// /api/v1/auth — the authentication surface, assembled from per-capability // routers. // // This file owns the mount table and nothing else; no route is declared here. // Each capability router mounts at the prefix it already owned inside the old // monolithic auth.routes.js, so the emitted URL set is byte-identical — proved by // a zero-line diff in server/routes.manifest.json (`npm run routes:manifest`). // // **There is deliberately no group gate.** /auth is where an anonymous caller // becomes authenticated, so most of it must stay reachable logged-out. The // authenticated parts gate themselves: meRouter and notifRouter each apply // `noindex, requireAuth` at their own router level, and /sso/:provider/link // carries requireAuth per route. // // **Mount order is load-bearing** — see the two notes inline below. // // See docs/website/API_V2_PLAN.md § Phase 2 for the split. const express = require('express') const mobileRouter = require('./mobile.routes') const ssoRouter = require('./sso.routes') const meRouter = require('./me.routes') const notifRouter = require('./notifications.routes') const loginRouter = require('./login.router') const registerRouter = require('./register.router') const inviteRouter = require('./invite.router') const passwordRouter = require('./password.router') const sessionRouter = require('./session.router') const authRouter = express.Router() // Native/Android bearer-token auth. Additive alongside the web cookie flow below. authRouter.use('/mobile', mobileRouter) // SSO discovery + OAuth redirect flow. Mounted **pathless** because it owns two // prefixes (/auth/providers and /auth/sso/*); it declares no router-level // middleware, so passing through it is a no-op for every other route. authRouter.use(ssoRouter) // Role-agnostic self-service ("me") — /auth/me/account*, reusing the same // account.controller handlers as /player/account/* and /admin/account/* behind // requireAuth (any role). Additive; gives the app one self surface that never // touches /admin. authRouter.use('/me', meRouter) // Push-notification self-service — /auth/me/devices*, /auth/me/notifications/*. // A second sub-router at /me (Express allows multiple), same requireAuth gate, // keeping the notification surface separate from the account/identity handlers. authRouter.use('/me', notifRouter) // Credential surfaces, each at the prefix it owns. authRouter.use('/login', loginRouter) authRouter.use('/register', registerRouter) authRouter.use('/invite', inviteRouter) authRouter.use('/password', passwordRouter) // The two singletons that own no path segment of their own: POST /logout and // GET /me. Mounted at the group root and **last**, because `use('/me', …)` above // matches the bare path /me too: GET /auth/me runs meRouter's and notifRouter's // `noindex, requireAuth`, matches no route inside either, and falls through to // here. Mounting this ahead of them would drop the X-Robots-Tag header they set. // Safe at the root only because session.router.js declares no router-level // middleware (see the note in that file). authRouter.use('/', sessionRouter) module.exports = authRouter