Commit Graph
6933 Commits
Author SHA1 Message Date
ec9edc357a feat: API Key plugin (#1515)
* feat: API-key plugin

* add: `deleteAllExpiredApiKeys` functionality

* fix: fetching sessions from headers

* update: types & create-api-key now checks for min & max expiresIn values

* tests: Started working on tests

* add: features

- added list functionality
- added min & max prefix length
- added min & max name length
- added metadata enable/disable option
- added `disableSessionForAPIKeys` option
- verify API key now checks for expiration & refills
- added regex to check prefix of api key

* fix: create-api-key's expiration using `/` instead of `*`

* update: schema `metadata` transforms invalid values as `null`

* fix: create-api-key metadata should go through transformation

* fix: missing metadata wouldn't have `'null'` as value

* update: error types

* fix: remove console.logs from verify

* fix: rate-limit not working

* fix: rate-limit plugin options types

* chore: remove logs

* update: removed `key` field from result apiKey type of the update-api-key endpoint

* fix: typo

* update: create & update if checks

- create now checks if custom expiration times are allowed
- update now allows name values & checks if name is within length range
- update now also checks for custom expiration times are allowed

* update(WIP): tests

* fix: added the missing error throw when there is no values to update

* fix: update-api-key checks expiresIn in days, not ms

- also updated create-api-key & update-api-key to have more detailed event logging

* fix: update api key's remaining count's min & max checks

- also added more detail to the events

* fix: update-api-key can now update refillInterval & refillAmount properly

* fix: metadata in update-api-key transforms between string & obj correctly

* add: all of the `update` tests

* update: get-api-key metadata is now obj instead of string

* add: listApiKeys functionality

* fix: get-session to use mock session based on header API keys

* update: tests to test against get-session, get-api-key, and list-api-key

* add: `start` field to show the first few characters of an API key

* fix: very silly mistake

* update: tests to validate `start` property

* update: create-api-key checks if properties are set from server & allows for custom rate-limit rules

- also updated tests to check against this

* update: verify-api-key to check if a row has the right user-id

- this also should speed up the DB process too. (I'm pretty sure)

* update: `delete-all-expired-api-keys` endpoint added & updated list-api-keys endpoint function name

* add: customAPIKeyValidator fn, and fixed verification `remaining` and `lastRefillAt` values updating DB incorrectly

* update: documentation

* add: rate-limiting enable/disable on a per-key level

* update: docs

* fix: correct expiration time units and improve error messages in API key handling

* fix: allow creating apiKeys by providing userId on the server

* fix: user userId instead of headers to differ server vs client calls on create api key

* wip

* fix: JSDoc comment

* fix: tests not passing due to invalid expiresIn value

Since the expiresIn got changed from `ms` to `sec`, this needed to be changed as well.

* wip

* fix(api-key): update tests and error messages for API key verification

* fix(api-key): update API key fixes

* refactor tests and remove events

* refactor(api-key): remove unused event handling and clean up type definitions

* add: minimum values to `create-api-key` numeric input options

* fix: remove `opts.events` in delete-api-key route

* refactor: all returning routes which can contain `key`

- more performant
- better typed
- cleaner code

:D

* update: added minimum values to update-api-key endpoint as well

* fix: removed `maximumRemaining` & `minimumRemaining` default values in `opts`

* docs: ready (unless I make minor adjustments later) 🫡

* fix(docs): links & invalid code examples

* fix: output transform of metadata to use ParseJSON

* fix: tests failing due to async metadata transform output

* fix: return types for verify-api-key endpoint

* fix: tests failing due to invalid expiresIn minimum value

* docs: reorder sidebar items for API Key

* wip

* docs(api-key): enhance documentation with permissions and usage details

- Updated API key documentation with comprehensive permissions explanation
- Added examples for setting default permissions, creating, verifying, and updating API keys with permissions
- Clarified API key creation, verification, and update processes
- Improved code examples and descriptions for better understanding

