@companyio/auth-fastify
v0.1.32
Published
Fastify authentication boundary for company APIs
Readme
@companyio/auth-fastify
Fastify plugin for bearer-token authentication. Supply a verifyAccessToken function, then protect routes with requireUser.
Use
import { authFastify, requireUser } from '@companyio/auth-fastify';
await app.register(authFastify, {
verifyAccessToken: (token) => sessions.verify(token),
});
app.get('/private', { preHandler: requireUser }, async (request) => ({ user: request.user }));Invalid or missing tokens return HTTP 401 responses.
Schema
This package owns prisma/auth.prisma (User, Session, UserRole) and the source SQL prisma/migrations/0001_auth_baseline. The host copy is apps/api/prisma/migrations/20260926000200_auth_baseline.
pnpm exec auth init --schema apps/api/prisma/schema.prismaauth init appends that fragment when User is missing. It does not copy the migration and it does not connect to PostgreSQL. The host applies the baseline with pnpm --filter @companyio/api exec prisma migrate deploy --config prisma7.config.ts. Business and branch ids live on User. There is no Membership model.
Build
pnpm --filter @companyio/auth-fastify build