCondition({ a: "test2" })).toBe(false);
|
||||||
|
expect(p.meetsFilter({ a: "test" }, vars)).toBe(true);
|
||||||
|
expect(p.meetsFilter({ a: "test2" }, vars)).toBe(false);
|
||||||
|
expect(p.meetsFilter({ a: "test2" })).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("Guard", () => {
|
||||||
|
it("collects filters", () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{
|
||||||
|
filterable: true,
|
||||||
|
},
|
||||||
|
s.object({
|
||||||
|
a: s.number(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: { a: { $eq: 1 } },
|
||||||
|
filter: { foo: "bar" },
|
||||||
|
effect: "filter",
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
const guard = new Guard([p], [r], {
|
||||||
|
enabled: true,
|
||||||
|
});
|
||||||
|
expect(guard.filters(p, { role: r.name }, { a: 1 }).filter).toEqual({ foo: "bar" });
|
||||||
|
expect(guard.filters(p, { role: r.name }, { a: 2 }).filter).toBeUndefined();
|
||||||
|
// if no user context given, filter cannot be applied
|
||||||
|
expect(guard.filters(p, {}, { a: 1 }).filter).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("collects filters for default role", () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{
|
||||||
|
filterable: true,
|
||||||
|
},
|
||||||
|
s.object({
|
||||||
|
a: s.number(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role(
|
||||||
|
"test",
|
||||||
|
[
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: { a: { $eq: 1 } },
|
||||||
|
filter: { foo: "bar" },
|
||||||
|
effect: "filter",
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
],
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
const guard = new Guard([p], [r], {
|
||||||
|
enabled: true,
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(
|
||||||
|
guard.filters(
|
||||||
|
p,
|
||||||
|
{
|
||||||
|
role: r.name,
|
||||||
|
},
|
||||||
|
{ a: 1 },
|
||||||
|
).filter,
|
||||||
|
).toEqual({ foo: "bar" });
|
||||||
|
expect(
|
||||||
|
guard.filters(
|
||||||
|
p,
|
||||||
|
{
|
||||||
|
role: r.name,
|
||||||
|
},
|
||||||
|
{ a: 2 },
|
||||||
|
).filter,
|
||||||
|
).toBeUndefined();
|
||||||
|
// if no user context given, the default role is applied
|
||||||
|
// hence it can be found
|
||||||
|
expect(guard.filters(p, {}, { a: 1 }).filter).toEqual({ foo: "bar" });
|
||||||
|
});
|
||||||
|
|
||||||
|
it("merges filters correctly", () => {
|
||||||
|
expect(mergeFilters({ foo: "bar" }, { baz: "qux" })).toEqual({
|
||||||
|
foo: { $eq: "bar" },
|
||||||
|
baz: { $eq: "qux" },
|
||||||
|
});
|
||||||
|
expect(mergeFilters({ foo: "bar" }, { baz: { $eq: "qux" } })).toEqual({
|
||||||
|
foo: { $eq: "bar" },
|
||||||
|
baz: { $eq: "qux" },
|
||||||
|
});
|
||||||
|
expect(mergeFilters({ foo: "bar" }, { foo: "baz" })).toEqual({ foo: { $eq: "baz" } });
|
||||||
|
|
||||||
|
expect(mergeFilters({ foo: "bar" }, { foo: { $lt: 1 } })).toEqual({
|
||||||
|
foo: { $eq: "bar", $lt: 1 },
|
||||||
|
});
|
||||||
|
|
||||||
|
// overwrite base $or with priority
|
||||||
|
expect(mergeFilters({ $or: { foo: "one" } }, { foo: "bar" })).toEqual({
|
||||||
|
$or: {
|
||||||
|
foo: {
|
||||||
|
$eq: "bar",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
foo: {
|
||||||
|
$eq: "bar",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
// ignore base $or if priority has different key
|
||||||
|
expect(mergeFilters({ $or: { other: "one" } }, { foo: "bar" })).toEqual({
|
||||||
|
$or: {
|
||||||
|
other: {
|
||||||
|
$eq: "one",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
foo: {
|
||||||
|
$eq: "bar",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("permission middleware", () => {
|
||||||
|
const makeApp = (
|
||||||
|
permissions: Permission<any, any, any, any>[],
|
||||||
|
roles: Role[] = [],
|
||||||
|
config: Partial<GuardConfig> = {},
|
||||||
|
) => {
|
||||||
|
const app = {
|
||||||
|
module: {
|
||||||
|
auth: {
|
||||||
|
enabled: true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
modules: {
|
||||||
|
ctx: () => ({
|
||||||
|
guard: new Guard(permissions, roles, {
|
||||||
|
enabled: true,
|
||||||
|
...config,
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return new Hono()
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("app", app);
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.use(auth())
|
||||||
|
.onError((err, c) => {
|
||||||
|
if (err instanceof Exception) {
|
||||||
|
return c.json(err.toJSON(), err.code as any);
|
||||||
|
}
|
||||||
|
return c.json({ error: err.message }, "code" in err ? (err.code as any) : 500);
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
it("allows if guard is disabled", async () => {
|
||||||
|
const p = new Permission("test");
|
||||||
|
const hono = makeApp([p], [], { enabled: false }).get("/test", permission(p, {}), async (c) =>
|
||||||
|
c.text("test"),
|
||||||
|
);
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(await res.text()).toBe("test");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("denies if guard is enabled", async () => {
|
||||||
|
const p = new Permission("test");
|
||||||
|
const hono = makeApp([p]).get("/test", permission(p, {}), async (c) => c.text("test"));
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(403);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("allows if user has (plain) role", async () => {
|
||||||
|
const p = new Permission("test");
|
||||||
|
const r = Role.create("test", { permissions: [p.name] });
|
||||||
|
const hono = makeApp([p], [r])
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user: { id: 0, role: r.name } });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get("/test", permission(p, {}), async (c) => c.text("test"));
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("allows if user has role with policy", async () => {
|
||||||
|
const p = new Permission("test");
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $gte: 1 },
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
const hono = makeApp([p], [r], {
|
||||||
|
context: {
|
||||||
|
a: 1,
|
||||||
|
},
|
||||||
|
})
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user: { id: 0, role: r.name } });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get("/test", permission(p, {}), async (c) => c.text("test"));
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("denies if user with role doesn't meet condition", async () => {
|
||||||
|
const p = new Permission("test");
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(
|
||||||
|
p,
|
||||||
|
[
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $lt: 1 },
|
||||||
|
},
|
||||||
|
// default effect is allow
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
// change default effect to deny if no condition is met
|
||||||
|
"deny",
|
||||||
|
),
|
||||||
|
]);
|
||||||
|
const hono = makeApp([p], [r], {
|
||||||
|
context: {
|
||||||
|
a: 1,
|
||||||
|
},
|
||||||
|
})
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user: { id: 0, role: r.name } });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get("/test", permission(p, {}), async (c) => c.text("test"));
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(403);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("allows if user with role doesn't meet condition (from middleware)", async () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{},
|
||||||
|
s.object({
|
||||||
|
a: s.number(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $eq: 1 },
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
const hono = makeApp([p], [r])
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user: { id: 0, role: r.name } });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get(
|
||||||
|
"/test",
|
||||||
|
permission(p, {
|
||||||
|
context: (c) => ({
|
||||||
|
a: 1,
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
);
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("throws if permission context is invalid", async () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{},
|
||||||
|
s.object({
|
||||||
|
a: s.number({ minimum: 2 }),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $eq: 1 },
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
const hono = makeApp([p], [r])
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user: { id: 0, role: r.name } });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get(
|
||||||
|
"/test",
|
||||||
|
permission(p, {
|
||||||
|
context: (c) => ({
|
||||||
|
a: 1,
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
);
|
||||||
|
|
||||||
|
const res = await hono.request("/test");
|
||||||
|
// expecting 500 because bknd should have handled it correctly
|
||||||
|
expect(res.status).toBe(500);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("checks context on routes with permissions", async () => {
|
||||||
|
const make = (user: any) => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{},
|
||||||
|
s.object({
|
||||||
|
a: s.number(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role("test", [
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $eq: 1 },
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
return makeApp([p], [r])
|
||||||
|
.use(async (c, next) => {
|
||||||
|
// @ts-expect-error
|
||||||
|
c.set("auth", { registered: true, user });
|
||||||
|
await next();
|
||||||
|
})
|
||||||
|
.get(
|
||||||
|
"/valid",
|
||||||
|
permission(p, {
|
||||||
|
context: (c) => ({
|
||||||
|
a: 1,
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
)
|
||||||
|
.get(
|
||||||
|
"/invalid",
|
||||||
|
permission(p, {
|
||||||
|
// @ts-expect-error
|
||||||
|
context: (c) => ({
|
||||||
|
b: "1",
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
)
|
||||||
|
.get(
|
||||||
|
"/invalid2",
|
||||||
|
permission(p, {
|
||||||
|
// @ts-expect-error
|
||||||
|
context: (c) => ({}),
|
||||||
|
}),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
)
|
||||||
|
.get(
|
||||||
|
"/invalid3",
|
||||||
|
// @ts-expect-error
|
||||||
|
permission(p),
|
||||||
|
async (c) => c.text("test"),
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
const hono = make({ id: 0, role: "test" });
|
||||||
|
const valid = await hono.request("/valid");
|
||||||
|
expect(valid.status).toBe(200);
|
||||||
|
const invalid = await hono.request("/invalid");
|
||||||
|
expect(invalid.status).toBe(500);
|
||||||
|
const invalid2 = await hono.request("/invalid2");
|
||||||
|
expect(invalid2.status).toBe(500);
|
||||||
|
const invalid3 = await hono.request("/invalid3");
|
||||||
|
expect(invalid3.status).toBe(500);
|
||||||
|
|
||||||
|
{
|
||||||
|
const hono = make(null);
|
||||||
|
const valid = await hono.request("/valid");
|
||||||
|
expect(valid.status).toBe(403);
|
||||||
|
const invalid = await hono.request("/invalid");
|
||||||
|
expect(invalid.status).toBe(500);
|
||||||
|
const invalid2 = await hono.request("/invalid2");
|
||||||
|
expect(invalid2.status).toBe(500);
|
||||||
|
const invalid3 = await hono.request("/invalid3");
|
||||||
|
expect(invalid3.status).toBe(500);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("Role", () => {
|
||||||
|
it("serializes and deserializes", () => {
|
||||||
|
const p = new Permission(
|
||||||
|
"test",
|
||||||
|
{
|
||||||
|
filterable: true,
|
||||||
|
},
|
||||||
|
s.object({
|
||||||
|
a: s.number({ minimum: 2 }),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const r = new Role(
|
||||||
|
"test",
|
||||||
|
[
|
||||||
|
new RolePermission(p, [
|
||||||
|
new Policy({
|
||||||
|
condition: {
|
||||||
|
a: { $eq: 1 },
|
||||||
|
},
|
||||||
|
effect: "deny",
|
||||||
|
filter: {
|
||||||
|
b: { $lt: 1 },
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]),
|
||||||
|
],
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
const json = JSON.parse(JSON.stringify(r.toJSON()));
|
||||||
|
const r2 = Role.create(p.name, json);
|
||||||
|
expect(r2.toJSON()).toEqual(r.toJSON());
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -66,4 +66,14 @@ describe("object-query", () => {
|
|||||||
expect(result).toBe(expected);
|
expect(result).toBe(expected);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("paths", () => {
|
||||||
|
const result = validate({ "user.age": { $lt: 18 } }, { user: { age: 17 } });
|
||||||
|
expect(result).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("empty filters", () => {
|
||||||
|
const result = validate({}, { user: { age: 17 } });
|
||||||
|
expect(result).toBe(true);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -0,0 +1,120 @@
|
|||||||
|
import { describe, expect, test } from "bun:test";
|
||||||
|
import {
|
||||||
|
makeValidator,
|
||||||
|
exp,
|
||||||
|
Expression,
|
||||||
|
isPrimitive,
|
||||||
|
type Primitive,
|
||||||
|
} from "../../../src/core/object/query/query";
|
||||||
|
|
||||||
|
describe("query", () => {
|
||||||
|
test("isPrimitive", () => {
|
||||||
|
expect(isPrimitive(1)).toBe(true);
|
||||||
|
expect(isPrimitive("1")).toBe(true);
|
||||||
|
expect(isPrimitive(true)).toBe(true);
|
||||||
|
expect(isPrimitive(false)).toBe(true);
|
||||||
|
|
||||||
|
// not primitives
|
||||||
|
expect(isPrimitive(null)).toBe(false);
|
||||||
|
expect(isPrimitive(undefined)).toBe(false);
|
||||||
|
expect(isPrimitive([])).toBe(false);
|
||||||
|
expect(isPrimitive({})).toBe(false);
|
||||||
|
expect(isPrimitive(Symbol("test"))).toBe(false);
|
||||||
|
expect(isPrimitive(new Date())).toBe(false);
|
||||||
|
expect(isPrimitive(new Error())).toBe(false);
|
||||||
|
expect(isPrimitive(new Set())).toBe(false);
|
||||||
|
expect(isPrimitive(new Map())).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("strict expression creation", () => {
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp()).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("")).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("invalid")).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("$eq")).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("$eq", 1)).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("$eq", () => null)).toThrow();
|
||||||
|
// @ts-expect-error
|
||||||
|
expect(() => exp("$eq", () => null, 1)).toThrow();
|
||||||
|
expect(
|
||||||
|
exp(
|
||||||
|
"$eq",
|
||||||
|
() => true,
|
||||||
|
() => null,
|
||||||
|
),
|
||||||
|
).toBeInstanceOf(Expression);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("$eq is required", () => {
|
||||||
|
expect(() => makeValidator([])).toThrow();
|
||||||
|
expect(() =>
|
||||||
|
makeValidator([
|
||||||
|
exp(
|
||||||
|
"$valid",
|
||||||
|
() => true,
|
||||||
|
() => null,
|
||||||
|
),
|
||||||
|
]),
|
||||||
|
).toThrow();
|
||||||
|
expect(
|
||||||
|
makeValidator([
|
||||||
|
exp(
|
||||||
|
"$eq",
|
||||||
|
() => true,
|
||||||
|
() => null,
|
||||||
|
),
|
||||||
|
]),
|
||||||
|
).toBeDefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("validates filter structure", () => {
|
||||||
|
const validator = makeValidator([
|
||||||
|
exp(
|
||||||
|
"$eq",
|
||||||
|
(v: Primitive) => isPrimitive(v),
|
||||||
|
(e, a) => e === a,
|
||||||
|
),
|
||||||
|
exp(
|
||||||
|
"$like",
|
||||||
|
(v: string) => typeof v === "string",
|
||||||
|
(e, a) => e === a,
|
||||||
|
),
|
||||||
|
]);
|
||||||
|
|
||||||
|
// @ts-expect-error intentionally typed as union of given expression keys
|
||||||
|
expect(validator.expressionKeys).toEqual(["$eq", "$like"]);
|
||||||
|
|
||||||
|
// @ts-expect-error "$and" is not allowed
|
||||||
|
expect(() => validator.convert({ $and: {} })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error "$or" must be an object
|
||||||
|
expect(() => validator.convert({ $or: [] })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error "invalid" is not a valid expression key
|
||||||
|
expect(() => validator.convert({ foo: { invalid: "bar" } })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error "invalid" is not a valid expression key
|
||||||
|
expect(() => validator.convert({ foo: { $invalid: "bar" } })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error "null" is not a valid value
|
||||||
|
expect(() => validator.convert({ foo: null })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error only primitives are allowed for $eq
|
||||||
|
expect(() => validator.convert({ foo: { $eq: [] } })).toThrow();
|
||||||
|
|
||||||
|
// @ts-expect-error only strings are allowed for $like
|
||||||
|
expect(() => validator.convert({ foo: { $like: 1 } })).toThrow();
|
||||||
|
|
||||||
|
// undefined values are ignored
|
||||||
|
expect(validator.convert({ foo: undefined })).toEqual({});
|
||||||
|
|
||||||
|
expect(validator.convert({ foo: "bar" })).toEqual({ foo: { $eq: "bar" } });
|
||||||
|
expect(validator.convert({ foo: { $eq: "bar" } })).toEqual({ foo: { $eq: "bar" } });
|
||||||
|
expect(validator.convert({ foo: { $like: "bar" } })).toEqual({ foo: { $like: "bar" } });
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -194,6 +194,182 @@ describe("Core Utils", async () => {
|
|||||||
expect(result).toEqual(expected);
|
expect(result).toEqual(expected);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("recursivelyReplacePlaceholders", () => {
|
||||||
|
// test basic replacement with simple pattern
|
||||||
|
const obj1 = { a: "Hello, {$name}!", b: { c: "Hello, {$name}!" } };
|
||||||
|
const variables1 = { name: "John" };
|
||||||
|
const result1 = utils.recursivelyReplacePlaceholders(obj1, /\{\$(\w+)\}/g, variables1);
|
||||||
|
expect(result1).toEqual({ a: "Hello, John!", b: { c: "Hello, John!" } });
|
||||||
|
|
||||||
|
// test the specific example from the user request
|
||||||
|
const obj2 = { some: "value", here: "@auth.user" };
|
||||||
|
const variables2 = { auth: { user: "what" } };
|
||||||
|
const result2 = utils.recursivelyReplacePlaceholders(obj2, /^@([a-z\.]+)$/, variables2);
|
||||||
|
expect(result2).toEqual({ some: "value", here: "what" });
|
||||||
|
|
||||||
|
// test with arrays
|
||||||
|
const obj3 = { items: ["@config.name", "static", "@config.version"] };
|
||||||
|
const variables3 = { config: { name: "MyApp", version: "1.0.0" } };
|
||||||
|
const result3 = utils.recursivelyReplacePlaceholders(obj3, /^@([a-z\.]+)$/, variables3);
|
||||||
|
expect(result3).toEqual({ items: ["MyApp", "static", "1.0.0"] });
|
||||||
|
|
||||||
|
// test with nested objects and deep paths
|
||||||
|
const obj4 = {
|
||||||
|
user: "@auth.user.name",
|
||||||
|
settings: {
|
||||||
|
theme: "@ui.theme",
|
||||||
|
nested: {
|
||||||
|
value: "@deep.nested.value",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
const variables4 = {
|
||||||
|
auth: { user: { name: "Alice" } },
|
||||||
|
ui: { theme: "dark" },
|
||||||
|
deep: { nested: { value: "found" } },
|
||||||
|
};
|
||||||
|
const result4 = utils.recursivelyReplacePlaceholders(obj4, /^@([a-z\.]+)$/, variables4);
|
||||||
|
expect(result4).toEqual({
|
||||||
|
user: "Alice",
|
||||||
|
settings: {
|
||||||
|
theme: "dark",
|
||||||
|
nested: {
|
||||||
|
value: "found",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
// test with missing paths (should return original match)
|
||||||
|
const obj5 = { value: "@missing.path" };
|
||||||
|
const variables5 = { existing: "value" };
|
||||||
|
const result5 = utils.recursivelyReplacePlaceholders(obj5, /^@([a-z\.]+)$/, variables5);
|
||||||
|
expect(result5).toEqual({ value: "@missing.path" });
|
||||||
|
|
||||||
|
// test with non-matching strings (should remain unchanged)
|
||||||
|
const obj6 = { value: "normal string", other: "not@matching" };
|
||||||
|
const variables6 = { some: "value" };
|
||||||
|
const result6 = utils.recursivelyReplacePlaceholders(obj6, /^@([a-z\.]+)$/, variables6);
|
||||||
|
expect(result6).toEqual({ value: "normal string", other: "not@matching" });
|
||||||
|
|
||||||
|
// test with primitive values (should handle gracefully)
|
||||||
|
expect(
|
||||||
|
utils.recursivelyReplacePlaceholders("@test.value", /^@([a-z\.]+)$/, {
|
||||||
|
test: { value: "replaced" },
|
||||||
|
}),
|
||||||
|
).toBe("replaced");
|
||||||
|
expect(utils.recursivelyReplacePlaceholders(123, /^@([a-z\.]+)$/, {})).toBe(123);
|
||||||
|
expect(utils.recursivelyReplacePlaceholders(null, /^@([a-z\.]+)$/, {})).toBe(null);
|
||||||
|
|
||||||
|
// test type preservation for full string matches
|
||||||
|
const variables7 = { test: { value: 123, flag: true, data: null, arr: [1, 2, 3] } };
|
||||||
|
const result7 = utils.recursivelyReplacePlaceholders(
|
||||||
|
{
|
||||||
|
number: "@test.value",
|
||||||
|
boolean: "@test.flag",
|
||||||
|
nullValue: "@test.data",
|
||||||
|
array: "@test.arr",
|
||||||
|
},
|
||||||
|
/^@([a-z\.]+)$/,
|
||||||
|
variables7,
|
||||||
|
null,
|
||||||
|
);
|
||||||
|
expect(result7).toEqual({
|
||||||
|
number: 123,
|
||||||
|
boolean: true,
|
||||||
|
nullValue: null,
|
||||||
|
array: [1, 2, 3],
|
||||||
|
});
|
||||||
|
|
||||||
|
// test partial string replacement (should convert to string)
|
||||||
|
const result8 = utils.recursivelyReplacePlaceholders(
|
||||||
|
{ message: "The value is @test.value!" },
|
||||||
|
/@([a-z\.]+)/g,
|
||||||
|
variables7,
|
||||||
|
);
|
||||||
|
expect(result8).toEqual({ message: "The value is 123!" });
|
||||||
|
|
||||||
|
// test with fallback parameter
|
||||||
|
const obj9 = { user: "@user.id", config: "@config.theme" };
|
||||||
|
const variables9 = {}; // empty context
|
||||||
|
const result9 = utils.recursivelyReplacePlaceholders(
|
||||||
|
obj9,
|
||||||
|
/^@([a-z\.]+)$/,
|
||||||
|
variables9,
|
||||||
|
null,
|
||||||
|
);
|
||||||
|
expect(result9).toEqual({ user: null, config: null });
|
||||||
|
|
||||||
|
// test with fallback for partial matches
|
||||||
|
const obj10 = { message: "Hello @user.name, welcome!" };
|
||||||
|
const variables10 = {}; // empty context
|
||||||
|
const result10 = utils.recursivelyReplacePlaceholders(
|
||||||
|
obj10,
|
||||||
|
/@([a-z\.]+)/g,
|
||||||
|
variables10,
|
||||||
|
"Guest",
|
||||||
|
);
|
||||||
|
expect(result10).toEqual({ message: "Hello Guest, welcome!" });
|
||||||
|
|
||||||
|
// test with different fallback types
|
||||||
|
const obj11 = {
|
||||||
|
stringFallback: "@missing.string",
|
||||||
|
numberFallback: "@missing.number",
|
||||||
|
booleanFallback: "@missing.boolean",
|
||||||
|
objectFallback: "@missing.object",
|
||||||
|
};
|
||||||
|
const variables11 = {};
|
||||||
|
const result11 = utils.recursivelyReplacePlaceholders(
|
||||||
|
obj11,
|
||||||
|
/^@([a-z\.]+)$/,
|
||||||
|
variables11,
|
||||||
|
"default",
|
||||||
|
);
|
||||||
|
expect(result11).toEqual({
|
||||||
|
stringFallback: "default",
|
||||||
|
numberFallback: "default",
|
||||||
|
booleanFallback: "default",
|
||||||
|
objectFallback: "default",
|
||||||
|
});
|
||||||
|
|
||||||
|
// test fallback with arrays
|
||||||
|
const obj12 = { items: ["@item1", "@item2", "static"] };
|
||||||
|
const variables12 = { item1: "found" }; // item2 is missing
|
||||||
|
const result12 = utils.recursivelyReplacePlaceholders(
|
||||||
|
obj12,
|
||||||
|
/^@([a-zA-Z0-9\.]+)$/,
|
||||||
|
variables12,
|
||||||
|
"missing",
|
||||||
|
);
|
||||||
|
expect(result12).toEqual({ items: ["found", "missing", "static"] });
|
||||||
|
|
||||||
|
// test fallback with nested objects
|
||||||
|
const obj13 = {
|
||||||
|
user: "@user.id",
|
||||||
|
settings: {
|
||||||
|
theme: "@theme.name",
|
||||||
|
nested: {
|
||||||
|
value: "@deep.value",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
const variables13 = {}; // empty context
|
||||||
|
const result13 = utils.recursivelyReplacePlaceholders(
|
||||||
|
obj13,
|
||||||
|
/^@([a-z\.]+)$/,
|
||||||
|
variables13,
|
||||||
|
null,
|
||||||
|
);
|
||||||
|
expect(result13).toEqual({
|
||||||
|
user: null,
|
||||||
|
settings: {
|
||||||
|
theme: null,
|
||||||
|
nested: {
|
||||||
|
value: null,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("file", async () => {
|
describe("file", async () => {
|
||||||
@@ -264,6 +440,35 @@ describe("Core Utils", async () => {
|
|||||||
height: 512,
|
height: 512,
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("isFileAccepted", () => {
|
||||||
|
const file = new File([""], "file.txt", {
|
||||||
|
type: "text/plain",
|
||||||
|
});
|
||||||
|
expect(utils.isFileAccepted(file, "text/plain")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, "text/plain,text/html")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, "text/html")).toBe(false);
|
||||||
|
|
||||||
|
{
|
||||||
|
const file = new File([""], "file.jpg", {
|
||||||
|
type: "image/jpeg",
|
||||||
|
});
|
||||||
|
