own-stack
serverclient island
render: dynamic · session none

Sign in without a password.

Auth is the layer teams hand to a vendor first. Here it is one package we own, mounted in two lines, with no password table to leak.

How it is wired

One handler, two lines

@yannvr/auth speaks plain Request → Response, so Waku mounts it like any other file under src/pages/_api/. Storage is injected: this demo hands it a SQLite file through node:sqlite, which ships inside Node.

// src/pages/_api/api/auth/[...route].ts
import { auth } from '../../../../lib/auth';
export const POST = (request: Request) => auth.handleAuth(request);

One session read per request

React's cache() verifies the cookie once, however many components ask. Sign-out is a server function with the same guard as every other one: no session, nothing to do.

// src/lib/session.ts
export const getSession = cache(() => auth.readSession(requestHeaders()));

this page used to say auth was not wired. we had probed the wrong folder, then ported our own passkey package off Next.js. the account you make here is a throwaway: no email asked, nothing worth stealing

home