Files
netris-nestri/packages/auth
Wanjohi 4ed36e0d38 fix(auth): give the sign-in input a text colour, and restore the theme
The email field computed its own background one step lighter than the page
and never set `color`. Form controls do not inherit it, so the text someone
typed was the UA default — black, over a near-black field. There was no
`color-scheme` either, so the browser rendered the control in light
appearance to begin with.

The theme was a second, separate loss: `issuer()` still takes one and calls
`setTheme`, but nothing had passed one since `packages/auth` became a
vendored fork, so every sign-in rendered as OpenAuth — its font, its
periwinkle, its logo. Restored from the pre-fork config, with the logo and
favicon repointed because both URLs it carried now 404 and a broken `logo`
renders a broken image rather than falling back.
2026-09-17 22:54:00 +03:00
..
2026-08-06 22:13:51 +03:00
2026-08-06 22:13:51 +03:00
2026-08-06 22:32:33 +03:00
2026-08-06 22:13:51 +03:00

packages/auth (@nestri/auth)

Framework-agnostic OpenAuth implementation for Nestri — the OAuth/OIDC issuer, client, subjects, and the login UI. A vendored/forked build of OpenAuth.

What it does

Everything needed to run your own authentication provider:

  • issuer.ts — the authorization server: routes for /authorize, /callback, /token, /userinfo, .well-known/*, plus the login UI (React renderer).
  • client.tscreateClient to verify JWTs against the issuer ("who is this token?").
  • subject.ts — typed JWT subjects (zod schemas for the token payload).
  • provider/* — drop-in OAuth/OIDC providers (steam, discord, github, google, apple, microsoft, slack, spotify, twitch, x, yahoo, facebook, linkedin, cognito, keycloak, jumpcloud, oauth2, oidc, password, ssh, code, arctic).
  • storage/* — persistence adapters for keys/sessions/codes: memory, cloudflare (KV), aws, dynamo.
  • ui/* — the login page components (forms, password, code, theme, CSS).
  • jwt.ts, keys.ts, pkce.ts, random.ts — signing, keypair management, PKCE, randomness.

Usage

Consumed by the apps/auth worker, e.g.:

import { issuer } from '@nestri/auth/index';
import { CloudflareStorage } from '@nestri/auth/storage/cloudflare';
import { SteamProvider } from '@nestri/auth/provider/steam';

The API uses createClient (from @openauth/openauth/client) or the bundled client.ts to verify tokens against the issuer URL.

Scripts

bun test      # run tests
bun run build # build (see script/build.ts)

Note

@openauthjs is the upstream project; this package's exports are meant to be API-compatible with a pinned preference toward tree-shaking-friendly imports. Prefer importing subpaths over the barrel (@nestri/auth/index).