## Summary - Replace Redis command fakes with `ioredis-mock` in API tests. - Run the production Lua scripts through `EVAL`. - Keep Redis behavior tests on the same command and Pub/Sub implementation used by production code. ## Stack - This PR is the base for #2289. - It replaces #2291 as the merge-to-`main` unit. #2291 merged into the old ConfigKV branch before the stack could be reordered. ## Tests - `pnpm install --frozen-lockfile --offline --ignore-scripts` - `pnpm exec vitest run <6 changed API test files>` (73 tests passed) - `pnpm exec eslint <7 changed API TypeScript files>` - `git diff --check` ## Visual changes None. This PR changes test infrastructure only. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added isolated in-memory Redis support for automated testing. * Updated billing, Stripe, flux, concurrency, and user-deletion tests to use a shared Redis test setup. * Improved verification of Redis operations while preserving existing test coverage and expected outcomes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: RainbowBird <rbxin2003@outlook.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
@proj-airi/api-server
Project AIRI's resource API. Authentication is a separate workspace app at
server/apps/auth; this package does not instantiate Better Auth or expose
auth/OIDC routes.
Responsibilities
- Hono business APIs and WebSocket endpoints.
- Characters, chats, providers, Flux, Stripe, model routing, and billing.
- PostgreSQL migration ownership for the currently shared database.
- Redis cache, configuration KV, and cross-instance Pub/Sub.
- Local verification of Auth-issued OIDC JWTs through public JWKS.
Run locally
pnpm -F @proj-airi/api-server dev
pnpm -F @proj-airi/api-server typecheck
pnpm -F @proj-airi/api-server exec vitest run
pnpm -F @proj-airi/api-server build
Run the complete local backend from the repository root:
pnpm dev:backend
For source-level debugging, start @proj-airi/api-server and
@proj-airi/auth-server separately instead.
server/docker-compose.yaml exposes the local Caddy gateway at http://localhost:6112 and keeps
the API and Auth container ports private.
Service boundaries
AUTH_SERVER_URLis Auth's canonical public issuer origin used for JWKS, issuer, and audience validation. It must exactly equal Auth'sPUBLIC_URL./internal/auth/*is reachable only on the deployment's trusted private network. The public edge must reject/internal/*and the API service must not have its own public ingress.AUTH_SERVER_INTERNAL_URLoptionally sends JWKS fetches directly to Auth on the private network while issuer and audience remainAUTH_SERVER_URL.- Auth tables and principal types come from
@proj-airi/auth-shared; no module underserver/apps/authis imported.
Railway
Deploy this as the Resource API Railway service with Config File Path
/server/apps/api/railway.toml; keep the service Root Directory at the
repository root because the Dockerfile copies shared workspace packages. The
config owns its Dockerfile, start command, /readyz healthcheck, and the
watch patterns for every copied build input.
Set AUTH_SERVER_INTERNAL_URL from Auth's Railway private domain. It is only
the private JWKS route; AUTH_SERVER_URL remains the public Auth issuer URL.
See server/README.md for the complete
cross-service variable and migration contract.