Files
mcpedia/apps/web/app/api/auth/login/route.ts
T
asepharyana 57f90018da feat: Phase 11 — CRUD (create/update/delete) + auth + web UI
- Core: createDocument/updateDocument/deleteDocument (file + DB + revision + chunks)
- Parser: stringifyFile (serialize markdown with frontmatter to disk)
- API: tRPC CRUD routers (auth-gated via requireWriteAuth middleware)
- API: createContext now passes expectedSecret from deps (request-scoped auth)
- MCP: 3 new write tools (create_document, update_document, delete_document)
- Web: /create page + ?edit=1 form, /api/auth/login (cookie-based), /api/docs REST CRUD
- Web: Edit buttons on homepage + doc pages (auth-gated)
- Tests: 8 new tests (5 tRPC CRUD + 3 MCP CRUD auth), 40 total all green
2026-08-20 13:08:27 +07:00

75 lines
2.3 KiB
TypeScript

import { NextRequest, NextResponse } from "next/server";
import { ADMIN_PASSWORD } from "@mcpedia/config";
import { createHmac, timingSafeEqual } from "node:crypto";
// POST /api/auth/login — verify admin password, set a signed cookie.
// Uses a simple HMAC cookie (no JWT library) — sufficient for a single-admin KB.
const COOKIE_NAME = "mcpedia_admin";
const COOKIE_MAX_AGE = 60 * 60 * 24 * 7; // 7 days
function signCookie(value: string): string {
const secret = ADMIN_PASSWORD || "fallback";
const sig = createHmac("sha256", secret).update(value).digest("hex");
return `${value}.${sig}`;
}
function verifyCookie(cookieValue: string | undefined): boolean {
if (!cookieValue) return false;
const [value, sig] = cookieValue.split(".");
if (!value || !sig) return false;
const expected = signCookie(value);
return timingSafeEqual(
Buffer.from(cookieValue),
Buffer.from(expected),
);
}
export async function POST(req: NextRequest) {
const body = await req.json().catch(() => ({}));
const { password } = body;
if (!ADMIN_PASSWORD || typeof password !== "string") {
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
}
const ok = timingSafeEqual(
Buffer.from(password),
Buffer.from(ADMIN_PASSWORD),
);
if (!ok) {
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
}
const cookie = signCookie("admin");
const res = NextResponse.json({ ok: true });
res.cookies.set(COOKIE_NAME, cookie, {
maxAge: COOKIE_MAX_AGE,
httpOnly: true,
path: "/",
sameSite: "lax",
secure: process.env.NODE_ENV === "production",
});
return res;
}
// GET /api/auth/login — returns 200 if currently authenticated, 401 otherwise.
export async function GET(req: NextRequest) {
const cookie = req.cookies.get(COOKIE_NAME)?.value;
if (verifyCookie(cookie)) return NextResponse.json({ ok: true });
return NextResponse.json({ ok: false }, { status: 401 });
}
// DELETE /api/auth/login — clear the cookie (logout).
export async function DELETE() {
const res = NextResponse.json({ ok: true });
res.cookies.delete({ name: COOKIE_NAME, path: "/" });
return res;
}
// Exported for server components to call directly.
export function isAuthenticated(req: NextRequest): boolean {
const cookie = req.cookies.get(COOKIE_NAME)?.value;
return verifyCookie(cookie);
}