Initial commit: Kalendartool (Next.js, Prisma, Docker)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Kühn
2026-10-08 14:38:04 +02:00
commit bc49c3074e
94 changed files with 12812 additions and 0 deletions

55
app/auth/hub/route.ts Normal file
View File

@@ -0,0 +1,55 @@
/**
* GET /auth/hub?token=... – SSO-Einstiegspunkt der MultiToolApp-Plattform.
*
* Ablauf (platform-plan.md §5.2):
* 1. Hub-Token validieren (RS256 via JWKS vom Hub, aud = HUB_TOOL_SLUG)
* 2. JIT-Provisioning (Account an hubId koppeln oder anlegen)
* 3. Eigene Session setzen (bewährtes calendar_session-Cookie)
* 4. Redirect auf das Kalender-Dashboard
*
* Fehler → Redirect auf /login mit ?hubError=... (keine Details im Query,
* nur grober Code; Details stehen im Server-Log).
*/
import { NextRequest, NextResponse } from "next/server";
import { verifyHubToken } from "@/lib/auth/hub";
import { provisionHubUser } from "@/lib/auth/hub-provisioning";
import { createSessionToken, setSessionCookie } from "@/lib/auth/session";
/** basePath der App (Proxy-Modus) – Redirect-Ziele müssen darunter liegen. */
function getBasePath(): string {
return (process.env.HUB_BASE_PATH ?? "").replace(/\/$/, "");
}
export async function GET(request: NextRequest) {
const basePath = getBasePath();
const loginUrl = new URL(`${basePath}/login`, request.url);
try {
const token = request.nextUrl.searchParams.get("token");
if (!token) {
loginUrl.searchParams.set("hubError", "missing_token");
return NextResponse.redirect(loginUrl);
}
// 1. Token validieren (Signatur/TTL/aud/iss)
const identity = await verifyHubToken(token);
// 2. JIT-Provisioning
const user = await provisionHubUser(identity);
// 3. Eigene Session setzen
const sessionToken = await createSessionToken({
id: user.id,
email: user.email,
role: user.role,
});
await setSessionCookie(sessionToken);
// 4. Weiter ins Tool (basePath-kompatibel)
return NextResponse.redirect(new URL(`${basePath}/`, request.url));
} catch (error) {
console.error("Hub-SSO fehlgeschlagen:", error);
loginUrl.searchParams.set("hubError", "invalid_token");
return NextResponse.redirect(loginUrl);
}
}