* chore: lint

* fix(docs): incorrect wording / explanation on refillInterval/refillAmount

* add(docs): missing permissions info in docs

---------

Co-authored-by: Bereket Engida <bekacru@gmail.com>
2025-02-28 17:11:03 +03:00
Bereket Engida eef60b16bd chore: move test prisma client 2025-02-28 13:26:34 +03:00
Bereket Engida 9b7b0529f1 chore: update tsconfig to exclude test directories 2025-02-28 13:20:47 +03:00
Bereket Engida ee9a20219b chore: update lockfile 2025-02-28 11:15:39 +03:00
Bereket Engida 687913773a chore: improve build configuration and add tsc type generation 2025-02-28 11:14:10 +03:00
Bereket Engida 44352d7414 chore: migrate from tsup to unbuild 2025-02-28 09:45:39 +03:00
Mohamad Malek AlkhodaryandGitHub 20965ff851 docs: fix file import typo (#1592) 2025-02-28 07:27:18 +03:00
Bereket Engida dca7fe539d chore: update lockfile 2025-02-27 20:29:53 +03:00
Bereket Engida 0237a73ef4 chore(deps): update @better-fetch/fetch to v1.1.15 in better-auth 2025-02-27 20:21:44 +03:00
Bereket Engida 89905481aa chore: export types from @better-fetch/fetch 2025-02-27 18:59:43 +03:00
Bereket Engida bb387fed5c chore: fix expo types 2025-02-27 18:52:16 +03:00
Bereket Engida c50be9d086 chore(deps): update @better-fetch/fetch to v1.1.15 across projects 2025-02-27 18:28:37 +03:00
Bereket Engida 3a4182bbdd chore: lint 2025-02-27 18:22:29 +03:00
Bereket Engida 69b1ed60fd chore: fix lockfile 2025-02-27 14:53:15 +03:00
Bereket Engida 17f187ebc0 chore: release v1.2.0-beta.17 v1.2.0-beta.17 2025-02-27 14:20:43 +03:00
Bereket Engida 7ba1af2ff9 Merge branch 'main' into v1.2 2025-02-27 14:20:23 +03:00
Bereket Engida 55a3cd3c47 demo: client only auth demo 2025-02-27 10:38:11 +03:00
Bereket Engida 7d9c2ab3b7 chore: increase build memory limit 2025-02-26 07:41:54 +03:00
Bereket Engida 821e65bea8 chore: configure Turborepo remote cache 2025-02-26 00:59:24 +03:00
Bereket Engida 4c8aff3489 chore: configure server-side external packages and increase build memory limit 2025-02-26 00:38:01 +03:00
Bereket Engida 76bd9e8c0b chore(deps): upgrade fumadocs and related packages 2025-02-26 00:30:31 +03:00
Bereket Engida dbfb050b4c chore(deps): bump zod to v3.24.2 2025-02-25 23:38:20 +03:00
Bereket Engida c488e306ea docs: add llms.txt 2025-02-25 22:35:30 +03:00
Bereket Engida f9b5d82641 chore: update lock file 2025-02-25 22:19:38 +03:00
Bereket Engida 74b0bf5e47 fix(generic-oauth): store additional token details during account linking 2025-02-25 22:18:55 +03:00
MaxwellandGitHub 96a1ad5ce2 docs(fix): typo in jsdoc for anonymous plugin (#1575) 2025-02-25 21:54:39 +03:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ff727ba11e chore(deps): bump solid-js in /examples/astro-example (#1574)
Bumps [solid-js](https://github.com/solidjs/solid) from 1.8.23 to 1.9.4.
- [Release notes](https://github.com/solidjs/solid/releases)
- [Changelog](https://github.com/solidjs/solid/blob/main/CHANGELOG.md)
- [Commits](https://github.com/solidjs/solid/compare/v1.8.23...v1.9.4)