expect(utils.isFileAccepted(file, "image/jpeg")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, "image/jpeg,image/png")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, "image/png")).toBe(false);
|
||||||
|
expect(utils.isFileAccepted(file, "image/*")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, ".jpg")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, ".jpg,.png")).toBe(true);
|
||||||
|
expect(utils.isFileAccepted(file, ".png")).toBe(false);
|
||||||
|
}
|
||||||
|
|
||||||
|
{
|
||||||
|
const file = new File([""], "file.png");
|
||||||
|
expect(utils.isFileAccepted(file, undefined as any)).toBe(true);
|
||||||
|
}
|
||||||
|
|
||||||
|
expect(() => utils.isFileAccepted(null as any, "text/plain")).toThrow();
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("dates", () => {
|
describe("dates", () => {
|
||||||
|
|||||||
@@ -30,9 +30,9 @@ describe("some tests", async () => {
|
|||||||
const query = await em.repository(users).findId(1);
|
const query = await em.repository(users).findId(1);
|
||||||
|
|
||||||
expect(query.sql).toBe(
|
expect(query.sql).toBe(
|
||||||
'select "users"."id" as "id", "users"."username" as "username", "users"."email" as "email" from "users" where "id" = ? limit ?',
|
'select "users"."id" as "id", "users"."username" as "username", "users"."email" as "email" from "users" where "id" = ? order by "users"."id" asc limit ? offset ?',
|
||||||
);
|
);
|
||||||
expect(query.parameters).toEqual([1, 1]);
|
expect(query.parameters).toEqual([1, 1, 0]);
|
||||||
expect(query.data).toBeUndefined();
|
expect(query.data).toBeUndefined();
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,85 @@
|
|||||||
|
import { describe, beforeAll, afterAll, test } from "bun:test";
|
||||||
|
import type { PostgresConnection } from "data/connection/postgres/PostgresConnection";
|
||||||
|
import { pg, postgresJs } from "bknd";
|
||||||
|
import { Pool } from "pg";
|
||||||
|
import postgres from "postgres";
|
||||||
|
import { disableConsoleLog, enableConsoleLog, $waitUntil } from "bknd/utils";
|
||||||
|
import { $ } from "bun";
|
||||||
|
import { connectionTestSuite } from "data/connection/connection-test-suite";
|
||||||
|
import { bunTestRunner } from "adapter/bun/test";
|
||||||
|
|
||||||
|
const credentials = {
|
||||||
|
host: "localhost",
|
||||||
|
port: 5430,
|
||||||
|
user: "postgres",
|
||||||
|
password: "postgres",
|
||||||
|
database: "bknd",
|
||||||
|
};
|
||||||
|
|
||||||
|
async function cleanDatabase(connection: InstanceType<typeof PostgresConnection>) {
|
||||||
|
const kysely = connection.kysely;
|
||||||
|
|
||||||
|
// drop all tables+indexes & create new schema
|
||||||
|
await kysely.schema.dropSchema("public").ifExists().cascade().execute();
|
||||||
|
await kysely.schema.dropIndex("public").ifExists().cascade().execute();
|
||||||
|
await kysely.schema.createSchema("public").execute();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function isPostgresRunning() {
|
||||||
|
try {
|
||||||
|
// Try to actually connect to PostgreSQL
|
||||||
|
const conn = pg({ pool: new Pool(credentials) });
|
||||||
|
await conn.ping();
|
||||||
|
await conn.close();
|
||||||
|
return true;
|
||||||
|
} catch (e) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("postgres", () => {
|
||||||
|
beforeAll(async () => {
|
||||||
|
if (!(await isPostgresRunning())) {
|
||||||
|
await $`docker run --rm --name bknd-test-postgres -d -e POSTGRES_PASSWORD=${credentials.password} -e POSTGRES_USER=${credentials.user} -e POSTGRES_DB=${credentials.database} -p ${credentials.port}:5432 postgres:17`;
|
||||||
|
await $waitUntil("Postgres is running", isPostgresRunning);
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 500));
|
||||||
|
}
|
||||||
|
|
||||||
|
disableConsoleLog();
|
||||||
|
});
|
||||||
|
afterAll(async () => {
|
||||||
|
if (await isPostgresRunning()) {
|
||||||
|
try {
|
||||||
|
await $`docker stop bknd-test-postgres`;
|
||||||
|
} catch (e) {}
|
||||||
|
}
|
||||||
|
|
||||||
|
enableConsoleLog();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe.serial.each([
|
||||||
|
["pg", () => pg({ pool: new Pool(credentials) })],
|
||||||
|
["postgresjs", () => postgresJs({ postgres: postgres(credentials) })],
|
||||||
|
])("%s", (name, createConnection) => {
|
||||||
|
connectionTestSuite(
|
||||||
|
{
|
||||||
|
...bunTestRunner,
|
||||||
|
test: test.serial,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
makeConnection: () => {
|
||||||
|
const connection = createConnection();
|
||||||
|
return {
|
||||||
|
connection,
|
||||||
|
dispose: async () => {
|
||||||
|
await cleanDatabase(connection);
|
||||||
|
await connection.close();
|
||||||
|
},
|
||||||
|
};
|
||||||
|
},
|
||||||
|
rawDialectDetails: [],
|
||||||
|
disableConsoleLog: false,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -124,6 +124,81 @@ describe("[Repository]", async () => {
|
|||||||
.then((r) => [r.count, r.total]),
|
.then((r) => [r.count, r.total]),
|
||||||
).resolves.toEqual([undefined, undefined]);
|
).resolves.toEqual([undefined, undefined]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("auto join", async () => {
|
||||||
|
const schema = $em(
|
||||||
|
{
|
||||||
|
posts: $entity("posts", {
|
||||||
|
title: $text(),
|
||||||
|
content: $text(),
|
||||||
|
}),
|
||||||
|
comments: $entity("comments", {
|
||||||
|
content: $text(),
|
||||||
|
}),
|
||||||
|
another: $entity("another", {
|
||||||
|
title: $text(),
|
||||||
|
}),
|
||||||
|
},
|
||||||
|
({ relation }, { posts, comments }) => {
|
||||||
|
relation(comments).manyToOne(posts);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
const em = schema.proto.withConnection(getDummyConnection().dummyConnection);
|
||||||
|
await em.schema().sync({ force: true });
|
||||||
|
|
||||||
|
await em.mutator("posts").insertOne({ title: "post1", content: "content1" });
|
||||||
|
await em
|
||||||
|
.mutator("comments")
|
||||||
|
.insertMany([{ content: "comment1", posts_id: 1 }, { content: "comment2" }] as any);
|
||||||
|
|
||||||
|
const res = await em.repo("comments").findMany({
|
||||||
|
where: {
|
||||||
|
"posts.title": "post1",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(res.data as any).toEqual([
|
||||||
|
{
|
||||||
|
id: 1,
|
||||||
|
content: "comment1",
|
||||||
|
posts_id: 1,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
|
||||||
|
{
|
||||||
|
// manual join should still work
|
||||||
|
const res = await em.repo("comments").findMany({
|
||||||
|
join: ["posts"],
|
||||||
|
where: {
|
||||||
|
"posts.title": "post1",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(res.data as any).toEqual([
|
||||||
|
{
|
||||||
|
id: 1,
|
||||||
|
content: "comment1",
|
||||||
|
posts_id: 1,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
// inexistent should be detected and thrown
|
||||||
|
expect(
|
||||||
|
em.repo("comments").findMany({
|
||||||
|
where: {
|
||||||
|
"random.title": "post1",
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
).rejects.toThrow(/Invalid where field/);
|
||||||
|
|
||||||
|
// existing alias, but not a relation should throw
|
||||||
|
expect(
|
||||||
|
em.repo("comments").findMany({
|
||||||
|
where: {
|
||||||
|
"another.title": "post1",
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
).rejects.toThrow(/Invalid where field/);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("[data] Repository (Events)", async () => {
|
describe("[data] Repository (Events)", async () => {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
// eslint-disable-next-line import/no-unresolved
|
// eslint-disable-next-line import/no-unresolved
|
||||||
import { afterAll, describe, expect, test } from "bun:test";
|
import { afterAll, describe, expect, spyOn, test } from "bun:test";
|
||||||
import { randomString } from "core/utils";
|
import { randomString } from "core/utils";
|
||||||
import { Entity, EntityManager } from "data/entities";
|
import { Entity, EntityManager } from "data/entities";
|
||||||
import { TextField, EntityIndex } from "data/fields";
|
import { TextField, EntityIndex } from "data/fields";
|
||||||
@@ -268,4 +268,39 @@ describe("SchemaManager tests", async () => {
|
|||||||
const diffAfter = await em.schema().getDiff();
|
const diffAfter = await em.schema().getDiff();
|
||||||
expect(diffAfter.length).toBe(0);
|
expect(diffAfter.length).toBe(0);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("returns statements", async () => {
|
||||||
|
const amount = 5;
|
||||||
|
const entities = new Array(amount)
|
||||||
|
.fill(0)
|
||||||
|
.map(() => new Entity(randomString(16), [new TextField("text")]));
|
||||||
|
const em = new EntityManager(entities, dummyConnection);
|
||||||
|
const statements = await em.schema().sync({ force: true });
|
||||||
|
expect(statements.length).toBe(amount);
|
||||||
|
expect(statements.every((stmt) => Object.keys(stmt).join(",") === "sql,parameters")).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("batches statements", async () => {
|
||||||
|
const { dummyConnection } = getDummyConnection();
|
||||||
|
const entities = new Array(20)
|
||||||
|
.fill(0)
|
||||||
|
.map(() => new Entity(randomString(16), [new TextField("text")]));
|
||||||
|
const em = new EntityManager(entities, dummyConnection);
|
||||||
|
const spy = spyOn(em.connection, "executeQueries");
|
||||||
|
const statements = await em.schema().sync();
|
||||||
|
expect(statements.length).toBe(entities.length);
|
||||||
|
expect(statements.every((stmt) => Object.keys(stmt).join(",") === "sql,parameters")).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
await em.schema().sync({ force: true });
|
||||||
|
expect(spy).toHaveBeenCalledTimes(1);
|
||||||
|
const tables = await em.connection.kysely
|
||||||
|
.selectFrom("sqlite_master")
|
||||||
|
.where("type", "=", "table")
|
||||||
|
.selectAll()
|
||||||
|
.execute();
|
||||||
|
expect(tables.length).toBe(entities.length + 1); /* 1+ for sqlite_sequence */
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -59,7 +59,7 @@ describe("SqliteIntrospector", () => {
|
|||||||
dataType: "INTEGER",
|
dataType: "INTEGER",
|
||||||
isNullable: false,
|
isNullable: false,
|
||||||
isAutoIncrementing: true,
|
isAutoIncrementing: true,
|
||||||
hasDefaultValue: false,
|
hasDefaultValue: true,
|
||||||
comment: undefined,
|
comment: undefined,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -89,7 +89,7 @@ describe("SqliteIntrospector", () => {
|
|||||||
dataType: "INTEGER",
|
dataType: "INTEGER",
|
||||||
isNullable: false,
|
isNullable: false,
|
||||||
isAutoIncrementing: true,
|
isAutoIncrementing: true,
|
||||||
hasDefaultValue: false,
|
hasDefaultValue: true,
|
||||||
comment: undefined,
|
comment: undefined,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ describe("[data] JsonField", async () => {
|
|||||||
const field = new JsonField("test");
|
const field = new JsonField("test");
|
||||||
fieldTestSuite(bunTestRunner, JsonField, {
|
fieldTestSuite(bunTestRunner, JsonField, {
|
||||||
defaultValue: { a: 1 },
|
defaultValue: { a: 1 },
|
||||||
sampleValues: ["string", { test: 1 }, 1],
|
//sampleValues: ["string", { test: 1 }, 1],
|
||||||
schemaType: "text",
|
schemaType: "text",
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -33,9 +33,9 @@ describe("[data] JsonField", async () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
test("getValue", async () => {
|
test("getValue", async () => {
|
||||||
expect(field.getValue({ test: 1 }, "form")).toBe('{\n "test": 1\n}');
|
expect(field.getValue({ test: 1 }, "form")).toEqual({ test: 1 });
|
||||||
expect(field.getValue("string", "form")).toBe('"string"');
|
expect(field.getValue("string", "form")).toBe("string");
|
||||||
expect(field.getValue(1, "form")).toBe("1");
|
expect(field.getValue(1, "form")).toBe(1);
|
||||||
|
|
||||||
expect(field.getValue('{"test":1}', "submit")).toEqual({ test: 1 });
|
expect(field.getValue('{"test":1}', "submit")).toEqual({ test: 1 });
|
||||||
expect(field.getValue('"string"', "submit")).toBe("string");
|
expect(field.getValue('"string"', "submit")).toBe("string");
|
||||||
@@ -43,6 +43,5 @@ describe("[data] JsonField", async () => {
|
|||||||
|
|
||||||
expect(field.getValue({ test: 1 }, "table")).toBe('{"test":1}');
|
expect(field.getValue({ test: 1 }, "table")).toBe('{"test":1}');
|
||||||
expect(field.getValue("string", "table")).toBe('"string"');
|
expect(field.getValue("string", "table")).toBe('"string"');
|
||||||
expect(field.getValue(1, "form")).toBe("1");
|
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { afterAll, beforeAll, describe, expect, it } from "bun:test";
|
import { afterAll, beforeAll, describe, expect, it } from "bun:test";
|
||||||
import { App, createApp, type AuthResponse } from "../../src";
|
import { App, createApp, type AuthResponse } from "../../src";
|
||||||
import { auth } from "../../src/auth/middlewares";
|
import { auth } from "../../src/modules/middlewares";
|
||||||
import { randomString, secureRandomString, withDisabledConsole } from "../../src/core/utils";
|
import { randomString, secureRandomString, withDisabledConsole } from "../../src/core/utils";
|
||||||
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
import { getDummyConnection } from "../helper";
|
import { getDummyConnection } from "../helper";
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ import { assetsPath, assetsTmpPath } from "../helper";
|
|||||||
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
beforeAll(() => {
|
beforeAll(() => {
|
||||||
//disableConsoleLog();
|
disableConsoleLog();
|
||||||
registries.media.register("local", StorageLocalAdapter);
|
registries.media.register("local", StorageLocalAdapter);
|
||||||
});
|
});
|
||||||
afterAll(enableConsoleLog);
|
afterAll(enableConsoleLog);
|
||||||
|
|||||||
@@ -10,12 +10,6 @@ beforeAll(disableConsoleLog);
|
|||||||
afterAll(enableConsoleLog);
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
describe("AppAuth", () => {
|
describe("AppAuth", () => {
|
||||||
test.skip("...", () => {
|
|
||||||
const auth = new AppAuth({});
|
|
||||||
console.log(auth.toJSON());
|
|
||||||
console.log(auth.config);
|
|
||||||
});
|
|
||||||
|
|
||||||
moduleTestSuite(AppAuth);
|
moduleTestSuite(AppAuth);
|
||||||
|
|
||||||
let ctx: ModuleBuildContext;
|
let ctx: ModuleBuildContext;
|
||||||
@@ -39,11 +33,9 @@ describe("AppAuth", () => {
|
|||||||
await auth.build();
|
await auth.build();
|
||||||
|
|
||||||
const oldConfig = auth.toJSON(true);
|
const oldConfig = auth.toJSON(true);
|
||||||
//console.log(oldConfig);
|
|
||||||
await auth.schema().patch("enabled", true);
|
await auth.schema().patch("enabled", true);
|
||||||
await auth.build();
|
await auth.build();
|
||||||
const newConfig = auth.toJSON(true);
|
const newConfig = auth.toJSON(true);
|
||||||
//console.log(newConfig);
|
|
||||||
expect(newConfig.jwt.secret).not.toBe(oldConfig.jwt.secret);
|
expect(newConfig.jwt.secret).not.toBe(oldConfig.jwt.secret);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -69,7 +61,6 @@ describe("AppAuth", () => {
|
|||||||
const app = new AuthController(auth).getController();
|
const app = new AuthController(auth).getController();
|
||||||
|
|
||||||
{
|
{
|
||||||
disableConsoleLog();
|
|
||||||
const res = await app.request("/password/register", {
|
const res = await app.request("/password/register", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: {
|
headers: {
|
||||||
@@ -80,7 +71,6 @@ describe("AppAuth", () => {
|
|||||||
password: "12345678",
|
password: "12345678",
|
||||||
}),
|
}),
|
||||||
});
|
});
|
||||||
enableConsoleLog();
|
|
||||||
expect(res.status).toBe(200);
|
expect(res.status).toBe(200);
|
||||||
|
|
||||||
const { data: users } = await ctx.em.repository("users").findMany();
|
const { data: users } = await ctx.em.repository("users").findMany();
|
||||||
@@ -119,7 +109,6 @@ describe("AppAuth", () => {
|
|||||||
const app = new AuthController(auth).getController();
|
const app = new AuthController(auth).getController();
|
||||||
|
|
||||||
{
|
{
|
||||||
disableConsoleLog();
|
|
||||||
const res = await app.request("/password/register", {
|
const res = await app.request("/password/register", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
headers: {
|
headers: {
|
||||||
@@ -130,7 +119,6 @@ describe("AppAuth", () => {
|
|||||||
password: "12345678",
|
password: "12345678",
|
||||||
}),
|
}),
|
||||||
});
|
});
|
||||||
enableConsoleLog();
|
|
||||||
expect(res.status).toBe(200);
|
expect(res.status).toBe(200);
|
||||||
|
|
||||||
const { data: users } = await ctx.em.repository("users").findMany();
|
const { data: users } = await ctx.em.repository("users").findMany();
|
||||||
|
|||||||
@@ -1,10 +1,14 @@
|
|||||||
import { describe, expect, test } from "bun:test";
|
import { describe, expect, test, beforeAll, afterAll } from "bun:test";
|
||||||
import { createApp } from "core/test/utils";
|
import { createApp } from "core/test/utils";
|
||||||
import { em, entity, text } from "data/prototype";
|
import { em, entity, text } from "data/prototype";
|
||||||
import { registries } from "modules/registries";
|
import { registries } from "modules/registries";
|
||||||
import { StorageLocalAdapter } from "adapter/node/storage/StorageLocalAdapter";
|
import { StorageLocalAdapter } from "adapter/node/storage/StorageLocalAdapter";
|
||||||
import { AppMedia } from "../../src/media/AppMedia";
|
import { AppMedia } from "../../src/media/AppMedia";
|
||||||
import { moduleTestSuite } from "./module-test-suite";
|
import { moduleTestSuite } from "./module-test-suite";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
describe("AppMedia", () => {
|
describe("AppMedia", () => {
|
||||||
test.skip("...", () => {
|
test.skip("...", () => {
|
||||||
|
|||||||
@@ -1,7 +1,11 @@
|
|||||||
import { it, expect, describe } from "bun:test";
|
import { it, expect, describe, beforeAll, afterAll } from "bun:test";
|
||||||
import { DbModuleManager } from "modules/db/DbModuleManager";
|
import { DbModuleManager } from "modules/db/DbModuleManager";
|
||||||
import { getDummyConnection } from "../helper";
|
import { getDummyConnection } from "../helper";
|
||||||
import { TABLE_NAME } from "modules/db/migrations";
|
import { TABLE_NAME } from "modules/db/migrations";
|
||||||
|
import { disableConsoleLog, enableConsoleLog } from "core/utils/test";
|
||||||
|
|
||||||
|
beforeAll(disableConsoleLog);
|
||||||
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
describe("DbModuleManager", () => {
|
describe("DbModuleManager", () => {
|
||||||
it("should extract secrets", async () => {
|
it("should extract secrets", async () => {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ import { s, stripMark } from "core/utils/schema";
|
|||||||
import { Connection } from "data/connection/Connection";
|
import { Connection } from "data/connection/Connection";
|
||||||
import { entity, text } from "data/prototype";
|
import { entity, text } from "data/prototype";
|
||||||
|
|
||||||
beforeAll(disableConsoleLog);
|
beforeAll(() => disableConsoleLog());
|
||||||
afterAll(enableConsoleLog);
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
describe("ModuleManager", async () => {
|
describe("ModuleManager", async () => {
|
||||||
@@ -82,7 +82,6 @@ describe("ModuleManager", async () => {
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
} as any;
|
} as any;
|
||||||
//const { version, ...json } = mm.toJSON() as any;
|
|
||||||
|
|
||||||
const { dummyConnection } = getDummyConnection();
|
const { dummyConnection } = getDummyConnection();
|
||||||
const db = dummyConnection.kysely;
|
const db = dummyConnection.kysely;
|
||||||
@@ -97,10 +96,6 @@ describe("ModuleManager", async () => {
|
|||||||
|
|
||||||
await mm2.build();
|
await mm2.build();
|
||||||
|
|
||||||
/* console.log({
|
|
||||||
json,
|
|
||||||
configs: mm2.configs(),
|
|
||||||
}); */
|
|
||||||
//expect(stripMark(json)).toEqual(stripMark(mm2.configs()));
|
//expect(stripMark(json)).toEqual(stripMark(mm2.configs()));
|
||||||
expect(mm2.configs().data.entities?.test).toBeDefined();
|
expect(mm2.configs().data.entities?.test).toBeDefined();
|
||||||
expect(mm2.configs().data.entities?.test?.fields?.content).toBeDefined();
|
expect(mm2.configs().data.entities?.test?.fields?.content).toBeDefined();
|
||||||
@@ -228,8 +223,6 @@ describe("ModuleManager", async () => {
|
|||||||
const c = getDummyConnection();
|
const c = getDummyConnection();
|
||||||
const mm = new ModuleManager(c.dummyConnection);
|
const mm = new ModuleManager(c.dummyConnection);
|
||||||
await mm.build();
|
await mm.build();
|
||||||
console.log("==".repeat(30));
|
|
||||||
console.log("");
|
|
||||||
const json = mm.configs();
|
const json = mm.configs();
|
||||||
|
|
||||||
const c2 = getDummyConnection();
|
const c2 = getDummyConnection();
|
||||||
@@ -275,7 +268,6 @@ describe("ModuleManager", async () => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
override async build() {
|
override async build() {
|
||||||
//console.log("building FailingModule", this.config);
|
|
||||||
if (this.config.value && this.config.value < 0) {
|
if (this.config.value && this.config.value < 0) {
|
||||||
throw new Error("value must be positive, given: " + this.config.value);
|
throw new Error("value must be positive, given: " + this.config.value);
|
||||||
}
|
}
|
||||||
@@ -296,9 +288,6 @@ describe("ModuleManager", async () => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
beforeEach(() => disableConsoleLog(["log", "warn", "error"]));
|
|
||||||
afterEach(enableConsoleLog);
|
|
||||||
|
|
||||||
test("it builds", async () => {
|
test("it builds", async () => {
|
||||||
const { dummyConnection } = getDummyConnection();
|
const { dummyConnection } = getDummyConnection();
|
||||||
const mm = new TestModuleManager(dummyConnection);
|
const mm = new TestModuleManager(dummyConnection);
|
||||||
|
|||||||
+12
-21
@@ -1,29 +1,19 @@
|
|||||||
import pkg from "./package.json" with { type: "json" };
|
import pkg from "./package.json" with { type: "json" };
|
||||||
import c from "picocolors";
|
import c from "picocolors";
|
||||||
import { formatNumber } from "bknd/utils";
|
import { formatNumber } from "bknd/utils";
|
||||||
import * as esbuild from "esbuild";
|
|
||||||
|
|
||||||
const deps = Object.keys(pkg.dependencies);
|
const deps = Object.keys(pkg.dependencies);
|
||||||
const external = ["jsonv-ts/*", "wrangler", "bknd", "bknd/*", ...deps];
|
const external = [
|
||||||
|
"jsonv-ts/*",
|
||||||
if (process.env.DEBUG) {
|
"wrangler",
|
||||||
const result = await esbuild.build({
|
"bknd",
|
||||||
entryPoints: ["./src/cli/index.ts"],
|
"bknd/*",
|
||||||
outdir: "./dist/cli",
|
"@vitejs/plugin-react",
|
||||||
platform: "node",
|
"vite",
|
||||||
minify: true,
|
"@tailwindcss/vite",
|
||||||
format: "esm",
|
"@cloudflare/vite-plugin",
|
||||||
metafile: true,
|
...deps,
|
||||||
bundle: true,
|
];
|
||||||
external,
|
|
||||||
define: {
|
|
||||||
__isDev: "0",
|
|
||||||
__version: JSON.stringify(pkg.version),
|
|
||||||
},
|
|
||||||
});
|
|
||||||
await Bun.write("./dist/cli/metafile-esm.json", JSON.stringify(result.metafile, null, 2));
|
|
||||||
process.exit(0);
|
|
||||||
}
|
|
||||||
|
|
||||||
const result = await Bun.build({
|
const result = await Bun.build({
|
||||||
entrypoints: ["./src/cli/index.ts"],
|
entrypoints: ["./src/cli/index.ts"],
|
||||||
@@ -31,6 +21,7 @@ const result = await Bun.build({
|
|||||||
outdir: "./dist/cli",
|
outdir: "./dist/cli",
|
||||||
env: "PUBLIC_*",
|
env: "PUBLIC_*",
|
||||||
minify: true,
|
minify: true,
|
||||||
|
banner: `const __originalLog=console.log;console.log=(...o)=>{const n=o[0];"string"==typeof n&&n.includes("[dotenv@")||__originalLog.apply(console,o)};`,
|
||||||
external,
|
external,
|
||||||
define: {
|
define: {
|
||||||
__isDev: "0",
|
__isDev: "0",
|
||||||
|
|||||||
+16
-1
@@ -85,12 +85,18 @@ async function buildApi() {
|
|||||||
sourcemap,
|
sourcemap,
|
||||||
watch,
|
watch,
|
||||||
define,
|
define,
|
||||||
entry: ["src/index.ts", "src/core/utils/index.ts", "src/plugins/index.ts"],
|
entry: [
|
||||||
|
"src/index.ts",
|
||||||
|
"src/core/utils/index.ts",
|
||||||
|
"src/plugins/index.ts",
|
||||||
|
"src/modes/index.ts",
|
||||||
|
],
|
||||||
outDir: "dist",
|
outDir: "dist",
|
||||||
external: [...external],
|
external: [...external],
|
||||||
metafile: true,
|
metafile: true,
|
||||||
target: "esnext",
|
target: "esnext",
|
||||||
platform: "browser",
|
platform: "browser",
|
||||||
|
removeNodeProtocol: false,
|
||||||
format: ["esm"],
|
format: ["esm"],
|
||||||
splitting: false,
|
splitting: false,
|
||||||
loader: {
|
loader: {
|
||||||
@@ -180,6 +186,9 @@ async function buildUiElements() {
|
|||||||
outDir: "dist/ui/elements",
|
outDir: "dist/ui/elements",
|
||||||
external: [
|
external: [
|
||||||
"ui/client",
|
"ui/client",
|
||||||
|
"bknd",
|
||||||
|
/^bknd\/.*/,
|
||||||
|
"wouter",
|
||||||
"react",
|
"react",
|
||||||
"react-dom",
|
"react-dom",
|
||||||
"react/jsx-runtime",
|
"react/jsx-runtime",
|
||||||
@@ -223,6 +232,7 @@ function baseConfig(adapter: string, overrides: Partial<tsup.Options> = {}): tsu
|
|||||||
outDir: `dist/adapter/${adapter}`,
|
outDir: `dist/adapter/${adapter}`,
|
||||||
metafile: true,
|
metafile: true,
|
||||||
splitting: false,
|
splitting: false,
|
||||||
|
removeNodeProtocol: false,
|
||||||
onSuccess: async () => {
|
onSuccess: async () => {
|
||||||
delayTypes();
|
delayTypes();
|
||||||
oldConsole.log(c.cyan("[Adapter]"), adapter || "base", c.green("built"));
|
oldConsole.log(c.cyan("[Adapter]"), adapter || "base", c.green("built"));
|
||||||
@@ -258,6 +268,11 @@ async function buildAdapters() {
|
|||||||
|
|
||||||
// specific adatpers
|
// specific adatpers
|
||||||
tsup.build(baseConfig("react-router")),
|
tsup.build(baseConfig("react-router")),
|
||||||
|
tsup.build(
|
||||||
|
baseConfig("browser", {
|
||||||
|
external: [/^sqlocal\/?.*?/, "wouter"],
|
||||||
|
}),
|
||||||
|
),
|
||||||
tsup.build(
|
tsup.build(
|
||||||
baseConfig("bun", {
|
baseConfig("bun", {
|
||||||
external: [/^bun\:.*/],
|
external: [/^bun\:.*/],
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
[install]
|
|
||||||
#registry = "http://localhost:4873"
|
|
||||||
|
|
||||||
[test]
|
|
||||||
coverageSkipTestFiles = true
|
|
||||||
console.depth = 10
|
|
||||||
@@ -3,11 +3,14 @@ import { createApp } from "bknd/adapter/bun";
|
|||||||
async function generate() {
|
async function generate() {
|
||||||
console.info("Generating MCP documentation...");
|
console.info("Generating MCP documentation...");
|
||||||
const app = await createApp({
|
const app = await createApp({
|
||||||
|
connection: {
|
||||||
|
url: ":memory:",
|
||||||
|
},
|
||||||
config: {
|
config: {
|
||||||
server: {
|
server: {
|
||||||
mcp: {
|
mcp: {
|
||||||
enabled: true,
|
enabled: true,
|
||||||
path: "/mcp",
|
path: "/mcp2",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
auth: {
|
auth: {
|
||||||
@@ -25,9 +28,9 @@ async function generate() {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
await app.build();
|
await app.build();
|
||||||
|
await app.getMcpClient().ping();
|
||||||
|
|
||||||
const res = await app.server.request("/mcp?explain=1");
|
const { tools, resources } = app.mcp!.toJSON();
|
||||||
const { tools, resources } = await res.json();
|
|
||||||
await Bun.write("../docs/mcp.json", JSON.stringify({ tools, resources }, null, 2));
|
await Bun.write("../docs/mcp.json", JSON.stringify({ tools, resources }, null, 2));
|
||||||
|
|
||||||
console.info("MCP documentation generated.");
|
console.info("MCP documentation generated.");
|
||||||
|
|||||||
+71
-50
@@ -3,7 +3,7 @@
|
|||||||
"type": "module",
|
"type": "module",
|
||||||
"sideEffects": false,
|
"sideEffects": false,
|
||||||
"bin": "./dist/cli/index.js",
|
"bin": "./dist/cli/index.js",
|
||||||
"version": "0.18.1",
|
"version": "0.20.0-rc.1",
|
||||||
"description": "Lightweight Firebase/Supabase alternative built to run anywhere — incl. Next.js, React Router, Astro, Cloudflare, Bun, Node, AWS Lambda & more.",
|
"description": "Lightweight Firebase/Supabase alternative built to run anywhere — incl. Next.js, React Router, Astro, Cloudflare, Bun, Node, AWS Lambda & more.",
|
||||||
"homepage": "https://bknd.io",
|
"homepage": "https://bknd.io",
|
||||||
"repository": {
|
"repository": {
|
||||||
@@ -13,7 +13,7 @@
|
|||||||
"bugs": {
|
"bugs": {
|
||||||
"url": "https://github.com/bknd-io/bknd/issues"
|
"url": "https://github.com/bknd-io/bknd/issues"
|
||||||
},
|
},
|
||||||
"packageManager": "bun@1.2.22",
|
"packageManager": "bun@1.3.3",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=22.13"
|
"node": ">=22.13"
|
||||||
},
|
},
|
||||||
@@ -49,93 +49,104 @@
|
|||||||
"license": "FSL-1.1-MIT",
|
"license": "FSL-1.1-MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@cfworker/json-schema": "^4.1.1",
|
"@cfworker/json-schema": "^4.1.1",
|
||||||
"@codemirror/lang-html": "^6.4.9",
|
"@codemirror/lang-html": "^6.4.11",
|
||||||
"@codemirror/lang-json": "^6.0.1",
|
"@codemirror/lang-json": "^6.0.2",
|
||||||
"@hello-pangea/dnd": "^18.0.1",
|
"@hello-pangea/dnd": "^18.0.1",
|
||||||
"@hono/swagger-ui": "^0.5.1",
|
"@hono/swagger-ui": "^0.5.2",
|
||||||
"@mantine/core": "^7.17.1",
|
"@mantine/core": "^7.17.1",
|
||||||
"@mantine/hooks": "^7.17.1",
|
"@mantine/hooks": "^7.17.1",
|
||||||
"@tanstack/react-form": "^1.0.5",
|
"@tanstack/react-form": "^1.0.5",
|
||||||
"@uiw/react-codemirror": "^4.23.10",
|
"@uiw/react-codemirror": "^4.25.2",
|
||||||
"@xyflow/react": "^12.4.4",
|
"@xyflow/react": "^12.9.2",
|
||||||
"aws4fetch": "^1.0.20",
|
"aws4fetch": "^1.0.20",
|
||||||
"bcryptjs": "^3.0.2",
|
"bcryptjs": "^3.0.3",
|
||||||
"dayjs": "^1.11.13",
|
"dayjs": "^1.11.19",
|
||||||
"fast-xml-parser": "^5.0.8",
|
"fast-xml-parser": "^5.3.1",
|
||||||
"hono": "4.8.3",
|
"hono": "4.10.4",
|
||||||
"json-schema-library": "10.0.0-rc7",
|
"json-schema-library": "10.0.0-rc7",
|
||||||
"json-schema-to-ts": "^3.1.1",
|
"json-schema-to-ts": "^3.1.1",
|
||||||
"jsonv-ts": "0.8.5",
|
"jsonv-ts": "^0.10.1",
|
||||||
"kysely": "0.27.6",
|
"kysely": "0.28.8",
|
||||||
"lodash-es": "^4.17.21",
|
"lodash-es": "^4.17.21",
|
||||||
"oauth4webapi": "^2.11.1",
|
"oauth4webapi": "^2.11.1",
|
||||||
"object-path-immutable": "^4.1.2",
|
"object-path-immutable": "^4.1.2",
|
||||||
"radix-ui": "^1.1.3",
|
|
||||||
"picocolors": "^1.1.1",
|
"picocolors": "^1.1.1",
|
||||||
"swr": "^2.3.3"
|
"radix-ui": "^1.1.3",
|
||||||
|
"swr": "^2.3.6",
|
||||||
|
"use-sync-external-store": "^1.6.0",
|
||||||
|
"zustand": "^4"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@aws-sdk/client-s3": "^3.758.0",
|
"@aws-sdk/client-s3": "^3.922.0",
|
||||||
"@bluwy/giget-core": "^0.1.2",
|
"@bluwy/giget-core": "^0.1.6",
|
||||||
"@clack/prompts": "^0.11.0",
|
"@clack/prompts": "^0.11.0",
|
||||||
"@cloudflare/vitest-pool-workers": "^0.9.3",
|
"@cloudflare/vite-plugin": "^1.15.3",
|
||||||
"@cloudflare/workers-types": "^4.20250606.0",
|
"@cloudflare/vitest-pool-workers": "^0.10.4",
|
||||||
|
"@cloudflare/workers-types": "^4.20251014.0",
|
||||||
"@dagrejs/dagre": "^1.1.4",
|
"@dagrejs/dagre": "^1.1.4",
|
||||||
"@hono/vite-dev-server": "^0.21.0",
|
"@hono/vite-dev-server": "^0.23.0",
|
||||||
"@hookform/resolvers": "^4.1.3",
|
"@hookform/resolvers": "^5.2.2",
|
||||||
"@libsql/client": "^0.15.9",
|
"@libsql/client": "^0.15.15",
|
||||||
"@mantine/modals": "^7.17.1",
|
"@mantine/modals": "^7.17.1",
|
||||||
"@mantine/notifications": "^7.17.1",
|
"@mantine/notifications": "^7.17.1",
|
||||||
"@playwright/test": "^1.51.1",
|
"@playwright/test": "^1.56.1",
|
||||||
"@rjsf/core": "5.22.2",
|
"@rjsf/core": "5.22.2",
|
||||||
|
"@rjsf/utils": "5.22.0",
|
||||||
"@standard-schema/spec": "^1.0.0",
|
"@standard-schema/spec": "^1.0.0",
|
||||||
"@tabler/icons-react": "3.18.0",
|
"@tabler/icons-react": "3.35.0",
|
||||||
"@tailwindcss/postcss": "^4.0.12",
|
"@tailwindcss/postcss": "^4.1.16",
|
||||||
"@tailwindcss/vite": "^4.0.12",
|
"@tailwindcss/vite": "^4.1.16",
|
||||||
|
"@tanstack/react-store": "^0.8.0",
|
||||||
"@testing-library/jest-dom": "^6.6.3",
|
"@testing-library/jest-dom": "^6.6.3",
|
||||||
"@testing-library/react": "^16.2.0",
|
"@testing-library/react": "^16.2.0",
|
||||||
"@types/node": "^22.13.10",
|
"@types/node": "^24.10.0",
|
||||||
|
"@types/pg": "^8.15.6",
|
||||||
"@types/react": "^19.0.10",
|
"@types/react": "^19.0.10",
|
||||||
"@types/react-dom": "^19.0.4",
|
"@types/react-dom": "^19.0.4",
|
||||||
"@vitejs/plugin-react": "^4.3.4",
|
"@vitejs/plugin-react": "^5.1.0",
|
||||||
"@vitest/coverage-v8": "^3.0.9",
|
"@vitest/coverage-v8": "3.0.9",
|
||||||
"autoprefixer": "^10.4.21",
|
"autoprefixer": "^10.4.21",
|
||||||
"clsx": "^2.1.1",
|
"clsx": "^2.1.1",
|
||||||
"dotenv": "^16.4.7",
|
"commander": "^14.0.2",
|
||||||
|
"dotenv": "^17.2.3",
|
||||||
"jotai": "^2.12.2",
|
"jotai": "^2.12.2",
|
||||||
"jsdom": "^26.0.0",
|
"jsdom": "^26.1.0",
|
||||||
"kysely-d1": "^0.3.0",
|
|
||||||
"kysely-generic-sqlite": "^1.2.1",
|
"kysely-generic-sqlite": "^1.2.1",
|
||||||
|
"kysely-postgres-js": "^2.0.0",
|
||||||
|
"libsql": "^0.5.22",
|
||||||
"libsql-stateless-easy": "^1.8.0",
|
"libsql-stateless-easy": "^1.8.0",
|
||||||
"open": "^10.1.0",
|
"miniflare": "^4.20251011.2",
|
||||||
|
"open": "^10.2.0",
|
||||||
"openapi-types": "^12.1.3",
|
"openapi-types": "^12.1.3",
|
||||||
|
"pg": "^8.16.3",
|
||||||
"postcss": "^8.5.3",
|
"postcss": "^8.5.3",
|
||||||
"postcss-preset-mantine": "^1.17.0",
|
"postcss-preset-mantine": "^1.18.0",
|
||||||
"postcss-simple-vars": "^7.0.1",
|
"postcss-simple-vars": "^7.0.1",
|
||||||
"posthog-js-lite": "^3.4.2",
|
"postgres": "^3.4.7",
|
||||||
|
"posthog-js-lite": "^3.6.0",
|
||||||
"react": "^19.0.0",
|
"react": "^19.0.0",
|
||||||
"react-dom": "^19.0.0",
|
"react-dom": "^19.0.0",
|
||||||
"react-hook-form": "^7.54.2",
|
"react-hook-form": "^7.66.0",
|
||||||
"react-icons": "5.2.1",
|
"react-icons": "5.5.0",
|
||||||
"react-json-view-lite": "^2.4.1",
|
"react-json-view-lite": "^2.5.0",
|
||||||
"sql-formatter": "^15.4.11",
|
"sql-formatter": "^15.6.10",
|
||||||
|
"sqlocal": "^0.16.0",
|
||||||
"tailwind-merge": "^3.0.2",
|
"tailwind-merge": "^3.0.2",
|
||||||
"tailwindcss": "^4.0.12",
|
"tailwindcss": "^4.1.16",
|
||||||
"tailwindcss-animate": "^1.0.7",
|
"tailwindcss-animate": "^1.0.7",
|
||||||
"tsc-alias": "^1.8.11",
|
"tsc-alias": "^1.8.16",
|
||||||
"tsup": "^8.4.0",
|
"tsup": "^8.5.0",
|
||||||
"tsx": "^4.19.3",
|
"tsx": "^4.20.6",
|
||||||
"uuid": "^11.1.0",
|
"uuid": "^13.0.0",
|
||||||
"vite": "^6.3.5",
|
"vite": "^7.1.12",
|
||||||
"vite-plugin-circular-dependency": "^0.5.0",
|
"vite-plugin-circular-dependency": "^0.5.0",
|
||||||
"vite-tsconfig-paths": "^5.1.4",
|
"vite-tsconfig-paths": "^5.1.4",
|
||||||
"vitest": "^3.0.9",
|
"vitest": "3.0.9",
|
||||||
"wouter": "^3.6.0",
|
"wouter": "^3.7.1",
|
||||||
"wrangler": "^4.37.1",
|
"wrangler": "^4.52.1"
|
||||||
"miniflare": "^4.20250913.0"
|
|
||||||
},
|
},
|
||||||
"optionalDependencies": {
|
"optionalDependencies": {
|
||||||
"@hono/node-server": "^1.14.3"
|
"@hono/node-server": "^1.19.6"
|
||||||
},
|
},
|
||||||
"peerDependencies": {
|
"peerDependencies": {
|
||||||
"react": ">=19",
|
"react": ">=19",
|
||||||
@@ -180,6 +191,11 @@
|
|||||||
"import": "./dist/plugins/index.js",
|
"import": "./dist/plugins/index.js",
|
||||||
"require": "./dist/plugins/index.js"
|
"require": "./dist/plugins/index.js"
|
||||||
},
|
},
|
||||||
|
"./modes": {
|
||||||
|
"types": "./dist/types/modes/index.d.ts",
|
||||||
|
"import": "./dist/modes/index.js",
|
||||||
|
"require": "./dist/modes/index.js"
|
||||||
|
},
|
||||||
"./adapter/sqlite": {
|
"./adapter/sqlite": {
|
||||||
"types": "./dist/types/adapter/sqlite/edge.d.ts",
|
"types": "./dist/types/adapter/sqlite/edge.d.ts",
|
||||||
"import": {
|
"import": {
|
||||||
@@ -243,6 +259,11 @@
|
|||||||
"import": "./dist/adapter/aws/index.js",
|
"import": "./dist/adapter/aws/index.js",
|
||||||
"require": "./dist/adapter/aws/index.js"
|
"require": "./dist/adapter/aws/index.js"
|
||||||
},
|
},
|
||||||
|
"./adapter/browser": {
|
||||||
|
"types": "./dist/types/adapter/browser/index.d.ts",
|
||||||
|
"import": "./dist/adapter/browser/index.js",
|
||||||
|
"require": "./dist/adapter/browser/index.js"
|
||||||
|
},
|
||||||
"./dist/main.css": "./dist/ui/main.css",
|
"./dist/main.css": "./dist/ui/main.css",
|
||||||
"./dist/styles.css": "./dist/ui/styles.css",
|
"./dist/styles.css": "./dist/ui/styles.css",
|
||||||
"./dist/manifest.json": "./dist/static/.vite/manifest.json",
|
"./dist/manifest.json": "./dist/static/.vite/manifest.json",
|
||||||
|
|||||||
+47
-33
@@ -40,6 +40,7 @@ export type ApiOptions = {
|
|||||||
data?: SubApiOptions<DataApiOptions>;
|
data?: SubApiOptions<DataApiOptions>;
|
||||||
auth?: SubApiOptions<AuthApiOptions>;
|
auth?: SubApiOptions<AuthApiOptions>;
|
||||||
media?: SubApiOptions<MediaApiOptions>;
|
media?: SubApiOptions<MediaApiOptions>;
|
||||||
|
credentials?: RequestCredentials;
|
||||||
} & (
|
} & (
|
||||||
| {
|
| {
|
||||||
token?: string;
|
token?: string;
|
||||||
@@ -60,14 +61,14 @@ export class Api {
|
|||||||
private token?: string;
|
private token?: string;
|
||||||
private user?: TApiUser;
|
private user?: TApiUser;
|
||||||
private verified = false;
|
private verified = false;
|
||||||
private token_transport: "header" | "cookie" | "none" = "header";
|
public token_transport: "header" | "cookie" | "none" = "header";
|
||||||
|
|
||||||
public system!: SystemApi;
|
public system!: SystemApi;
|
||||||
public data!: DataApi;
|
public data!: DataApi;
|
||||||
public auth!: AuthApi;
|
public auth!: AuthApi;
|
||||||
public media!: MediaApi;
|
public media!: MediaApi;
|
||||||
|
|
||||||
constructor(private options: ApiOptions = {}) {
|
constructor(public options: ApiOptions = {}) {
|
||||||
// only mark verified if forced
|
// only mark verified if forced
|
||||||
this.verified = options.verified === true;
|
this.verified = options.verified === true;
|
||||||
|
|
||||||
@@ -129,29 +130,45 @@ export class Api {
|
|||||||
} else if (this.storage) {
|
} else if (this.storage) {
|
||||||
this.storage.getItem(this.tokenKey).then((token) => {
|
this.storage.getItem(this.tokenKey).then((token) => {
|
||||||
this.token_transport = "header";
|
this.token_transport = "header";
|
||||||
this.updateToken(token ? String(token) : undefined);
|
this.updateToken(token ? String(token) : undefined, {
|
||||||
|
verified: true,
|
||||||
|
trigger: false,
|
||||||
|
});
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Make storage async to allow async storages even if sync given
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
private get storage() {
|
private get storage() {
|
||||||
if (!this.options.storage) return null;
|
const storage = this.options.storage;
|
||||||
return {
|
return new Proxy(
|
||||||
getItem: async (key: string) => {
|
{},
|
||||||
return await this.options.storage!.getItem(key);
|
{
|
||||||
|
get(_, prop) {
|
||||||
|
return (...args: any[]) => {
|
||||||
|
const response = storage ? storage[prop](...args) : undefined;
|
||||||
|
if (response instanceof Promise) {
|
||||||
|
return response;
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
// biome-ignore lint/suspicious/noThenProperty: it's a promise :)
|
||||||
|
then: (fn) => fn(response),
|
||||||
|
};
|
||||||
|
};
|
||||||
|
},
|
||||||
},
|
},
|
||||||
setItem: async (key: string, value: string) => {
|
) as any;
|
||||||
return await this.options.storage!.setItem(key, value);
|
|
||||||
},
|
|
||||||
removeItem: async (key: string) => {
|
|
||||||
return await this.options.storage!.removeItem(key);
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
|
||||||
updateToken(token?: string, opts?: { rebuild?: boolean; trigger?: boolean }) {
|
updateToken(
|
||||||
|
token?: string,
|
||||||
|
opts?: { rebuild?: boolean; verified?: boolean; trigger?: boolean },
|
||||||
|
) {
|
||||||
this.token = token;
|
this.token = token;
|
||||||
this.verified = false;
|
this.verified = opts?.verified === true;
|
||||||
|
|
||||||
if (token) {
|
if (token) {
|
||||||
this.user = omitKeys(decode(token).payload as any, ["iat", "iss", "exp"]) as any;
|
this.user = omitKeys(decode(token).payload as any, ["iat", "iss", "exp"]) as any;
|
||||||
@@ -159,21 +176,22 @@ export class Api {
|
|||||||
this.user = undefined;
|
this.user = undefined;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const emit = () => {
|
||||||
|
if (opts?.trigger !== false) {
|
||||||
|
this.options.onAuthStateChange?.(this.getAuthState());
|
||||||
|
}
|
||||||
|
};
|
||||||
if (this.storage) {
|
if (this.storage) {
|
||||||
const key = this.tokenKey;
|
const key = this.tokenKey;
|
||||||
|
|
||||||
if (token) {
|
if (token) {
|
||||||
this.storage.setItem(key, token).then(() => {
|
this.storage.setItem(key, token).then(emit);
|
||||||
this.options.onAuthStateChange?.(this.getAuthState());
|
|
||||||
});
|
|
||||||
} else {
|
} else {
|
||||||
this.storage.removeItem(key).then(() => {
|
this.storage.removeItem(key).then(emit);
|
||||||
this.options.onAuthStateChange?.(this.getAuthState());
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if (opts?.trigger !== false) {
|
if (opts?.trigger !== false) {
|
||||||
this.options.onAuthStateChange?.(this.getAuthState());
|
emit();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -182,6 +200,7 @@ export class Api {
|
|||||||
|
|
||||||
private markAuthVerified(verfied: boolean) {
|
private markAuthVerified(verfied: boolean) {
|
||||||
this.verified = verfied;
|
this.verified = verfied;
|
||||||
|
this.options.onAuthStateChange?.(this.getAuthState());
|
||||||
return this;
|
return this;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -208,11 +227,6 @@ export class Api {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async verifyAuth() {
|
async verifyAuth() {
|
||||||
if (!this.token) {
|
|
||||||
this.markAuthVerified(false);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const { ok, data } = await this.auth.me();
|
const { ok, data } = await this.auth.me();
|
||||||
const user = data?.user;
|
const user = data?.user;
|
||||||
@@ -221,10 +235,10 @@ export class Api {
|
|||||||
}
|
}
|
||||||
|
|
||||||
this.user = user;
|
this.user = user;
|
||||||
this.markAuthVerified(true);
|
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
this.markAuthVerified(false);
|
|
||||||
this.updateToken(undefined);
|
this.updateToken(undefined);
|
||||||
|
} finally {
|
||||||
|
this.markAuthVerified(true);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -239,6 +253,7 @@ export class Api {
|
|||||||
headers: this.options.headers,
|
headers: this.options.headers,
|
||||||
token_transport: this.token_transport,
|
token_transport: this.token_transport,
|
||||||
verbose: this.options.verbose,
|
verbose: this.options.verbose,
|
||||||
|
credentials: this.options.credentials,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -257,10 +272,9 @@ export class Api {
|
|||||||
this.auth = new AuthApi(
|
this.auth = new AuthApi(
|
||||||
{
|
{
|
||||||
...baseParams,
|
...baseParams,
|
||||||
credentials: this.options.storage ? "omit" : "include",
|
|
||||||
...this.options.auth,
|
...this.options.auth,
|
||||||
onTokenUpdate: (token) => {
|
onTokenUpdate: (token, verified) => {
|
||||||
this.updateToken(token, { rebuild: true });
|
this.updateToken(token, { rebuild: true, verified, trigger: true });
|
||||||
this.options.auth?.onTokenUpdate?.(token);
|
this.options.auth?.onTokenUpdate?.(token);
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
+8
-5
@@ -5,7 +5,6 @@ import type { em as prototypeEm } from "data/prototype";
|
|||||||
import { Connection } from "data/connection/Connection";
|
import { Connection } from "data/connection/Connection";
|
||||||
import type { Hono } from "hono";
|
import type { Hono } from "hono";
|
||||||
import {
|
import {
|
||||||
type InitialModuleConfigs,
|
|
||||||
type ModuleConfigs,
|
type ModuleConfigs,
|
||||||
type Modules,
|
type Modules,
|
||||||
ModuleManager,
|
ModuleManager,
|
||||||
@@ -245,9 +244,8 @@ export class App<
|
|||||||
|
|
||||||
get fetch(): Hono["fetch"] {
|
get fetch(): Hono["fetch"] {
|
||||||
if (!this.isBuilt()) {
|
if (!this.isBuilt()) {
|
||||||
throw new Error("App is not built yet, run build() first");
|
console.error("App is not built yet, run build() first");
|
||||||
}
|
}
|
||||||
|
|
||||||
return this.server.fetch as any;
|
return this.server.fetch as any;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -296,6 +294,7 @@ export class App<
|
|||||||
return this.module.auth.createUser(p);
|
return this.module.auth.createUser(p);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// @todo: potentially add option to clone the app, so that when used in listeners, it won't trigger listeners
|
||||||
getApi(options?: LocalApiOptions) {
|
getApi(options?: LocalApiOptions) {
|
||||||
const fetcher = this.server.request as typeof fetch;
|
const fetcher = this.server.request as typeof fetch;
|
||||||
if (options && options instanceof Request) {
|
if (options && options instanceof Request) {
|
||||||
@@ -311,8 +310,9 @@ export class App<
|
|||||||
throw new Error("MCP is not enabled");
|
throw new Error("MCP is not enabled");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const url = new URL(config.path, "http://localhost").toString();
|
||||||
return new McpClient({
|
return new McpClient({
|
||||||
url: "http://localhost" + config.path,
|
url,
|
||||||
fetch: this.server.request,
|
fetch: this.server.request,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -380,11 +380,14 @@ export class App<
|
|||||||
if (results.length > 0) {
|
if (results.length > 0) {
|
||||||
for (const { name, result } of results) {
|
for (const { name, result } of results) {
|
||||||
if (result) {
|
if (result) {
|
||||||
$console.log(`[Plugin:${name}] schema`);
|
|
||||||
ctx.helper.ensureSchema(result);
|
ctx.helper.ensureSchema(result);
|
||||||
|
if (ctx.flags.sync_required) {
|
||||||
|
$console.log(`[Plugin:${name}] schema, sync required`);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
await this.options?.manager?.onModulesBuilt?.(ctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -8,12 +8,15 @@ export type AstroBkndConfig<Env = AstroEnv> = FrameworkBkndConfig<Env>;
|
|||||||
|
|
||||||
export async function getApp<Env = AstroEnv>(
|
export async function getApp<Env = AstroEnv>(
|
||||||
config: AstroBkndConfig<Env> = {},
|
config: AstroBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = import.meta.env as Env,
|
||||||
) {
|
) {
|
||||||
return await createFrameworkApp(config, args ?? import.meta.env);
|
return await createFrameworkApp(config, args);
|
||||||
}
|
}
|
||||||
|
|
||||||
export function serve<Env = AstroEnv>(config: AstroBkndConfig<Env> = {}, args: Env = {} as Env) {
|
export function serve<Env = AstroEnv>(
|
||||||
|
config: AstroBkndConfig<Env> = {},
|
||||||
|
args: Env = import.meta.env as Env,
|
||||||
|
) {
|
||||||
return async (fnArgs: TAstro) => {
|
return async (fnArgs: TAstro) => {
|
||||||
return (await getApp(config, args)).fetch(fnArgs.request);
|
return (await getApp(config, args)).fetch(fnArgs.request);
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,153 @@
|
|||||||
|
import {
|
||||||
|
createContext,
|
||||||
|
lazy,
|
||||||
|
Suspense,
|
||||||
|
useContext,
|
||||||
|
useEffect,
|
||||||
|
useState,
|
||||||
|
type ReactNode,
|
||||||
|
} from "react";
|
||||||
|
import { checksum } from "bknd/utils";
|
||||||
|
import { App, registries, sqlocal, type BkndConfig } from "bknd";
|
||||||
|
import { Route, Router, Switch } from "wouter";
|
||||||
|
import { ClientProvider } from "bknd/client";
|
||||||
|
import { SQLocalKysely } from "sqlocal/kysely";
|
||||||
|
import type { ClientConfig, DatabasePath } from "sqlocal";
|
||||||
|
import { OpfsStorageAdapter } from "bknd/adapter/browser";
|
||||||
|
import type { BkndAdminConfig } from "bknd/ui";
|
||||||
|
|
||||||
|
const Admin = lazy(() =>
|
||||||
|
Promise.all([
|
||||||
|
import("bknd/ui"),
|
||||||
|
// @ts-ignore
|
||||||
|
import("bknd/dist/styles.css"),
|
||||||
|
]).then(([mod]) => ({
|
||||||
|
default: mod.Admin,
|
||||||
|
})),
|
||||||
|
);
|
||||||
|
|
||||||
|
function safeViewTransition(fn: () => void) {
|
||||||
|
if (document.startViewTransition) {
|
||||||
|
document.startViewTransition(fn);
|
||||||
|
} else {
|
||||||
|
fn();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export type BrowserBkndConfig<Args = ImportMetaEnv> = Omit<
|
||||||
|
BkndConfig<Args>,
|
||||||
|
"connection" | "app"
|
||||||
|
> & {
|
||||||
|
adminConfig?: BkndAdminConfig;
|
||||||
|
connection?: ClientConfig | DatabasePath;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type BkndBrowserAppProps = {
|
||||||
|
children: ReactNode;
|
||||||
|
header?: ReactNode;
|
||||||
|
loading?: ReactNode;
|
||||||
|
notFound?: ReactNode;
|
||||||
|
} & BrowserBkndConfig;
|
||||||
|
|
||||||
