@reuters-graphics/gfx-better-auth
v0.1.0
Published
Magic-link auth for Reuters Graphics SvelteKit apps, gated to Thomson Reuters staff. An opinionated better-auth preset with the schema, routes, emails and dev flow already wired.
Downloads
173
Keywords
Readme
@reuters-graphics/gfx-better-auth
Magic-link sign-in for Reuters Graphics SvelteKit apps, gated to Thomson Reuters staff. An opinionated better-auth preset with the schema, routes, emails and dev flow already wired.
This package is for Reuters Graphics apps only
The sign-in domain is hardcoded to
@thomsonreuters.comand is deliberately not configurable, so the package cannot do anything useful outside Thomson Reuters. It is published publicly because that is how our own apps install it, not because it is a general-purpose library.Full documentation lives in the repository, which is private. If you work here, start with
USAGE.md. If you don't, this is unlikely to be what you want — better-auth itself almost certainly is.
Install
pnpm add @reuters-graphics/gfx-better-authPeers: better-auth (>=1.7.5 <1.8.0), drizzle-orm, @sveltejs/kit, svelte. Node ≥ 22, plus
a Postgres and a Drizzle instance.
Four edits
// 1. src/lib/server/db/schema/index.ts
export * from '@reuters-graphics/gfx-better-auth/schema';
// 2. src/lib/server/auth.ts
import { createGfxAuth } from '@reuters-graphics/gfx-better-auth/server';
export const auth = createGfxAuth({
db,
appName,
baseURL,
secret,
postmark,
});
// 3. src/hooks.server.ts
import { building } from '$app/environment';
export const handle = sequence(gfxAuth({ auth, building }), myHandle);
// 4. src/app.d.ts
interface Locals extends GfxAuthLocals {}Then pnpm db:generate && pnpm db:migrate.
⚠️ gfxAuth must come before anything reading event.locals.user. Pass building if your app
prerenders anything.
What you get
Magic-link sign-in gated at the endpoint; sign-in, sent, confirm and sign-out pages served from the
hook with no route files and no JavaScript; event.locals.user and .session; a route guard; and
a development flow that needs no credentials.
You do not get roles or permissions — this package proves who someone is, not what they may do.
Entry points
| | |
| ---------- | --------------------------------------------------------- |
| . | Types and the domain helpers. Safe anywhere |
| ./schema | The four Drizzle tables, and columns to spread |
| ./server | 🚨 createGfxAuth, the handle, requireUser, signInAs |
| ./client | The browser client. Optional |
| ./emails | The sign-in email, and InactiveRecipientError |
Everything else
Configuration, session semantics, extending the user model, testing, and the reasoning behind any
of it: see USAGE.md in the repository.
MIT · Reuters Graphics
