Class: Belt::CLI::AuthCommand
- Inherits:
-
Object
- Object
- Belt::CLI::AuthCommand
show all
- Includes:
- AppDetection
- Defined in:
- lib/belt/cli/auth_command.rb
Constant Summary
collapse
- TEMPLATE_DIR =
File.expand_path('../../templates/generate/auth', __dir__)
- MODULE_DIR =
'infrastructure/modules/app'
Class Method Summary
collapse
Instance Method Summary
collapse
#detect_app_name, #detect_environments, #detect_namespace, #find_contracts_file_path, #find_routes_file_path, #find_schema_file_path, #s3_safe_name
Constructor Details
#initialize(pools:, force: false, signup: false) ⇒ AuthCommand
Returns a new instance of AuthCommand.
89
90
91
92
93
94
95
|
# File 'lib/belt/cli/auth_command.rb', line 89
def initialize(pools:, force: false, signup: false)
@pool_names = pools
@force = force
@signup = signup
@app_name = detect_app_name
@pools = build_pool_metadata
end
|
Class Method Details
.destroy(_args) ⇒ Object
28
29
30
|
# File 'lib/belt/cli/auth_command.rb', line 28
def self.destroy(_args)
new(pools: [], force: false).remove
end
|
.parse_pools(args) ⇒ Object
Parse pool names from args. Default to ["main"] if none provided.
83
84
85
86
87
|
# File 'lib/belt/cli/auth_command.rb', line 83
def self.parse_pools(args)
names = args.reject { |a| a.start_with?('-') }
names = ['main'] if names.empty?
names.map(&:downcase).map { |n| n.gsub(/[^a-z0-9_]/, '_') }
end
|
.print_help ⇒ Object
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
|
# File 'lib/belt/cli/auth_command.rb', line 32
def self.print_help
puts <<~HELP
Generate Cognito user pool infrastructure for authentication.
Usage: belt generate auth [pool_names...] [options]
Options:
--signup Allow public user registration (generates frontend views)
--force, -f Overwrite existing cognito.tf (skip collision check)
Arguments:
pool_names Optional pool names for multiple user pools.
If omitted, generates a single pool named "main".
Examples:
belt g auth # Admin-only, single pool
belt g auth --signup # Public signup with frontend views
belt g auth web # Named pool: "web"
belt g auth web mobile # Two pools
belt g auth --force # Overwrite existing
What this generates:
infrastructure/modules/app/cognito.tf User pool + client resources
infrastructure/modules/app/cognito_outputs.tf Pool ID, ARN, and client ID outputs
With --signup (when frontend/ exists):
frontend/src/lib/auth.js Auth module (signIn, signUp, etc.)
frontend/src/lib/apiClient.js API client with Authorization header
frontend/src/pages/auth/Login.jsx Login page
frontend/src/pages/auth/SignUp.jsx Registration page
frontend/src/pages/auth/ConfirmEmail.jsx Email verification page
frontend/src/components/ProtectedRoute.jsx Route guard component
Without --signup (admin-only, default):
frontend/src/lib/auth.js Auth module (signIn only)
frontend/src/lib/apiClient.js API client with Authorization header
frontend/src/pages/auth/Login.jsx Login page
frontend/src/components/ProtectedRoute.jsx Route guard component
It also patches:
infrastructure/modules/app/main.tf Adds cognito_user_pool_arns to conveyor_belt
After running:
1. Review the generated Cognito config in cognito.tf
2. Add auth: :cognito to your routes namespace
3. Run `belt deploy` to create the user pool
4. Create your account (admin-only): aws cognito-idp admin-create-user ...
HELP
end
|
.run(args) ⇒ Object
15
16
17
18
19
20
21
22
23
24
25
26
|
# File 'lib/belt/cli/auth_command.rb', line 15
def self.run(args)
if args.include?('--help') || args.include?('-h')
print_help
exit 0
end
force = args.delete('--force') || args.delete('-f')
signup = args.delete('--signup')
pools = parse_pools(args)
new(pools: pools, force: force, signup: signup).generate
end
|
Instance Method Details
#generate ⇒ Object
97
98
99
100
101
102
103
104
105
106
107
108
109
|
# File 'lib/belt/cli/auth_command.rb', line 97
def generate
check_collision! unless @force
ensure_module_dir!
write_cognito_tf
write_cognito_outputs_tf
patch_main_tf
patch_env_outputs
generate_frontend_auth if frontend?
puts "\nā Auth generated!"
print_next_steps
end
|
#print_create_user_step(step_num) ⇒ Object
139
140
141
142
143
144
145
146
|
# File 'lib/belt/cli/auth_command.rb', line 139
def print_create_user_step(step_num)
puts " #{step_num}. Create your account:"
puts ' aws cognito-idp admin-create-user \\'
puts ' --user-pool-id <pool-id-from-terraform-output> \\'
puts ' --username your@email.com \\'
puts ' --temporary-password TempPass123 \\'
puts ' --message-action SUPPRESS'
end
|
#print_next_steps ⇒ Object
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
|
# File 'lib/belt/cli/auth_command.rb', line 111
def print_next_steps
puts "\nNext steps:"
puts ' 1. Add auth: :cognito to your routes namespace:'
puts ''
puts ' namespace :api, auth: :cognito do'
puts ' # your resources...'
puts ' end'
puts ''
if frontend?
puts ' 2. Wire auth into your frontend/src/App.jsx:'
puts ''
puts " import Login from './pages/auth/Login'"
puts " import ProtectedRoute from './components/ProtectedRoute'"
puts ''
puts ' // Add login route:'
puts ' <Route path="/login" element={<Login onLogin={() => window.location.href = \'/\'} />} />'
puts ''
puts ' // Wrap protected routes:'
puts ' <Route path="/*" element={<ProtectedRoute><YourApp /></ProtectedRoute>} />'
puts ''
puts ' 3. Deploy: belt deploy'
print_create_user_step(4) unless @signup
else
puts ' 2. Deploy: belt deploy'
print_create_user_step(3) unless @signup
end
end
|
#remove ⇒ Object
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
|
# File 'lib/belt/cli/auth_command.rb', line 148
def remove
removed = []
cognito_tf = File.join(MODULE_DIR, 'cognito.tf')
cognito_outputs_tf = File.join(MODULE_DIR, 'cognito_outputs.tf')
if File.exist?(cognito_tf)
FileUtils.rm(cognito_tf)
removed << cognito_tf
puts " remove #{cognito_tf}"
end
if File.exist?(cognito_outputs_tf)
FileUtils.rm(cognito_outputs_tf)
removed << cognito_outputs_tf
puts " remove #{cognito_outputs_tf}"
end
unpatch_main_tf
removed << File.join(MODULE_DIR, 'main.tf') if @main_tf_patched
if removed.empty?
puts ' Nothing to remove ā auth was not generated.'
else
puts "\nā Auth destroyed!"
end
end
|