Better Auth für Express 5: Auth-Routen einbinden und APIs mit requireAuth schützen
Code3 DateienKontext~405 TokensPrüfung bestanden
Installieren
$
genpm add @yohangel/auth-expressWas du bekommst
- Quellcode in src/lib/auth-express/, 3 Dateien. (4,3 kB)
- KI-Regeln in src/lib/auth-express/AGENTS.md, dazu Regeldateien für die IDE.
- Löst @yohangel/auth für dich auf.
README
Dieses Paket hat keine README.
~405 Tokens→ src/lib/auth-express/AGENTS.md→ .cursor/rules/genpm-yohangel-auth-express.mdc
Genau das liest deine KI, wenn sie in src/lib/auth-express arbeitet. Sonst wird ihrem Kontext nichts hinzugefügt.
@yohangel/auth-express — rules for AI agents
Purpose
Connects @yohangel/auth to Express 5: mounts Better Auth on /api/auth/* and provides requireAuth / optionalAuth middleware that put the session in res.locals.
Module map
index.ts—mountAuth(app, opts),requireAuth,optionalAuth,AuthLocalstype,createAuthre-export.
Integration (do this after installing)
- Order matters — mount auth BEFORE body parsers:
import express from 'express'; import { mountAuth, requireAuth } from './lib/auth-express/index.js'; const app = express(); mountAuth(app, { sendEmail }); // /api/auth/* app.use(express.json()); app.get('/api/me', requireAuth, (req, res) => res.json({ id: res.locals.user.id })); - Frontend on another origin:
app.use(cors({ origin: ['https://app.example.com'], credentials: true }))beforemountAuth, and list that origin inAUTH_TRUSTED_ORIGINS. - Behind a proxy/CDN set
app.set('trust proxy', 1)andAUTH_IP_HEADERso rate limits use the real client IP. - Express 4 is not supported (route syntax
*splatis Express 5). Project must be ESM ("type": "module").
Conventions
- Protect routes with
requireAuth; readres.locals.user/res.locals.session(typed byAuthLocals). - Authorization (who can do what) goes in your handlers after
requireAuth, never on the client.
Don't
- Don't put
express.json()beforemountAuth(Better Auth must read the raw body). - Don't use
cors({ origin: '*', credentials: true }). - Don't return
res.locals.session(contains the token) to the client.
# @yohangel/auth-express — rules for AI agents
## Purpose
Connects `@yohangel/auth` to Express 5: mounts Better Auth on `/api/auth/*` and provides `requireAuth` / `optionalAuth` middleware that put the session in `res.locals`.
## Module map
- `index.ts` — `mountAuth(app, opts)`, `requireAuth`, `optionalAuth`, `AuthLocals` type, `createAuth` re-export.
## Integration (do this after installing)
1. Order matters — mount auth BEFORE body parsers:
```ts
import express from 'express';
import { mountAuth, requireAuth } from './lib/auth-express/index.js';
const app = express();
mountAuth(app, { sendEmail }); // /api/auth/*
app.use(express.json());
app.get('/api/me', requireAuth, (req, res) => res.json({ id: res.locals.user.id }));
```
2. Frontend on another origin: `app.use(cors({ origin: ['https://app.example.com'], credentials: true }))` before `mountAuth`, and list that origin in `AUTH_TRUSTED_ORIGINS`.
3. Behind a proxy/CDN set `app.set('trust proxy', 1)` and `AUTH_IP_HEADER` so rate limits use the real client IP.
4. Express 4 is not supported (route syntax `*splat` is Express 5). Project must be ESM (`"type": "module"`).
## Conventions
- Protect routes with `requireAuth`; read `res.locals.user` / `res.locals.session` (typed by `AuthLocals`).
- Authorization (who can do what) goes in your handlers after `requireAuth`, never on the client.
## Don't
- Don't put `express.json()` before `mountAuth` (Better Auth must read the raw body).
- Don't use `cors({ origin: '*', credentials: true })`.
- Don't return `res.locals.session` (contains the token) to the client.
Der genaue Baum, der nach .genpmignore eingebunden wird. Gepinnt an
# @yohangel/auth-express — rules for AI agents
## Purpose
Connects `@yohangel/auth` to Express 5: mounts Better Auth on `/api/auth/*` and provides `requireAuth` / `optionalAuth` middleware that put the session in `res.locals`.
## Module map
- `index.ts` — `mountAuth(app, opts)`, `requireAuth`, `optionalAuth`, `AuthLocals` type, `createAuth` re-export.
## Integration (do this after installing)
1. Order matters — mount auth BEFORE body parsers:
```ts
import express from 'express';
import { mountAuth, requireAuth } from './lib/auth-express/index.js';
const app = express();
mountAuth(app, { sendEmail }); // /api/auth/*
app.use(express.json());
app.get('/api/me', requireAuth, (req, res) => res.json({ id: res.locals.user.id }));
```
2. Frontend on another origin: `app.use(cors({ origin: ['https://app.example.com'], credentials: true }))` before `mountAuth`, and list that origin in `AUTH_TRUSTED_ORIGINS`.
3. Behind a proxy/CDN set `app.set('trust proxy', 1)` and `AUTH_IP_HEADER` so rate limits use the real client IP.
4. Express 4 is not supported (route syntax `*splat` is Express 5). Project must be ESM (`"type": "module"`).
## Conventions
- Protect routes with `requireAuth`; read `res.locals.user` / `res.locals.session` (typed by `AuthLocals`).
- Authorization (who can do what) goes in your handlers after `requireAuth`, never on the client.
## Don't
- Don't put `express.json()` before `mountAuth` (Better Auth must read the raw body).
- Don't use `cors({ origin: '*', credentials: true })`.
- Don't return `res.locals.session` (contains the token) to the client.
Dieses Paket deklariert keine MCP-Server.
| Version | Commit | Veröffentlicht | Prüfung |
|---|---|---|---|
| 1.0.0 | 7145b9d | vor 3 Stunden | ✔ Prüfung bestanden |
- npm
- keine
- vorgeschlagen
- GenPM schlägt den npm-Befehl vor und führt ihn nur aus, wenn du zustimmst.
- Prüfung
- Prüfung bestanden · 0 Befunde
- Commit
- auth-express@1.0.0 → 7145b9d58055b5145085782c958b7577f1d65276 · nach dem Abruf verifiziert
- Skripte
- Keine. GenPM führt niemals Paketcode aus.
- Lizenz
- MIT
- Meldung
- Stimmt etwas nicht?