- Add `users` PocketBase collection (username, password_hash, role, created) - Implement HMAC-SHA256 signed cookie auth in hooks.server.ts; token payload is userId:username:role - Add User type, getUserByUsername, createUser (scrypt), loginUser (timing-safe) to pocketbase.ts - Add login/register page with tabbed form UI and server actions - Add logout route that clears the auth cookie - Add layout.server.ts auth guard: redirect unauthenticated users to /login - Extend App.Locals and App.PageData with role field - Add AUTH_SECRET, POCKETBASE_ADMIN_EMAIL/PASSWORD to .env.example - Install @types/node for Node crypto/scrypt types
16 lines
383 B
TypeScript
16 lines
383 B
TypeScript
import { redirect } from '@sveltejs/kit';
|
|
import type { LayoutServerLoad } from './$types';
|
|
|
|
// Routes that are accessible without being logged in
|
|
const PUBLIC_ROUTES = new Set(['/login']);
|
|
|
|
export const load: LayoutServerLoad = async ({ locals, url }) => {
|
|
if (!PUBLIC_ROUTES.has(url.pathname) && !locals.user) {
|
|
redirect(302, `/login`);
|
|
}
|
|
|
|
return {
|
|
user: locals.user
|
|
};
|
|
};
|