chore: Update Readme

This commit is contained in:
Wanjohi
2026-08-06 22:32:33 +03:00
parent 293c099835
commit a8b9a11de0
8 changed files with 244 additions and 3 deletions

46
packages/auth/README.md Normal file
View File

@@ -0,0 +1,46 @@
# packages/auth (`@nestri/auth`)
Framework-agnostic OpenAuth implementation for Nestri — the OAuth/OIDC **issuer**, **client**,
**subjects**, and the login **UI**. A vendored/forked build of **OpenAuth**.
## What it does
Everything needed to run your own authentication provider:
- **`issuer.ts`** — the authorization server: routes for `/authorize`, `/callback`, `/token`,
`/userinfo`, `.well-known/*`, plus the login UI (React renderer).
- **`client.ts`** — `createClient` to verify JWTs against the issuer ("who is this token?").
- **`subject.ts`** — typed JWT subjects (`zod` schemas for the token payload).
- **`provider/*`** — drop-in OAuth/OIDC providers (steam, discord, github, google, apple,
microsoft, slack, spotify, twitch, x, yahoo, facebook, linkedin, cognito, keycloak, jumpcloud,
oauth2, oidc, password, ssh, code, arctic).
- **`storage/*`** — persistence adapters for keys/sessions/codes: `memory`, `cloudflare` (KV),
`aws`, `dynamo`.
- **`ui/*`** — the login page components (forms, password, code, theme, CSS).
- **`jwt.ts`, `keys.ts`, `pkce.ts`, `random.ts`** — signing, keypair management, PKCE, randomness.
## Usage
Consumed by the [`apps/auth`](../../apps/auth/README.md) worker, e.g.:
```ts
import { issuer } from '@nestri/auth/index';
import { CloudflareStorage } from '@nestri/auth/storage/cloudflare';
import { SteamProvider } from '@nestri/auth/provider/steam';
```
The API uses `createClient` (from `@openauth/openauth/client`) or the bundled `client.ts` to verify
tokens against the issuer URL.
## Scripts
```sh
bun test # run tests
bun run build # build (see script/build.ts)
```
## Note
`@openauthjs` is the upstream project; this package's exports are meant to be API-compatible with a
pinned preference toward tree-shaking-friendly imports. Prefer importing subpaths over the barrel
(`@nestri/auth/index`).

60
packages/core/README.md Normal file
View File

@@ -0,0 +1,60 @@
# packages/core
`@nestri/core` — the **domain layer** for Nestri. All business logic, database access, and
serialization lives here. The API and auth workers are thin pass-through translation layers on top.
## What it contains
| Area | Files | Purpose |
| ---- | ----- | ------- |
| **db** | `db/index.ts`, `db/types.ts`, `db/test.ts` | Drizzle + Postgres (`Database.use/transaction`), ULID column helpers |
| **users** | `user/*` | Users, linked accounts, fingerprints, library |
| **teams** | `team/*` | Teams + membership with roles (`team_member`) |
| **games** | `game/*` | Game catalog, depot content, per-host downloads |
| **steam** | `steam/index.ts` | Steam API integration & SSH identity resolution |
| **auth** | `auth/subjects.ts` | JWT subjects shared with the auth worker |
| **infra** | `env.ts`, `context.ts`, `actor.ts`, `fn.ts`, `id.ts`, `error.ts`, `examples.ts` | Environment, Actor model, zod-typed `fn()` wrappers, IDs, error types, examples |
| **migrations** | `migrations/` | Drizzle-kit SQL migrations for Postgres schema |
## Conventions
- **Domain namespaces** (`user/`, `team/`, ...) expose typed `fn()` functions that validate input
with a Zod schema and serialize DB rows inside the function boundary — the API routes never see raw table rows.
- **Actor model**: `Actor.userID`, `Actor.type`, ... pull the current authenticated identity from
`AsyncLocalStorage` (set by the API middleware / auth worker) without passing it through call chains.
- **Soft delete**: every table has `time_deleted`; queries filter with `isNull(table.timeDeleted)`.
- **IDs**: ULIDs via `Identifier.ascending('user')``usr_...`.
- Tables are defined in `*.sql.ts` files (drizzle) with namespaces in `index.ts`.
- Environment is read through `Env.get()`, init by worker bindings.
## Structure
```text
src/
├── actor.ts, env.ts, id.ts, fn.ts, error.ts, examples.ts
├── db/
├── auth/
├── user/ (user.sql.ts, linked-account.*, fingerprint.*, library.*, index.ts)
├── team/ (team.sql.ts, member.*, index.ts)
├── game/ (game.sql.ts, depot.*, download.*, index.ts)
├── steam/ (index.ts)
├── pairing-code/
├── access-token/
└── machine/
```
## Scripts
```sh
bun run db:push # push schema (drizzle-kit)
bun run db # open drizzle-kit
```
## Usage
```ts
import { Team } from '@nestri/core/team/index';
import { Database } from '@nestri/core/db/index';
const team = await Team.fromID('tem_...');
```