mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 09:15:19 +03:00
Comments and served API descriptions here had grown references that only make sense to someone with our internal notes: relative paths that escape this tree, filenames and titles of documents nobody outside can open, quoted prose from them, and the name of a component that has no public surface — once in an OpenAPI description, which is published output rather than source. None of it was load-bearing. Every case restates as what the code actually requires, and every rewrite came out shorter: "in the words the host agent reports" for a component name, "republished as addresses are discovered" for a quoted phrase, "a size tier sets vCPU, RAM and the output geometry" for a sentence that had been carrying a path. Internal reasoning is now cited exactly one way, ref(d-NNNN) in a source comment, with the rule that the sentence must still stand if the marker is deleted. CLAUDE.md leads with it, because the previous version of this mistake was made by people who knew the repo was public and it still took ten occurrences to notice, so "be careful" is not a mechanism. Commit messages get the stricter rule and carry no references at all: a comment can be fixed by the next commit and a published message cannot be fixed at all. Git hooks now enforce both halves. The check caught a real one while being written: the CLAUDE.md table spelled out the paths it was prohibiting, which discloses them to exactly the reader it protects against. 138 tests, 0 fail.
apps/auth
The authentication worker for Nestri — a Cloudflare Worker built on
@nestri/auth (OpenAuth-style issuer).
What it does
Hosts the OpenID Connect / OAuth issuer and the login UI:
- Steam OAuth — the primary login flow. After Steam redirects back, the worker fetches the
player's profile, creates (or finds) the
User+LinkedAccountrows in Postgres, auto-creates a personal team on first login, and issues a JWTusersubject containing{ userID, linkedAccountID }. - SSH login — authenticates a device via its SSH fingerprint (keyed by
SSH_AUTH_KEY), resolving the identity throughSteam.resolveSshIdentityin@nestri/core.
Key details
- Signing keys are generated at runtime and persisted in the
AuthStorageKV namespace. - JWT subjects are defined in
@nestri/core/auth/subjects. - The API worker calls this worker via a service binding (
AUTH), verified throughAUTH_ISSUER_URL.
Structure
src/index.ts # Worker entrypoint: issuer config + success callbacks (steam, ssh)
test/ # Worker tests
Running
Deployed through Alchemy (apps/auth worker in alchemy.run.ts at the repo root) with bindings
AuthStorage (KV), HYPERDRIVE (Postgres), STEAM_API_KEY, SSH_AUTH_KEY.