mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 09:15:19 +03:00
A single secret that turned any request into an operator was the only credential several routes accepted, and it had no caller left: the device pairing it existed for is on hold, and nothing in this tree or any client sent it. What remained was a key that bypassed authentication entirely, required to boot, and checked by nobody. Every route behind it had a better answer available: - Library and game sync move to host credentials. Both took a `userId` in the body, which meant one secret could write into anybody's library. A host now says which of its enrolled users a batch is for, and that claim is checked against the Steam sign-ins it actually holds — one box carries several people's accounts, so the pair is the unit. - Download-state reporting narrows to hosts alone, and the body that could name a different host is gone. Which host is reporting comes from its own credentials, and a body that still names one is refused rather than ignored. - Linking a Steam account is always for the caller. - Creating a game by hand is deleted; syncing already upserts the catalogue. - Reading the waitlist is deleted. Every address on it belongs to someone who has not agreed to anything, and answering it over HTTP made that list something a leaked key could drain. - The pairing-code routes are deleted with the flow they served. The domain module and its table stay, so returning to it is a route file rather than a migration. Nothing in the API now accepts a credential that stands for more than one caller: every request resolves to a specific user or a specific host, which is what lets a route say "the caller's own library" and mean it. BREAKING CHANGE: the `x-nestri-admin-token` header is no longer accepted and `ADMIN_SHARED_SECRET` is no longer read. `POST /games`, `GET /waitlist` and the `/pairing-code` routes are gone; `POST /games/sync` and `POST /library/sync` now require host credentials and take `userId` in the body; `POST /steam/link` no longer accepts `userId`; `POST /games/download-state` no longer accepts `hostId`.
38 lines
1.8 KiB
Plaintext
38 lines
1.8 KiB
Plaintext
# Copy to `.env` before `docker compose up`. Compose reads every credential
|
|
# from here and has no defaults of its own — it refuses to start naming the
|
|
# variable it wanted rather than falling back to a value that would be public.
|
|
|
|
# The local database. Throwaway values are fine; these three are what compose
|
|
# creates the container with and what it builds DATABASE_URL from.
|
|
POSTGRES_USER=postgres
|
|
POSTGRES_PASSWORD=postgres
|
|
POSTGRES_DB=nestri
|
|
|
|
# For anything run outside a container — `bun dev`, `bun run db:migrate`.
|
|
DATABASE_URL=postgres://postgres:postgres@localhost:5432/nestri
|
|
|
|
# The database the tests run against. Required — DB-backed tests refuse to run
|
|
# rather than fall back to a database nobody named.
|
|
#
|
|
# **Point it at the same database as DATABASE_URL above.** "Isolated" means
|
|
# isolated from anything you care about, not isolated from DATABASE_URL: route
|
|
# tests reach the database through the app and core tests reach it directly, so
|
|
# two different values put the fixtures in one database and the assertions in
|
|
# the other. That fails around forty tests, in neither half's own code, with
|
|
# nothing in the output pointing at this line.
|
|
TEST_DATABASE_URL=postgres://postgres:postgres@localhost:5432/nestri
|
|
|
|
# The issuer's public URL — the address a token's `iss` claim will carry.
|
|
AUTH_ISSUER_URL=http://localhost:1337
|
|
# Where to reach the issuer, if that is not where it lives. Unset unless the
|
|
# public name is unroutable from where the API runs; docker compose sets it.
|
|
AUTH_INTERNAL_URL=
|
|
|
|
# Mail delivery. All three together, or none of them plus EMAIL_DEV_LOG=true,
|
|
# which prints sign-in codes to the log instead of sending them. Printing them
|
|
# is a local-development convenience and nothing else.
|
|
EMAIL_SEND_URL=
|
|
EMAIL_API_KEY=
|
|
EMAIL_FROM=
|
|
EMAIL_DEV_LOG=true
|