Client: useNostr.ts's auto-restore now calls GET /api/auth/me (a plain
authFetch, no body) instead of POSTing {pubkey} to /api/auth/login —
identity is derived server-side from the JWT alone, never claimed by
the client.
Server: POST /login is reduced to a pure, documented-deprecated read.
Removed the creator auto-create branch and the creator auto-upgrade
db.update block — an unauthenticated request can no longer mutate the
database via this endpoint. The identical creator auto-create/upgrade
logic already exists, correctly gated behind NIP-98 verification, in
POST /nostr/session, so a creator signing in with a real signer still
gets the same row created/upgraded. Added a handler doc comment plus a
new auth.test.ts case asserting an unregistered creator pubkey now
returns exists:false and leaves the bots table row count unchanged.
e2e/helpers/auth.ts: doc comments updated to describe loginWithPubkey
as a read-only test lookup helper, not a login; request/signature
unchanged so existing e2e specs keep working.
Verification: auth.test.ts + auth-edge.test.ts + auth-audit.test.ts +
auth-me.test.ts = 56/56 pass. Full server suite (bypassing pnpm's
install-gate via ./node_modules/.bin/vitest, since this environment's
pnpm needs an interactive build-approval step unrelated to this task)
= 810/817 pass, remaining 7 are pre-existing timing/perf flakes under
CPU load (lifecycle/speed-meta/tier-balance/bot-auth constant-time),
none touching auth. tsc (server) and vue-tsc (frontend) both exit 0.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -114,15 +114,14 @@ if (typeof document !== 'undefined') {
|
||||
})
|
||||
}
|
||||
|
||||
// Auto-restore session from JWT on first load
|
||||
// Auto-restore session from JWT on first load.
|
||||
// Identity comes from the token alone — GET /api/auth/me derives the
|
||||
// pubkey server-side via extractPubkeyFromAuth, so no bare pubkey is
|
||||
// ever sent to claim a session (D-01/BOT-01).
|
||||
if (!autoRestoreRan && pubkey.value && !bot.value && getToken() && !isTokenExpired()) {
|
||||
autoRestoreRan = true;
|
||||
(globalThis as any).__bf_autoRestoreRan = true
|
||||
authFetch('/api/auth/login', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ pubkey: pubkey.value }),
|
||||
}).then(r => r.json()).then(data => {
|
||||
authFetch('/api/auth/me').then(r => r.json()).then(data => {
|
||||
if (data.exists) {
|
||||
bot.value = normalizeBotData(data.bot)
|
||||
store('bf_bot', bot.value)
|
||||
|
||||
Reference in New Issue
Block a user