|
const BkndBrowserAppContext = createContext<{
|
||||||
|
app: App;
|
||||||
|
hash: string;
|
||||||
|
}>(undefined!);
|
||||||
|
|
||||||
|
export function BkndBrowserApp({
|
||||||
|
children,
|
||||||
|
adminConfig,
|
||||||
|
header,
|
||||||
|
loading,
|
||||||
|
notFound,
|
||||||
|
...config
|
||||||
|
}: BkndBrowserAppProps) {
|
||||||
|
const [app, setApp] = useState<App | undefined>(undefined);
|
||||||
|
const [hash, setHash] = useState<string>("");
|
||||||
|
const adminRoutePath = (adminConfig?.basepath ?? "") + "/*?";
|
||||||
|
|
||||||
|
async function onBuilt(app: App) {
|
||||||
|
safeViewTransition(async () => {
|
||||||
|
setApp(app);
|
||||||
|
setHash(await checksum(app.toJSON()));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
setup({ ...config, adminConfig })
|
||||||
|
.then((app) => onBuilt(app as any))
|
||||||
|
.catch(console.error);
|
||||||
|
}, []);
|
||||||
|
|
||||||
|
if (!app) {
|
||||||
|
return (
|
||||||
|
loading ?? (
|
||||||
|
<Center>
|
||||||
|
<span style={{ opacity: 0.2 }}>Loading...</span>
|
||||||
|
</Center>
|
||||||
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return (
|
||||||
|
<BkndBrowserAppContext.Provider value={{ app, hash }}>
|
||||||
|
<ClientProvider storage={window.localStorage} fetcher={app.server.request}>
|
||||||
|
{header}
|
||||||
|
<Router key={hash}>
|
||||||
|
<Switch>
|
||||||
|
{children}
|
||||||
|
|
||||||
|
<Route path={adminRoutePath}>
|
||||||
|
<Suspense>
|
||||||
|
<Admin config={adminConfig} />
|
||||||
|
</Suspense>
|
||||||
|
</Route>
|
||||||
|
<Route path="*">
|
||||||
|
{notFound ?? (
|
||||||
|
<Center style={{ fontSize: "48px", fontFamily: "monospace" }}>404</Center>
|
||||||
|
)}
|
||||||
|
</Route>
|
||||||
|
</Switch>
|
||||||
|
</Router>
|
||||||
|
</ClientProvider>
|
||||||
|
</BkndBrowserAppContext.Provider>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function useApp() {
|
||||||
|
return useContext(BkndBrowserAppContext);
|
||||||
|
}
|
||||||
|
|
||||||
|
const Center = (props: React.HTMLAttributes<HTMLDivElement>) => (
|
||||||
|
<div
|
||||||
|
{...props}
|
||||||
|
style={{
|
||||||
|
width: "100%",
|
||||||
|
minHeight: "100vh",
|
||||||
|
display: "flex",
|
||||||
|
justifyContent: "center",
|
||||||
|
alignItems: "center",
|
||||||
|
...(props.style ?? {}),
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
|
||||||
|
let initialized = false;
|
||||||
|
async function setup(config: BrowserBkndConfig = {}) {
|
||||||
|
if (initialized) return;
|
||||||
|
initialized = true;
|
||||||
|
|
||||||
|
registries.media.register("opfs", OpfsStorageAdapter);
|
||||||
|
|
||||||
|
const app = App.create({
|
||||||
|
...config,
|
||||||
|
// @ts-ignore
|
||||||
|
connection: sqlocal(new SQLocalKysely(config.connection ?? ":localStorage:")),
|
||||||
|
});
|
||||||
|
|
||||||
|
await config.beforeBuild?.(app);
|
||||||
|
await app.build({ sync: true });
|
||||||
|
await config.onBuilt?.(app);
|
||||||
|
|
||||||
|
return app;
|
||||||
|
}
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
import { describe, beforeAll, vi, afterAll, spyOn } from "bun:test";
|
||||||
|
import { OpfsStorageAdapter } from "./OpfsStorageAdapter";
|
||||||
|
// @ts-ignore
|
||||||
|
import { assetsPath } from "../../../__test__/helper";
|
||||||
|
import { adapterTestSuite } from "media/storage/adapters/adapter-test-suite";
|
||||||
|
import { bunTestRunner } from "adapter/bun/test";
|
||||||
|
import { MockFileSystemDirectoryHandle } from "adapter/browser/mock";
|
||||||
|
|
||||||
|
describe("OpfsStorageAdapter", async () => {
|
||||||
|
let mockRoot: MockFileSystemDirectoryHandle;
|
||||||
|
let testSuiteAdapter: OpfsStorageAdapter;
|
||||||
|
|
||||||
|
const _mock = spyOn(global, "navigator");
|
||||||
|
|
||||||
|
beforeAll(() => {
|
||||||
|
// mock navigator.storage.getDirectory()
|
||||||
|
mockRoot = new MockFileSystemDirectoryHandle("opfs-root");
|
||||||
|
const mockNavigator = {
|
||||||
|
storage: {
|
||||||
|
getDirectory: vi.fn().mockResolvedValue(mockRoot),
|
||||||
|
},
|
||||||
|
};
|
||||||
|
// @ts-ignore
|
||||||
|
_mock.mockReturnValue(mockNavigator);
|
||||||
|
testSuiteAdapter = new OpfsStorageAdapter();
|
||||||
|
});
|
||||||
|
|
||||||
|
afterAll(() => {
|
||||||
|
_mock.mockRestore();
|
||||||
|
});
|
||||||
|
|
||||||
|
const file = Bun.file(`${assetsPath}/image.png`);
|
||||||
|
await adapterTestSuite(bunTestRunner, () => testSuiteAdapter, file);
|
||||||
|
});
|
||||||
@@ -0,0 +1,265 @@
|
|||||||
|
import type { FileBody, FileListObject, FileMeta, FileUploadPayload } from "bknd";
|
||||||
|
import { StorageAdapter, guessMimeType } from "bknd";
|
||||||
|
import { parse, s, isFile, isBlob } from "bknd/utils";
|
||||||
|
|
||||||
|
export const opfsAdapterConfig = s.object(
|
||||||
|
{
|
||||||
|
root: s.string({ default: "" }).optional(),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "OPFS",
|
||||||
|
description: "Origin Private File System storage",
|
||||||
|
additionalProperties: false,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
export type OpfsAdapterConfig = s.Static<typeof opfsAdapterConfig>;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Storage adapter for OPFS (Origin Private File System)
|
||||||
|
* Provides browser-based file storage using the File System Access API
|
||||||
|
*/
|
||||||
|
export class OpfsStorageAdapter extends StorageAdapter {
|
||||||
|
private config: OpfsAdapterConfig;
|
||||||
|
private rootPromise: Promise<FileSystemDirectoryHandle>;
|
||||||
|
|
||||||
|
constructor(config: Partial<OpfsAdapterConfig> = {}) {
|
||||||
|
super();
|
||||||
|
this.config = parse(opfsAdapterConfig, config);
|
||||||
|
this.rootPromise = this.initializeRoot();
|
||||||
|
}
|
||||||
|
|
||||||
|
private async initializeRoot(): Promise<FileSystemDirectoryHandle> {
|
||||||
|
const opfsRoot = await navigator.storage.getDirectory();
|
||||||
|
if (!this.config.root) {
|
||||||
|
return opfsRoot;
|
||||||
|
}
|
||||||
|
|
||||||
|
// navigate to or create nested directory structure
|
||||||
|
const parts = this.config.root.split("/").filter(Boolean);
|
||||||
|
let current = opfsRoot;
|
||||||
|
for (const part of parts) {
|
||||||
|
current = await current.getDirectoryHandle(part, { create: true });
|
||||||
|
}
|
||||||
|
return current;
|
||||||
|
}
|
||||||
|
|
||||||
|
getSchema() {
|
||||||
|
return opfsAdapterConfig;
|
||||||
|
}
|
||||||
|
|
||||||
|
getName(): string {
|
||||||
|
return "opfs";
|
||||||
|
}
|
||||||
|
|
||||||
|
async listObjects(prefix?: string): Promise<FileListObject[]> {
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
const files: FileListObject[] = [];
|
||||||
|
|
||||||
|
for await (const [name, handle] of root.entries()) {
|
||||||
|
if (handle.kind === "file") {
|
||||||
|
if (!prefix || name.startsWith(prefix)) {
|
||||||
|
const file = await (handle as FileSystemFileHandle).getFile();
|
||||||
|
files.push({
|
||||||
|
key: name,
|
||||||
|
last_modified: new Date(file.lastModified),
|
||||||
|
size: file.size,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return files;
|
||||||
|
}
|
||||||
|
|
||||||
|
private async computeEtagFromArrayBuffer(buffer: ArrayBuffer): Promise<string> {
|
||||||
|
const hashBuffer = await crypto.subtle.digest("SHA-256", buffer);
|
||||||
|
const hashArray = Array.from(new Uint8Array(hashBuffer));
|
||||||
|
const hashHex = hashArray.map((byte) => byte.toString(16).padStart(2, "0")).join("");
|
||||||
|
|
||||||
|
// wrap the hex string in quotes for ETag format
|
||||||
|
return `"${hashHex}"`;
|
||||||
|
}
|
||||||
|
|
||||||
|
async putObject(key: string, body: FileBody): Promise<string | FileUploadPayload> {
|
||||||
|
if (body === null) {
|
||||||
|
throw new Error("Body is empty");
|
||||||
|
}
|
||||||
|
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
const fileHandle = await root.getFileHandle(key, { create: true });
|
||||||
|
const writable = await fileHandle.createWritable();
|
||||||
|
|
||||||
|
try {
|
||||||
|
let contentBuffer: ArrayBuffer;
|
||||||
|
|
||||||
|
if (isFile(body)) {
|
||||||
|
contentBuffer = await body.arrayBuffer();
|
||||||
|
await writable.write(contentBuffer);
|
||||||
|
} else if (body instanceof ReadableStream) {
|
||||||
|
const chunks: Uint8Array[] = [];
|
||||||
|
const reader = body.getReader();
|
||||||
|
try {
|
||||||
|
while (true) {
|
||||||
|
const { done, value } = await reader.read();
|
||||||
|
if (done) break;
|
||||||
|
chunks.push(value);
|
||||||
|
await writable.write(value);
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
reader.releaseLock();
|
||||||
|
}
|
||||||
|
// compute total size and combine chunks for etag
|
||||||
|
const totalSize = chunks.reduce((sum, chunk) => sum + chunk.length, 0);
|
||||||
|
const combined = new Uint8Array(totalSize);
|
||||||
|
let offset = 0;
|
||||||
|
for (const chunk of chunks) {
|
||||||
|
combined.set(chunk, offset);
|
||||||
|
offset += chunk.length;
|
||||||
|
}
|
||||||
|
contentBuffer = combined.buffer;
|
||||||
|
} else if (isBlob(body)) {
|
||||||
|
contentBuffer = await (body as Blob).arrayBuffer();
|
||||||
|
await writable.write(contentBuffer);
|
||||||
|
} else {
|
||||||
|
// body is ArrayBuffer or ArrayBufferView
|
||||||
|
if (ArrayBuffer.isView(body)) {
|
||||||
|
const view = body as ArrayBufferView;
|
||||||
|
contentBuffer = view.buffer.slice(
|
||||||
|
view.byteOffset,
|
||||||
|
view.byteOffset + view.byteLength,
|
||||||
|
) as ArrayBuffer;
|
||||||
|
} else {
|
||||||
|
contentBuffer = body as ArrayBuffer;
|
||||||
|
}
|
||||||
|
await writable.write(body);
|
||||||
|
}
|
||||||
|
|
||||||
|
await writable.close();
|
||||||
|
return await this.computeEtagFromArrayBuffer(contentBuffer);
|
||||||
|
} catch (error) {
|
||||||
|
await writable.abort();
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async deleteObject(key: string): Promise<void> {
|
||||||
|
try {
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
await root.removeEntry(key);
|
||||||
|
} catch {
|
||||||
|
// file doesn't exist, which is fine
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async objectExists(key: string): Promise<boolean> {
|
||||||
|
try {
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
await root.getFileHandle(key);
|
||||||
|
return true;
|
||||||
|
} catch {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private parseRangeHeader(
|
||||||
|
rangeHeader: string,
|
||||||
|
fileSize: number,
|
||||||
|
): { start: number; end: number } | null {
|
||||||
|
// parse "bytes=start-end" format
|
||||||
|
const match = rangeHeader.match(/^bytes=(\d*)-(\d*)$/);
|
||||||
|
if (!match) return null;
|
||||||
|
|
||||||
|
const [, startStr, endStr] = match;
|
||||||
|
let start = startStr ? Number.parseInt(startStr, 10) : 0;
|
||||||
|
let end = endStr ? Number.parseInt(endStr, 10) : fileSize - 1;
|
||||||
|
|
||||||
|
// handle suffix-byte-range-spec (e.g., "bytes=-500")
|
||||||
|
if (!startStr && endStr) {
|
||||||
|
start = Math.max(0, fileSize - Number.parseInt(endStr, 10));
|
||||||
|
end = fileSize - 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
// validate range
|
||||||
|
if (start < 0 || end >= fileSize || start > end) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return { start, end };
|
||||||
|
}
|
||||||
|
|
||||||
|
async getObject(key: string, headers: Headers): Promise<Response> {
|
||||||
|
try {
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
const fileHandle = await root.getFileHandle(key);
|
||||||
|
const file = await fileHandle.getFile();
|
||||||
|
const fileSize = file.size;
|
||||||
|
const mimeType = guessMimeType(key);
|
||||||
|
|
||||||
|
const responseHeaders = new Headers({
|
||||||
|
"Accept-Ranges": "bytes",
|
||||||
|
"Content-Type": mimeType || "application/octet-stream",
|
||||||
|
});
|
||||||
|
|
||||||
|
const rangeHeader = headers.get("range");
|
||||||
|
|
||||||
|
if (rangeHeader) {
|
||||||
|
const range = this.parseRangeHeader(rangeHeader, fileSize);
|
||||||
|
|
||||||
|
if (!range) {
|
||||||
|
// invalid range - return 416 Range Not Satisfiable
|
||||||
|
responseHeaders.set("Content-Range", `bytes */${fileSize}`);
|
||||||
|
return new Response("", {
|
||||||
|
status: 416,
|
||||||
|
headers: responseHeaders,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const { start, end } = range;
|
||||||
|
const arrayBuffer = await file.arrayBuffer();
|
||||||
|
const chunk = arrayBuffer.slice(start, end + 1);
|
||||||
|
|
||||||
|
responseHeaders.set("Content-Range", `bytes ${start}-${end}/${fileSize}`);
|
||||||
|
responseHeaders.set("Content-Length", chunk.byteLength.toString());
|
||||||
|
|
||||||
|
return new Response(chunk, {
|
||||||
|
status: 206, // Partial Content
|
||||||
|
headers: responseHeaders,
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
// normal request - return entire file
|
||||||
|
const content = await file.arrayBuffer();
|
||||||
|
responseHeaders.set("Content-Length", content.byteLength.toString());
|
||||||
|
|
||||||
|
return new Response(content, {
|
||||||
|
status: 200,
|
||||||
|
headers: responseHeaders,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// handle file reading errors
|
||||||
|
return new Response("", { status: 404 });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
getObjectUrl(_key: string): string {
|
||||||
|
throw new Error("Method not implemented.");
|
||||||
|
}
|
||||||
|
|
||||||
|
async getObjectMeta(key: string): Promise<FileMeta> {
|
||||||
|
const root = await this.rootPromise;
|
||||||
|
const fileHandle = await root.getFileHandle(key);
|
||||||
|
const file = await fileHandle.getFile();
|
||||||
|
|
||||||
|
return {
|
||||||
|
type: guessMimeType(key) || "application/octet-stream",
|
||||||
|
size: file.size,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
toJSON(_secrets?: boolean) {
|
||||||
|
return {
|
||||||
|
type: this.getName(),
|
||||||
|
config: this.config,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
export * from "./OpfsStorageAdapter";
|
||||||
|
export * from "./BkndBrowserApp";
|
||||||
@@ -0,0 +1,136 @@
|
|||||||
|
// mock OPFS API for testing
|
||||||
|
class MockFileSystemFileHandle {
|
||||||
|
kind: "file" = "file";
|
||||||
|
name: string;
|
||||||
|
private content: ArrayBuffer;
|
||||||
|
private lastModified: number;
|
||||||
|
|
||||||
|
constructor(name: string, content: ArrayBuffer = new ArrayBuffer(0)) {
|
||||||
|
this.name = name;
|
||||||
|
this.content = content;
|
||||||
|
this.lastModified = Date.now();
|
||||||
|
}
|
||||||
|
|
||||||
|
async getFile(): Promise<File> {
|
||||||
|
return new File([this.content], this.name, {
|
||||||
|
lastModified: this.lastModified,
|
||||||
|
type: this.guessMimeType(),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
async createWritable(): Promise<FileSystemWritableFileStream> {
|
||||||
|
const handle = this;
|
||||||
|
return {
|
||||||
|
async write(data: any) {
|
||||||
|
if (data instanceof ArrayBuffer) {
|
||||||
|
handle.content = data;
|
||||||
|
} else if (ArrayBuffer.isView(data)) {
|
||||||
|
handle.content = data.buffer.slice(
|
||||||
|
data.byteOffset,
|
||||||
|
data.byteOffset + data.byteLength,
|
||||||
|
) as ArrayBuffer;
|
||||||
|
} else if (data instanceof Blob) {
|
||||||
|
handle.content = await data.arrayBuffer();
|
||||||
|
}
|
||||||
|
handle.lastModified = Date.now();
|
||||||
|
},
|
||||||
|
async close() {},
|
||||||
|
async abort() {},
|
||||||
|
async seek(_position: number) {},
|
||||||
|
async truncate(_size: number) {},
|
||||||
|
} as FileSystemWritableFileStream;
|
||||||
|
}
|
||||||
|
|
||||||
|
private guessMimeType(): string {
|
||||||
|
const ext = this.name.split(".").pop()?.toLowerCase();
|
||||||
|
const mimeTypes: Record<string, string> = {
|
||||||
|
png: "image/png",
|
||||||
|
jpg: "image/jpeg",
|
||||||
|
jpeg: "image/jpeg",
|
||||||
|
gif: "image/gif",
|
||||||
|
webp: "image/webp",
|
||||||
|
svg: "image/svg+xml",
|
||||||
|
txt: "text/plain",
|
||||||
|
json: "application/json",
|
||||||
|
pdf: "application/pdf",
|
||||||
|
};
|
||||||
|
return mimeTypes[ext || ""] || "application/octet-stream";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class MockFileSystemDirectoryHandle {
|
||||||
|
kind: "directory" = "directory";
|
||||||
|
name: string;
|
||||||
|
private files: Map<string, MockFileSystemFileHandle> = new Map();
|
||||||
|
private directories: Map<string, MockFileSystemDirectoryHandle> = new Map();
|
||||||
|
|
||||||
|
constructor(name: string = "root") {
|
||||||
|
this.name = name;
|
||||||
|
}
|
||||||
|
|
||||||
|
async getFileHandle(
|
||||||
|
name: string,
|
||||||
|
options?: FileSystemGetFileOptions,
|
||||||
|
): Promise<FileSystemFileHandle> {
|
||||||
|
if (this.files.has(name)) {
|
||||||
|
return this.files.get(name) as any;
|
||||||
|
}
|
||||||
|
if (options?.create) {
|
||||||
|
const handle = new MockFileSystemFileHandle(name);
|
||||||
|
this.files.set(name, handle);
|
||||||
|
return handle as any;
|
||||||
|
}
|
||||||
|
throw new Error(`File not found: ${name}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
async getDirectoryHandle(
|
||||||
|
name: string,
|
||||||
|
options?: FileSystemGetDirectoryOptions,
|
||||||
|
): Promise<FileSystemDirectoryHandle> {
|
||||||
|
if (this.directories.has(name)) {
|
||||||
|
return this.directories.get(name) as any;
|
||||||
|
}
|
||||||
|
if (options?.create) {
|
||||||
|
const handle = new MockFileSystemDirectoryHandle(name);
|
||||||
|
this.directories.set(name, handle);
|
||||||
|
return handle as any;
|
||||||
|
}
|
||||||
|
throw new Error(`Directory not found: ${name}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
async removeEntry(name: string, _options?: FileSystemRemoveOptions): Promise<void> {
|
||||||
|
this.files.delete(name);
|
||||||
|
this.directories.delete(name);
|
||||||
|
}
|
||||||
|
|
||||||
|
async *entries(): AsyncIterableIterator<[string, FileSystemHandle]> {
|
||||||
|
for (const [name, handle] of this.files) {
|
||||||
|
yield [name, handle as any];
|
||||||
|
}
|
||||||
|
for (const [name, handle] of this.directories) {
|
||||||
|
yield [name, handle as any];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async *keys(): AsyncIterableIterator<string> {
|
||||||
|
for (const name of this.files.keys()) {
|
||||||
|
yield name;
|
||||||
|
}
|
||||||
|
for (const name of this.directories.keys()) {
|
||||||
|
yield name;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async *values(): AsyncIterableIterator<FileSystemHandle> {
|
||||||
|
for (const handle of this.files.values()) {
|
||||||
|
yield handle as any;
|
||||||
|
}
|
||||||
|
for (const handle of this.directories.values()) {
|
||||||
|
yield handle as any;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
[Symbol.asyncIterator](): AsyncIterableIterator<[string, FileSystemHandle]> {
|
||||||
|
return this.entries();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,18 +1,16 @@
|
|||||||
/// <reference types="bun-types" />
|
|
||||||
|
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import { type RuntimeBkndConfig, createRuntimeApp } from "bknd/adapter";
|
import { type RuntimeBkndConfig, createRuntimeApp } from "bknd/adapter";
|
||||||
import { registerLocalMediaAdapter } from ".";
|
import { registerLocalMediaAdapter } from ".";
|
||||||
import { config, type App } from "bknd";
|
import { config, type App } from "bknd";
|
||||||
import type { ServeOptions } from "bun";
|
|
||||||
import { serveStatic } from "hono/bun";
|
import { serveStatic } from "hono/bun";
|
||||||
|
|
||||||
type BunEnv = Bun.Env;
|
type BunEnv = Bun.Env;
|
||||||
export type BunBkndConfig<Env = BunEnv> = RuntimeBkndConfig<Env> & Omit<ServeOptions, "fetch">;
|
export type BunBkndConfig<Env = BunEnv> = RuntimeBkndConfig<Env> &
|
||||||
|
Omit<Bun.Serve.Options<undefined, string>, "fetch">;
|
||||||
|
|
||||||
export async function createApp<Env = BunEnv>(
|
export async function createApp<Env = BunEnv>(
|
||||||
{ distPath, serveStatic: _serveStatic, ...config }: BunBkndConfig<Env> = {},
|
{ distPath, serveStatic: _serveStatic, ...config }: BunBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = Bun.env as Env,
|
||||||
) {
|
) {
|
||||||
const root = path.resolve(distPath ?? "./node_modules/bknd/dist", "static");
|
const root = path.resolve(distPath ?? "./node_modules/bknd/dist", "static");
|
||||||
registerLocalMediaAdapter();
|
registerLocalMediaAdapter();
|
||||||
@@ -26,18 +24,18 @@ export async function createApp<Env = BunEnv>(
|
|||||||
}),
|
}),
|
||||||
...config,
|
...config,
|
||||||
},
|
},
|
||||||
args ?? (process.env as Env),
|
args,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
export function createHandler<Env = BunEnv>(
|
export function createHandler<Env = BunEnv>(
|
||||||
config: BunBkndConfig<Env> = {},
|
config: BunBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = Bun.env as Env,
|
||||||
) {
|
) {
|
||||||
let app: App | undefined;
|
let app: App | undefined;
|
||||||
return async (req: Request) => {
|
return async (req: Request) => {
|
||||||
if (!app) {
|
if (!app) {
|
||||||
app = await createApp(config, args ?? (process.env as Env));
|
app = await createApp(config, args);
|
||||||
}
|
}
|
||||||
return app.fetch(req);
|
return app.fetch(req);
|
||||||
};
|
};
|
||||||
@@ -45,6 +43,7 @@ export function createHandler<Env = BunEnv>(
|
|||||||
|
|
||||||
export function serve<Env = BunEnv>(
|
export function serve<Env = BunEnv>(
|
||||||
{
|
{
|
||||||
|
app,
|
||||||
distPath,
|
distPath,
|
||||||
connection,
|
connection,
|
||||||
config: _config,
|
config: _config,
|
||||||
@@ -54,15 +53,17 @@ export function serve<Env = BunEnv>(
|
|||||||
buildConfig,
|
buildConfig,
|
||||||
adminOptions,
|
adminOptions,
|
||||||
serveStatic,
|
serveStatic,
|
||||||
|
beforeBuild,
|
||||||
...serveOptions
|
...serveOptions
|
||||||
}: BunBkndConfig<Env> = {},
|
}: BunBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = Bun.env as Env,
|
||||||
) {
|
) {
|
||||||
Bun.serve({
|
Bun.serve({
|
||||||
...serveOptions,
|
...(serveOptions as any),
|
||||||
port,
|
port,
|
||||||
fetch: createHandler(
|
fetch: createHandler(
|
||||||
{
|
{
|
||||||
|
app,
|
||||||
connection,
|
connection,
|
||||||
config: _config,
|
config: _config,
|
||||||
options,
|
options,
|
||||||
@@ -71,6 +72,7 @@ export function serve<Env = BunEnv>(
|
|||||||
adminOptions,
|
adminOptions,
|
||||||
distPath,
|
distPath,
|
||||||
serveStatic,
|
serveStatic,
|
||||||
|
beforeBuild,
|
||||||
},
|
},
|
||||||
args,
|
args,
|
||||||
),
|
),
|
||||||
|
|||||||
@@ -1,3 +1,11 @@
|
|||||||
export * from "./bun.adapter";
|
export * from "./bun.adapter";
|
||||||
export * from "../node/storage";
|
export * from "../node/storage";
|
||||||
export * from "./connection/BunSqliteConnection";
|
export * from "./connection/BunSqliteConnection";
|
||||||
|
|
||||||
|
export async function writer(path: string, content: string) {
|
||||||
|
await Bun.write(path, content);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function reader(path: string) {
|
||||||
|
return await Bun.file(path).text();
|
||||||
|
}
|
||||||
|
|||||||
@@ -5,8 +5,8 @@ import { adapterTestSuite } from "adapter/adapter-test-suite";
|
|||||||
import { bunTestRunner } from "adapter/bun/test";
|
import { bunTestRunner } from "adapter/bun/test";
|
||||||
import { type CloudflareBkndConfig, createApp } from "./cloudflare-workers.adapter";
|
import { type CloudflareBkndConfig, createApp } from "./cloudflare-workers.adapter";
|
||||||
|
|
||||||
/* beforeAll(disableConsoleLog);
|
beforeAll(disableConsoleLog);
|
||||||
afterAll(enableConsoleLog); */
|
afterAll(enableConsoleLog);
|
||||||
|
|
||||||
describe("cf adapter", () => {
|
describe("cf adapter", () => {
|
||||||
const DB_URL = ":memory:";
|
const DB_URL = ":memory:";
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
import type { RuntimeBkndConfig } from "bknd/adapter";
|
import type { RuntimeBkndConfig } from "bknd/adapter";
|
||||||
import { Hono } from "hono";
|
import { Hono } from "hono";
|
||||||
import { serveStatic } from "hono/cloudflare-workers";
|
import { serveStatic } from "hono/cloudflare-workers";
|
||||||
import type { MaybePromise } from "bknd";
|
import type { App, MaybePromise } from "bknd";
|
||||||
import { $console } from "bknd/utils";
|
import { $console } from "bknd/utils";
|
||||||
import { createRuntimeApp } from "bknd/adapter";
|
import { createRuntimeApp } from "bknd/adapter";
|
||||||
