@strav/jina
Headless authentication flows for the Strav framework. Registration, login, logout, password reset, email verification, two-factor authentication (TOTP), password confirmation, and profile updates — all as JSON API endpoints.
Install
bun add @strav/jina
bun strav install jina
Requires @strav/core as a peer dependency.
Setup
import { defineActions } from '@strav/jina'
import User from './models/user'
const actions = defineActions<User>({
async createUser(data) { return User.create(data) },
async findByEmail(email) { return User.query().where('email', email).first() },
async findById(id) { return User.find(id) },
passwordHashOf(user) { return user.password },
emailOf(user) { return user.email },
async updatePassword(user, pw) { user.password = pw; await user.save() },
})
import { JinaProvider } from '@strav/jina'
app.use(new JinaProvider(actions))
Routes
Routes are registered automatically:
| POST | /register | registration |
| POST | /login | login |
| POST | /logout | logout |
| POST | /forgot-password | password-reset |
| POST | /reset-password | password-reset |
| POST | /email/send | email-verification |
| GET | /email/verify/:token | email-verification |
| POST | /two-factor/enable | two-factor |
| POST | /two-factor/confirm | two-factor |
| DELETE | /two-factor | two-factor |
| POST | /two-factor/challenge | two-factor |
| POST | /confirm-password | password-confirmation |
| PUT | /password | update-password |
| PUT | /profile | update-profile |
Middleware
import { verified, confirmed, twoFactorChallenge } from '@strav/jina'
router.group({ middleware: [auth(), verified()] }, r => {
r.delete('/account', compose([confirmed()], deleteAccountHandler))
})
Documentation
See the full Jina guide.
License
MIT