---
updated-dependencies:
- dependency-name: solid-js
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-25 21:54:09 +03:00
Krishna SantoshandGitHub 2c81dcab7c docs(fix): add missing word 'change' (#1572) 2025-02-25 16:27:33 +03:00
Ignat S.andGitHub 388942ebaa fix: correct option name in the reset password error message (#1573)
Seems like `sendResetPasswordToken` isn't seen anywhere esle in the project and is supposed to be just `sendResetPassword`.
2025-02-25 16:15:31 +03:00
Bereket Engida df2f5a4c79 chore: release v1.1.22-beta.2 v1.1.22-beta.2 2025-02-25 13:43:16 +03:00
Bereket Engida c3a44b5563 docs: update security policy 2025-02-25 13:43:10 +03:00
Bereket Engida 16131fa8bd chore(deps): upgrade vitest to v3.0.7 and update related dependencies 2025-02-25 12:19:13 +03:00
PitonsSkipperandGitHub 1ecc717483 fix: add last semi-colon to the compiled migrations to support Cloudflare D1 migration (#1569)
* Update get-migration.ts

Add last semi-colon to the compiled migrations

* Update test snapshot migrations.sql
2025-02-25 12:12:02 +03:00
Bereket EngidaandGitHub 1a3aff29a7 feat(client): add basePath option on createAuthClient (#1571)
* chore(dependencies): update @better-fetch/fetch to 1.1.15

* feat(client): add basePath option
2025-02-25 10:38:57 +03:00
Bereket EngidaandBereket Engida c7d348a565 fix(two-factor): should respect remember me value when a user logins in with 2fa (#1566)
* fix(two-factor): respect remember me value when using 2fa login

* fix(two-factor): clean up temporary cookies
2025-02-25 09:52:38 +03:00
Bereket EngidaandGitHub da1ee9e2e6 fix(two-factor): should respect remember me value when a user logins in with 2fa (#1566)
* fix(two-factor): respect remember me value when using 2fa login

* fix(two-factor): clean up temporary cookies
2025-02-25 09:47:10 +03:00
Bereket Engida b469339996 ci: configure push event branches for workflow 2025-02-25 09:43:12 +03:00
Bereket Engida 52ed183bdc chore: release v1.1.22-beta.1 v1.1.22-beta.1 2025-02-24 23:50:04 +03:00
Bereket Engida 79b8700d36 fix(origin-check): support callback URLs with query parameters 2025-02-24 23:38:50 +03:00
Bereket Engida 474b01e0fb chore: release v1.2.0-beta.16 v1.2.0-beta.16 2025-02-24 22:26:06 +03:00
Bereket Engida 814ac503d4 Merge branch 'main' into v1.2 2025-02-24 22:25:53 +03:00
MaxwellandGitHub cdedfd2582 docs: add author avatar on community plugins (#1565) 2025-02-24 22:23:44 +03:00
Bereket Engida 4c5f0c279f chore: release v1.1.21 v1.1.21 2025-02-24 22:13:05 +03:00
Bereket Engida ee0d6be569 fix(open-api): add authentication schemes 2025-02-24 22:11:55 +03:00
Bereket Engida ade3974ed5 chore: release v1.1.21-beta.1 v1.1.21-beta.1 2025-02-24 21:57:18 +03:00
Bereket Engida b381cac7aa fix(origin-check): add tests for callback URLs with malicious patterns 2025-02-24 21:56:39 +03:00
Bereket Engida e5d148a0b0 fix(kysely-adapter): handle field conversion on where clauses 2025-02-24 20:33:00 +03:00
Leonardo E. DominguezandGitHub 8a820898e8 fix: oauth failing when using drizzle adapter (#1563) 2025-02-24 19:53:24 +03:00
Bereket Engida 5812195479 chore: release v1.2.0-beta.15 v1.2.0-beta.15 2025-02-24 14:55:49 +03:00
Bereket Engida c410f6dae0 Merge branch 'main' into v1.2 2025-02-24 14:55:44 +03:00