-
Notifications
You must be signed in to change notification settings - Fork 7
feat(user-api): User API — platform accounts & self-service API keys (backend) #2044
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 22 commits
Commits
Show all changes
66 commits
Select commit
Hold shift + click to select a range
ff45872
feat(user-api): scaffold user identity service with better-auth SIWE
brunod-e d9e042a
feat(user-api): user-scoped draft proposals behind SIWE sessions
brunod-e 562c6c6
feat(user-api): resolve better-auth instance from x-forwarded-host
brunod-e 52e20ab
chore: changeset for user-api service
brunod-e 83e8429
feat(user-api): add magic-link and Google sign-in (env-gated)
brunod-e c457bb2
chore(infra): add Railway build config for the user-api service
brunod-e 5aaa6ac
fix(user-api): resolve SIWE host from x-anticapture-host first
brunod-e 6fb93cf
docs(user-api): correct BETTER_AUTH_URL guidance + track .env.example
brunod-e bc8bc23
refactor(user-api): derive better-auth baseURL per host, drop BETTER_…
brunod-e bffe89e
feat(user-api): expose enabled sign-in methods at GET /auth/methods
brunod-e b1c8e28
feat(api)!: absorb the drafts cutover, scoped Authful provisioning an…
brunod-e c96bf63
feat(dashboard): platform accounts, drafts on the User API & API Keys…
brunod-e 9ca055d
fix(dashboard): gate the API Keys page behind sign-in instead of over…
brunod-e 940838f
fix(dashboard): tie wallet-born sessions to the wallet and harden the…
brunod-e 9e8168a
fix(dashboard): refresh the session store after SIWE verify and keep …
brunod-e 5ae02d7
fix(dashboard): route better-auth's self-generated URLs through the p…
brunod-e 27f94c9
fix(user-api): send magic links through an interstitial page, not the…
brunod-e bf0b0a6
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 9da635b
feat(dashboard): magic-link interstitial page at /auth/magic-link
brunod-e 28f7348
feat(dashboard): account chip for wallet-less platform sessions
brunod-e 0bb8e90
fix(user-api): address codex review — claim on every path, atomic quo…
brunod-e 163ca41
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 4a4590a
fix(dashboard): address codex + UI review on the accounts/API-keys su…
brunod-e 845d698
fix(user-api): require the JSON body on POST /me/api-keys
brunod-e 6e79415
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e f8e6390
fix(dashboard): point agent snippets at the MCP server's real /mcp path
brunod-e d6a1cc3
fix(authful): accept absent optional secrets under zod v4
brunod-e a3e39ec
revert(api): keep the DAO-API draft routes until the dashboard cutove…
brunod-e a57ef16
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e fe815fe
feat(api)!: retire the DAO-API draft routes now that the dashboard is…
brunod-e 851b35e
fix(dashboard): don't run SIWE sign-in when a signed-in user needs a …
brunod-e ffd990a
feat(user-api): sign-in from Vercel preview links (Railway PR envs only)
brunod-e 7aff9cc
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 75bf04b
feat(dashboard): one-click preview login button (server-advertised)
brunod-e d9b3e25
refactor(user-api): drop the preview test-credential login, keep dyna…
brunod-e 4c6a55e
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e d7fba83
refactor(dashboard): remove the preview-login button
brunod-e 459e10a
perf(dashboard): prefetch auth methods at mount, not on modal open
brunod-e 504f974
feat(user-api): copy provider profile onto the user on account link
brunod-e b8f794c
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 20f461b
refactor(user-api): apply /simplify review cleanups
brunod-e a86c302
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 2dbb9cc
refactor(dashboard): apply /simplify review cleanups
brunod-e 4fe0739
feat(dashboard): open api-keys page to signed-out users & design revi…
brunod-e d8eee2f
fix(dashboard): copy stays a labeled button, pinned flush to the corner
brunod-e 6a17ff9
fix(dashboard): overlap the copy button border with the code block's
brunod-e fb62a4b
