logicsrc/apps/logicsrc-web/src/app/api/oauth/coinpay/start/route.ts
Anthony Ettinger f0a9f3890e Migrate logicsrc-web from Vite SPA to Next.js 16 App Router
Replaces the Vite single-page app + custom Node server.js with a Next.js
16.2.6 App Router app.

- proxy.ts (src/proxy.ts): www.logicsrc.com -> logicsrc.com 301 over https,
  preserving path + query (the original request, now via Next 16 Proxy).
- One SSR page via an optional catch-all ([[...slug]]) that renders the same
  marketing/spec page for each known top-level route (/docs, /blog, /openspec,
  ...) and 404s unknown paths, preserving existing canonical URLs. Markup is a
  faithful server-rendered port of the old main.ts (SEO upgrade over the prior
  client render); interactivity (hire-us form, CoinPay button, section scroll)
  moves to a client component.
- API routes ported to app/api/**: hire-us coinpay-checkout + project-request,
  oauth/coinpay start/callback/session, webhooks/coinpay. Shared logic in
  src/lib/coinpay.ts (eligibility, payment-rail selection, webhook verify,
  HMAC session sign/verify, cookies).
- commandboard-api (/health + /api/boards|tasks|plugins/*) is no longer mounted
  in-process; next.config.ts proxies those paths to COMMANDBOARD_API_URL via
  afterFiles rewrites (our own /api routes match first).
- Build/start switch to next build / next start. Contract tests rewritten to
  exercise proxy.ts, the route handlers, and pure helpers directly (21 passing);
  Playwright webServer updated.

Deployment (Railway): set COMMANDBOARD_API_URL to the commandboard-api service
URL and run it as its own service; root start now runs next start.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 03:41:48 +00:00

34 lines
1.2 KiB
TypeScript

import { NextResponse } from "next/server";
import { randomBytes } from "node:crypto";
import { json } from "@/lib/http";
import { COINPAY_OAUTH_STATE_COOKIE, getCoinPayOAuthConfig, serializeCookie } from "@/lib/coinpay";
export const dynamic = "force-dynamic";
// GET /api/oauth/coinpay/start — begin CoinPay OAuth: set a signed state cookie
// and redirect to the provider's authorize endpoint.
export async function GET() {
const config = getCoinPayOAuthConfig();
if (!config) {
return json({ success: false, error: "CoinPay OAuth is not configured" }, 503);
}
const state = randomBytes(16).toString("hex");
const authorizeUrl = new URL("/api/oauth/authorize", config.issuer);
authorizeUrl.searchParams.set("response_type", "code");
authorizeUrl.searchParams.set("client_id", config.clientId);
authorizeUrl.searchParams.set("redirect_uri", config.redirectUri);
authorizeUrl.searchParams.set("scope", config.scopes);
authorizeUrl.searchParams.set("state", state);
return new NextResponse(null, {
status: 302,
headers: {
location: authorizeUrl.toString(),
"set-cookie": serializeCookie(COINPAY_OAUTH_STATE_COOKIE, state, {
maxAge: 600,
path: "/api/oauth/coinpay"
})
}
});
}