Initial, working login and logout with spotify

This commit is contained in:
Pablu23
2025-09-02 14:20:05 +02:00
commit 24b4647ab3
33 changed files with 5919 additions and 0 deletions

2
.env.example Normal file
View File

@@ -0,0 +1,2 @@
DATABASE_URL=local.db
PUBLIC_CLIENT_ID=ABCD

26
.gitignore vendored Normal file
View File

@@ -0,0 +1,26 @@
node_modules
# Output
.output
.vercel
.netlify
.wrangler
/.svelte-kit
/build
# OS
.DS_Store
Thumbs.db
# Env
.env
.env.*
!.env.example
!.env.test
# Vite
vite.config.js.timestamp-*
vite.config.ts.timestamp-*
# SQLite
*.db

1
.npmrc Normal file
View File

@@ -0,0 +1 @@
engine-strict=true

10
.prettierignore Normal file
View File

@@ -0,0 +1,10 @@
# Package Managers
package-lock.json
pnpm-lock.yaml
yarn.lock
bun.lock
bun.lockb
# Miscellaneous
/static/
/drizzle/

15
.prettierrc Normal file
View File

@@ -0,0 +1,15 @@
{
"useTabs": true,
"singleQuote": true,
"trailingComma": "none",
"printWidth": 100,
"plugins": ["prettier-plugin-svelte"],
"overrides": [
{
"files": "*.svelte",
"options": {
"parser": "svelte"
}
}
]
}

38
README.md Normal file
View File

@@ -0,0 +1,38 @@
# sv
Everything you need to build a Svelte project, powered by [`sv`](https://github.com/sveltejs/cli).
## Creating a project
If you're seeing this, you've probably already done this step. Congrats!
```sh
# create a new project in the current directory
npx sv create
# create a new project in my-app
npx sv create my-app
```
## Developing
Once you've created a project and installed dependencies with `npm install` (or `pnpm install` or `yarn`), start a development server:
```sh
npm run dev
# or start the server and open the app in a new browser tab
npm run dev -- --open
```
## Building
To create a production version of your app:
```sh
npm run build
```
You can preview the production build with `npm run preview`.
> To deploy your app, you may need to install an [adapter](https://svelte.dev/docs/kit/adapters) for your target environment.

11
drizzle.config.ts Normal file
View File

@@ -0,0 +1,11 @@
import { defineConfig } from 'drizzle-kit';
if (!process.env.DATABASE_URL) throw new Error('DATABASE_URL is not set');
export default defineConfig({
schema: './src/lib/server/db/schema.ts',
dialect: 'sqlite',
dbCredentials: { url: process.env.DATABASE_URL },
verbose: true,
strict: true
});

40
eslint.config.js Normal file
View File

@@ -0,0 +1,40 @@
import prettier from 'eslint-config-prettier';
import { includeIgnoreFile } from '@eslint/compat';
import js from '@eslint/js';
import svelte from 'eslint-plugin-svelte';
import globals from 'globals';
import { fileURLToPath } from 'node:url';
import ts from 'typescript-eslint';
import svelteConfig from './svelte.config.js';
const gitignorePath = fileURLToPath(new URL('./.gitignore', import.meta.url));
export default ts.config(
includeIgnoreFile(gitignorePath),
js.configs.recommended,
...ts.configs.recommended,
...svelte.configs.recommended,
prettier,
...svelte.configs.prettier,
{
languageOptions: {
globals: { ...globals.browser, ...globals.node }
},
rules: {
// typescript-eslint strongly recommend that you do not use the no-undef lint rule on TypeScript projects.
// see: https://typescript-eslint.io/troubleshooting/faqs/eslint/#i-get-errors-from-the-no-undef-rule-about-global-variables-not-being-defined-even-though-there-are-no-typescript-errors
'no-undef': 'off'
}
},
{
files: ['**/*.svelte', '**/*.svelte.ts', '**/*.svelte.js'],
languageOptions: {
parserOptions: {
projectService: true,
extraFileExtensions: ['.svelte'],
parser: ts.parser,
svelteConfig
}
}
}
);

