Add OAuth backend scaffold
This commit is contained in:
91
backend/README.md
Normal file
91
backend/README.md
Normal file
@@ -0,0 +1,91 @@
|
||||
# FeelAloud Backend
|
||||
|
||||
Backend for real accounts:
|
||||
|
||||
- E-Mail and password registration/login
|
||||
- Sign in with Apple ID-token verification
|
||||
- Google ID-token verification
|
||||
- JWT session tokens for the app
|
||||
- Premium entitlement storage prepared for App Store Server verification
|
||||
|
||||
## Setup
|
||||
|
||||
1. Install dependencies:
|
||||
|
||||
```bash
|
||||
npm install
|
||||
```
|
||||
|
||||
2. Create PostgreSQL database and enable UUID generation:
|
||||
|
||||
```sql
|
||||
create extension if not exists pgcrypto;
|
||||
```
|
||||
|
||||
3. Copy config:
|
||||
|
||||
```bash
|
||||
cp .env.example .env
|
||||
```
|
||||
|
||||
4. Fill `.env`:
|
||||
|
||||
- `JWT_SECRET`: at least 32 random characters
|
||||
- `APPLE_CLIENT_ID`: app bundle id, currently `de.feelaloud`
|
||||
- `GOOGLE_CLIENT_IDS`: Google OAuth iOS/Web client IDs, comma-separated
|
||||
|
||||
5. Initialize DB:
|
||||
|
||||
```bash
|
||||
npm run db:init
|
||||
```
|
||||
|
||||
6. Start local API:
|
||||
|
||||
```bash
|
||||
npm run dev
|
||||
```
|
||||
|
||||
## Endpoints
|
||||
|
||||
- `GET /health`
|
||||
- `POST /auth/email/register`
|
||||
- `POST /auth/email/login`
|
||||
- `POST /auth/email/change-password`
|
||||
- `POST /auth/apple`
|
||||
- `POST /auth/google`
|
||||
- `GET /me`
|
||||
- `GET /premium/status`
|
||||
- `POST /premium/app-store/transaction`
|
||||
|
||||
## iOS Configuration
|
||||
|
||||
In the app, set the backend URL in Settings -> Profil once that UI is wired, or set `authBackendURL` in `UserDefaults` during testing:
|
||||
|
||||
```swift
|
||||
UserDefaults.standard.set("http://localhost:8080", forKey: "authBackendURL")
|
||||
```
|
||||
|
||||
For local device testing use your Mac's LAN IP instead of `localhost`.
|
||||
|
||||
## Required Apple/Google Console Setup
|
||||
|
||||
Apple:
|
||||
|
||||
- Paid Apple Developer account
|
||||
- App capability: Sign in with Apple
|
||||
- Bundle ID: `de.feelaloud`
|
||||
- For server/web flows: Services ID and private key if you later exchange authorization codes server-side
|
||||
|
||||
Google:
|
||||
|
||||
- Google Cloud project
|
||||
- OAuth consent screen
|
||||
- iOS OAuth client for bundle ID `de.feelaloud`
|
||||
- Add the resulting client ID to `GOOGLE_CLIENT_IDS`
|
||||
|
||||
Premium:
|
||||
|
||||
- Digital premium features must stay on StoreKit/In-App Purchase.
|
||||
- PayPal is not the payment rail for iOS digital premium unlocks.
|
||||
- Server-side transaction verification can be completed with App Store Server API once App Store Connect keys are available.
|
||||
Reference in New Issue
Block a user