fix(dashboard): use arbitrary-value negative inset for the copy button
brunod-e ae29065
refactor(dashboard): extract the CodeBlock design-system component
brunod-e 698268d
style(dashboard): align action popovers with the combobox dropdown
brunod-e 69cce1e
fix(dashboard): teach tailwind-merge the rounded-base token
brunod-e b9a3074
style(dashboard): square the connect-wallet chip (rounded-base)
brunod-e 5b1c3c3
fix: address codex and reviewer feedback on the user-api PR
brunod-e f3e1767
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 0ef8b50
fix(dashboard): address codex review on the accounts PR
brunod-e d39173e
chore: group public token metrics by single tenant
pikonha dd6bfb4
chore: remove ts ingore any
pikonha 244edbe
fix: address second codex round on the user-api PR
brunod-e 22d16c6
Merge branch 'feat/user-api' into feat/user-dashboard
brunod-e 476c726
fix(dashboard): revoking a key clears its session plaintext
brunod-e 64c7e7d
Merge remote-tracking branch 'origin/dev' into feat/user-api
brunod-e ed9ac55
feat(dashboard): integrate whitelabel support across authentication c…
brunod-e bd335b8
feat(draft-storage): implement excludePersistedDrafts to filter local…
brunod-e 2f9355d
Merge pull request #2051 from blockful/feat/user-dashboard
brunod-e 1c3db82
Merge branch 'feat/user-api' of https://github.com/blockful/anticaptu…
brunod-e 6b91739
fix: broken pnpm lock
brunod-e a6fdcb5
test(user-api): raise vitest hook/test timeouts for slow schema push
brunod-e File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| --- | ||
| "@anticapture/authful": patch | ||
| --- | ||
|
|
||
| Self-service (`user:*`) API keys: the internal token validation metric buckets the per-user tenant label as `user:*` so the Prometheus series set stays bounded, matching Gateful's usage metric. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| --- | ||
| "@anticapture/gateful": patch | ||
| --- | ||
|
|
||
| Self-service (`user:*`) API keys: usage metrics bucket the per-user tenant label as `user:*` so the Prometheus series set stays bounded, and cached positive token verdicts use a 30s TTL (instead of 300s) so a key revoked from the dashboard stops authenticating within seconds. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,4 @@ | ||
| --- | ||
| --- | ||
|
|
||
| chore: add a local dev-stack lane for the User API (`scripts/dev.sh`) + `pnpm user-api` root alias. Optional, mirroring Address Enrichment — runs via `railway run` when the service is available and exports `USER_API_URL` for the dashboard `/api/user` proxy; skipped otherwise so existing flows are unaffected. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| --- | ||
| "@anticapture/authful": minor | ||
| "@anticapture/user-api": minor | ||
| --- | ||
|
|
||
| Add self-service API keys (DEV-950). Authful gains an optional scoped provisioning key that may only mint/revoke `user:*` tenants and cannot list all tenants (the admin key stays unrestricted). The User API brokers end-user keys through it: `POST/GET/DELETE /me/api-keys` (session-authenticated) mint into Authful under tenant `user:<userId>`, return the plaintext exactly once, and store only ownership (never the secret) — with a per-user quota and Authful-first revocation. Both surfaces stay disabled until their env is configured. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| --- | ||
| "@anticapture/user-api": minor | ||
| --- | ||
|
|
||
| New user identity & session service (`apps/user-api`). Provides SIWE | ||
| authentication via better-auth (EOA + EIP-1271, per-host domain resolution for | ||
| whitelabel) and session-scoped draft proposals: identity comes from the | ||
| session cookie, drafts are keyed by user with a `daoId` filter, the share | ||
| endpoint is public with a server-derived `isOwner`, and migrated rows are | ||
| claimed on first sign-in. Reached only through the dashboard's `/api/user` | ||
| proxy, independent of Gateful. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.