Something went wrong. Try again.
An ATProto professional-networking prototype. Reuses Sifa and XPTracker lexicons rather than minting its own.
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839/** * LinkedAt has no working sign-in. * * The three /api/auth routes used to look functional: the callback validated * the OAuth state parameter and then set `linkedat_session=mock-session`, a * cookie no code ever read. Nothing was authenticated and nothing was * authorized, but the shape of the flow suggested otherwise. These routes now * return 501 so that is unambiguous. * * The pieces needed to finish this already exist and are tested: * * - `createAtprotoOAuthClient` / `startOAuthLogin` in * `packages/atproto/src/oauth/client.ts` build the authorization URL. * - `encryptSessionForStorage` / `decryptSessionFromStorage` in * `packages/atproto/src/oauth/session-store.ts` seal the session payload * with AES-256-GCM. * - `oauth_sessions` in `packages/db/src/schema.ts` is where sealed sessions * belong. * * What is missing is the exchange itself and a session store that survives a * process restart. `createAtprotoOAuthClient` currently uses in-memory state * and session stores, which cannot work on serverless (every invocation gets a * fresh module) and lose all sessions on restart anywhere else. Replacing those * two stores with `oauth_sessions`-backed implementations is the first task. * * See the Status section of README.md. */export const AUTH_NOT_IMPLEMENTED_MESSAGE = "ATProto OAuth is not implemented. LinkedAt cannot sign anyone in yet, so no " + "session is issued and no record can be written to a PDS. See the Status " + "section of README.md.";
export function authNotImplemented(): Response { return new Response(AUTH_NOT_IMPLEMENTED_MESSAGE, { status: 501, headers: { "Content-Type": "text/plain; charset=utf-8" } });}