5259
package-lock.json generated Normal file

File diff suppressed because it is too large Load Diff

45
package.json Normal file
View File

@@ -0,0 +1,45 @@
{
"name": "hitstar",
"private": true,
"version": "0.0.1",
"type": "module",
"scripts": {
"dev": "vite dev",
"build": "vite build",
"preview": "vite preview",
"prepare": "svelte-kit sync || echo ''",
"check": "svelte-kit sync && svelte-check --tsconfig ./tsconfig.json",
"check:watch": "svelte-kit sync && svelte-check --tsconfig ./tsconfig.json --watch",
"format": "prettier --write .",
"lint": "prettier --check . && eslint .",
"db:push": "drizzle-kit push",
"db:generate": "drizzle-kit generate",
"db:migrate": "drizzle-kit migrate",
"db:studio": "drizzle-kit studio"
},
"devDependencies": {
"@eslint/compat": "^1.2.5",
"@eslint/js": "^9.18.0",
"@sveltejs/adapter-node": "^5.2.12",
"@sveltejs/kit": "^2.22.0",
"@sveltejs/vite-plugin-svelte": "^6.0.0",
"@types/better-sqlite3": "^7.6.12",
"@types/node": "^22",
"drizzle-kit": "^0.30.2",
"eslint": "^9.18.0",
"eslint-config-prettier": "^10.0.1",
"eslint-plugin-svelte": "^3.0.0",
"globals": "^16.0.0",
"prettier": "^3.4.2",
"prettier-plugin-svelte": "^3.3.3",
"svelte": "^5.0.0",
"svelte-check": "^4.0.0",
"typescript": "^5.0.0",
"typescript-eslint": "^8.20.0",
"vite": "^7.0.4"
},
"dependencies": {
"better-sqlite3": "^11.8.0",
"drizzle-orm": "^0.40.0"
}
}

21
src/app.d.ts vendored Normal file
View File

@@ -0,0 +1,21 @@
// See https://svelte.dev/docs/kit/types#app.d.ts
// for information about these interfaces
declare global {
namespace App {
// interface Error {}
interface Locals {
user: {
isLoggedIn: boolean;
email: string | undefined;
username: string | undefined | null;
}
}
// interface PageData {}
// interface PageState {}
// interface Platform {}
}
}
export { };

11
src/app.html Normal file
View File

@@ -0,0 +1,11 @@
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
%sveltekit.head%
</head>
<body data-sveltekit-preload-data="hover">
<div style="display: contents">%sveltekit.body%</div>
</body>
</html>

34
src/hooks.server.ts Normal file
View File

@@ -0,0 +1,34 @@
import { db } from '$lib/server/db';
import { sessionsTable, usersTable } from '$lib/server/db/schema';
import { eq } from 'drizzle-orm';
import type { Handle } from '@sveltejs/kit';
export const handle: Handle = async ({ event, resolve }) => {
const sessionId = event.cookies.get('session_id');
let user = {
isLoggedIn: false,
email: "",
username: ""
};
if (sessionId) {
const session = await db.query.sessionsTable.findFirst({
with: {
user: true
},
where: eq(sessionsTable.id, sessionId)
});
if (session && session.user && session.user.email) {
user = {
isLoggedIn: true,
email: session.user.email,
username: session.user.username || "Unknown username"
};
}
}
event.locals.user = user;
const response = await resolve(event);
return response;
}

View File

@@ -0,0 +1 @@
<svg xmlns="http://www.w3.org/2000/svg" width="107" height="128" viewBox="0 0 107 128"><title>svelte-logo</title><path d="M94.157 22.819c-10.4-14.885-30.94-19.297-45.792-9.835L22.282 29.608A29.92 29.92 0 0 0 8.764 49.65a31.5 31.5 0 0 0 3.108 20.231 30 30 0 0 0-4.477 11.183 31.9 31.9 0 0 0 5.448 24.116c10.402 14.887 30.942 19.297 45.791 9.835l26.083-16.624A29.92 29.92 0 0 0 98.235 78.35a31.53 31.53 0 0 0-3.105-20.232 30 30 0 0 0 4.474-11.182 31.88 31.88 0 0 0-5.447-24.116" style="fill:#ff3e00"/><path d="M45.817 106.582a20.72 20.72 0 0 1-22.237-8.243 19.17 19.17 0 0 1-3.277-14.503 18 18 0 0 1 .624-2.435l.49-1.498 1.337.981a33.6 33.6 0 0 0 10.203 5.098l.97.294-.09.968a5.85 5.85 0 0 0 1.052 3.878 6.24 6.24 0 0 0 6.695 2.485 5.8 5.8 0 0 0 1.603-.704L69.27 76.28a5.43 5.43 0 0 0 2.45-3.631 5.8 5.8 0 0 0-.987-4.371 6.24 6.24 0 0 0-6.698-2.487 5.7 5.7 0 0 0-1.6.704l-9.953 6.345a19 19 0 0 1-5.296 2.326 20.72 20.72 0 0 1-22.237-8.243 19.17 19.17 0 0 1-3.277-14.502 17.99 17.99 0 0 1 8.13-12.052l26.081-16.623a19 19 0 0 1 5.3-2.329 20.72 20.72 0 0 1 22.237 8.243 19.17 19.17 0 0 1 3.277 14.503 18 18 0 0 1-.624 2.435l-.49 1.498-1.337-.98a33.6 33.6 0 0 0-10.203-5.1l-.97-.294.09-.968a5.86 5.86 0 0 0-1.052-3.878 6.24 6.24 0 0 0-6.696-2.485 5.8 5.8 0 0 0-1.602.704L37.73 51.72a5.42 5.42 0 0 0-2.449 3.63 5.79 5.79 0 0 0 .986 4.372 6.24 6.24 0 0 0 6.698 2.486 5.8 5.8 0 0 0 1.602-.704l9.952-6.342a19 19 0 0 1 5.295-2.328 20.72 20.72 0 0 1 22.237 8.242 19.17 19.17 0 0 1 3.277 14.503 18 18 0 0 1-8.13 12.053l-26.081 16.622a19 19 0 0 1-5.3 2.328" style="fill:#fff"/></svg>

