mirror of
https://github.com/tomru/pfadi-bussle.git
synced 2026-03-03 22:47:15 +01:00
73 lines
2.1 KiB
TypeScript
73 lines
2.1 KiB
TypeScript
import { NextApiRequest, NextApiResponse } from 'next'
|
|
import NextAuth from 'next-auth'
|
|
import EmailProvider from 'next-auth/providers/email'
|
|
import GitHubProvider from 'next-auth/providers/github'
|
|
|
|
import { MongoDBAdapter } from '@next-auth/mongodb-adapter'
|
|
import { MONGO_URI } from '../../../db'
|
|
import { MongoClient, ServerApiVersion } from 'mongodb'
|
|
|
|
let client: MongoClient
|
|
|
|
const ADMIN_EMAIL = process.env.ADMIN_EMAIL
|
|
const GITHUB_USERS_GRANTED = ['111471']
|
|
|
|
async function getMongoClient() {
|
|
if (!client) {
|
|
client = new MongoClient(MONGO_URI, {
|
|
serverApi: {
|
|
version: ServerApiVersion.v1,
|
|
strict: true,
|
|
deprecationErrors: true,
|
|
}
|
|
})
|
|
await client.connect()
|
|
}
|
|
|
|
return client
|
|
}
|
|
|
|
export default async function auth(req: NextApiRequest, res: NextApiResponse) {
|
|
return await NextAuth(req, res, {
|
|
secret: process.env.NEXTAUTH_SECRET,
|
|
adapter: MongoDBAdapter(getMongoClient()),
|
|
providers: [
|
|
GitHubProvider({
|
|
clientId: process.env.GITHUB_CLIENT_ID,
|
|
clientSecret: process.env.GITHUB_CLIENT_SECRET,
|
|
}),
|
|
EmailProvider({
|
|
server: {
|
|
host: "wirtanen.uberspace.de",
|
|
port: 465,
|
|
secure: true,
|
|
auth: {
|
|
user: process.env.SMTP_USER,
|
|
pass: process.env.SMTP_PASS,
|
|
},
|
|
logger: true,
|
|
debug: true,
|
|
},
|
|
from: process.env.FROM_EMAIL,
|
|
}),
|
|
],
|
|
callbacks: {
|
|
async signIn({ account, email }) {
|
|
// if user sigin requested magic link via EmailProvider
|
|
if (account.provider === 'email') {
|
|
if (email?.verificationRequest) {
|
|
// only allow admins by email entered
|
|
return account.providerAccountId === ADMIN_EMAIL
|
|
}
|
|
|
|
// if user accesses with magic link, also only allow admin
|
|
return account.providerAccountId === ADMIN_EMAIL
|
|
} else if (account.provider === 'github') {
|
|
// only one and only one user
|
|
return GITHUB_USERS_GRANTED.includes(account.providerAccountId)
|
|
}
|
|
return false
|
|
},
|
|
},
|
|
})
|
|
} |