Scaffold Next.js 16 app + wire NextAuth Credentials to auth core

Minimal but real App Router app that builds (next build exit 0):
- src/lib/auth.ts: NextAuth v5 Credentials provider calling checkLogin()
  (argon2id/bcrypt + md5->argon2id upgrade gated by CONVERT_PASSWORDS), JWT
  session, /api/auth/[...nextauth] route handler.
- src/app: root layout, home (force-dynamic, reads hotel_name via siteSettings),
  /login client form (signIn).
- next.config.ts: pinned turbopack.root, serverExternalPackages for the Prisma
  MariaDB adapter; tsconfig set up for Next.

Routes: / (dynamic), /login, /api/auth. Verified: next build exit 0, 28 tests.
Still needs DB+APP_KEY to run auth end-to-end. i18n/middleware/pages to follow.
This commit is contained in:
Simo committed 2026-06-27 16:11:52 +02:00
1 parent ec2d46e583
commit 443d908909
12 files changed
+798 -20

No files matched your search

+49
View File
@@ -0,0 +1,49 @@
import NextAuth from "next-auth";
import Credentials from "next-auth/providers/credentials";
import { checkLogin } from "@/lib/auth/password";
import { prisma } from "@/lib/prisma";
import { env } from "@/env";
export const { handlers, signIn, signOut, auth } = NextAuth({
trustHost: true,
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
pages: { signIn: "/login" },
providers: [
Credentials({
credentials: {
username: { label: "Username", type: "text" },
password: { label: "Password", type: "password" },
},
authorize: async (credentials) => {
const username = String(credentials?.username ?? "").trim();
const password = String(credentials?.password ?? "");
if (!username || !password) return null;
const user = await prisma.user.findUnique({ where: { username } });
if (!user) return null;
// Byte-compatible AtomCMS check (argon2id/bcrypt + md5->argon2id upgrade).
const res = await checkLogin(password, user.password, {
convertPasswords: env.CONVERT_PASSWORDS,
});
if (!res.valid) return null;
if (res.upgradedHash) {
await prisma.user.update({
where: { id: user.id },
data: { password: res.upgradedHash },
});
}
return { id: String(user.id), name: user.username };
},
}),
],
callbacks: {
// NextAuth stores the user id in token.sub automatically; surface it on the session.
session({ session, token }) {
if (token.sub && session.user) session.user.id = token.sub;
return session;
},
},
});