After

Width:  |  Height:  |  Size: 1.5 KiB

1
src/lib/index.ts Normal file
View File

@@ -0,0 +1 @@
// place files you want to import through the `$lib` alias in this folder.

View File

@@ -0,0 +1,43 @@
import { PUBLIC_CLIENT_ID, PUBLIC_REDIRECT_URI } from "$env/static/public";
export const generateRandomString = (length: number) => {
const possible = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';
const values = crypto.getRandomValues(new Uint8Array(length));
return values.reduce((acc, x) => acc + possible[x % possible.length], "");
}
export const sha256 = async (plain: string) => {
const encoder = new TextEncoder()
const data = encoder.encode(plain)
return crypto.subtle.digest('SHA-256', data)
}
export const base64encode = (input: ArrayBuffer) => {
return btoa(String.fromCharCode(...new Uint8Array(input)))
.replace(/=/g, '')
.replace(/\+/g, '-')
.replace(/\//g, '_');
}
export const getToken = async (code: string, codeVerifier: string) => {
const url = "https://accounts.spotify.com/api/token";
const payload = {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
client_id: PUBLIC_CLIENT_ID,
grant_type: 'authorization_code',
code,
redirect_uri: PUBLIC_REDIRECT_URI,
code_verifier: codeVerifier
})
};
const body = await fetch(url, payload);
const response = await body.json();
return response;
}

View File

@@ -0,0 +1,10 @@
import { drizzle } from 'drizzle-orm/better-sqlite3';
import Database from 'better-sqlite3';
import * as schema from './schema';
import { env } from '$env/dynamic/private';
if (!env.DATABASE_URL) throw new Error('DATABASE_URL is not set');
const client = new Database(env.DATABASE_URL);
export const db = drizzle(client, { schema });

View File

@@ -0,0 +1,55 @@
import { relations } from 'drizzle-orm';
import { sqliteTable, integer, text, type AnySQLiteColumn, primaryKey } from 'drizzle-orm/sqlite-core';
export const usersTable = sqliteTable('users', {
email: text('email').primaryKey(),
username: text('username'),
});
export const sessionsTable = sqliteTable('sessions', {
id: text('id').primaryKey(),
accessToken: text('access_token'),
refreshToken: text('refresh_token'),
userEmail: text('user_email').references((): AnySQLiteColumn => usersTable.email)
});
export const sessionsRelations = relations(sessionsTable, ({ one }) => ({
user: one(usersTable, { fields: [sessionsTable.userEmail], references: [usersTable.email] })
}))
export const userRelations = relations(usersTable, ({ one, many }) => ({
session: one(sessionsTable),
usersInLobby: many(usersInLobby)
}));
export const lobbysTable = sqliteTable('lobbys', {
id: integer('id').primaryKey({ autoIncrement: true }),
hostEmail: text('host_email').references((): AnySQLiteColumn => usersTable.email),
});
export const lobbysRelations = relations(lobbysTable, ({ many }) => ({
usersInLobby: many(usersInLobby)
}));
export const usersInLobby = sqliteTable('user_in_lobby', {
userEmail: text('user_email').notNull().references((): AnySQLiteColumn => usersTable.email),
lobbyId: integer('lobby_id').notNull().references((): AnySQLiteColumn => lobbysTable.id)
}, (t) => [
primaryKey({ columns: [t.userEmail, t.lobbyId] })
])
export const usersToLobbysRelations = relations(usersInLobby, ({ one }) => ({
lobby: one(lobbysTable, {
fields: [usersInLobby.lobbyId],
references: [lobbysTable.id]
}),
user: one(usersTable, {
fields: [usersInLobby.userEmail],
references: [usersTable.email]
})
}));
export const states = sqliteTable('auth_states', {
id: text('id').primaryKey(),
codeVerifier: text('code_verifier').notNull()
})

