Scaffold Next.js 16 app + wire NextAuth Credentials to auth core

Minimal but real App Router app that builds (next build exit 0):
- src/lib/auth.ts: NextAuth v5 Credentials provider calling checkLogin()
  (argon2id/bcrypt + md5->argon2id upgrade gated by CONVERT_PASSWORDS), JWT
  session, /api/auth/[...nextauth] route handler.
- src/app: root layout, home (force-dynamic, reads hotel_name via siteSettings),
  /login client form (signIn).
- next.config.ts: pinned turbopack.root, serverExternalPackages for the Prisma
  MariaDB adapter; tsconfig set up for Next.

Routes: / (dynamic), /login, /api/auth. Verified: next build exit 0, 28 tests.
Still needs DB+APP_KEY to run auth end-to-end. i18n/middleware/pages to follow.
This commit is contained in:
Simo committed 2026-06-27 16:11:52 +02:00
1 parent ec2d46e583
commit 443d908909
12 files changed
+798 -20

No files matched your search

+3
View File
@@ -0,0 +1,3 @@
import { handlers } from "@/lib/auth";
export const { GET, POST } = handlers;
+15
View File
@@ -0,0 +1,15 @@
import type { Metadata } from "next";
import type { ReactNode } from "react";
export const metadata: Metadata = {
title: "AtomCMS",
description: "AtomCMS — retro hotel CMS (Next.js conversion)",
};
export default function RootLayout({ children }: { children: ReactNode }) {
return (
<html lang="en">
<body>{children}</body>
</html>
);
}
+49
View File
@@ -0,0 +1,49 @@
"use client";
import { signIn } from "next-auth/react";
import { type FormEvent, useState } from "react";
export default function LoginPage() {
const [username, setUsername] = useState("");
const [password, setPassword] = useState("");
const [error, setError] = useState<string | null>(null);
const [pending, setPending] = useState(false);
async function onSubmit(e: FormEvent) {
e.preventDefault();
setError(null);
setPending(true);
const res = await signIn("credentials", { username, password, redirect: false });
setPending(false);
if (!res || res.error) {
setError("Invalid username or password");
return;
}
window.location.href = "/";
}
return (
<main style={{ fontFamily: "system-ui", padding: "2rem", maxWidth: 360 }}>
<h1>Login</h1>
<form onSubmit={onSubmit} style={{ display: "grid", gap: "0.5rem" }}>
<input
value={username}
onChange={(e) => setUsername(e.target.value)}
placeholder="Username"
autoComplete="username"
/>
<input
type="password"
value={password}
onChange={(e) => setPassword(e.target.value)}
placeholder="Password"
autoComplete="current-password"
/>
<button type="submit" disabled={pending}>
{pending ? "Signing in…" : "Sign in"}
</button>
</form>
{error && <p style={{ color: "crimson" }}>{error}</p>}
</main>
);
}
+17
View File
@@ -0,0 +1,17 @@
import Link from "next/link";
import { siteSettings } from "@/lib/services/site-settings";
// Reads settings from the DB at request time — never at build.
export const dynamic = "force-dynamic";
export default async function HomePage() {
const hotelName = (await siteSettings.get("hotel_name", "Atom")) ?? "Atom";
return (
<main style={{ fontFamily: "system-ui", padding: "2rem", maxWidth: 640 }}>
<h1>Welcome to {hotelName}</h1>
<p>AtomCMS → Next.js conversion. Foundation, full Prisma schema and auth core are in place.</p>
<Link href="/login">Login →</Link>
</main>
);
}
+7
View File
@@ -9,6 +9,13 @@ const schema = z.object({
DATABASE_POOL_SIZE: z.coerce.number().int().positive().default(40),
DATABASE_IDLE_TIMEOUT_MS: z.coerce.number().int().positive().default(300_000),
HOTEL_NAME: z.string().default("Atom"),
// NextAuth v5 reads AUTH_SECRET itself; declared here for documentation/typing.
AUTH_SECRET: z.string().min(1).optional(),
// Mirrors Laravel config('habbo.site.convert_passwords') — enables md5->argon2id.
CONVERT_PASSWORDS: z
.string()
.optional()
.transform((v) => v === "true" || v === "1"),
});
type Env = z.infer<typeof schema>;
+49
View File
@@ -0,0 +1,49 @@
import NextAuth from "next-auth";
import Credentials from "next-auth/providers/credentials";
import { checkLogin } from "@/lib/auth/password";
import { prisma } from "@/lib/prisma";
import { env } from "@/env";
export const { handlers, signIn, signOut, auth } = NextAuth({
trustHost: true,
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
pages: { signIn: "/login" },
providers: [
Credentials({
credentials: {
username: { label: "Username", type: "text" },
password: { label: "Password", type: "password" },
},
authorize: async (credentials) => {
const username = String(credentials?.username ?? "").trim();
const password = String(credentials?.password ?? "");
if (!username || !password) return null;
const user = await prisma.user.findUnique({ where: { username } });
if (!user) return null;
// Byte-compatible AtomCMS check (argon2id/bcrypt + md5->argon2id upgrade).
const res = await checkLogin(password, user.password, {
convertPasswords: env.CONVERT_PASSWORDS,
});
if (!res.valid) return null;
if (res.upgradedHash) {
await prisma.user.update({
where: { id: user.id },
data: { password: res.upgradedHash },
});
}
return { id: String(user.id), name: user.username };
},
}),
],
callbacks: {
// NextAuth stores the user id in token.sub automatically; surface it on the session.
session({ session, token }) {
if (token.sub && session.user) session.user.id = token.sub;
return session;
},
},
});
+7
View File
@@ -0,0 +1,7 @@
import type { DefaultSession } from "next-auth";
declare module "next-auth" {
interface Session {
user: { id: string } & DefaultSession["user"];
}
}