feat: Introduce NextAuth.js for authentication, including default admin seeding and user table auto-creation.

This commit is contained in:
Michael committed 2026-03-10 11:38:12 +01:00
1 parent 3ce22defa7
commit 47872a994f
2 files changed
+21 -10

No files matched your search

+6 -3
View File
@@ -28,16 +28,19 @@ export async function ensureAdminExists() {
.limit(1);
if (adminUser.length === 0) {
console.log("BMAD: Default admin account not found. Initializing (admin/admin)...");
console.log("[AUTH] Admin user not found. Seeding default (admin/admin)...");
await db.insert(users).values({
username: "admin",
passwordHash: hashPassword("admin"),
role: "admin"
});
console.log("[AUTH] Default admin seeded successfully.");
return true;
} else {
console.log("[AUTH] Admin user already exists.");
}
} catch (err) {
console.error("BMAD: CRITICAL Error checking/seeding users table.", err);
} catch (err: any) {
console.error("[AUTH] CRITICAL Error during ensureAdminExists:", err.message || err);
}
return false;
}
+15 -7
View File
@@ -22,26 +22,34 @@ export const { handlers, auth, signIn, signOut } = NextAuth({
if (!credentials?.username || !credentials?.password) return null;
try {
console.log(`[AUTH] Checking user "${credentials.username}" in database...`);
const [user] = await db.select()
.from(users)
.where(eq(users.username, credentials.username as string));
console.log(`BMAD: Auth attempt for "${credentials.username}". User found: ${!!user}`);
console.log(`[AUTH] User found in DB: ${!!user}`);
if (!user) return null;
if (!user) {
console.warn(`[AUTH] User "${credentials.username}" not found.`);
return null;
}
const isValid = verifyPassword(credentials.password as string, user.passwordHash);
console.log(`BMAD: Password valid for "${credentials.username}": ${isValid}`);
console.log(`[AUTH] Password valid for "${credentials.username}": ${isValid}`);
if (!isValid) return null;
if (!isValid) {
console.warn(`[AUTH] Invalid password for user "${credentials.username}".`);
return null;
}
return {
id: user.id.toString(),
name: user.username,
username: user.username,
role: user.role,
};
} catch (err) {
console.error("Auth Error:", err);
} catch (err: any) {
console.error("[AUTH] CRITICAL ERROR during authorize callback:", err.message || err);
// Propage l'erreur pour que Next-Auth la gère (mais authorize doit retourner null ou l'utilisateur)
return null;
}
}