Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/client/CLIENT_SERVER_INTEGRATION_TESTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -638,8 +638,11 @@ export function createMockServer() {
}));
}),

// Auth
rest.post('/api/v1/auth/login', (req, res, ctx) => {
// Auth — better-auth route names, not `/auth/login`: `client.auth.login`
// calls POST /auth/sign-in/email, `register` /auth/sign-up/email, `logout`
// /auth/sign-out, `me` GET /auth/get-session. The audited route table is
// packages/plugins/plugin-auth/src/auth-route-ledger.ts.
rest.post('/api/v1/auth/sign-in/email', (req, res, ctx) => {
return res(ctx.json({
success: true,
data: {
Expand Down
38 changes: 31 additions & 7 deletions packages/plugins/plugin-auth/IMPLEMENTATION_SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ Successfully integrated the Better-Auth library (v1.4.18) into `@objectstack/plu
- **AuthPlugin class** - Full plugin lifecycle (init, start, destroy)
- **AuthManager class** - Real implementation with better-auth integration
- **Lazy initialization** - Better-auth instance created only when needed
- **Route registration** - HTTP endpoints for login, register, logout, session
- **Route registration** - the auth base path (`/api/v1/auth/*`) forwarded to better-auth; see [API Routes](#api-routes)
- **Service registration** - Registers 'auth' service in ObjectKernel
- **Configuration support** - Uses AuthConfig schema from @objectstack/spec/system
- **TypeScript types** - Proper typing for IHttpRequest and IHttpResponse
Expand Down Expand Up @@ -86,12 +86,36 @@ packages/plugins/plugin-auth/
6. **Plugin Pattern**: Follows established ObjectStack plugin conventions
7. **TypeScript-First**: Full type safety with proper interface definitions

## API Routes Registered

- `POST /api/v1/auth/login` - User login (stub)
- `POST /api/v1/auth/register` - User registration (stub)
- `POST /api/v1/auth/logout` - User logout (stub)
- `GET /api/v1/auth/session` - Get current session (stub)
## API Routes

The plugin does **not** hand-register a `login` / `register` / `logout` / `session` route
set. Everything under the auth base path (`/api/v1/auth` by default, `basePath` in the
plugin options) is forwarded to better-auth through a single catch-all mount, so
**better-auth's own route table is the route table** — plus a handful of ObjectStack-owned
routes (`/config`, `/bootstrap-status`, `/admin/*`, …) mounted ahead of it.

**The single source of truth is [`src/auth-route-ledger.ts`](./src/auth-route-ledger.ts)**
(#3656): the reviewed `AUTH_ROUTE_LEDGER` rows — every route the SDK actually calls, each
naming its client method — plus the full `BETTER_AUTH_MOUNTED_SURFACE` inventory, both
verified against the live `auth.api` table by `auth-route-ledger.conformance.test.ts`.
Read the ledger instead of a copy: a list transcribed into this file drifts the next time
better-auth is upgraded, and this section is the proof (it advertised four routes that
never existed).

The core routes, spelled the way better-auth actually serves them — same names as
[`content/docs/api/plugin-endpoints.mdx`](../../../content/docs/api/plugin-endpoints.mdx):

| Route | SDK method |
|:------|:-----------|
| `POST /api/v1/auth/sign-in/email` | `auth.login` |
| `POST /api/v1/auth/sign-up/email` | `auth.register` |
| `POST /api/v1/auth/sign-out` | `auth.logout` |
| `GET /api/v1/auth/get-session` | `auth.me` |

There is no `/auth/login`, `/auth/register`, `/auth/logout` or `/auth/session` route. The
one legacy explicit `POST /api/v1/auth/login` mount that made the first of them look
reachable lived in the runtime dispatcher, answered HTTP 500 to every caller, and was
deleted in #5085.

## Dependencies

Expand Down
Loading