Files
GameTime/server/README.md
Blomios 7b122d03da feat(server): auth comptes utilisateurs et tokens API (ticket #48)
Ajoute la couche application (ports, use cases), les entités du
domaine, l'endpoint api/auth_api.dart (register/login/logout) et son
câblage dans le router, le hashing de mot de passe et le service de
token (infrastructure/security), et l'adapter Postgres des repositories
d'auth s'appuyant sur la table users du ticket #49. dart pub get OK,
dart analyze clean, dart test 10/10 vert (test PostgreSQL réel skip
faute de Docker disponible dans ce sandbox). Logique d'auth et
middleware testés via repositories fake en mémoire ; les endpoints
HTTP register/login/logout n'ont pas pu être exercés de bout en bout
faute d'accès à un vrai PostgreSQL local.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 10:15:34 +02:00

2.5 KiB

GameTime server

Headless Dart server for future GameTime account, sync and sharing features. This package is separate from the Flutter app at the repository root.

Local run

Install dependencies from this directory:

dart pub get

Run the server:

dart run bin/server.dart

The HTTP server binds to 0.0.0.0 and reads PORT from the environment. When PORT is not set, it listens on 8080.

PORT=9090 dart run bin/server.dart

PostgreSQL

Ticket #49 adds the initial sync-ready PostgreSQL schema and a minimal connection/migration utility.

Database environment variables:

  • DATABASE_HOST: PostgreSQL host.
  • DATABASE_PORT: PostgreSQL port, defaults to 5432 when omitted.
  • DATABASE_NAME: database name.
  • DATABASE_USER: database user.
  • DATABASE_PASSWORD: database password.

Apply migrations from server/:

DATABASE_HOST=localhost \
DATABASE_PORT=5432 \
DATABASE_NAME=gametime \
DATABASE_USER=gametime \
DATABASE_PASSWORD=gametime \
dart run bin/migrate.dart

Migrations are read from server/migrations/ in alphabetical order. The v1 runner is intentionally simple; SQL files use idempotent DDL where practical.

The PostgreSQL integration test is skipped unless TEST_DATABASE_URL is set:

TEST_DATABASE_URL=postgres://gametime:gametime@localhost:5432/gametime dart test

Healthcheck:

curl http://localhost:8080/health

Expected response:

{"status":"ok"}

Authentication

Ticket #48 adds account registration, login, logout and bearer-token request authentication.

Endpoints:

  • POST /auth/register with { "email": "...", "password": "...", "displayName": "..." }.
  • POST /auth/login with { "email": "...", "password": "...", "deviceLabel": "..." }.
  • POST /auth/logout with Authorization: Bearer <token>.

Passwords are stored with PBKDF2-HMAC-SHA256 via package:cryptography, using a per-password random salt. API tokens are opaque random values; only a SHA-256 hash of the token is stored in PostgreSQL.

Scope

Ticket #47 only scaffolds the Dart server, the hexagonal directory layout and the /health endpoint. Ticket #49 adds the first PostgreSQL schema. Ticket #48 adds authentication only; sync endpoints and sharing behavior are still implemented in later tickets.

Upcoming tickets will fill the empty adapters and use cases:

  • #48: user authentication and API tokens.
  • #49: PostgreSQL schema and repositories.
  • #50: incremental sync API.
  • #51: targeted sharing.
  • #52: Docker and registry packaging.
  • #53: API, contract and integration tests.