Skip to content

feat: separate admin service into auth and firebase auth - #166

Merged
frodi-karlsson merged 2 commits into
mainfrom
auth-service
Oct 9, 2026
Merged

frodi-karlsson merged 2 commits into
mainfrom
auth-service

Conversation

@frodi-karlsson

@frodi-karlsson frodi-karlsson commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Introduces replacements for the base admin service via two modules that are more generically useful and composable:

  • FirebaseAuthService - verifies Firebase ID tokens: reads the token from a configured cookie/header and resolves it to an email. Also serves the Firebase login page and login handler.
  • AuthService - the provider-agnostic auth flow. The app supplies authenticate (who is this) and getPermissions (what may they do). The service then handles resolving the caller's status based on these, requiring various things, and constructing auth middlewares
const firebaseAuthService = new FirebaseAuthService(() => firebaseService.auth(), {
  tokenCookie: 'my_token',
  tokenHeader: 'x-my-token',
})

const authService = new AuthService<{ req: BackendRequest }>({
  authenticate: req => firebaseAuthService.getEmailByToken(firebaseAuthService.getToken(req)),
  getPermissions: email => getPermissionsFromDb(email),
  onCheck: (check, ctx) => auditLog(check, ctx), // optional
  authEnabled: env.authEnabled,
})

// Use as middleware
const requireAuth = authService.getLoginRedirectMiddleware({ loginHtmlPath: '/login.html' })
router.get('/users', requireAuth(['READ_USERS']), handler)

// Or resolve first, then check synchronously
const resolved = await authService.resolve(req)
authService.require(resolved, ['WRITE_USERS'], { ctx: { req, recordId } }) // 401 / 403

I expect it will hold well for any auth solution similar to firebase

Note

I really like the commit sha: fabdbbb image

@frodi-karlsson
frodi-karlsson marked this pull request as ready for review October 6, 2026 21:35

@kirillgroshkov kirillgroshkov left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

Sorry it took me long to get to it.

I chose to not go into deep research of the perfect API, and to agree with your proposal instead 👍

@frodi-karlsson
frodi-karlsson merged commit deff38e into main Oct 9, 2026
3 checks passed
@frodi-karlsson
frodi-karlsson deleted the auth-service branch October 9, 2026 08:20
@frodi-karlsson

Copy link
Copy Markdown
Contributor Author

oh sorry i didn't see you request David

@kirillgroshkov

kirillgroshkov commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

oh sorry i didn't see you request David

Not important, as I already reviewed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants