25 Commits
Author SHA1 Message Date
RainbowBird 27111382b4 fix(server): reconcile auth split with main 2026-08-12 23:33:58 +08:00
RainbowBird d5c95dca13 chore(server): define Railway service deployment config 2026-08-12 23:33:58 +08:00
RainbowBird 818cd0803f fix(auth-server): revoke social authorizations on account deletion (#2221) 2026-08-12 23:33:58 +08:00
RainbowBirdandautofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> 22b5249c64 refactor(server): split independent auth service (#2202)
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
2026-08-12 23:33:58 +08:00
Neko Ayaka a9906bf13b fix(deps): pin eventa to beta.13 2026-08-12 18:15:04 +08:00
Neko 1ca59ea5c5 fix(api-server): pin Eventa WebSocket protocol (#2259) 2026-08-12 00:04:41 +08:00
RainbowBird d4f1837994 fix(auth): trust proxy client IP for rate limits 2026-08-11 23:03:21 +08:00
Neko Ayaka 66d7ef207e refactor(stage-web,stage-pages,stage-ui): better structure for asr & vad 2026-08-09 18:22:29 +08:00
RainbowBird dd4658bd41 perf(api): remove legacy rolling user metric (#2233) 2026-08-06 18:31:29 +08:00
LuluCursorautofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
ff7f64ace8 feat(server): add Steam OpenID sign-in and account linking plugin (#2226)
## Summary

Adds a self-contained better-auth plugin
(`server/apps/api/src/libs/auth-plugins/steam.ts`) implementing Steam
OpenID 2.0 sign-in, account linking, and callback verification via "dumb
mode".

Steam's web login is OpenID 2.0, not OAuth2/OIDC, so it cannot be
registered as a `socialProviders` entry, and better-auth has no plugin
hook for extending its OAuth2 endpoints with a non-OAuth2 protocol. The
plugin therefore adds the endpoints Steam's protocol needs: `POST
/sign-in/steam`, `POST /link/steam`, and `GET /steam/callback`.

- Callback verification uses OpenID "dumb mode"
(`openid.mode=check_authentication`): one extra round trip to Steam
instead of managing RSA association state.
- New sign-ups get a placeholder `<steamid64>@steam.placeholder.local`
with `emailVerified: true`, mirroring Apple Sign In's
`<sub>@apple.placeholder.local`.
- The plugin's request/query schemas use Zod; a `// NOTICE:` documents
that better-auth's OpenAPI generator is Zod-native. Steam verification
uses `ofetch`.
- Wires Steam into `apps/ui-server-auth` sign-in and profile "Connected
accounts", plus the shared `OAuthProvider` / `defaultSignInProviders` in
`packages/stage-ui`.
- Linking routes through `/link/steam` via the client's `$fetch`;
unlinking needs no special-casing (`/unlink-account` already takes a
free-form `providerId`).

No Steam Web API key is required for this browser-based flow.

We intentionally do not depend on community Steam packages (e.g.
`better-auth-steam`) or the still-open upstream draft
([better-auth#4877](https://github.com/better-auth/better-auth/pull/4877)).
Steam never returns an email, and we need sign-up that does not ask the
user for one plus first-class account linking; the available options
either require an email at sign-in, lack linking, or are abandoned /
blocked — shipping a small in-tree plugin is the safer auth dependency
for this requirement.

## Test plan

- [x] `pnpm exec vitest run
server/apps/api/src/libs/auth-plugins/steam.test.ts` — 6/6 passing
- [x] `pnpm -F @proj-airi/ui-server-auth exec vitest run` — 32/32
passing
- [x] `pnpm -F @proj-airi/stage-ui exec vitest run
src/libs/steam-auth-client.test.ts
src/composables/use-linked-accounts.test.ts` — 5/5 passing
- [x] `pnpm -F @proj-airi/api-server typecheck`
- [x] `pnpm -F @proj-airi/ui-server-auth typecheck`
- [x] `pnpm -F @proj-airi/stage-ui typecheck`

## Follow-ups

- Desktop Steam ticket sign-in (top of this stack): silent startup
ticket exchange for Steam builds; the server resolves or creates the
AIRI user for the verified SteamID before issuing an OIDC code.
- Steam persona name/avatar via `GetPlayerSummaries` inside the plugin,
if display names beyond `Steam User <id>` are wanted.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
2026-08-05 23:57:55 +08:00
RainbowBird 2abb1ac9ff fix(server): index hot Postgres query paths (#2218) 2026-08-04 21:24:26 +08:00
RainbowBird 04485788d0 perf(server): allow Neon to scale to zero when idle (#2217) 2026-08-04 10:58:27 +00:00
RainbowBird 4f4d256a49 perf(server): add query indexes and cache admin metrics (#2213)
Signed-off-by: RainbowBird <git@luoling.moe>
2026-08-04 17:31:16 +08:00
RainbowBird d5a241b10e chore: migrate services to integration folder 2026-08-02 20:12:13 +08:00
RainbowBird 4ccde2c96e chore: move the server to an independent folder 2026-08-02 18:43:57 +08:00
Neko Ayaka cf1f1fe038 chore: cleanup
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-03 13:06:39 +08:00
Neko Ayaka 89d4825d1f debug: remove api dir completely
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 21:35:47 +08:00
Neko Ayaka 87e8413fa0 chore: fix
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 21:09:19 +08:00
Neko Ayaka 8b1338c123 chore: tts
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 20:49:31 +08:00
Anthony Fu ff2c537a76 init: init 2024-12-02 20:49:31 +08:00
Neko Ayaka a282115d78 chore: configure rules for static assets 2024-12-02 20:49:24 +08:00
Neko Ayaka 8ee4a3cd2f refactor: cleanup code
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 00:31:39 +08:00
Neko Ayaka 36a191b477 refactor: cleanup code
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 00:31:39 +08:00
Neko Ayaka d791c8315a feat: streamable audio
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 00:31:39 +08:00
Neko Ayaka d9ae0aae38 init: init
Signed-off-by: Neko Ayaka <neko@ayaka.moe>
2024-12-02 00:31:36 +08:00