import { registerAsyncsExecutionContext, makeConfig, type CloudflareContext } from "./config";
|
import { registerAsyncsExecutionContext, makeConfig, type CloudflareContext } from "./config";
|
||||||
@@ -37,26 +37,30 @@ export async function createApp<Env extends CloudflareEnv = CloudflareEnv>(
|
|||||||
config: CloudflareBkndConfig<Env> = {},
|
config: CloudflareBkndConfig<Env> = {},
|
||||||
ctx: Partial<CloudflareContext<Env>> = {},
|
ctx: Partial<CloudflareContext<Env>> = {},
|
||||||
) {
|
) {
|
||||||
const appConfig = await makeConfig(
|
const appConfig = await makeConfig(config, ctx);
|
||||||
|
return await createRuntimeApp<Env>(
|
||||||
{
|
{
|
||||||
...config,
|
...appConfig,
|
||||||
onBuilt: async (app) => {
|
onBuilt: async (app) => {
|
||||||
if (ctx.ctx) {
|
if (ctx.ctx) {
|
||||||
registerAsyncsExecutionContext(app, ctx?.ctx);
|
registerAsyncsExecutionContext(app, ctx?.ctx);
|
||||||
}
|
}
|
||||||
await config.onBuilt?.(app);
|
await appConfig.onBuilt?.(app);
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
ctx,
|
ctx?.env,
|
||||||
);
|
);
|
||||||
return await createRuntimeApp<Env>(appConfig, ctx?.env);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// compatiblity
|
// compatiblity
|
||||||
export const getFresh = createApp;
|
export const getFresh = createApp;
|
||||||
|
|
||||||
|
let app: App | undefined;
|
||||||
export function serve<Env extends CloudflareEnv = CloudflareEnv>(
|
export function serve<Env extends CloudflareEnv = CloudflareEnv>(
|
||||||
config: CloudflareBkndConfig<Env> = {},
|
config: CloudflareBkndConfig<Env> = {},
|
||||||
|
serveOptions?: (args: Env) => {
|
||||||
|
warm?: boolean;
|
||||||
|
},
|
||||||
) {
|
) {
|
||||||
return {
|
return {
|
||||||
async fetch(request: Request, env: Env, ctx: ExecutionContext) {
|
async fetch(request: Request, env: Env, ctx: ExecutionContext) {
|
||||||
@@ -92,8 +96,11 @@ export function serve<Env extends CloudflareEnv = CloudflareEnv>(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const context = { request, env, ctx } as CloudflareContext<Env>;
|
const { warm } = serveOptions?.(env) ?? {};
|
||||||
const app = await createApp(config, context);
|
if (!app || warm !== true) {
|
||||||
|
const context = { request, env, ctx } as CloudflareContext<Env>;
|
||||||
|
app = await createApp(config, context);
|
||||||
|
}
|
||||||
|
|
||||||
return app.fetch(request, env, ctx);
|
return app.fetch(request, env, ctx);
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -65,37 +65,31 @@ export function withPlatformProxy<Env extends CloudflareEnv>(
|
|||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
...config,
|
|
||||||
beforeBuild: async (app, registries) => {
|
|
||||||
if (!use_proxy) return;
|
|
||||||
const env = await getEnv();
|
|
||||||
registerMedia(env, registries as any);
|
|
||||||
await config?.beforeBuild?.(app, registries);
|
|
||||||
},
|
|
||||||
bindings: async (env) => {
|
|
||||||
return (await config?.bindings?.(await getEnv(env))) || {};
|
|
||||||
},
|
|
||||||
// @ts-ignore
|
// @ts-ignore
|
||||||
app: async (_env) => {
|
app: async (_env) => {
|
||||||
const env = await getEnv(_env);
|
const env = await getEnv(_env);
|
||||||
const binding = use_proxy ? getBinding(env, "D1Database") : undefined;
|
const binding = use_proxy ? getBinding(env, "D1Database") : undefined;
|
||||||
|
const appConfig = typeof config.app === "function" ? await config.app(env) : config;
|
||||||
|
const connection =
|
||||||
|
use_proxy && binding
|
||||||
|
? d1Sqlite({
|
||||||
|
binding: binding.value as any,
|
||||||
|
})
|
||||||
|
: appConfig.connection;
|
||||||
|
|
||||||
if (config?.app === undefined && use_proxy && binding) {
|
return {
|
||||||
return {
|
...appConfig,
|
||||||
connection: d1Sqlite({
|
beforeBuild: async (app, registries) => {
|
||||||
binding: binding.value,
|
if (!use_proxy) return;
|
||||||
}),
|
const env = await getEnv();
|
||||||
};
|
registerMedia(env, registries as any);
|
||||||
} else if (typeof config?.app === "function") {
|
await config?.beforeBuild?.(app, registries);
|
||||||
const appConfig = await config?.app(env);
|
},
|
||||||
if (binding) {
|
bindings: async (env) => {
|
||||||
appConfig.connection = d1Sqlite({
|
return (await config?.bindings?.(await getEnv(env))) || {};
|
||||||
binding: binding.value,
|
},
|
||||||
}) as any;
|
connection,
|
||||||
}
|
};
|
||||||
return appConfig;
|
|
||||||
}
|
|
||||||
return config?.app || {};
|
|
||||||
},
|
},
|
||||||
} satisfies CloudflareBkndConfig<Env>;
|
} satisfies CloudflareBkndConfig<Env>;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -49,6 +49,8 @@ export function registerMedia(
|
|||||||
* @todo: add tests (bun tests won't work, need node native tests)
|
* @todo: add tests (bun tests won't work, need node native tests)
|
||||||
*/
|
*/
|
||||||
export class StorageR2Adapter extends StorageAdapter {
|
export class StorageR2Adapter extends StorageAdapter {
|
||||||
|
public keyPrefix: string = "";
|
||||||
|
|
||||||
constructor(private readonly bucket: R2Bucket) {
|
constructor(private readonly bucket: R2Bucket) {
|
||||||
super();
|
super();
|
||||||
}
|
}
|
||||||
@@ -175,6 +177,9 @@ export class StorageR2Adapter extends StorageAdapter {
|
|||||||
}
|
}
|
||||||
|
|
||||||
protected getKey(key: string) {
|
protected getKey(key: string) {
|
||||||
|
if (this.keyPrefix.length > 0) {
|
||||||
|
return `${this.keyPrefix}/${key}`.replace(/^\/\//, "/");
|
||||||
|
}
|
||||||
return key;
|
return key;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+43
-21
@@ -6,18 +6,24 @@ import {
|
|||||||
guessMimeType,
|
guessMimeType,
|
||||||
type MaybePromise,
|
type MaybePromise,
|
||||||
registries as $registries,
|
registries as $registries,
|
||||||
|
type Merge,
|
||||||
} from "bknd";
|
} from "bknd";
|
||||||
import { $console } from "bknd/utils";
|
import { $console } from "bknd/utils";
|
||||||
import type { Context, MiddlewareHandler, Next } from "hono";
|
import type { Context, MiddlewareHandler, Next } from "hono";
|
||||||
import type { AdminControllerOptions } from "modules/server/AdminController";
|
import type { AdminControllerOptions } from "modules/server/AdminController";
|
||||||
import type { Manifest } from "vite";
|
import type { Manifest } from "vite";
|
||||||
|
|
||||||
export type BkndConfig<Args = any> = CreateAppConfig & {
|
export type BkndConfig<Args = any, Additional = {}> = Merge<
|
||||||
app?: Omit<BkndConfig, "app"> | ((args: Args) => MaybePromise<Omit<BkndConfig<Args>, "app">>);
|
CreateAppConfig &
|
||||||
onBuilt?: (app: App) => MaybePromise<void>;
|
Omit<Additional, "app"> & {
|
||||||
beforeBuild?: (app?: App, registries?: typeof $registries) => MaybePromise<void>;
|
app?:
|
||||||
buildConfig?: Parameters<App["build"]>[0];
|
| Omit<BkndConfig<Args, Additional>, "app">
|
||||||
};
|
| ((args: Args) => MaybePromise<Omit<BkndConfig<Args, Additional>, "app">>);
|
||||||
|
onBuilt?: (app: App) => MaybePromise<void>;
|
||||||
|
beforeBuild?: (app?: App, registries?: typeof $registries) => MaybePromise<void>;
|
||||||
|
buildConfig?: Parameters<App["build"]>[0];
|
||||||
|
}
|
||||||
|
>;
|
||||||
|
|
||||||
export type FrameworkBkndConfig<Args = any> = BkndConfig<Args>;
|
export type FrameworkBkndConfig<Args = any> = BkndConfig<Args>;
|
||||||
|
|
||||||
@@ -51,11 +57,10 @@ export async function makeConfig<Args = DefaultArgs>(
|
|||||||
return { ...rest, ...additionalConfig };
|
return { ...rest, ...additionalConfig };
|
||||||
}
|
}
|
||||||
|
|
||||||
// a map that contains all apps by id
|
|
||||||
export async function createAdapterApp<Config extends BkndConfig = BkndConfig, Args = DefaultArgs>(
|
export async function createAdapterApp<Config extends BkndConfig = BkndConfig, Args = DefaultArgs>(
|
||||||
config: Config = {} as Config,
|
config: Config = {} as Config,
|
||||||
args?: Args,
|
args?: Args,
|
||||||
): Promise<App> {
|
): Promise<{ app: App; config: BkndConfig<Args> }> {
|
||||||
await config.beforeBuild?.(undefined, $registries);
|
await config.beforeBuild?.(undefined, $registries);
|
||||||
|
|
||||||
const appConfig = await makeConfig(config, args);
|
const appConfig = await makeConfig(config, args);
|
||||||
@@ -64,35 +69,43 @@ export async function createAdapterApp<Config extends BkndConfig = BkndConfig, A
|
|||||||
if (Connection.isConnection(config.connection)) {
|
if (Connection.isConnection(config.connection)) {
|
||||||
connection = config.connection;
|
connection = config.connection;
|
||||||
} else {
|
} else {
|
||||||
|
if (connection) {
|
||||||
|
$console.warn(
|
||||||
|
"Connection is not a valid connection object, using default SQLite connection",
|
||||||
|
);
|
||||||
|
}
|
||||||
const sqlite = (await import("bknd/adapter/sqlite")).sqlite;
|
const sqlite = (await import("bknd/adapter/sqlite")).sqlite;
|
||||||
const conf = appConfig.connection ?? { url: ":memory:" };
|
const conf = appConfig.connection ?? { url: "file:data.db" };
|
||||||
connection = sqlite(conf) as any;
|
connection = sqlite(conf) as any;
|
||||||
$console.info(`Using ${connection!.name} connection`, conf.url);
|
$console.info(`Using ${connection!.name} connection`, conf.url);
|
||||||
}
|
}
|
||||||
appConfig.connection = connection;
|
appConfig.connection = connection;
|
||||||
}
|
}
|
||||||
|
|
||||||
return App.create(appConfig);
|
return {
|
||||||
|
app: App.create(appConfig),
|
||||||
|
config: appConfig,
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
export async function createFrameworkApp<Args = DefaultArgs>(
|
export async function createFrameworkApp<Args = DefaultArgs>(
|
||||||
config: FrameworkBkndConfig = {},
|
config: FrameworkBkndConfig = {},
|
||||||
args?: Args,
|
args?: Args,
|
||||||
): Promise<App> {
|
): Promise<App> {
|
||||||
const app = await createAdapterApp(config, args);
|
const { app, config: appConfig } = await createAdapterApp(config, args);
|
||||||
|
|
||||||
if (!app.isBuilt()) {
|
if (!app.isBuilt()) {
|
||||||
if (config.onBuilt) {
|
if (config.onBuilt) {
|
||||||
app.emgr.onEvent(
|
app.emgr.onEvent(
|
||||||
App.Events.AppBuiltEvent,
|
App.Events.AppBuiltEvent,
|
||||||
async () => {
|
async () => {
|
||||||
await config.onBuilt?.(app);
|
await appConfig.onBuilt?.(app);
|
||||||
},
|
},
|
||||||
"sync",
|
"sync",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
await config.beforeBuild?.(app, $registries);
|
await appConfig.beforeBuild?.(app, $registries);
|
||||||
await app.build(config.buildConfig);
|
await app.build(config.buildConfig);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -103,7 +116,7 @@ export async function createRuntimeApp<Args = DefaultArgs>(
|
|||||||
{ serveStatic, adminOptions, ...config }: RuntimeBkndConfig<Args> = {},
|
{ serveStatic, adminOptions, ...config }: RuntimeBkndConfig<Args> = {},
|
||||||
args?: Args,
|
args?: Args,
|
||||||
): Promise<App> {
|
): Promise<App> {
|
||||||
const app = await createAdapterApp(config, args);
|
const { app, config: appConfig } = await createAdapterApp(config, args);
|
||||||
|
|
||||||
if (!app.isBuilt()) {
|
if (!app.isBuilt()) {
|
||||||
app.emgr.onEvent(
|
app.emgr.onEvent(
|
||||||
@@ -116,7 +129,7 @@ export async function createRuntimeApp<Args = DefaultArgs>(
|
|||||||
app.modules.server.get(path, handler);
|
app.modules.server.get(path, handler);
|
||||||
}
|
}
|
||||||
|
|
||||||
await config.onBuilt?.(app);
|
await appConfig.onBuilt?.(app);
|
||||||
if (adminOptions !== false) {
|
if (adminOptions !== false) {
|
||||||
app.registerAdminController(adminOptions);
|
app.registerAdminController(adminOptions);
|
||||||
}
|
}
|
||||||
@@ -124,7 +137,7 @@ export async function createRuntimeApp<Args = DefaultArgs>(
|
|||||||
"sync",
|
"sync",
|
||||||
);
|
);
|
||||||
|
|
||||||
await config.beforeBuild?.(app, $registries);
|
await appConfig.beforeBuild?.(app, $registries);
|
||||||
await app.build(config.buildConfig);
|
await app.build(config.buildConfig);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -147,23 +160,32 @@ export async function createRuntimeApp<Args = DefaultArgs>(
|
|||||||
* });
|
* });
|
||||||
* ```
|
* ```
|
||||||
*/
|
*/
|
||||||
export function serveStaticViaImport(opts?: { manifest?: Manifest }) {
|
export function serveStaticViaImport(opts?: {
|
||||||
|
manifest?: Manifest;
|
||||||
|
appendRaw?: boolean;
|
||||||
|
package?: string;
|
||||||
|
}) {
|
||||||
let files: string[] | undefined;
|
let files: string[] | undefined;
|
||||||
|
const pkg = opts?.package ?? "bknd";
|
||||||
|
|
||||||
// @ts-ignore
|
// @ts-ignore
|
||||||
return async (c: Context, next: Next) => {
|
return async (c: Context, next: Next) => {
|
||||||
if (!files) {
|
if (!files) {
|
||||||
const manifest =
|
const manifest =
|
||||||
opts?.manifest ||
|
opts?.manifest ||
|
||||||
((await import("bknd/dist/manifest.json", { with: { type: "json" } }))
|
((
|
||||||
.default as Manifest);
|
await import(/* @vite-ignore */ `${pkg}/dist/manifest.json`, {
|
||||||
|
with: { type: "json" },
|
||||||
|
})
|
||||||
|
).default as Manifest);
|
||||||
files = Object.values(manifest).flatMap((asset) => [asset.file, ...(asset.css || [])]);
|
files = Object.values(manifest).flatMap((asset) => [asset.file, ...(asset.css || [])]);
|
||||||
}
|
}
|
||||||
|
|
||||||
const path = c.req.path.substring(1);
|
const path = c.req.path.substring(1);
|
||||||
if (files.includes(path)) {
|
if (files.includes(path)) {
|
||||||
try {
|
try {
|
||||||
const content = await import(/* @vite-ignore */ `bknd/static/${path}?raw`, {
|
const url = `${pkg}/static/${path}${opts?.appendRaw ? "?raw" : ""}`;
|
||||||
|
const content = await import(/* @vite-ignore */ url, {
|
||||||
with: { type: "text" },
|
with: { type: "text" },
|
||||||
}).then((m) => m.default);
|
}).then((m) => m.default);
|
||||||
|
|
||||||
@@ -176,7 +198,7 @@ export function serveStaticViaImport(opts?: { manifest?: Manifest }) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
console.error("Error serving static file:", e);
|
console.error(`Error serving static file "${path}":`, String(e));
|
||||||
return c.text("File not found", 404);
|
return c.text("File not found", 404);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { createFrameworkApp, type FrameworkBkndConfig } from "bknd/adapter";
|
import { createFrameworkApp, type FrameworkBkndConfig } from "bknd/adapter";
|
||||||
import { isNode } from "bknd/utils";
|
import { isNode } from "bknd/utils";
|
||||||
|
// @ts-expect-error next is not installed
|
||||||
import type { NextApiRequest } from "next";
|
import type { NextApiRequest } from "next";
|
||||||
|
|
||||||
type NextjsEnv = NextApiRequest["env"];
|
type NextjsEnv = NextApiRequest["env"];
|
||||||
@@ -9,16 +10,18 @@ export type NextjsBkndConfig<Env = NextjsEnv> = FrameworkBkndConfig<Env> & {
|
|||||||
|
|
||||||
export async function getApp<Env = NextjsEnv>(
|
export async function getApp<Env = NextjsEnv>(
|
||||||
config: NextjsBkndConfig<Env>,
|
config: NextjsBkndConfig<Env>,
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
return await createFrameworkApp(config, args ?? (process.env as Env));
|
return await createFrameworkApp(config, args);
|
||||||
}
|
}
|
||||||
|
|
||||||
function getCleanRequest(req: Request, cleanRequest: NextjsBkndConfig["cleanRequest"]) {
|
function getCleanRequest(req: Request, cleanRequest: NextjsBkndConfig["cleanRequest"]) {
|
||||||
if (!cleanRequest) return req;
|
if (!cleanRequest) return req;
|
||||||
|
|
||||||
const url = new URL(req.url);
|
const url = new URL(req.url);
|
||||||
cleanRequest?.searchParams?.forEach((k) => url.searchParams.delete(k));
|
cleanRequest?.searchParams?.forEach((k) => {
|
||||||
|
url.searchParams.delete(k);
|
||||||
|
});
|
||||||
|
|
||||||
if (isNode()) {
|
if (isNode()) {
|
||||||
return new Request(url.toString(), {
|
return new Request(url.toString(), {
|
||||||
@@ -39,7 +42,7 @@ function getCleanRequest(req: Request, cleanRequest: NextjsBkndConfig["cleanRequ
|
|||||||
|
|
||||||
export function serve<Env = NextjsEnv>(
|
export function serve<Env = NextjsEnv>(
|
||||||
{ cleanRequest, ...config }: NextjsBkndConfig<Env> = {},
|
{ cleanRequest, ...config }: NextjsBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
return async (req: Request) => {
|
return async (req: Request) => {
|
||||||
const app = await getApp(config, args);
|
const app = await getApp(config, args);
|
||||||
|
|||||||
@@ -1,3 +1,13 @@
|
|||||||
|
import { readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
export * from "./node.adapter";
|
export * from "./node.adapter";
|
||||||
export * from "./storage";
|
export * from "./storage";
|
||||||
export * from "./connection/NodeSqliteConnection";
|
export * from "./connection/NodeSqliteConnection";
|
||||||
|
|
||||||
|
export async function writer(path: string, content: string) {
|
||||||
|
await writeFile(path, content);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function reader(path: string) {
|
||||||
|
return await readFile(path, "utf-8");
|
||||||
|
}
|
||||||
|
|||||||
@@ -17,14 +17,14 @@ export type NodeBkndConfig<Env = NodeEnv> = RuntimeBkndConfig<Env> & {
|
|||||||
|
|
||||||
export async function createApp<Env = NodeEnv>(
|
export async function createApp<Env = NodeEnv>(
|
||||||
{ distPath, relativeDistPath, ...config }: NodeBkndConfig<Env> = {},
|
{ distPath, relativeDistPath, ...config }: NodeBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
const root = path.relative(
|
const root = path.relative(
|
||||||
process.cwd(),
|
process.cwd(),
|
||||||
path.resolve(distPath ?? relativeDistPath ?? "./node_modules/bknd/dist", "static"),
|
path.resolve(distPath ?? relativeDistPath ?? "./node_modules/bknd/dist", "static"),
|
||||||
);
|
);
|
||||||
if (relativeDistPath) {
|
if (relativeDistPath) {
|
||||||
console.warn("relativeDistPath is deprecated, please use distPath instead");
|
$console.warn("relativeDistPath is deprecated, please use distPath instead");
|
||||||
}
|
}
|
||||||
|
|
||||||
registerLocalMediaAdapter();
|
registerLocalMediaAdapter();
|
||||||
@@ -33,19 +33,18 @@ export async function createApp<Env = NodeEnv>(
|
|||||||
serveStatic: serveStatic({ root }),
|
serveStatic: serveStatic({ root }),
|
||||||
...config,
|
...config,
|
||||||
},
|
},
|
||||||
// @ts-ignore
|
args,
|
||||||
args ?? { env: process.env },
|
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
export function createHandler<Env = NodeEnv>(
|
export function createHandler<Env = NodeEnv>(
|
||||||
config: NodeBkndConfig<Env> = {},
|
config: NodeBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
let app: App | undefined;
|
let app: App | undefined;
|
||||||
return async (req: Request) => {
|
return async (req: Request) => {
|
||||||
if (!app) {
|
if (!app) {
|
||||||
app = await createApp(config, args ?? (process.env as Env));
|
app = await createApp(config, args);
|
||||||
}
|
}
|
||||||
return app.fetch(req);
|
return app.fetch(req);
|
||||||
};
|
};
|
||||||
@@ -53,7 +52,7 @@ export function createHandler<Env = NodeEnv>(
|
|||||||
|
|
||||||
export function serve<Env = NodeEnv>(
|
export function serve<Env = NodeEnv>(
|
||||||
{ port = $config.server.default_port, hostname, listener, ...config }: NodeBkndConfig<Env> = {},
|
{ port = $config.server.default_port, hostname, listener, ...config }: NodeBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
honoServe(
|
honoServe(
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { describe, beforeAll, afterAll } from "vitest";
|
import { describe } from "vitest";
|
||||||
import * as node from "./node.adapter";
|
import * as node from "./node.adapter";
|
||||||
import { adapterTestSuite } from "adapter/adapter-test-suite";
|
import { adapterTestSuite } from "adapter/adapter-test-suite";
|
||||||
import { viTestRunner } from "adapter/node/vitest";
|
import { viTestRunner } from "adapter/node/vitest";
|
||||||
|
|||||||
@@ -8,14 +8,14 @@ export type ReactRouterBkndConfig<Env = ReactRouterEnv> = FrameworkBkndConfig<En
|
|||||||
|
|
||||||
export async function getApp<Env = ReactRouterEnv>(
|
export async function getApp<Env = ReactRouterEnv>(
|
||||||
config: ReactRouterBkndConfig<Env>,
|
config: ReactRouterBkndConfig<Env>,
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
return await createFrameworkApp(config, args ?? process.env);
|
return await createFrameworkApp(config, args);
|
||||||
}
|
}
|
||||||
|
|
||||||
export function serve<Env = ReactRouterEnv>(
|
export function serve<Env = ReactRouterEnv>(
|
||||||
config: ReactRouterBkndConfig<Env> = {},
|
config: ReactRouterBkndConfig<Env> = {},
|
||||||
args: Env = {} as Env,
|
args: Env = process.env as Env,
|
||||||
) {
|
) {
|
||||||
return async (fnArgs: ReactRouterFunctionArgs) => {
|
return async (fnArgs: ReactRouterFunctionArgs) => {
|
||||||
return (await getApp(config, args)).fetch(fnArgs.request);
|
return (await getApp(config, args)).fetch(fnArgs.request);
|
||||||
|
|||||||
+17
-2
@@ -2,7 +2,7 @@ import type { DB, PrimaryFieldType } from "bknd";
|
|||||||
import * as AuthPermissions from "auth/auth-permissions";
|
import * as AuthPermissions from "auth/auth-permissions";
|
||||||
import type { AuthStrategy } from "auth/authenticate/strategies/Strategy";
|
import type { AuthStrategy } from "auth/authenticate/strategies/Strategy";
|
||||||
import type { PasswordStrategy } from "auth/authenticate/strategies/PasswordStrategy";
|
import type { PasswordStrategy } from "auth/authenticate/strategies/PasswordStrategy";
|
||||||
import { $console, secureRandomString, transformObject } from "bknd/utils";
|
import { $console, secureRandomString, transformObject, pickKeys } from "bknd/utils";
|
||||||
import type { Entity, EntityManager } from "data/entities";
|
import type { Entity, EntityManager } from "data/entities";
|
||||||
import { em, entity, enumm, type FieldSchema } from "data/prototype";
|
import { em, entity, enumm, type FieldSchema } from "data/prototype";
|
||||||
import { Module } from "modules/Module";
|
import { Module } from "modules/Module";
|
||||||
@@ -61,7 +61,7 @@ export class AppAuth extends Module<AppAuthSchema> {
|
|||||||
|
|
||||||
// register roles
|
// register roles
|
||||||
const roles = transformObject(this.config.roles ?? {}, (role, name) => {
|
const roles = transformObject(this.config.roles ?? {}, (role, name) => {
|
||||||
return Role.create({ name, ...role });
|
return Role.create(name, role);
|
||||||
});
|
});
|
||||||
this.ctx.guard.setRoles(Object.values(roles));
|
this.ctx.guard.setRoles(Object.values(roles));
|
||||||
this.ctx.guard.setConfig(this.config.guard ?? {});
|
this.ctx.guard.setConfig(this.config.guard ?? {});
|
||||||
@@ -113,6 +113,19 @@ export class AppAuth extends Module<AppAuthSchema> {
|
|||||||
return authConfigSchema;
|
return authConfigSchema;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
getGuardContextSchema() {
|
||||||
|
const userschema = this.getUsersEntity().toSchema() as any;
|
||||||
|
return {
|
||||||
|
type: "object",
|
||||||
|
properties: {
|
||||||
|
user: {
|
||||||
|
type: "object",
|
||||||
|
properties: pickKeys(userschema.properties, this.config.jwt.fields as any),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
get authenticator(): Authenticator {
|
get authenticator(): Authenticator {
|
||||||
this.throwIfNotBuilt();
|
this.throwIfNotBuilt();
|
||||||
return this._authenticator!;
|
return this._authenticator!;
|
||||||
@@ -210,10 +223,12 @@ export class AppAuth extends Module<AppAuthSchema> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const strategies = this.authenticator.getStrategies();
|
const strategies = this.authenticator.getStrategies();
|
||||||
|
const roles = Object.fromEntries(this.ctx.guard.getRoles().map((r) => [r.name, r.toJSON()]));
|
||||||
|
|
||||||
return {
|
return {
|
||||||
...this.config,
|
...this.config,
|
||||||
...this.authenticator.toJSON(secrets),
|
...this.authenticator.toJSON(secrets),
|
||||||
|
roles,
|
||||||
strategies: transformObject(strategies, (strategy) => ({
|
strategies: transformObject(strategies, (strategy) => ({
|
||||||
enabled: this.isStrategyEnabled(strategy),
|
enabled: this.isStrategyEnabled(strategy),
|
||||||
...strategy.toJSON(secrets),
|
...strategy.toJSON(secrets),
|
||||||
|
|||||||
+11
-10
@@ -4,7 +4,7 @@ import type { AuthResponse, SafeUser, AuthStrategy } from "bknd";
|
|||||||
import { type BaseModuleApiOptions, ModuleApi } from "modules/ModuleApi";
|
import { type BaseModuleApiOptions, ModuleApi } from "modules/ModuleApi";
|
||||||
|
|
||||||