View File

@@ -0,0 +1,11 @@
export const getJson = async (accessToken: string, subUri: string) => {
const baseUrl = new URL("https://api.spotify.com/");
const requestUrl = new URL(subUri, baseUrl);
return await fetch(requestUrl, {
method: 'GET',
headers: {
"Authorization": `Bearer ${accessToken}`
}
})
}

View File

@@ -0,0 +1,5 @@
import { getJson } from "./base"
export const getCurrentUserProfile = async (accessToken: string) => {
return await (await getJson(accessToken, "/v1/me")).json()
}

11
src/routes/+layout.svelte Normal file
View File

@@ -0,0 +1,11 @@
<script lang="ts">
import favicon from '$lib/assets/favicon.svg';
let { children } = $props();
</script>
<svelte:head>
<link rel="icon" href={favicon} />
</svelte:head>
{@render children?.()}

View File

@@ -0,0 +1,13 @@
import { db } from "$lib/server/db";
import { usersTable } from "$lib/server/db/schema";
import type { PageServerLoad } from "./$types";
export const load: PageServerLoad = async ({ locals }) => {
const allUsers = await db.select().from(usersTable);
return {
user: locals.user,
users: allUsers
}
};

75
src/routes/+page.svelte Normal file
View File

@@ -0,0 +1,75 @@
<script lang="ts">
import { goto } from '$app/navigation';
import type { PageProps } from './$types';
let { data }: PageProps = $props();
let users = $state(data.users);
let user = $state(data.user);
</script>
<h1>Welcome to SvelteKit</h1>
<p>Visit <a href="https://svelte.dev/docs/kit">svelte.dev/docs/kit</a> to read the documentation</p>
<!-- <div>
<label>Email: <input type="text" bind:value={email} /></label>
<label>Username: <input type="text" bind:value={username} /></label>
</div> -->
{#if !user.isLoggedIn}
<button onclick={async () => await goto('/login')}> Login </button>
{:else}
<h2>Hello {user.username}</h2>
<button
onclick={async () => {
user.username = "";
user.email = "";
user.isLoggedIn = false;
await goto('/logout');
}}
>
Logout
</button>
{/if}
<!--
<button
onclick={async () => {
const response = await fetch('/api/createUser', {
method: 'POST',
body: JSON.stringify({
email: email,
username: username
}),
headers: {
'Content-Type': 'application/json'
}
});
console.log(response.status);
if (response.ok) {
const newUser: Array<any> = await response.json();
users.push(...newUser);
} else {
console.log(`Encountered Error ${response.status}`);
}
}}>Create User</button
> -->
<button
onclick={async () => {
const response = await fetch('/api/deleteUsers', {
method: 'POST'
});
users.splice(0, users.length);
}}>Delete all Users</button
>
<ul>
{#each users as user (user.email)}
<li>
{user.username} = {user.email}
</li>
{/each}
</ul>

View File

@@ -0,0 +1,20 @@
import { db } from "$lib/server/db";
import { usersTable } from "$lib/server/db/schema";
import { json } from "@sveltejs/kit";
import type { Actions } from "../../$types";
export async function POST({ request }) {
const user = await request.json();
const u: typeof usersTable.$inferInsert = {
email: user.email,
username: user.username
};
const result = await db.insert(usersTable).values(u).onConflictDoNothing().returning();
if (result.length <= 0) {
return new Response(null, { status: 409 });
}
return json(result, { status: 201 })
}

View File

@@ -0,0 +1,11 @@
import { db } from "$lib/server/db"
import { sessionsTable, usersTable } from "$lib/server/db/schema"
import { DefaultViewBuilderCore } from "drizzle-orm/gel-core";
export async function POST() {
await db.delete(sessionsTable);
await db.delete(usersTable);
return new Response();
}

