Repository navigation
Feat/oauth endpoints - #56
Conversation
|
Warning Review limit reached
More reviews will be available in 49 minutes and 27 seconds. Learn how PR review limits work. To continue reviewing without waiting, enable usage-based billing in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses rolling per-developer review limits. Reviews become available again as older review attempts age out of the rolling limit window. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdds Google and GitHub OAuth social login via ChangesOAuth Social Login
Sequence Diagram(s)sequenceDiagram
participant Client
participant BetterAuth as better-auth (/api/auth/*)
participant OAuthCallback as oauthCallback (/api/v1/auth/oauth/callback)
participant GoogleGitHub as Google / GitHub
Client->>BetterAuth: GET /api/auth/signin/google (or github)
BetterAuth->>GoogleGitHub: OAuth redirect
GoogleGitHub-->>BetterAuth: Authorization code callback
BetterAuth-->>Client: Session cookie set, redirect to /api/v1/auth/oauth/callback
Client->>OAuthCallback: GET /callback (with session cookie)
OAuthCallback->>BetterAuth: getSession(fromNodeHeaders)
BetterAuth-->>OAuthCallback: session (user + username)
alt username is null (new user)
OAuthCallback-->>Client: redirect /onboarding
else username exists (returning user)
OAuthCallback-->>Client: redirect /dashboard
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/controllers/oauth.controller.ts`:
- Around line 16-18: The destination assignment in the oauth.controller.ts file
only checks if session.user.username is null, but this allows empty strings and
other falsy values to pass through and incorrectly redirect to the dashboard.
Replace the null-only check with a presence check that evaluates the truthiness
of session.user.username so that any missing, empty, or falsy username value
will correctly redirect to the onboarding flow instead of the dashboard.
In `@apps/api/src/lib/auth.ts`:
- Around line 17-25: The socialProviders object unconditionally includes google
and github providers even when their credentials (clientId and clientSecret)
might be empty strings from the config.oauth object. Implement validation to
check if the required credentials for each provider exist and are not empty
before including them in the socialProviders configuration. Only add the google
provider if both config.oauth.googleClientId and config.oauth.googleClientSecret
are present with non-empty values, and similarly for the github provider with
config.oauth.githubClientId and config.oauth.githubClientSecret. This ensures
misconfiguration is caught immediately at startup rather than at runtime during
login attempts.
In `@apps/api/src/lib/env.ts`:
- Around line 9-17: The oauth configuration properties (googleClientId,
googleClientSecret, githubClientId, githubClientSecret) and the frontend URL are
using default fallback values that mask missing environment variables, allowing
the service to boot with broken OAuth setup. Remove the empty string defaults
for all OAuth properties and remove the localhost fallback for the frontend URL,
then add validation logic that throws an error at startup if any of these
required environment variables (GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET,
GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, and FRONTEND_URL) are not provided. This
ensures the application fails fast with clear error messages rather than running
with incomplete configuration.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 56513e64-6ab7-4559-8399-042dc6cca3d6
📒 Files selected for processing (9)
apps/api/.env.exampleapps/api/src/controllers/oauth.controller.tsapps/api/src/lib/auth.tsapps/api/src/lib/env.tsapps/api/src/routes/index.tsapps/api/src/routes/user/oauth.routes.tspackages/db/prisma/migrations/20260623000000_oauth_schema/migration.sqlpackages/db/prisma/schema/auth.prismapackages/db/prisma/schema/user.prisma
📜 Review details
🧰 Additional context used
🪛 dotenv-linter (4.0.0)
apps/api/.env.example
[warning] 6-6: [UnorderedKey] The GOOGLE_CLIENT_ID key should go before the NODE_ENV key
(UnorderedKey)
[warning] 7-7: [UnorderedKey] The GOOGLE_CLIENT_SECRET key should go before the NODE_ENV key
(UnorderedKey)
[warning] 8-8: [UnorderedKey] The GITHUB_CLIENT_ID key should go before the GOOGLE_CLIENT_ID key
(UnorderedKey)
[warning] 9-9: [UnorderedKey] The GITHUB_CLIENT_SECRET key should go before the GOOGLE_CLIENT_ID key
(UnorderedKey)
[warning] 10-10: [UnorderedKey] The FRONTEND_URL key should go before the GITHUB_CLIENT_ID key
(UnorderedKey)
🔇 Additional comments (6)
packages/db/prisma/schema/auth.prisma (1)
33-39: LGTM!apps/api/src/routes/user/oauth.routes.ts (1)
1-8: LGTM!apps/api/src/routes/index.ts (1)
8-20: LGTM!packages/db/prisma/schema/user.prisma (1)
21-21: LGTM!packages/db/prisma/migrations/20260623000000_oauth_schema/migration.sql (1)
1-13: LGTM!apps/api/.env.example (1)
6-10: LGTM!
Basharkhan7776
left a comment
There was a problem hiding this comment.
Nice will test and change in testing
What's Changed
This PR introduces OAuth authentication support using Google and GitHub via
better-auth. It implements a redirect-based onboarding flow that directs new users to an onboarding screen, while returning users go straight to the dashboard.Closes #49
Key Implementation Details
1. Database Schema Updates
Accountmodel to camelCase (refreshToken,accessToken,expiresAt, etc.) to comply withbetter-authrequirements.usernamefield to theUsermodel. This acts as the primary indicator for whether a user has completed the onboarding flow.2. Authentication Configuration
src/lib/auth.ts.usernameunderuser.additionalFieldsin thebetter-authconfiguration to expose it on the session object.3. OAuth Routes & Controllers
better-auth's internal handlers at/api/auth/*insrc/routes/index.ts.GET /api/v1/auth/oauth/callback.oauthCallbackcontroller:auth.api.getSession.FRONTEND_URL/onboardingifusernameisnull(new user).FRONTEND_URL/dashboardifusernameis set (returning user).4. Environment Configuration
.env.exampleandsrc/lib/env.tswith OAuth credentials and frontend URL configurations:GOOGLE_CLIENT_ID&GOOGLE_CLIENT_SECRETGITHUB_CLIENT_ID&GITHUB_CLIENT_SECRETFRONTEND_URLSetup Instructions for Reviewers
.env.exampleto your.envfile and populate them with valid OAuth application credentials.bun run db:migrate.better-authendpoints (e.g.,http://localhost:3000/api/auth/callback/google).OAuth Authentication Implementation
usernamefield as the primary indicator for tracking onboarding completion status