feat(auth): add user authentication with roles, HMAC-signed cookies, and login/register UI

- Add `users` PocketBase collection (username, password_hash, role, created)
- Implement HMAC-SHA256 signed cookie auth in hooks.server.ts; token payload is userId:username:role
- Add User type, getUserByUsername, createUser (scrypt), loginUser (timing-safe) to pocketbase.ts
- Add login/register page with tabbed form UI and server actions
- Add logout route that clears the auth cookie
- Add layout.server.ts auth guard: redirect unauthenticated users to /login
- Extend App.Locals and App.PageData with role field
- Add AUTH_SECRET, POCKETBASE_ADMIN_EMAIL/PASSWORD to .env.example
- Install @types/node for Node crypto/scrypt types
This commit is contained in:
Admin
2026-03-03 14:03:11 +05:00
parent 1820fa7303
commit 3c26dfe2c0
11 changed files with 441 additions and 5 deletions

5
ui/src/app.d.ts vendored
View File

@@ -5,8 +5,11 @@ declare global {
// interface Error {}
interface Locals {
sessionId: string;
user: { id: string; username: string; role: string } | null;
}
interface PageData {
user?: { id: string; username: string; role: string } | null;
}
// interface PageData {}
// interface PageState {}
// interface Platform {}
}