trails/apps/journal/app/routes/auth.verify.server.ts
Ullrich Schäfer df562742e1
fix(journal): extract loaders/actions for the remaining 21 mixed routes
Completes the .server.ts split started in #418. Every route that mixes
a default-export component with a server-only loader/action now has a
sibling <route>.server.ts holding the data-fetching helpers; the route
.tsx is a thin delegator.

Routes converted (21):
  activities._index, activities.$id, activities.new, auth.accept-terms,
  auth.verify, explore, feed, notifications, routes._index, routes.$id,
  routes.$id.edit, routes.new, settings, settings.account,
  settings.connections.komoot, settings.profile, settings.security,
  sync.import.$provider, sync.import.komoot, users.$username.followers,
  users.$username.following

Pattern (same as home.tsx / users.$username.tsx / settings.connections.tsx):
- loader → `return data(await loadX(request, params?))`
- action → `return await xAction(request, params?)`
- All `getDb` / Drizzle schema / `~/lib/*.server` imports move to the
  .server.ts sibling.
- `throw redirect(...)` and `throw data(...)` propagate through the
  delegator unchanged.

No behavior changes — pure module-graph cleanup. Component modules no
longer transitively import the DB client; Vite's tree-shake of
server-only code is now backed by an explicit, file-local contract.

Verified:
- pnpm typecheck — green
- pnpm lint — green
- pnpm test — 181 passed, 31 integration-gated skipped
- pnpm --filter @trails-cool/journal build — succeeds

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 11:05:40 +02:00

35 lines
1.4 KiB
TypeScript

// Server-only loader for /auth/verify. See `home.server.ts` for the pattern.
import { redirect, data } from "react-router";
import { verifyMagicToken, verifyEmailChange } from "~/lib/auth.server";
import { requireSessionUser } from "~/lib/auth/session.server";
import { completeAuth } from "~/lib/auth/completion.server";
export async function loadAuthVerify(request: Request) {
const url = new URL(request.url);
const token = url.searchParams.get("token");
const isEmailChange = url.searchParams.get("email-change") === "1";
if (!token) {
return data({ error: "Missing token" }, { status: 400 });
}
try {
if (isEmailChange) {
const user = await requireSessionUser(request);
await verifyEmailChange(token, user.id);
return redirect("/settings/account");
}
const userId = await verifyMagicToken(token);
// Default destination after magic-link sign-in is "/?add-passkey=1"
// (prompt to set up a passkey now that they're in). If the link
// carried a returnTo, completeAuth's safeReturnTo will honor any
// same-origin path and otherwise fall back to "/" — handle the
// add-passkey default before delegating.
const returnTo = url.searchParams.get("returnTo") ?? "/?add-passkey=1";
return completeAuth({ userId, request, returnTo, mode: "redirect" });
} catch (e) {
return data({ error: (e as Error).message }, { status: 400 });
}
}