export type AuthApiOptions = BaseModuleApiOptions & {
|
export type AuthApiOptions = BaseModuleApiOptions & {
|
||||||
onTokenUpdate?: (token?: string) => void | Promise<void>;
|
onTokenUpdate?: (token?: string, verified?: boolean) => void | Promise<void>;
|
||||||
credentials?: "include" | "same-origin" | "omit";
|
credentials?: "include" | "same-origin" | "omit";
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -17,23 +17,19 @@ export class AuthApi extends ModuleApi<AuthApiOptions> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async login(strategy: string, input: any) {
|
async login(strategy: string, input: any) {
|
||||||
const res = await this.post<AuthResponse>([strategy, "login"], input, {
|
const res = await this.post<AuthResponse>([strategy, "login"], input);
|
||||||
credentials: this.options.credentials,
|
|
||||||
});
|
|
||||||
|
|
||||||
if (res.ok && res.body.token) {
|
if (res.ok && res.body.token) {
|
||||||
await this.options.onTokenUpdate?.(res.body.token);
|
await this.options.onTokenUpdate?.(res.body.token, true);
|
||||||
}
|
}
|
||||||
return res;
|
return res;
|
||||||
}
|
}
|
||||||
|
|
||||||
async register(strategy: string, input: any) {
|
async register(strategy: string, input: any) {
|
||||||
const res = await this.post<AuthResponse>([strategy, "register"], input, {
|
const res = await this.post<AuthResponse>([strategy, "register"], input);
|
||||||
credentials: this.options.credentials,
|
|
||||||
});
|
|
||||||
|
|
||||||
if (res.ok && res.body.token) {
|
if (res.ok && res.body.token) {
|
||||||
await this.options.onTokenUpdate?.(res.body.token);
|
await this.options.onTokenUpdate?.(res.body.token, true);
|
||||||
}
|
}
|
||||||
return res;
|
return res;
|
||||||
}
|
}
|
||||||
@@ -71,6 +67,11 @@ export class AuthApi extends ModuleApi<AuthApiOptions> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async logout() {
|
async logout() {
|
||||||
await this.options.onTokenUpdate?.(undefined);
|
return this.get(["logout"], undefined, {
|
||||||
|
headers: {
|
||||||
|
// this way bknd detects a json request and doesn't redirect back
|
||||||
|
Accept: "application/json",
|
||||||
|
},
|
||||||
|
}).then(() => this.options.onTokenUpdate?.(undefined, true));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -60,7 +60,10 @@ export class AuthController extends Controller {
|
|||||||
if (create) {
|
if (create) {
|
||||||
hono.post(
|
hono.post(
|
||||||
"/create",
|
"/create",
|
||||||
permission([AuthPermissions.createUser, DataPermissions.entityCreate]),
|
permission(AuthPermissions.createUser, {}),
|
||||||
|
permission(DataPermissions.entityCreate, {
|
||||||
|
context: (c) => ({ entity: this.auth.config.entity_name }),
|
||||||
|
}),
|
||||||
describeRoute({
|
describeRoute({
|
||||||
summary: "Create a new user",
|
summary: "Create a new user",
|
||||||
tags: ["auth"],
|
tags: ["auth"],
|
||||||
@@ -223,7 +226,6 @@ export class AuthController extends Controller {
|
|||||||
|
|
||||||
const roles = Object.keys(this.auth.config.roles ?? {});
|
const roles = Object.keys(this.auth.config.roles ?? {});
|
||||||
mcp.tool(
|
mcp.tool(
|
||||||
// @todo: needs permission
|
|
||||||
"auth_user_create",
|
"auth_user_create",
|
||||||
{
|
{
|
||||||
description: "Create a new user",
|
description: "Create a new user",
|
||||||
@@ -238,14 +240,13 @@ export class AuthController extends Controller {
|
|||||||
}),
|
}),
|
||||||
},
|
},
|
||||||
async (params, c) => {
|
async (params, c) => {
|
||||||
await c.context.ctx().helper.throwUnlessGranted(AuthPermissions.createUser, c);
|
await c.context.ctx().helper.granted(c, AuthPermissions.createUser);
|
||||||
|
|
||||||
return c.json(await this.auth.createUser(params));
|
return c.json(await this.auth.createUser(params));
|
||||||
},
|
},
|
||||||
);
|
);
|
||||||
|
|
||||||
mcp.tool(
|
mcp.tool(
|
||||||
// @todo: needs permission
|
|
||||||
"auth_user_token",
|
"auth_user_token",
|
||||||
{
|
{
|
||||||
description: "Get a user token",
|
description: "Get a user token",
|
||||||
@@ -255,7 +256,7 @@ export class AuthController extends Controller {
|
|||||||
}),
|
}),
|
||||||
},
|
},
|
||||||
async (params, c) => {
|
async (params, c) => {
|
||||||
await c.context.ctx().helper.throwUnlessGranted(AuthPermissions.createToken, c);
|
await c.context.ctx().helper.granted(c, AuthPermissions.createToken);
|
||||||
|
|
||||||
const user = await getUser(params);
|
const user = await getUser(params);
|
||||||
return c.json({ user, token: await this.auth.authenticator.jwt(user) });
|
return c.json({ user, token: await this.auth.authenticator.jwt(user) });
|
||||||
@@ -263,7 +264,6 @@ export class AuthController extends Controller {
|
|||||||
);
|
);
|
||||||
|
|
||||||
mcp.tool(
|
mcp.tool(
|
||||||
// @todo: needs permission
|
|
||||||
"auth_user_password_change",
|
"auth_user_password_change",
|
||||||
{
|
{
|
||||||
description: "Change a user's password",
|
description: "Change a user's password",
|
||||||
@@ -274,7 +274,7 @@ export class AuthController extends Controller {
|
|||||||
}),
|
}),
|
||||||
},
|
},
|
||||||
async (params, c) => {
|
async (params, c) => {
|
||||||
await c.context.ctx().helper.throwUnlessGranted(AuthPermissions.changePassword, c);
|
await c.context.ctx().helper.granted(c, AuthPermissions.changePassword);
|
||||||
|
|
||||||
const user = await getUser(params);
|
const user = await getUser(params);
|
||||||
if (!(await this.auth.changePassword(user.id, params.password))) {
|
if (!(await this.auth.changePassword(user.id, params.password))) {
|
||||||
@@ -285,7 +285,6 @@ export class AuthController extends Controller {
|
|||||||
);
|
);
|
||||||
|
|
||||||
mcp.tool(
|
mcp.tool(
|
||||||
// @todo: needs permission
|
|
||||||
"auth_user_password_test",
|
"auth_user_password_test",
|
||||||
{
|
{
|
||||||
description: "Test a user's password",
|
description: "Test a user's password",
|
||||||
@@ -295,7 +294,7 @@ export class AuthController extends Controller {
|
|||||||
}),
|
}),
|
||||||
},
|
},
|
||||||
async (params, c) => {
|
async (params, c) => {
|
||||||
await c.context.ctx().helper.throwUnlessGranted(AuthPermissions.testPassword, c);
|
await c.context.ctx().helper.granted(c, AuthPermissions.testPassword);
|
||||||
|
|
||||||
const pw = this.auth.authenticator.strategy("password") as PasswordStrategy;
|
const pw = this.auth.authenticator.strategy("password") as PasswordStrategy;
|
||||||
const controller = pw.getController(this.auth.authenticator);
|
const controller = pw.getController(this.auth.authenticator);
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { Permission } from "core/security/Permission";
|
import { Permission } from "auth/authorize/Permission";
|
||||||
|
|
||||||
export const createUser = new Permission("auth.user.create");
|
export const createUser = new Permission("auth.user.create");
|
||||||
//export const updateUser = new Permission("auth.user.update");
|
//export const updateUser = new Permission("auth.user.update");
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { cookieConfig, jwtConfig } from "auth/authenticate/Authenticator";
|
import { cookieConfig, jwtConfig } from "auth/authenticate/Authenticator";
|
||||||
import { CustomOAuthStrategy, OAuthStrategy, PasswordStrategy } from "auth/authenticate/strategies";
|
import { CustomOAuthStrategy, OAuthStrategy, PasswordStrategy } from "auth/authenticate/strategies";
|
||||||
import { objectTransform, s } from "bknd/utils";
|
import { roleSchema } from "auth/authorize/Role";
|
||||||
|
import { objectTransform, omitKeys, pick, s } from "bknd/utils";
|
||||||
import { $object, $record } from "modules/mcp";
|
import { $object, $record } from "modules/mcp";
|
||||||
|
|
||||||
export const Strategies = {
|
export const Strategies = {
|
||||||
@@ -40,11 +41,8 @@ export type AppAuthCustomOAuthStrategy = s.Static<typeof STRATEGIES.custom_oauth
|
|||||||
const guardConfigSchema = s.object({
|
const guardConfigSchema = s.object({
|
||||||
enabled: s.boolean({ default: false }).optional(),
|
enabled: s.boolean({ default: false }).optional(),
|
||||||
});
|
});
|
||||||
export const guardRoleSchema = s.strictObject({
|
|
||||||
permissions: s.array(s.string()).optional(),
|
export const guardRoleSchema = roleSchema;
|
||||||
is_default: s.boolean().optional(),
|
|
||||||
implicit_allow: s.boolean().optional(),
|
|
||||||
});
|
|
||||||
|
|
||||||
export const authConfigSchema = $object(
|
export const authConfigSchema = $object(
|
||||||
"config_auth",
|
"config_auth",
|
||||||
|
|||||||
@@ -6,10 +6,8 @@ import { deleteCookie, getSignedCookie, setSignedCookie } from "hono/cookie";
|
|||||||
import { sign, verify } from "hono/jwt";
|
import { sign, verify } from "hono/jwt";
|
||||||
import { type CookieOptions, serializeSigned } from "hono/utils/cookie";
|
import { type CookieOptions, serializeSigned } from "hono/utils/cookie";
|
||||||
import type { ServerEnv } from "modules/Controller";
|
import type { ServerEnv } from "modules/Controller";
|
||||||
import { pick } from "lodash-es";
|
|
||||||
import { InvalidConditionsException } from "auth/errors";
|
import { InvalidConditionsException } from "auth/errors";
|
||||||
import { s, parse, secret, runtimeSupports, truncate, $console } from "bknd/utils";
|
import { s, parse, secret, runtimeSupports, truncate, $console, pickKeys } from "bknd/utils";
|
||||||
import { $object } from "modules/mcp";
|
|
||||||
import type { AuthStrategy } from "./strategies/Strategy";
|
import type { AuthStrategy } from "./strategies/Strategy";
|
||||||
|
|
||||||
type Input = any; // workaround
|
type Input = any; // workaround
|
||||||
@@ -44,6 +42,7 @@ export interface UserPool {
|
|||||||
const defaultCookieExpires = 60 * 60 * 24 * 7; // 1 week in seconds
|
const defaultCookieExpires = 60 * 60 * 24 * 7; // 1 week in seconds
|
||||||
export const cookieConfig = s
|
export const cookieConfig = s
|
||||||
.strictObject({
|
.strictObject({
|
||||||
|
domain: s.string().optional(),
|
||||||
path: s.string({ default: "/" }),
|
path: s.string({ default: "/" }),
|
||||||
sameSite: s.string({ enum: ["strict", "lax", "none"], default: "lax" }),
|
sameSite: s.string({ enum: ["strict", "lax", "none"], default: "lax" }),
|
||||||
secure: s.boolean({ default: true }),
|
secure: s.boolean({ default: true }),
|
||||||
@@ -229,7 +228,7 @@ export class Authenticator<
|
|||||||
|
|
||||||
// @todo: add jwt tests
|
// @todo: add jwt tests
|
||||||
async jwt(_user: SafeUser | ProfileExchange): Promise<string> {
|
async jwt(_user: SafeUser | ProfileExchange): Promise<string> {
|
||||||
const user = pick(_user, this.config.jwt.fields);
|
const user = pickKeys(_user, this.config.jwt.fields as any);
|
||||||
|
|
||||||
const payload: JWTPayload = {
|
const payload: JWTPayload = {
|
||||||
...user,
|
...user,
|
||||||
@@ -255,7 +254,7 @@ export class Authenticator<
|
|||||||
}
|
}
|
||||||
|
|
||||||
async safeAuthResponse(_user: User): Promise<AuthResponse> {
|
async safeAuthResponse(_user: User): Promise<AuthResponse> {
|
||||||
const user = pick(_user, this.config.jwt.fields) as SafeUser;
|
const user = pickKeys(_user, this.config.jwt.fields as any) as SafeUser;
|
||||||
return {
|
return {
|
||||||
user,
|
user,
|
||||||
token: await this.jwt(user),
|
token: await this.jwt(user),
|
||||||
@@ -290,6 +289,7 @@ export class Authenticator<
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
...cookieConfig,
|
...cookieConfig,
|
||||||
|
domain: cookieConfig.domain ?? undefined,
|
||||||
expires: new Date(Date.now() + expires * 1000),
|
expires: new Date(Date.now() + expires * 1000),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -327,6 +327,31 @@ export class Authenticator<
|
|||||||
await setSignedCookie(c, "auth", token, secret, this.cookieOptions);
|
await setSignedCookie(c, "auth", token, secret, this.cookieOptions);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async getAuthCookieHeader(token: string, headers = new Headers()) {
|
||||||
|
const c = {
|
||||||
|
header: (key: string, value: string) => {
|
||||||
|
headers.set(key, value);
|
||||||
|
},
|
||||||
|
};
|
||||||
|
await this.setAuthCookie(c as any, token);
|
||||||
|
return headers;
|
||||||
|
}
|
||||||
|
|
||||||
|
async removeAuthCookieHeader(headers = new Headers()) {
|
||||||
|
const c = {
|
||||||
|
header: (key: string, value: string) => {
|
||||||
|
headers.set(key, value);
|
||||||
|
},
|
||||||
|
req: {
|
||||||
|
raw: {
|
||||||
|
headers,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
this.deleteAuthCookie(c as any);
|
||||||
|
return headers;
|
||||||
|
}
|
||||||
|
|
||||||
async unsafeGetAuthCookie(token: string): Promise<string | undefined> {
|
async unsafeGetAuthCookie(token: string): Promise<string | undefined> {
|
||||||
// this works for as long as cookieOptions.prefix is not set
|
// this works for as long as cookieOptions.prefix is not set
|
||||||
return serializeSigned("auth", token, this.config.jwt.secret, this.cookieOptions);
|
return serializeSigned("auth", token, this.config.jwt.secret, this.cookieOptions);
|
||||||
@@ -354,7 +379,10 @@ export class Authenticator<
|
|||||||
|
|
||||||
// @todo: move this to a server helper
|
// @todo: move this to a server helper
|
||||||
isJsonRequest(c: Context): boolean {
|
isJsonRequest(c: Context): boolean {
|
||||||
return c.req.header("Content-Type") === "application/json";
|
return (
|
||||||
|
c.req.header("Content-Type") === "application/json" ||
|
||||||
|
c.req.header("Accept") === "application/json"
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async getBody(c: Context) {
|
async getBody(c: Context) {
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import type { User } from "bknd";
|
import type { User } from "bknd";
|
||||||
import type { Authenticator } from "auth/authenticate/Authenticator";
|
import type { Authenticator } from "auth/authenticate/Authenticator";
|
||||||
import { InvalidCredentialsException } from "auth/errors";
|
import { InvalidCredentialsException } from "auth/errors";
|
||||||
import { hash, $console, s, parse, jsc } from "bknd/utils";
|
import { hash, $console, s, parse, jsc, describeRoute } from "bknd/utils";
|
||||||
import { Hono } from "hono";
|
import { Hono } from "hono";
|
||||||
import { compare as bcryptCompare, genSalt as bcryptGenSalt, hash as bcryptHash } from "bcryptjs";
|
import { compare as bcryptCompare, genSalt as bcryptGenSalt, hash as bcryptHash } from "bcryptjs";
|
||||||
import { AuthStrategy } from "./Strategy";
|
import { AuthStrategy } from "./Strategy";
|
||||||
@@ -84,51 +84,67 @@ export class PasswordStrategy extends AuthStrategy<typeof schema> {
|
|||||||
});
|
});
|
||||||
const payloadSchema = this.getPayloadSchema();
|
const payloadSchema = this.getPayloadSchema();
|
||||||
|
|
||||||
hono.post("/login", jsc("query", redirectQuerySchema), async (c) => {
|
hono.post(
|
||||||
try {
|
"/login",
|
||||||
const body = parse(payloadSchema, await authenticator.getBody(c), {
|
describeRoute({
|
||||||
onError: (errors) => {
|
summary: "Login with email and password",
|
||||||
$console.error("Invalid login payload", [...errors]);
|
tags: ["auth"],
|
||||||
throw new InvalidCredentialsException();
|
}),
|
||||||
},
|
jsc("query", redirectQuerySchema),
|
||||||
});
|
async (c) => {
|
||||||
const { redirect } = c.req.valid("query");
|
try {
|
||||||
|
const body = parse(payloadSchema, await authenticator.getBody(c), {
|
||||||
return await authenticator.resolveLogin(c, this, body, this.verify(body.password), {
|
|
||||||
redirect,
|
|
||||||
});
|
|
||||||
} catch (e) {
|
|
||||||
return authenticator.respondWithError(c, e as any);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
hono.post("/register", jsc("query", redirectQuerySchema), async (c) => {
|
|
||||||
try {
|
|
||||||
const { redirect } = c.req.valid("query");
|
|
||||||
const { password, email, ...body } = parse(
|
|
||||||
payloadSchema,
|
|
||||||
await authenticator.getBody(c),
|
|
||||||
{
|
|
||||||
onError: (errors) => {
|
onError: (errors) => {
|
||||||
$console.error("Invalid register payload", [...errors]);
|
$console.error("Invalid login payload", [...errors]);
|
||||||
new InvalidCredentialsException();
|
throw new InvalidCredentialsException();
|
||||||
},
|
},
|
||||||
},
|
});
|
||||||
);
|
const { redirect } = c.req.valid("query");
|
||||||
|
|
||||||
const profile = {
|
return await authenticator.resolveLogin(c, this, body, this.verify(body.password), {
|
||||||
...body,
|
redirect,
|
||||||
email,
|
});
|
||||||
strategy_value: await this.hash(password),
|
} catch (e) {
|
||||||
};
|
return authenticator.respondWithError(c, e as any);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
return await authenticator.resolveRegister(c, this, profile, async () => void 0, {
|
hono.post(
|
||||||
redirect,
|
"/register",
|
||||||
});
|
describeRoute({
|
||||||
} catch (e) {
|
summary: "Register a new user with email and password",
|
||||||
return authenticator.respondWithError(c, e as any);
|
tags: ["auth"],
|
||||||
}
|
}),
|
||||||
});
|
jsc("query", redirectQuerySchema),
|
||||||
|
async (c) => {
|
||||||
|
try {
|
||||||
|
const { redirect } = c.req.valid("query");
|
||||||
|
const { password, email, ...body } = parse(
|
||||||
|
payloadSchema,
|
||||||
|
await authenticator.getBody(c),
|
||||||
|
{
|
||||||
|
onError: (errors) => {
|
||||||
|
$console.error("Invalid register payload", [...errors]);
|
||||||
|
new InvalidCredentialsException();
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
const profile = {
|
||||||
|
...body,
|
||||||
|
email,
|
||||||
|
strategy_value: await this.hash(password),
|
||||||
|
};
|
||||||
|
|
||||||
|
return await authenticator.resolveRegister(c, this, profile, async () => void 0, {
|
||||||
|
redirect,
|
||||||
|
});
|
||||||
|
} catch (e) {
|
||||||
|
return authenticator.respondWithError(c, e as any);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
return hono;
|
return hono;
|
||||||
}
|
}
|
||||||
|
|||||||
+248
-79
@@ -1,9 +1,12 @@
|
|||||||
import { Exception } from "core/errors";
|
import { Exception } from "core/errors";
|
||||||
import { $console, objectTransform } from "bknd/utils";
|
import { $console, mergeObject, type s } from "bknd/utils";
|
||||||
import { Permission } from "core/security/Permission";
|
import type { Permission, PermissionContext } from "auth/authorize/Permission";
|
||||||
import type { Context } from "hono";
|
import type { Context } from "hono";
|
||||||
import type { ServerEnv } from "modules/Controller";
|
import type { ServerEnv } from "modules/Controller";
|
||||||
import { Role } from "./Role";
|
import type { Role } from "./Role";
|
||||||
|
import { HttpStatus } from "bknd/utils";
|
||||||
|
import type { Policy, PolicySchema } from "./Policy";
|
||||||
|
import { convert, type ObjectQuery } from "core/object/query/object-query";
|
||||||
|
|
||||||
export type GuardUserContext = {
|
export type GuardUserContext = {
|
||||||
role?: string | null;
|
role?: string | null;
|
||||||
@@ -12,41 +15,43 @@ export type GuardUserContext = {
|
|||||||
|
|
||||||
export type GuardConfig = {
|
export type GuardConfig = {
|
||||||
enabled?: boolean;
|
enabled?: boolean;
|
||||||
|
context?: object;
|
||||||
};
|
};
|
||||||
export type GuardContext = Context<ServerEnv> | GuardUserContext;
|
export type GuardContext = Context<ServerEnv> | GuardUserContext;
|
||||||
|
|
||||||
export class Guard {
|
export class GuardPermissionsException extends Exception {
|
||||||
permissions: Permission[];
|
override name = "PermissionsException";
|
||||||
roles?: Role[];
|
override code = HttpStatus.FORBIDDEN;
|
||||||
config?: GuardConfig;
|
|
||||||
|
|
||||||
constructor(permissions: Permission[] = [], roles: Role[] = [], config?: GuardConfig) {
|
constructor(
|
||||||
|
public permission: Permission,
|
||||||
|
public policy?: Policy,
|
||||||
|
public description?: string,
|
||||||
|
) {
|
||||||
|
super(`Permission "${permission.name}" not granted`);
|
||||||
|
}
|
||||||
|
|
||||||
|
override toJSON(): any {
|
||||||
|
return {
|
||||||
|
...super.toJSON(),
|
||||||
|
description: this.description,
|
||||||
|
permission: this.permission.name,
|
||||||
|
policy: this.policy?.toJSON(),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class Guard {
|
||||||
|
constructor(
|
||||||
|
public permissions: Permission<any, any, any, any>[] = [],
|
||||||
|
public roles: Role[] = [],
|
||||||
|
public config?: GuardConfig,
|
||||||
|
) {
|
||||||
this.permissions = permissions;
|
this.permissions = permissions;
|
||||||
this.roles = roles;
|
this.roles = roles;
|
||||||
this.config = config;
|
this.config = config;
|
||||||
}
|
}
|
||||||
|
|
||||||
static create(
|
|
||||||
permissionNames: string[],
|
|
||||||
roles?: Record<
|
|
||||||
string,
|
|
||||||
{
|
|
||||||
permissions?: string[];
|
|
||||||
is_default?: boolean;
|
|
||||||
implicit_allow?: boolean;
|
|
||||||
}
|
|
||||||
>,
|
|
||||||
config?: GuardConfig,
|
|
||||||
) {
|
|
||||||
const _roles = roles
|
|
||||||
? objectTransform(roles, ({ permissions = [], is_default, implicit_allow }, name) => {
|
|
||||||
return Role.createWithPermissionNames(name, permissions, is_default, implicit_allow);
|
|
||||||
})
|
|
||||||
: {};
|
|
||||||
const _permissions = permissionNames.map((name) => new Permission(name));
|
|
||||||
return new Guard(_permissions, Object.values(_roles), config);
|
|
||||||
}
|
|
||||||
|
|
||||||
getPermissionNames(): string[] {
|
getPermissionNames(): string[] {
|
||||||
return this.permissions.map((permission) => permission.name);
|
return this.permissions.map((permission) => permission.name);
|
||||||
}
|
}
|
||||||
@@ -73,7 +78,7 @@ export class Guard {
|
|||||||
return this;
|
return this;
|
||||||
}
|
}
|
||||||
|
|
||||||
registerPermission(permission: Permission) {
|
registerPermission(permission: Permission<any, any, any, any>) {
|
||||||
if (this.permissions.find((p) => p.name === permission.name)) {
|
if (this.permissions.find((p) => p.name === permission.name)) {
|
||||||
throw new Error(`Permission ${permission.name} already exists`);
|
throw new Error(`Permission ${permission.name} already exists`);
|
||||||
}
|
}
|
||||||
@@ -82,9 +87,13 @@ export class Guard {
|
|||||||
return this;
|
return this;
|
||||||
}
|
}
|
||||||
|
|
||||||
registerPermissions(permissions: Record<string, Permission>);
|
registerPermissions(permissions: Record<string, Permission<any, any, any, any>>);
|
||||||
registerPermissions(permissions: Permission[]);
|
registerPermissions(permissions: Permission<any, any, any, any>[]);
|
||||||
registerPermissions(permissions: Permission[] | Record<string, Permission>) {
|
registerPermissions(
|
||||||
|
permissions:
|
||||||
|
| Permission<any, any, any, any>[]
|
||||||
|
| Record<string, Permission<any, any, any, any>>,
|
||||||
|
) {
|
||||||
const p = Array.isArray(permissions) ? permissions : Object.values(permissions);
|
const p = Array.isArray(permissions) ? permissions : Object.values(permissions);
|
||||||
|
|
||||||
for (const permission of p) {
|
for (const permission of p) {
|
||||||
@@ -117,56 +126,216 @@ export class Guard {
|
|||||||
return this.config?.enabled === true;
|
return this.config?.enabled === true;
|
||||||
}
|
}
|
||||||
|
|
||||||
hasPermission(permission: Permission, user?: GuardUserContext): boolean;
|
private collect(permission: Permission, c: GuardContext | undefined, context: any) {
|
||||||
hasPermission(name: string, user?: GuardUserContext): boolean;
|
|
||||||
hasPermission(permissionOrName: Permission | string, user?: GuardUserContext): boolean {
|
|
||||||
if (!this.isEnabled()) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
const name = typeof permissionOrName === "string" ? permissionOrName : permissionOrName.name;
|
|
||||||
$console.debug("guard: checking permission", {
|
|
||||||
name,
|
|
||||||
user: { id: user?.id, role: user?.role },
|
|
||||||
});
|
|
||||||
const exists = this.permissionExists(name);
|
|
||||||
if (!exists) {
|
|
||||||
throw new Error(`Permission ${name} does not exist`);
|
|
||||||
}
|
|
||||||
|
|
||||||
const role = this.getUserRole(user);
|
|
||||||
|
|
||||||
if (!role) {
|
|
||||||
$console.debug("guard: user has no role, denying");
|
|
||||||
return false;
|
|
||||||
} else if (role.implicit_allow === true) {
|
|
||||||
$console.debug(`guard: role "${role.name}" has implicit allow, allowing`);
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
const rolePermission = role.permissions.find(
|
|
||||||
