ZH
测试版翻译

@yohangel / auth-express

1.0.0 ▾
MIT
GitHub

适用于 Express 5 的 Better Auth:挂载认证路由并用 requireAuth 保护 API

代码3 个文件上下文约 405 个 token扫描通过

应用 .genpmignore 后将被注入的确切目录树。固定于

src/lib/auth-express/index.ts只读 · 7145b9d
// @yohangel/auth-express — Better Auth en Express 5. Monta las rutas ANTES de express.json() y protege rutas con
// `requireAuth`. La sesión queda en `res.locals.session` / `res.locals.user`.
import { fromNodeHeaders, toNodeHandler } from 'better-auth/node';
import type { Express, NextFunction, Request, RequestHandler, Response } from 'express';
import { type AuthSession, type CreateAuthOptions, createAuth, getAuth } from '../auth/index.js';

export { createAuth };

/** Crea la instancia (si no existe) y monta /api/auth/* (Express 5: `*splat`). Llamar antes de `express.json()`. */
export function mountAuth(app: Express, opts: CreateAuthOptions & { basePath?: string } = {}): void {
  const { basePath = '/api/auth', ...authOpts } = opts;
  const auth = createAuth(authOpts);
  app.all(`${basePath}/*splat`, toNodeHandler(auth));
}

export type AuthLocals = { session: AuthSession['session'] | null; user: AuthSession['user'] | null };

async function load(req: Request, res: Response): Promise<AuthSession | null> {
  const s = await getAuth().api.getSession({ headers: fromNodeHeaders(req.headers) });
  res.locals.session = s?.session ?? null;
  res.locals.user = s?.user ?? null;
  return s;
}

/** 401 JSON si no hay sesión válida. */
export const requireAuth: RequestHandler = async (req: Request, res: Response, next: NextFunction) => {
  try {
    if (!(await load(req, res))) {
      res.status(401).json({ error: 'unauthorized' });
      return;
    }
    next();
  } catch (e) {
    next(e);
  }
};

/** Carga la sesión si existe, sin bloquear. */
export const optionalAuth: RequestHandler = async (req, res, next) => {
  try {
    await load(req, res);
    next();
  } catch (e) {
    next(e);
  }
};

举报 @yohangel/auth-express

使用 GitHub 登录后才能举报包。