All checks were successful
continuous-integration/drone/tag Build is passing
# Merge Request: Auth / Author Flow Hardening and Client Separation ## Summary This change set improves the authentication–author lifecycle by clearly separating **Auth** and **Blog API** clients, ensuring an **Author is created at registration time**, and preventing user-controlled mutation of immutable identity fields in the UI. The result is a cleaner contract between services, fewer edge cases around missing authors, and more predictable client behavior. --- ## Key Changes ### 1. Username Made Read-Only in Profile UI - Disabled the `username` field in `Profile.tsx` - Prevents accidental or malicious mutation of identity-bound fields - Aligns UI behavior with backend ownership rules --- ### 2. Dedicated Auth vs Blog API Clients - Introduced a separate Axios client for the Auth service (`auth`) - Blog service continues to use `api` - Both clients: - Automatically attach JWT tokens - Share centralized `401` handling and token invalidation logic **Why:** Auth and Blog are separate concerns and potentially separate services. Explicit clients reduce coupling and eliminate ambiguous routing. --- ### 3. Registration Flow Now Creates Author Automatically - `register()` now: 1. Registers the user via Auth service 2. Creates a corresponding Author via Blog API This guarantees: - Every authenticated user has an Author record - No race condition or implicit author creation later --- ### 4. Correct Endpoint Usage for “Current User” - `/auth/me` is now correctly called via the Auth client - `/authors/me` replaces ID-based lookup for the current author - Eliminates dependency on user ID leaking across service boundaries --- ### 5. Centralized Token & Auth Error Handling - Shared request interceptor to attach JWT tokens - Shared response interceptor to handle `401` consistently - Token invalidation is now uniform across services --- ### 6. Environment Configuration Updated - Added `VITE_AUTH_BASE_URL` to support separate Auth service routing - Explicit environment contract avoids accidental misconfiguration --- ## Impact - Cleaner service boundaries - Deterministic user → author lifecycle - Reduced client-side complexity and edge cases - More secure handling of identity fields --- ## Notes / Follow-ups - Optional auto-login after registration is scaffolded but commented - Logout or redirect handling on `401` can be wired later via an event bus or global handler --- **Risk Level:** Low **Behavioral Change:** Yes (author auto-created on registration) **Backward Compatibility:** Requires Auth + Blog services to be reachable separately Reviewed-on: #1 Co-authored-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com> Co-committed-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
141 lines
3.9 KiB
YAML
141 lines
3.9 KiB
YAML
---
|
|
kind: pipeline
|
|
type: docker
|
|
name: default
|
|
|
|
platform:
|
|
os: linux
|
|
arch: arm64
|
|
|
|
workspace:
|
|
path: /drone/src
|
|
|
|
volumes:
|
|
- name: dockersock
|
|
host:
|
|
path: /var/run/docker.sock
|
|
|
|
steps:
|
|
- name: fetch-tags
|
|
image: docker:24
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- apk add --no-cache git
|
|
- git fetch --tags
|
|
- |
|
|
# Get latest Git tag and trim newline
|
|
LATEST_TAG=$(git describe --tags --abbrev=0 2>/dev/null | tr -d '\n')
|
|
echo "Latest Git tag fetched: $LATEST_TAG"
|
|
|
|
# Save to file for downstream steps
|
|
echo "$LATEST_TAG" > /drone/src/LATEST_TAG.txt
|
|
|
|
# Read back for verification
|
|
IMAGE_TAG=$(cat /drone/src/LATEST_TAG.txt | tr -d '\n')
|
|
echo "Image tag read from file: $IMAGE_TAG"
|
|
|
|
# Validate
|
|
if [ -z "$IMAGE_TAG" ]; then
|
|
echo "❌ No git tags found! Cannot continue."
|
|
exit 1
|
|
fi
|
|
|
|
- name: check-remote-image
|
|
image: docker:24
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- IMAGE_TAG=$(cat /drone/src/LATEST_TAG.txt | tr -d '\n')
|
|
|
|
- echo "Checking if apps/blog:$IMAGE_TAG exists on remote Docker..."
|
|
- echo "Existing Docker tags for apps/blog:"
|
|
- docker images --format "{{.Repository}}:{{.Tag}}" | grep "^apps/blog" || echo "(none)"
|
|
- |
|
|
if docker image inspect apps/blog:$IMAGE_TAG > /dev/null 2>&1; then
|
|
echo "✅ Docker image apps/blog:$IMAGE_TAG already exists — skipping build"
|
|
exit 78
|
|
else
|
|
echo "⚙️ Docker image apps/blog:$IMAGE_TAG not found — proceeding to build..."
|
|
fi
|
|
|
|
- name: build-image
|
|
image: docker:24
|
|
environment:
|
|
API_BASE_URL:
|
|
from_secret: API_BASE_URL
|
|
AUTH_BASE_URL:
|
|
from_secret: AUTH_BASE_URL
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- IMAGE_TAG=$(cat /drone/src/LATEST_TAG.txt | tr -d '\n')
|
|
|
|
- echo "🔨 Building Docker image apps/blog:$IMAGE_TAG ..."
|
|
- |
|
|
docker build --network=host \
|
|
--build-arg VITE_API_BASE_URL="$API_BASE_URL" \
|
|
--build-arg VITE_AUTH_BASE_URL="$AUTH_BASE_URL" \
|
|
-t apps/blog:$IMAGE_TAG \
|
|
-t apps/blog:latest \
|
|
/drone/src
|
|
|
|
- name: push-image
|
|
image: docker:24
|
|
environment:
|
|
REGISTRY_HOST:
|
|
from_secret: REGISTRY_HOST
|
|
REGISTRY_USER:
|
|
from_secret: REGISTRY_USER
|
|
REGISTRY_PASS:
|
|
from_secret: REGISTRY_PASS
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- IMAGE_TAG=$(cat /drone/src/LATEST_TAG.txt | tr -d '\n')
|
|
|
|
- echo "🔑 Logging into registry $REGISTRY_HOST ..."
|
|
- echo "$REGISTRY_PASS" | docker login $REGISTRY_HOST -u "$REGISTRY_USER" --password-stdin
|
|
- echo "🏷️ Tagging images with registry prefix..."
|
|
- docker tag apps/blog:$IMAGE_TAG $REGISTRY_HOST/apps/blog:$IMAGE_TAG
|
|
- docker tag apps/blog:$IMAGE_TAG $REGISTRY_HOST/apps/blog:latest
|
|
- echo "📤 Pushing apps/blog:$IMAGE_TAG ..."
|
|
- docker push $REGISTRY_HOST/apps/blog:$IMAGE_TAG
|
|
- echo "📤 Pushing apps/blog:latest ..."
|
|
- docker push $REGISTRY_HOST/apps/blog:latest
|
|
|
|
- name: stop-old
|
|
image: docker:24
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- echo "🛑 Stopping old container..."
|
|
- docker rm -f blog || true
|
|
|
|
- name: run-container
|
|
image: docker:24
|
|
volumes:
|
|
- name: dockersock
|
|
path: /var/run/docker.sock
|
|
commands:
|
|
- IMAGE_TAG=$(cat /drone/src/LATEST_TAG.txt | tr -d '\n')
|
|
|
|
- echo "🚀 Starting container apps/blog:$IMAGE_TAG ..."
|
|
- |
|
|
docker run -d \
|
|
--name blog \
|
|
-p 3002:3000 \
|
|
-e NODE_ENV=production \
|
|
--restart always \
|
|
apps/blog:$IMAGE_TAG
|
|
|
|
# Trigger rules
|
|
trigger:
|
|
event:
|
|
- tag
|