(rolePermission) => rolePermission.permission.name === name,
|
|
||||||
);
|
|
||||||
|
|
||||||
$console.debug("guard: rolePermission, allowing?", {
|
|
||||||
permission: name,
|
|
||||||
role: role.name,
|
|
||||||
allowing: !!rolePermission,
|
|
||||||
});
|
|
||||||
return !!rolePermission;
|
|
||||||
}
|
|
||||||
|
|
||||||
granted(permission: Permission | string, c?: GuardContext): boolean {
|
|
||||||
const user = c && "get" in c ? c.get("auth")?.user : c;
|
const user = c && "get" in c ? c.get("auth")?.user : c;
|
||||||
return this.hasPermission(permission as any, user);
|
const ctx = {
|
||||||
|
...((context ?? {}) as any),
|
||||||
|
...this.config?.context,
|
||||||
|
user,
|
||||||
|
};
|
||||||
|
const exists = this.permissionExists(permission.name);
|
||||||
|
const role = this.getUserRole(user);
|
||||||
|
const rolePermission = role?.permissions.find(
|
||||||
|
(rolePermission) => rolePermission.permission.name === permission.name,
|
||||||
|
);
|
||||||
|
return {
|
||||||
|
ctx,
|
||||||
|
user,
|
||||||
|
exists,
|
||||||
|
role,
|
||||||
|
rolePermission,
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
throwUnlessGranted(permission: Permission | string, c: GuardContext) {
|
granted<P extends Permission<any, any, any, any>>(
|
||||||
if (!this.granted(permission, c)) {
|
permission: P,
|
||||||
throw new Exception(
|
c: GuardContext,
|
||||||
`Permission "${typeof permission === "string" ? permission : permission.name}" not granted`,
|
context: PermissionContext<P>,
|
||||||
403,
|
): void;
|
||||||
|
granted<P extends Permission<any, any, undefined, any>>(permission: P, c: GuardContext): void;
|
||||||
|
granted<P extends Permission<any, any, any, any>>(
|
||||||
|
permission: P,
|
||||||
|
c: GuardContext,
|
||||||
|
context?: PermissionContext<P>,
|
||||||
|
): void {
|
||||||
|
if (!this.isEnabled()) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const { ctx: _ctx, exists, role, rolePermission } = this.collect(permission, c, context);
|
||||||
|
|
||||||
|
// validate context
|
||||||
|
let ctx = Object.assign({}, _ctx);
|
||||||
|
if (permission.context) {
|
||||||
|
ctx = permission.parseContext(ctx);
|
||||||
|
}
|
||||||
|
|
||||||
|
$console.debug("guard: checking permission", {
|
||||||
|
name: permission.name,
|
||||||
|
context: ctx,
|
||||||
|
});
|
||||||
|
if (!exists) {
|
||||||
|
throw new GuardPermissionsException(
|
||||||
|
permission,
|
||||||
|
undefined,
|
||||||
|
`Permission ${permission.name} does not exist`,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!role) {
|
||||||
|
throw new GuardPermissionsException(permission, undefined, "User has no role");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!rolePermission) {
|
||||||
|
if (role.implicit_allow === true) {
|
||||||
|
$console.debug(`guard: role "${role.name}" has implicit allow, allowing`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new GuardPermissionsException(
|
||||||
|
permission,
|
||||||
|
undefined,
|
||||||
|
`Role "${role.name}" does not have required permission`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (rolePermission?.policies.length > 0) {
|
||||||
|
$console.debug("guard: rolePermission has policies, checking");
|
||||||
|
|
||||||
|
// set the default effect of the role permission
|
||||||
|
let allowed = rolePermission.effect === "allow";
|
||||||
|
for (const policy of rolePermission.policies) {
|
||||||
|
$console.debug("guard: checking policy", { policy: policy.toJSON(), ctx });
|
||||||
|
// skip filter policies
|
||||||
|
if (policy.content.effect === "filter") continue;
|
||||||
|
|
||||||
|
// if condition is met, check the effect
|
||||||
|
const meets = policy.meetsCondition(ctx);
|
||||||
|
if (meets) {
|
||||||
|
$console.debug("guard: policy meets condition");
|
||||||
|
// if deny, then break early
|
||||||
|
if (policy.content.effect === "deny") {
|
||||||
|
$console.debug("guard: policy is deny, setting allowed to false");
|
||||||
|
allowed = false;
|
||||||
|
break;
|
||||||
|
|
||||||
|
// if allow, set allow but continue checking
|
||||||
|
} else if (policy.content.effect === "allow") {
|
||||||
|
allowed = true;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
$console.debug("guard: policy does not meet condition");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!allowed) {
|
||||||
|
throw new GuardPermissionsException(permission, undefined, "Policy condition unmet");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$console.debug("guard allowing", {
|
||||||
|
permission: permission.name,
|
||||||
|
role: role.name,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
filters<P extends Permission<any, any, any, any>>(
|
||||||
|
permission: P,
|
||||||
|
c: GuardContext,
|
||||||
|
context: PermissionContext<P>,
|
||||||
|
);
|
||||||
|
filters<P extends Permission<any, any, undefined, any>>(permission: P, c: GuardContext);
|
||||||
|
filters<P extends Permission<any, any, any, any>>(
|
||||||
|
permission: P,
|
||||||
|
c: GuardContext,
|
||||||
|
context?: PermissionContext<P>,
|
||||||
|
) {
|
||||||
|
if (!permission.isFilterable()) {
|
||||||
|
throw new GuardPermissionsException(permission, undefined, "Permission is not filterable");
|
||||||
|
}
|
||||||
|
|
||||||
|
const {
|
||||||
|
ctx: _ctx,
|
||||||
|
exists,
|
||||||
|
role,
|
||||||
|
user,
|
||||||
|
rolePermission,
|
||||||
|
} = this.collect(permission, c, context);
|
||||||
|
|
||||||
|
// validate context
|
||||||
|
let ctx = Object.assign(
|
||||||
|
{
|
||||||
|
user,
|
||||||
|
},
|
||||||
|
_ctx,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (permission.context) {
|
||||||
|
ctx = permission.parseContext(ctx, {
|
||||||
|
coerceDropUnknown: false,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const filters: PolicySchema["filter"][] = [];
|
||||||
|
const policies: Policy[] = [];
|
||||||
|
if (exists && role && rolePermission && rolePermission.policies.length > 0) {
|
||||||
|
for (const policy of rolePermission.policies) {
|
||||||
|
if (policy.content.effect === "filter") {
|
||||||
|
const meets = policy.meetsCondition(ctx);
|
||||||
|
if (meets) {
|
||||||
|
policies.push(policy);
|
||||||
|
filters.push(policy.getReplacedFilter(ctx));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const filter = filters.length > 0 ? mergeObject({}, ...filters) : undefined;
|
||||||
|
return {
|
||||||
|
filters,
|
||||||
|
filter,
|
||||||
|
policies,
|
||||||
|
merge: (givenFilter: object | undefined) => {
|
||||||
|
return mergeFilters(givenFilter ?? {}, filter ?? {});
|
||||||
|
},
|
||||||
|
matches: (subject: object | object[], opts?: { throwOnError?: boolean }) => {
|
||||||
|
const subjects = Array.isArray(subject) ? subject : [subject];
|
||||||
|
if (policies.length > 0) {
|
||||||
|
for (const policy of policies) {
|
||||||
|
for (const subject of subjects) {
|
||||||
|
if (!policy.meetsFilter(subject, ctx)) {
|
||||||
|
if (opts?.throwOnError) {
|
||||||
|
throw new GuardPermissionsException(
|
||||||
|
permission,
|
||||||
|
policy,
|
||||||
|
"Policy filter not met",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
},
|
||||||
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export function mergeFilters(base: ObjectQuery, priority: ObjectQuery) {
|
||||||
|
const base_converted = convert(base);
|
||||||
|
const priority_converted = convert(priority);
|
||||||
|
const merged = mergeObject(base_converted, priority_converted);
|
||||||
|
|
||||||
|
// in case priority filter is also contained in base's $and, merge priority in
|
||||||
|
if ("$or" in base_converted && base_converted.$or) {
|
||||||
|
const $ors = base_converted.$or as ObjectQuery;
|
||||||
|
const priority_keys = Object.keys(priority_converted);
|
||||||
|
for (const key of priority_keys) {
|
||||||
|
if (key in $ors) {
|
||||||
|
merged.$or[key] = mergeObject($ors[key], priority_converted[key]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return merged;
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,77 @@
|
|||||||
|
import { s, type ParseOptions, parse, InvalidSchemaError, HttpStatus } from "bknd/utils";
|
||||||
|
|
||||||
|
export const permissionOptionsSchema = s
|
||||||
|
.strictObject({
|
||||||
|
description: s.string(),
|
||||||
|
filterable: s.boolean(),
|
||||||
|
})
|
||||||
|
.partial();
|
||||||
|
|
||||||
|
export type TPermission = {
|
||||||
|
name: string;
|
||||||
|
description?: string;
|
||||||
|
filterable?: boolean;
|
||||||
|
context?: any;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type PermissionOptions = s.Static<typeof permissionOptionsSchema>;
|
||||||
|
export type PermissionContext<P extends Permission<any, any, any, any>> = P extends Permission<
|
||||||
|
any,
|
||||||
|
any,
|
||||||
|
infer Context,
|
||||||
|
any
|
||||||
|
>
|
||||||
|
? Context extends s.ObjectSchema
|
||||||
|
? s.Static<Context>
|
||||||
|
: never
|
||||||
|
: never;
|
||||||
|
|
||||||
|
export class InvalidPermissionContextError extends InvalidSchemaError {
|
||||||
|
override name = "InvalidPermissionContextError";
|
||||||
|
|
||||||
|
// changing to internal server error because it's an unexpected behavior
|
||||||
|
override code = HttpStatus.INTERNAL_SERVER_ERROR;
|
||||||
|
|
||||||
|
static from(e: InvalidSchemaError) {
|
||||||
|
return new InvalidPermissionContextError(e.schema, e.value, e.errors);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class Permission<
|
||||||
|
Name extends string = string,
|
||||||
|
Options extends PermissionOptions = {},
|
||||||
|
Context extends s.ObjectSchema | undefined = undefined,
|
||||||
|
ContextValue = Context extends s.ObjectSchema ? s.Static<Context> : undefined,
|
||||||
|
> {
|
||||||
|
constructor(
|
||||||
|
public name: Name,
|
||||||
|
public options: Options = {} as Options,
|
||||||
|
public context: Context = undefined as Context,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
isFilterable() {
|
||||||
|
return this.options.filterable === true;
|
||||||
|
}
|
||||||
|
|
||||||
|
parseContext(ctx: ContextValue, opts?: ParseOptions) {
|
||||||
|
// @todo: allow additional properties
|
||||||
|
if (!this.context) return ctx;
|
||||||
|
try {
|
||||||
|
return this.context ? parse(this.context!, ctx, opts) : undefined;
|
||||||
|
} catch (e) {
|
||||||
|
if (e instanceof InvalidSchemaError) {
|
||||||
|
throw InvalidPermissionContextError.from(e);
|
||||||
|
}
|
||||||
|
|
||||||
|
throw e;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
toJSON() {
|
||||||
|
return {
|
||||||
|
name: this.name,
|
||||||
|
...this.options,
|
||||||
|
context: this.context,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
import { s, parse, recursivelyReplacePlaceholders } from "bknd/utils";
|
||||||
|
import * as query from "core/object/query/object-query";
|
||||||
|
|
||||||
|
export const policySchema = s
|
||||||
|
.strictObject({
|
||||||
|
description: s.string(),
|
||||||
|
condition: s.object({}).optional() as s.Schema<{}, query.ObjectQuery | undefined>,
|
||||||
|
// @todo: potentially remove this, and invert from rolePermission.effect
|
||||||
|
effect: s.string({ enum: ["allow", "deny", "filter"], default: "allow" }),
|
||||||
|
filter: s.object({}).optional() as s.Schema<{}, query.ObjectQuery | undefined>,
|
||||||
|
})
|
||||||
|
.partial();
|
||||||
|
export type PolicySchema = s.Static<typeof policySchema>;
|
||||||
|
|
||||||
|
export class Policy<Schema extends PolicySchema = PolicySchema> {
|
||||||
|
public content: Schema;
|
||||||
|
|
||||||
|
constructor(content?: Schema) {
|
||||||
|
this.content = parse(policySchema, content ?? {}, {
|
||||||
|
withDefaults: true,
|
||||||
|
}) as Schema;
|
||||||
|
}
|
||||||
|
|
||||||
|
replace(context: object, vars?: Record<string, any>, fallback?: any) {
|
||||||
|
return vars
|
||||||
|
? recursivelyReplacePlaceholders(context, /^@([a-zA-Z_\.]+)$/, vars, fallback)
|
||||||
|
: context;
|
||||||
|
}
|
||||||
|
|
||||||
|
getReplacedFilter(context: object, fallback?: any) {
|
||||||
|
if (!this.content.filter) return context;
|
||||||
|
return this.replace(this.content.filter!, context, fallback);
|
||||||
|
}
|
||||||
|
|
||||||
|
meetsCondition(context: object, vars?: Record<string, any>) {
|
||||||
|
if (!this.content.condition) return true;
|
||||||
|
return query.validate(this.replace(this.content.condition!, vars), context);
|
||||||
|
}
|
||||||
|
|
||||||
|
meetsFilter(subject: object, vars?: Record<string, any>) {
|
||||||
|
if (!this.content.filter) return true;
|
||||||
|
return query.validate(this.replace(this.content.filter!, vars), subject);
|
||||||
|
}
|
||||||
|
|
||||||
|
getFiltered<Given extends any[]>(given: Given): Given {
|
||||||
|
return given.filter((item) => this.meetsFilter(item)) as Given;
|
||||||
|
}
|
||||||
|
|
||||||
|
toJSON() {
|
||||||
|
return this.content;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,10 +1,39 @@
|
|||||||
import { Permission } from "core/security/Permission";
|
import { s } from "bknd/utils";
|
||||||
|
import { Permission } from "./Permission";
|
||||||
|
import { Policy, policySchema } from "./Policy";
|
||||||
|
|
||||||
|
// default effect is allow for backward compatibility
|
||||||
|
const defaultEffect = "allow";
|
||||||
|
|
||||||
|
export const rolePermissionSchema = s.strictObject({
|
||||||
|
permission: s.string(),
|
||||||
|
effect: s.string({ enum: ["allow", "deny"], default: defaultEffect }).optional(),
|
||||||
|
policies: s.array(policySchema).optional(),
|
||||||
|
});
|
||||||
|
export type RolePermissionSchema = s.Static<typeof rolePermissionSchema>;
|
||||||
|
|
||||||
|
export const roleSchema = s.strictObject({
|
||||||
|
// @todo: remove anyOf, add migration
|
||||||
|
permissions: s.anyOf([s.array(s.string()), s.array(rolePermissionSchema)]).optional(),
|
||||||
|
is_default: s.boolean().optional(),
|
||||||
|
implicit_allow: s.boolean().optional(),
|
||||||
|
});
|
||||||
|
export type RoleSchema = s.Static<typeof roleSchema>;
|
||||||
|
|
||||||
export class RolePermission {
|
export class RolePermission {
|
||||||
constructor(
|
constructor(
|
||||||
public permission: Permission,
|
public permission: Permission<any, any, any, any>,
|
||||||
public config?: any,
|
public policies: Policy[] = [],
|
||||||
|
public effect: "allow" | "deny" = defaultEffect,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
|
toJSON() {
|
||||||
|
return {
|
||||||
|
permission: this.permission.name,
|
||||||
|
policies: this.policies.map((p) => p.toJSON()),
|
||||||
|
effect: this.effect,
|
||||||
|
};
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export class Role {
|
export class Role {
|
||||||
@@ -15,31 +44,23 @@ export class Role {
|
|||||||
public implicit_allow: boolean = false,
|
public implicit_allow: boolean = false,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
static createWithPermissionNames(
|
static create(name: string, config: RoleSchema) {
|
||||||
name: string,
|
const permissions =
|
||||||
permissionNames: string[],
|
config.permissions?.map((p: string | RolePermissionSchema) => {
|
||||||
is_default: boolean = false,
|
if (typeof p === "string") {
|
||||||
implicit_allow: boolean = false,
|
return new RolePermission(new Permission(p), []);
|
||||||
) {
|
}
|
||||||
return new Role(
|
const policies = p.policies?.map((policy) => new Policy(policy));
|
||||||
name,
|
return new RolePermission(new Permission(p.permission), policies, p.effect);
|
||||||
permissionNames.map((name) => new RolePermission(new Permission(name))),
|
}) ?? [];
|
||||||
is_default,
|
return new Role(name, permissions, config.is_default, config.implicit_allow);
|
||||||
implicit_allow,
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static create(config: {
|
toJSON() {
|
||||||
name: string;
|
return {
|
||||||
permissions?: string[];
|
permissions: this.permissions.map((p) => p.toJSON()),
|
||||||
is_default?: boolean;
|
is_default: this.is_default,
|
||||||
implicit_allow?: boolean;
|
implicit_allow: this.implicit_allow,
|
||||||
}) {
|
};
|
||||||
return new Role(
|
|
||||||
config.name,
|
|
||||||
config.permissions?.map((name) => new RolePermission(new Permission(name))) ?? [],
|
|
||||||
config.is_default,
|
|
||||||
config.implicit_allow,
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
import type { Permission } from "core/security/Permission";
|
|
||||||
import { $console, patternMatch } from "bknd/utils";
|
import { $console, patternMatch } from "bknd/utils";
|
||||||
import type { Context } from "hono";
|
import type { Context } from "hono";
|
||||||
import { createMiddleware } from "hono/factory";
|
import { createMiddleware } from "hono/factory";
|
||||||
@@ -49,7 +48,7 @@ export const auth = (options?: {
|
|||||||
// make sure to only register once
|
// make sure to only register once
|
||||||
if (authCtx.registered) {
|
if (authCtx.registered) {
|
||||||
skipped = true;
|
skipped = true;
|
||||||
$console.warn(`auth middleware already registered for ${getPath(c)}`);
|
$console.debug(`auth middleware already registered for ${getPath(c)}`);
|
||||||
} else {
|
} else {
|
||||||
authCtx.registered = true;
|
authCtx.registered = true;
|
||||||
|
|
||||||
@@ -67,48 +66,3 @@ export const auth = (options?: {
|
|||||||
authCtx.resolved = false;
|
authCtx.resolved = false;
|
||||||
authCtx.user = undefined;
|
authCtx.user = undefined;
|
||||||
});
|
});
|
||||||
|
|
||||||
export const permission = (
|
|
||||||
permission: Permission | Permission[],
|
|
||||||
options?: {
|
|
||||||
onGranted?: (c: Context<ServerEnv>) => Promise<Response | void | undefined>;
|
|
||||||
onDenied?: (c: Context<ServerEnv>) => Promise<Response | void | undefined>;
|
|
||||||
},
|
|
||||||
) =>
|
|
||||||
// @ts-ignore
|
|
||||||
createMiddleware<ServerEnv>(async (c, next) => {
|
|
||||||
const app = c.get("app");
|
|
||||||
const authCtx = c.get("auth");
|
|
||||||
if (!authCtx) {
|
|
||||||
throw new Error("auth ctx not found");
|
|
||||||
}
|
|
||||||
|
|
||||||
// in tests, app is not defined
|
|
||||||
if (!authCtx.registered || !app) {
|
|
||||||
const msg = `auth middleware not registered, cannot check permissions for ${getPath(c)}`;
|
|
||||||
if (app?.module.auth.enabled) {
|
|
||||||
throw new Error(msg);
|
|
||||||
} else {
|
|
||||||
$console.warn(msg);
|
|
||||||
}
|
|
||||||
} else if (!authCtx.skip) {
|
|
||||||
const guard = app.modules.ctx().guard;
|
|
||||||
const permissions = Array.isArray(permission) ? permission : [permission];
|
|
||||||
|
|
||||||
if (options?.onGranted || options?.onDenied) {
|
|
||||||
let returned: undefined | void | Response;
|
|
||||||
if (permissions.every((p) => guard.granted(p, c))) {
|
|
||||||
returned = await options?.onGranted?.(c);
|
|
||||||
} else {
|
|
||||||
returned = await options?.onDenied?.(c);
|
|
||||||
}
|
|
||||||
if (returned instanceof Response) {
|
|
||||||
return returned;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
permissions.some((p) => guard.throwUnlessGranted(p, c));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
await next();
|
|
||||||
});
|
|
||||||
@@ -0,0 +1,94 @@
|
|||||||
|
import type { Permission, PermissionContext } from "auth/authorize/Permission";
|
||||||
|
import { $console, threw } from "bknd/utils";
|
||||||
|
import type { Context, Hono } from "hono";
|
||||||
|
import type { RouterRoute } from "hono/types";
|
||||||
|
import { createMiddleware } from "hono/factory";
|
||||||
|
import type { ServerEnv } from "modules/Controller";
|
||||||
|
import type { MaybePromise } from "core/types";
|
||||||
|
import { GuardPermissionsException } from "auth/authorize/Guard";
|
||||||
|
|
||||||
|
function getPath(reqOrCtx: Request | Context) {
|
||||||
|
const req = reqOrCtx instanceof Request ? reqOrCtx : reqOrCtx.req.raw;
|
||||||
|
return new URL(req.url).pathname;
|
||||||
|
}
|
||||||
|
|
||||||
|
const permissionSymbol = Symbol.for("permission");
|
||||||
|
|
||||||
|
type PermissionMiddlewareOptions<P extends Permission<any, any, any, any>> = {
|
||||||
|
onGranted?: (c: Context<ServerEnv>) => MaybePromise<Response | void | undefined>;
|
||||||
|
onDenied?: (c: Context<ServerEnv>) => MaybePromise<Response | void | undefined>;
|
||||||
|
} & (P extends Permission<any, any, infer PC, any>
|
||||||
|
? PC extends undefined
|
||||||
|
? {
|
||||||
|
context?: never;
|
||||||
|
}
|
||||||
|
: {
|
||||||
|
context: (c: Context<ServerEnv>) => MaybePromise<PermissionContext<P>>;
|
||||||
|
}
|
||||||
|
: {
|
||||||
|
context?: never;
|
||||||
|
});
|
||||||
|
|
||||||
|
export function permission<P extends Permission<any, any, any, any>>(
|
||||||
|
permission: P,
|
||||||
|
options: PermissionMiddlewareOptions<P>,
|
||||||
|
) {
|
||||||
|
// @ts-ignore (middlewares do not always return)
|
||||||
|
const handler = createMiddleware<ServerEnv>(async (c, next) => {
|
||||||
|
const app = c.get("app");
|
||||||
|
const authCtx = c.get("auth");
|
||||||
|
if (!authCtx) {
|
||||||
|
throw new Error("auth ctx not found");
|
||||||
|
}
|
||||||
|
|
||||||
|
// in tests, app is not defined
|
||||||
|
if (!authCtx.registered || !app) {
|
||||||
|
const msg = `auth middleware not registered, cannot check permissions for ${getPath(c)}`;
|
||||||
|
if (app?.module.auth.enabled) {
|
||||||
|
throw new Error(msg);
|
||||||
|
} else {
|
||||||
|
$console.warn(msg);
|
||||||
|
}
|
||||||
|
} else if (!authCtx.skip) {
|
||||||
|
const guard = app.modules.ctx().guard;
|
||||||
|
const context = (await options?.context?.(c)) ?? ({} as any);
|
||||||
|
|
||||||
|
if (options?.onGranted || options?.onDenied) {
|
||||||
|
let returned: undefined | void | Response;
|
||||||
|
if (threw(() => guard.granted(permission, c, context), GuardPermissionsException)) {
|
||||||
|
returned = await options?.onDenied?.(c);
|
||||||
|
} else {
|
||||||
|
returned = await options?.onGranted?.(c);
|
||||||
|
}
|
||||||
|
if (returned instanceof Response) {
|
||||||
|
return returned;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
guard.granted(permission, c, context);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
await next();
|
||||||
|
});
|
||||||
|
|
||||||
|
return Object.assign(handler, {
|
||||||
|
[permissionSymbol]: { permission, options },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getPermissionRoutes(hono: Hono<any>) {
|
||||||
|
const routes: {
|
||||||
|
route: RouterRoute;
|
||||||
|
permission: Permission;
|
||||||
|
options: PermissionMiddlewareOptions<Permission>;
|
||||||
|
}[] = [];
|
||||||
|
for (const route of hono.routes) {
|
||||||
|
if (permissionSymbol in route.handler) {
|
||||||
|
routes.push({
|
||||||
|
route,
|
||||||
|
...(route.handler[permissionSymbol] as any),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return routes;
|
||||||
|
}
|
||||||
@@ -10,6 +10,7 @@ import color from "picocolors";
|
|||||||
import { overridePackageJson, updateBkndPackages } from "./npm";
|
import { overridePackageJson, updateBkndPackages } from "./npm";
|
||||||
import { type Template, templates, type TemplateSetupCtx } from "./templates";
|
import { type Template, templates, type TemplateSetupCtx } from "./templates";
|
||||||
import { createScoped, flush } from "cli/utils/telemetry";
|
import { createScoped, flush } from "cli/utils/telemetry";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
const config = {
|
const config = {
|
||||||
types: {
|
types: {
|
||||||
@@ -20,6 +21,7 @@ const config = {
|
|||||||
node: "Node.js",
|
node: "Node.js",
|
||||||
bun: "Bun",
|
bun: "Bun",
|
||||||
cloudflare: "Cloudflare",
|
cloudflare: "Cloudflare",
|
||||||
|
deno: "Deno",
|
||||||
aws: "AWS Lambda",
|
aws: "AWS Lambda",
|
||||||
},
|
},
|
||||||
framework: {
|
framework: {
|
||||||
@@ -259,17 +261,19 @@ async function action(options: {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// update package name
|
// update package name if there is a package.json
|
||||||
await overridePackageJson(
|
if (fs.existsSync(path.resolve(ctx.dir, "package.json"))) {
|
||||||
(pkg) => ({
|
await overridePackageJson(
|
||||||
...pkg,
|
(pkg) => ({
|
||||||
name: ctx.name,
|
...pkg,
|
||||||
}),
|
name: ctx.name,
|
||||||
{ dir: ctx.dir },
|
}),
|
||||||
);
|
{ dir: ctx.dir },
|
||||||
$p.log.success(`Updated package name to ${color.cyan(ctx.name)}`);
|
);
|
||||||
|
$p.log.success(`Updated package name to ${color.cyan(ctx.name)}`);
|
||||||
|
}
|
||||||
|
|
||||||
{
|
if (template.installDeps !== false) {
|
||||||
const install =
|
const install =
|
||||||
options.yes ??
