46 lines
2.4 KiB
Markdown
46 lines
2.4 KiB
Markdown
# AIRI Server Auth UI
|
|
|
|
Auth UI for the hosted AIRI server. It is a Vue/Vite app deployed separately from `server/apps/api` and used for Better Auth sign-in, email verification, password reset, profile, and Electron OIDC callback relay flows.
|
|
|
|
## Use When
|
|
|
|
- Building user-facing auth pages backed by server `/api/auth/*` endpoints.
|
|
- Updating login, sign-up, verification, reset-password, account profile, or Electron auth relay UX.
|
|
- Deploying the auth surface to Cloudflare Workers Static Assets.
|
|
|
|
## Do Not Use When
|
|
|
|
- Building the main stage app sign-in callback pages that consume OIDC tokens.
|
|
- Adding admin-only operational pages. Those belong in the standalone `proj-airi` admin repository.
|
|
|
|
## Commands
|
|
|
|
```sh
|
|
pnpm -F @proj-airi/ui-server-auth dev
|
|
pnpm -F @proj-airi/ui-server-auth typecheck
|
|
pnpm -F @proj-airi/ui-server-auth build
|
|
```
|
|
|
|
## Deployment
|
|
|
|
`pnpm -F @proj-airi/ui-server-auth build` writes to `apps/ui-server-auth/dist`. Vue Router owns `/ui/*`, while Vite assets are served from root `/assets-v2/*` so Cloudflare Pages can serve static files without rewriting nested asset paths. The versioned namespace moves existing clients away from previously poisoned `/assets/*` browser cache entries. Both namespaces use `Cache-Control: public, no-cache`, allowing browsers to retain files only when Pages revalidates them. `public/_redirects` scopes the SPA rewrite to `/ui/*`, and the top-level `public/404.html` keeps missing assets and other unknown paths as HTTP 404 responses.
|
|
|
|
The production GitHub Actions workflow deploys this app to the Cloudflare Pages project `moeru-ai-airi-auth` with separate auth-account credentials:
|
|
|
|
```sh
|
|
AUTH_CLOUDFLARE_ACCOUNT_ID=...
|
|
AUTH_CLOUDFLARE_API_TOKEN=...
|
|
```
|
|
|
|
`apps/ui-server-auth/wrangler.toml` remains available for Workers Static Assets deployments, but production CI uses Cloudflare Pages direct upload.
|
|
|
|
Production expects:
|
|
|
|
```sh
|
|
VITE_SERVER_URL=https://api.airi.build
|
|
```
|
|
|
|
The server redirects historical `/auth/*` URLs to `AUTH_UI_URL`, which defaults to `https://accounts.airi.build/ui`.
|
|
|
|
The `server-dev` workflow deploys a Cloudflare Pages branch build at `https://server-dev.airi-server-auth.pages.dev/ui/` with `VITE_SERVER_URL=https://airi-server-dev.up.railway.app`. Set the server-dev API environment variable `AUTH_UI_URL=https://server-dev.airi-server-auth.pages.dev/ui` when the full dev auth redirect chain should stay on server-dev.
|