|
options.yes ??
|
||||||
(await $p.confirm({
|
(await $p.confirm({
|
||||||
|
|||||||
@@ -93,17 +93,19 @@ export async function replacePackageJsonVersions(
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function updateBkndPackages(dir?: string, map?: Record<string, string>) {
|
export async function updateBkndPackages(dir?: string, map?: Record<string, string>) {
|
||||||
const versions = {
|
try {
|
||||||
bknd: await sysGetVersion(),
|
const versions = {
|
||||||
...(map ?? {}),
|
bknd: await sysGetVersion(),
|
||||||
};
|
...(map ?? {}),
|
||||||
await replacePackageJsonVersions(
|
};
|
||||||
async (pkg) => {
|
await replacePackageJsonVersions(
|
||||||
if (pkg in versions) {
|
async (pkg) => {
|
||||||
return versions[pkg];
|
if (pkg in versions) {
|
||||||
}
|
return versions[pkg];
|
||||||
return;
|
}
|
||||||
},
|
return;
|
||||||
{ dir },
|
},
|
||||||
);
|
{ dir },
|
||||||
|
);
|
||||||
|
} catch (e) {}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import { overrideJson } from "cli/commands/create/npm";
|
||||||
|
import type { Template } from "cli/commands/create/templates";
|
||||||
|
import { getVersion } from "cli/utils/sys";
|
||||||
|
|
||||||
|
export const deno = {
|
||||||
|
key: "deno",
|
||||||
|
title: "Deno Basic",
|
||||||
|
integration: "deno",
|
||||||
|
description: "A basic bknd Deno server with static assets",
|
||||||
|
path: "gh:bknd-io/bknd/examples/deno",
|
||||||
|
installDeps: false,
|
||||||
|
ref: true,
|
||||||
|
setup: async (ctx) => {
|
||||||
|
const version = await getVersion();
|
||||||
|
await overrideJson(
|
||||||
|
"deno.json",
|
||||||
|
(json) => ({ ...json, links: undefined, imports: { bknd: `npm:bknd@${version}` } }),
|
||||||
|
{ dir: ctx.dir },
|
||||||
|
);
|
||||||
|
},
|
||||||
|
} satisfies Template;
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { deno } from "cli/commands/create/templates/deno";
|
||||||
import { cloudflare } from "./cloudflare";
|
import { cloudflare } from "./cloudflare";
|
||||||
|
|
||||||
export type TemplateSetupCtx = {
|
export type TemplateSetupCtx = {
|
||||||
@@ -15,6 +16,7 @@ export type Integration =
|
|||||||
| "react-router"
|
| "react-router"
|
||||||
| "astro"
|
| "astro"
|
||||||
| "aws"
|
| "aws"
|
||||||
|
| "deno"
|
||||||
| "custom";
|
| "custom";
|
||||||
|
|
||||||
type TemplateScripts = "install" | "dev" | "build" | "start";
|
type TemplateScripts = "install" | "dev" | "build" | "start";
|
||||||
@@ -34,6 +36,11 @@ export type Template = {
|
|||||||
* adds a ref "#{ref}" to the path. If "true", adds the current version of bknd
|
* adds a ref "#{ref}" to the path. If "true", adds the current version of bknd
|
||||||
*/
|
*/
|
||||||
ref?: true | string;
|
ref?: true | string;
|
||||||
|
/**
|
||||||
|
* control whether to install dependencies automatically
|
||||||
|
* e.g. on deno, this is not needed
|
||||||
|
*/
|
||||||
|
installDeps?: boolean;
|
||||||
scripts?: Partial<Record<TemplateScripts, string>>;
|
scripts?: Partial<Record<TemplateScripts, string>>;
|
||||||
preinstall?: (ctx: TemplateSetupCtx) => Promise<void>;
|
preinstall?: (ctx: TemplateSetupCtx) => Promise<void>;
|
||||||
postinstall?: (ctx: TemplateSetupCtx) => Promise<void>;
|
postinstall?: (ctx: TemplateSetupCtx) => Promise<void>;
|
||||||
@@ -90,4 +97,5 @@ export const templates: Template[] = [
|
|||||||
path: "gh:bknd-io/bknd/examples/aws-lambda",
|
path: "gh:bknd-io/bknd/examples/aws-lambda",
|
||||||
ref: true,
|
ref: true,
|
||||||
},
|
},
|
||||||
|
deno,
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -0,0 +1,27 @@
|
|||||||
|
import type { CliCommand } from "cli/types";
|
||||||
|
import { Option } from "commander";
|
||||||
|
import { withConfigOptions, type WithConfigOptions } from "cli/utils/options";
|
||||||
|
import * as utils from "./utils";
|
||||||
|
import { $console } from "core/utils";
|
||||||
|
import { Project } from "./lib/Project";
|
||||||
|
|
||||||
|
export const dev: CliCommand = (program) =>
|
||||||
|
withConfigOptions(program.command("dev"))
|
||||||
|
.description("dev server")
|
||||||
|
.addOption(new Option("--build", "build the project"))
|
||||||
|
.action(action);
|
||||||
|
|
||||||
|
async function action(options: WithConfigOptions<{ build?: boolean }>) {
|
||||||
|
console.log("options", options);
|
||||||
|
const project = new Project({
|
||||||
|
templatePath: utils.TEMPLATE_PATH,
|
||||||
|
});
|
||||||
|
|
||||||
|
await project.init();
|
||||||
|
|
||||||
|
if (options.build) {
|
||||||
|
await project.build();
|
||||||
|
process.exit(0);
|
||||||
|
}
|
||||||
|
await project.listen();
|
||||||
|
}
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
import { RelativeFS } from "./RelativeFS";
|
||||||
|
//import { $console } from "bknd/utils";
|
||||||
|
import { type ViteDevServer, createServer, type UserConfig, createBuilder } from "vite";
|
||||||
|
import { readdir, copyFile, stat } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
import react from "@vitejs/plugin-react";
|
||||||
|
import tailwindcss from "@tailwindcss/vite";
|
||||||
|
import { cloudflare } from "@cloudflare/vite-plugin";
|
||||||
|
import { getRelativeDistPath } from "cli/utils/sys";
|
||||||
|
import { injectMain } from "./vite/inject-main";
|
||||||
|
import { devFsVitePlugin } from "adapter/cloudflare";
|
||||||
|
|
||||||
|
export type ProjectOptions = {
|
||||||
|
userPath?: string;
|
||||||
|
templatePath?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
// @todo: add multiple public dirs
|
||||||
|
// @todo: add npm install (first time)
|
||||||
|
// @todo: add package.json
|
||||||
|
export class Project {
|
||||||
|
public userFs: RelativeFS;
|
||||||
|
public templateFs: RelativeFS;
|
||||||
|
private _server?: ViteDevServer;
|
||||||
|
|
||||||
|
constructor(public options: ProjectOptions) {
|
||||||
|
this.userFs = new RelativeFS(options.userPath ?? process.cwd());
|
||||||
|
this.templateFs = new RelativeFS(options.templatePath ?? "src/cli/commands/dev/template");
|
||||||
|
}
|
||||||
|
|
||||||
|
get server() {
|
||||||
|
if (!this._server) {
|
||||||
|
throw new Error("Server not initialized");
|
||||||
|
}
|
||||||
|
return this._server!;
|
||||||
|
}
|
||||||
|
|
||||||
|
async init() {
|
||||||
|
const source = this.templateFs.root;
|
||||||
|
const destination = this.userFs.root;
|
||||||
|
|
||||||
|
// recursively copy all files and directories from source to dest
|
||||||
|
const copyRecursive = async (src: string, dst: string) => {
|
||||||
|
const entries = await readdir(src, { withFileTypes: true });
|
||||||
|
|
||||||
|
for (const entry of entries) {
|
||||||
|
const srcPath = path.join(src, entry.name);
|
||||||
|
const dstPath = path.join(dst, entry.name);
|
||||||
|
|
||||||
|
if (entry.isDirectory()) {
|
||||||
|
await this.userFs.makeDir(path.relative(destination, dstPath));
|
||||||
|
await copyRecursive(srcPath, dstPath);
|
||||||
|
} else if (entry.isFile()) {
|
||||||
|
const exists = await stat(dstPath)
|
||||||
|
.then((s) => s.isFile())
|
||||||
|
.catch(() => null);
|
||||||
|
|
||||||
|
// only copy everything from ".bknd" with override
|
||||||
|
if (!exists || (dstPath.includes(".bknd") && !dstPath.includes("bknd-types.d.ts"))) {
|
||||||
|
await copyFile(srcPath, dstPath);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
await copyRecursive(source, destination);
|
||||||
|
this._server = await createServer(this.getViteConfig());
|
||||||
|
}
|
||||||
|
|
||||||
|
private getViteConfig(): UserConfig {
|
||||||
|
return {
|
||||||
|
clearScreen: false,
|
||||||
|
publicDir: getRelativeDistPath() + "/static",
|
||||||
|
plugins: [
|
||||||
|
react(),
|
||||||
|
tailwindcss(),
|
||||||
|
devFsVitePlugin({ configFile: ".bknd/bknd.config.ts" }) as any,
|
||||||
|
cloudflare({
|
||||||
|
configPath: this.userFs.path(".bknd/wrangler.json"),
|
||||||
|
persistState: {
|
||||||
|
path: this.userFs.path(".bknd/state"),
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
injectMain({
|
||||||
|
appPath: "./src/App.tsx",
|
||||||
|
rootId: "root",
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
build: {
|
||||||
|
minify: true,
|
||||||
|
},
|
||||||
|
resolve: {
|
||||||
|
dedupe: ["react", "react-dom"],
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async build() {
|
||||||
|
const builder = await createBuilder(this.getViteConfig());
|
||||||
|
await builder.buildApp();
|
||||||
|
}
|
||||||
|
|
||||||
|
async listen() {
|
||||||
|
await this.server.listen();
|
||||||
|
this.server.printUrls();
|
||||||
|
this.server.bindCLIShortcuts({ print: true });
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
import {
|
||||||
|
mkdir,
|
||||||
|
stat,
|
||||||
|
readFile as nodeReadFile,
|
||||||
|
writeFile as nodeWriteFile,
|
||||||
|
} from "node:fs/promises";
|
||||||
|
import { getRootPath } from "cli/utils/sys";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
export class RelativeFS {
|
||||||
|
public root: string;
|
||||||
|
|
||||||
|
constructor(p: string) {
|
||||||
|
this.root = path.resolve(getRootPath(), p);
|
||||||
|
}
|
||||||
|
|
||||||
|
path(p: string) {
|
||||||
|
return path.join(this.root, p);
|
||||||
|
}
|
||||||
|
|
||||||
|
async hasFile(path: string) {
|
||||||
|
try {
|
||||||
|
const s = await stat(this.path(path));
|
||||||
|
return s.isFile();
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async hasDir(path: string) {
|
||||||
|
try {
|
||||||
|
const s = await stat(this.path(path));
|
||||||
|
return s.isDirectory();
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async readFile(p: string) {
|
||||||
|
return await nodeReadFile(this.path(p), "utf-8");
|
||||||
|
}
|
||||||
|
|
||||||
|
async writeFile(p: string, content: string) {
|
||||||
|
return await nodeWriteFile(this.path(p), content);
|
||||||
|
}
|
||||||
|
|
||||||
|
async makeDir(p: string) {
|
||||||
|
return await mkdir(this.path(p), { recursive: true });
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
import type { PluginOption } from "vite";
|
||||||
|
|
||||||
|
export function injectMain(options?: { appPath?: string; rootId?: string }): PluginOption {
|
||||||
|
const appPath = options?.appPath ?? "/App.tsx";
|
||||||
|
const rootId = options?.rootId ?? "root";
|
||||||
|
const publicId = "/@virtual/react-main.js";
|
||||||
|
const internalId = "\0virtual-react-main.js";
|
||||||
|
|
||||||
|
return [
|
||||||
|
{
|
||||||
|
name: "bknd-virtual-react-entry",
|
||||||
|
transformIndexHtml(html) {
|
||||||
|
return {
|
||||||
|
html,
|
||||||
|
tags: [
|
||||||
|
{
|
||||||
|
tag: "script",
|
||||||
|
injectTo: "body",
|
||||||
|
attrs: {
|
||||||
|
type: "module",
|
||||||
|
src: publicId,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
},
|
||||||
|
resolveId(id) {
|
||||||
|
if (id === publicId) {
|
||||||
|
return internalId;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
},
|
||||||
|
load(id) {
|
||||||
|
if (id === internalId) {
|
||||||
|
return `
|
||||||
|
import React from "react";
|
||||||
|
import ReactDOM from "react-dom/client";
|
||||||
|
import App from "${appPath}";
|
||||||
|
import { ClientProvider } from "bknd/client";
|
||||||
|
|
||||||
|
const container = document.getElementById("${rootId}");
|
||||||
|
if (!container) {
|
||||||
|
throw new Error("Cannot find #${rootId} element");
|
||||||
|
}
|
||||||
|
|
||||||
|
const root = ReactDOM.createRoot(container);
|
||||||
|
root.render(
|
||||||
|
React.createElement(
|
||||||
|
React.StrictMode,
|
||||||
|
null,
|
||||||
|
React.createElement(ClientProvider, null, React.createElement(App, null))
|
||||||
|
)
|
||||||
|
);
|
||||||
|
`;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
import type { DB } from "bknd";
|
||||||
|
import type { Insertable, Selectable, Updateable } from "kysely";
|
||||||
|
|
||||||
|
declare global {
|
||||||
|
type BkndEntity<T extends keyof DB> = Selectable<DB[T]>;
|
||||||
|
type BkndEntityCreate<T extends keyof DB> = Insertable<DB[T]>;
|
||||||
|
type BkndEntityUpdate<T extends keyof DB> = Updateable<DB[T]>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{
|
||||||
|
"compilerOptions": {
|
||||||
|
"target": "ES2022",
|
||||||
|
"useDefineForClassFields": true,
|
||||||
|
"lib": ["ES2023", "DOM", "DOM.Iterable"],
|
||||||
|
"module": "ESNext",
|
||||||
|
"skipLibCheck": true,
|
||||||
|
"moduleResolution": "bundler",
|
||||||
|
"allowImportingTsExtensions": true,
|
||||||
|
"isolatedModules": true,
|
||||||
|
"moduleDetection": "force",
|
||||||
|
"noEmit": true,
|
||||||
|
"jsx": "react-jsx",
|
||||||
|
"strict": true,
|
||||||
|
"noUnusedLocals": true,
|
||||||
|
"noUnusedParameters": true,
|
||||||
|
"noFallthroughCasesInSwitch": true,
|
||||||
|
"noUncheckedSideEffectImports": true,
|
||||||
|
"types": ["vite/client"]
|
||||||
|
},
|
||||||
|
"include": ["bknd-types.d.ts"]
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
import { serve } from "bknd/adapter/cloudflare";
|
||||||
|
import config from "./bknd.config";
|
||||||
|
|
||||||
|
export default serve(config);
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
{
|
||||||
|
"name": "bknd-dev",
|
||||||
|
"main": "./worker.ts",
|
||||||
|
"compatibility_date": "2025-10-08",
|
||||||
|
"compatibility_flags": ["nodejs_compat"],
|
||||||
|
"observability": {
|
||||||
|
"enabled": true
|
||||||
|
},
|
||||||
|
"assets": {
|
||||||
|
"binding": "ASSETS",
|
||||||
|
"directory": "../dist/client",
|
||||||
|
"not_found_handling": "single-page-application",
|
||||||
|
"run_worker_first": ["!/", "/admin*", "/api*", "!/assets/*"]
|
||||||
|
},
|
||||||
|
"vars": {
|
||||||
|
"ENVIRONMENT": "development"
|
||||||
|
},
|
||||||
|
"d1_databases": [
|
||||||
|
{
|
||||||
|
"binding": "DB"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"r2_buckets": [
|
||||||
|
{
|
||||||
|
"binding": "BUCKET"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8" />
|
||||||
|
<link rel="icon" type="image/svg+xml" href="/vite.svg" />
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||||
|
<title>bknd + Vite + Cloudflare + React + TS</title>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
<div id="root"></div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
import "./styles.css";
|
||||||
|
|
||||||
|
export default function App() {
|
||||||
|
return <div>Hello World</div>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
import { Hono } from "hono";
|
||||||
|
import type { ServerEnv } from "bknd";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Add custom routes to the API here. Base path is `/api`.
|
||||||
|
*/
|
||||||
|
export default new Hono<ServerEnv>().get("/", (c) => {
|
||||||
|
// const app = c.var.app;
|
||||||
|
// const api = app.getApi();
|
||||||
|
return c.json({ message: "Hello, world!" });
|
||||||
|
});
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
import { AppEvents, DatabaseEvents, type EventManager } from "bknd";
|
||||||
|
|
||||||
|
export default function (emgr: EventManager) {
|
||||||
|
// emgr.onEvent(AppEvents.AppRequest, async (event) => {
|
||||||
|
// console.log("Request received", event.params.request.url);
|
||||||
|
// });
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
import { em, entity, text, boolean, number, datetime, json, jsonSchema, enumm } from "bknd";
|
||||||
|
|
||||||
|
export default em({
|
||||||
|
// todos: entity("todos", {
|
||||||
|
// title: text(),
|
||||||
|
// done: boolean(),
|
||||||
|
// }),
|
||||||
|
});
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
@import "tailwindcss";
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{
|
||||||
|
"extends": "./.bknd/tsconfig.json",
|
||||||
|
"include": ["src"]
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
import path from "node:path";
|
||||||
|
import {
|
||||||
|
mkdir,
|
||||||
|
stat,
|
||||||
|
readFile as nodeReadFile,
|
||||||
|
writeFile as nodeWriteFile,
|
||||||
|
} from "node:fs/promises";
|
||||||
|
import { getRootPath } from "cli/utils/sys";
|
||||||
|
|
||||||
|
export const TEMPLATE_PATH = "src/cli/commands/dev/template";
|
||||||
|
export const currentDir = process.cwd();
|
||||||
|
|
||||||
|
export const fs = (dir: string) => {
|
||||||
|
const PATH = path.resolve(getRootPath(), dir);
|
||||||
|
return {
|
||||||
|
PATH,
|
||||||
|
path: (_path: string) => path.join(PATH, _path),
|
||||||
|
hasFile: async (file: string) => {
|
||||||
|
try {
|
||||||
|
const s = await stat(path.join(PATH, file));
|
||||||
|
return s.isFile();
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
},
|
||||||
|
hasDir: async (_dir: string) => {
|
||||||
|
try {
|
||||||
|
const s = await stat(path.join(PATH, _dir));
|
||||||
|
return s.isDirectory();
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
},
|
||||||
|
readFile: (file: string) => nodeReadFile(path.join(PATH, file), "utf-8"),
|
||||||
|
readJsonFile: async (file: string) =>
|
||||||
|
JSON.parse(await nodeReadFile(path.join(PATH, file), "utf-8")),
|
||||||
|
writeFile: (file: string, content: string) => nodeWriteFile(path.join(PATH, file), content),
|
||||||
|
makeDir: (_newDir: string) => mkdir(path.join(PATH, _newDir)),
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -9,3 +9,4 @@ export { types } from "./types";
|
|||||||
export { mcp } from "./mcp/mcp";
|
export { mcp } from "./mcp/mcp";
|
||||||
export { sync } from "./sync";
|
export { sync } from "./sync";
|
||||||
export { secrets } from "./secrets";
|
export { secrets } from "./secrets";
|
||||||
|
export { dev } from "./dev/dev";
|
||||||
|
|||||||
@@ -67,7 +67,10 @@ export async function startServer(
|
|||||||
$console.info("Server listening on", url);
|
$console.info("Server listening on", url);
|
||||||
|
|
||||||
if (options.open) {
|
if (options.open) {
|
||||||
await open(url);
|
const p = await open(url, { wait: false });
|
||||||
|
p.on("error", () => {
|
||||||
|
$console.warn("Couldn't open url in browser");
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -110,7 +110,10 @@ export async function makeAppFromEnv(options: Partial<RunOptions> = {}) {
|
|||||||
// try to use an in-memory connection
|
// try to use an in-memory connection
|
||||||
} else if (options.memory) {
|
} else if (options.memory) {
|
||||||
console.info("Using", c.cyan("in-memory"), "connection");
|
console.info("Using", c.cyan("in-memory"), "connection");
|
||||||
app = await makeApp({ server: { platform: options.server } });
|
app = await makeApp({
|
||||||
|
server: { platform: options.server },
|
||||||
|
connection: { url: ":memory:" },
|
||||||
|
});
|
||||||
|
|
||||||
// finally try to use env variables
|
// finally try to use env variables
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import {
|
|||||||
log as $log,
|
log as $log,
|
||||||
password as $password,
|
password as $password,
|
||||||
text as $text,
|
text as $text,
|
||||||
|
select as $select,
|
||||||
} from "@clack/prompts";
|
} from "@clack/prompts";
|
||||||
import type { App } from "App";
|
import type { App } from "App";
|
||||||
import type { PasswordStrategy } from "auth/authenticate/strategies";
|
import type { PasswordStrategy } from "auth/authenticate/strategies";
|
||||||
@@ -29,6 +30,11 @@ async function action(action: "create" | "update" | "token", options: WithConfig
|
|||||||
server: "node",
|
server: "node",
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (!app.module.auth.enabled) {
|
||||||
|
$log.error("Auth is not enabled");
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
switch (action) {
|
switch (action) {
|
||||||
case "create":
|
case "create":
|
||||||
await create(app, options);
|
await create(app, options);
|
||||||
@@ -43,7 +49,28 @@ async function action(action: "create" | "update" | "token", options: WithConfig
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function create(app: App, options: any) {
|
async function create(app: App, options: any) {
|
||||||
const strategy = app.module.auth.authenticator.strategy("password") as PasswordStrategy;
|
const auth = app.module.auth;
|
||||||
|
let role: string | null = null;
|
||||||
|
const roles = Object.keys(auth.config.roles ?? {});
|
||||||
|
|
||||||
|
const strategy = auth.authenticator.strategy("password") as PasswordStrategy;
|
||||||
|
if (roles.length > 0) {
|
||||||
|
role = (await $select({
|
||||||
|
message: "Select role",
|
||||||
|
options: [
|
||||||
|
{
|
||||||
|
value: null,
|
||||||
|
label: "<none>",
|
||||||
|
hint: "No role will be assigned to the user",
|
||||||
|
},
|
||||||
|
...roles.map((role) => ({
|
||||||
|
value: role,
|
||||||
|
label: role,
|
||||||
|
})),
|
||||||
|
],
|
||||||
|
})) as any;
|
||||||
|
if ($isCancel(role)) process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
if (!strategy) {
|
if (!strategy) {
|
||||||
$log.error("Password strategy not configured");
|
$log.error("Password strategy not configured");
|
||||||
@@ -76,6 +103,7 @@ async function create(app: App, options: any) {
|
|||||||
const created = await app.createUser({
|
const created = await app.createUser({
|
||||||
email,
|
email,
|
||||||
password: await strategy.hash(password as string),
|
password: await strategy.hash(password as string),
|
||||||
|
role,
|
||||||
});
|
});
|
||||||
$log.success(`Created user: ${c.cyan(created.email)}`);
|
$log.success(`Created user: ${c.cyan(created.email)}`);
|
||||||
process.exit(0);
|
process.exit(0);
|
||||||
|
|||||||
@@ -1,5 +1,4 @@
|
|||||||
#!/usr/bin/env node
|
#!/usr/bin/env node
|
||||||
|
|
||||||
import { Command } from "commander";
|
import { Command } from "commander";
|
||||||
import color from "picocolors";
|
import color from "picocolors";
|
||||||
import * as commands from "./commands";
|
import * as commands from "./commands";
|
||||||
|
|||||||
@@ -0,0 +1,55 @@
|
|||||||
|
import { describe, it, expect } from "bun:test";
|
||||||
|
import { plunkEmail } from "./plunk";
|
||||||
|
|
||||||
|
const ALL_TESTS = !!process.env.ALL_TESTS;
|
||||||
|
|
||||||
|
describe.skipIf(ALL_TESTS)("plunk", () => {
|
||||||
|
it("should throw on failed", async () => {
|
||||||
|
const driver = plunkEmail({ apiKey: "invalid" });
|
||||||
|
expect(driver.send("foo@bar.com", "Test", "Test")).rejects.toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("should send an email", async () => {
|
||||||
|
const driver = plunkEmail({
|
||||||
|
apiKey: process.env.PLUNK_API_KEY!,
|
||||||
|
from: undefined, // Default to what Plunk sets
|
||||||
|
});
|
||||||
|
const response = await driver.send(
|
||||||
|
"help@bknd.io",
|
||||||
|
"Test Email from Plunk",
|
||||||
|
"This is a test email",
|
||||||
|
);
|
||||||
|
expect(response).toBeDefined();
|
||||||
|
expect(response.success).toBe(true);
|
||||||
|
expect(response.emails).toBeDefined();
|
||||||
|
expect(response.timestamp).toBeDefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("should send HTML email", async () => {
|
||||||
|
const driver = plunkEmail({
|
||||||
|
apiKey: process.env.PLUNK_API_KEY!,
|
||||||
|
from: undefined,
|
||||||
|
});
|
||||||
|
const htmlBody = "<h1>Test Email</h1><p>This is a test email</p>";
|
||||||
|
const response = await driver.send(
|
||||||
|
"help@bknd.io",
|
||||||
|
"HTML Test",
|
||||||
|
htmlBody,
|
||||||
|
);
|
||||||
|
expect(response).toBeDefined();
|
||||||
|
expect(response.success).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("should send with text and html", async () => {
|
||||||
|
const driver = plunkEmail({
|
||||||
|
apiKey: process.env.PLUNK_API_KEY!,
|
||||||
|
from: undefined,
|
||||||
|
});
|
||||||
|
const response = await driver.send("test@example.com", "Test Email", {
|
||||||
|
text: "help@bknd.io",
|
||||||
|
html: "<p>This is HTML</p>",
|
||||||
|
});
|
||||||
|
expect(response).toBeDefined();
|
||||||
|
expect(response.success).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user