View File

@@ -0,0 +1,53 @@
import { redirect } from "@sveltejs/kit";
import type { PageServerLoad } from "./$types";
import { eq } from 'drizzle-orm';
import { db } from "$lib/server/db";
import { sessionsTable, states, usersTable } from "$lib/server/db/schema";
import { generateRandomString, getToken } from "$lib/server/auth/spotify";
import { getCurrentUserProfile } from "$lib/server/spotify/users";
export const load: PageServerLoad = async ({ url, cookies }) => {
const code = url.searchParams.get('code');
const state = url.searchParams.get('state')
if (!state || !code) {
redirect(307, "/")
}
const s = await db.select().from(states).where(eq(states.id, state)).limit(1);
const token = await getToken(code, s[0].codeVerifier)
// console.log(token);
// TODO: Check if deletion was fulfilled
await db.delete(states).where(eq(states.id, state));
const userResponse = await getCurrentUserProfile(token.access_token)
// console.log(userResponse)
const isUser: boolean = (await db.$count(usersTable, eq(usersTable.email, userResponse.email))) === 1
if (!isUser) {
const user: typeof usersTable.$inferInsert = {
email: userResponse.email,
username: userResponse.display_name
}
await db.insert(usersTable).values(user);
}
const session: typeof sessionsTable.$inferInsert = {
id: generateRandomString(64),
accessToken: token.access_token,
refreshToken: token.refresh_token,
userEmail: userResponse.email,
// TODO: Session Timeouts MUST
}
const sessionResponse = await db.insert(sessionsTable).values(session);
cookies.set("session_id", session.id, { path: "/", secure: false});
redirect(307, "/")
};

View File

@@ -0,0 +1,2 @@
<h1>You ran into an error :(</h1>
<p>There should be more info, but isnt right now so you just gotta guess</p>

View File

@@ -0,0 +1,37 @@
import { PUBLIC_CLIENT_ID, PUBLIC_REDIRECT_URI } from "$env/static/public";
import { redirect } from "@sveltejs/kit";
import { generateRandomString, sha256, base64encode } from '$lib/server/auth/spotify';
import type { PageServerLoad } from "../$types";
import { db } from "$lib/server/db";
import { states } from "$lib/server/db/schema";
export const load: PageServerLoad = async () => {
const scope = 'user-read-private user-read-email';
const authUrl = new URL("https://accounts.spotify.com/authorize");
const verifier = generateRandomString(64);
const state = generateRandomString(64);
const s: typeof states.$inferInsert = {
id: state,
codeVerifier: verifier
};
await db.insert(states).values(s);
const hashed = await sha256(verifier);
const codeChallenge = base64encode(hashed);
const params = {
response_type: 'code',
client_id: PUBLIC_CLIENT_ID,
scope,
code_challenge_method: 'S256',
code_challenge: codeChallenge,
redirect_uri: PUBLIC_REDIRECT_URI,
state
}
authUrl.search = new URLSearchParams(params).toString();
redirect(307, authUrl);
};

View File

@@ -0,0 +1,18 @@
import { db } from "$lib/server/db";
import { sessionsTable } from "$lib/server/db/schema";
import { eq } from "drizzle-orm";
import type { PageServerLoad } from "../$types";
import { redirect } from "@sveltejs/kit";
export const load: PageServerLoad = async ({ cookies }) => {
const sessionId = cookies.get('session_id');
if (!sessionId) {
redirect(307, "/error")
}
db.delete(sessionsTable).where(eq(sessionsTable.id, sessionId))
cookies.delete('session_id', { path: "/" });
redirect(307, "/")
}

3
static/robots.txt Normal file
View File

@@ -0,0 +1,3 @@
# allow crawling everything by default
User-agent: *
Disallow:

12
svelte.config.js Normal file
View File

@@ -0,0 +1,12 @@
import adapter from '@sveltejs/adapter-node';
import { vitePreprocess } from '@sveltejs/vite-plugin-svelte';
/** @type {import('@sveltejs/kit').Config} */
const config = {
// Consult https://svelte.dev/docs/kit/integrations
// for more information about preprocessors
preprocess: vitePreprocess(),
kit: { adapter: adapter() }
};
export default config;

19
tsconfig.json Normal file
View File

@@ -0,0 +1,19 @@
{
"extends": "./.svelte-kit/tsconfig.json",
"compilerOptions": {
"allowJs": true,
"checkJs": true,
"esModuleInterop": true,
"forceConsistentCasingInFileNames": true,
"resolveJsonModule": true,
"skipLibCheck": true,
"sourceMap": true,
"strict": true,
"moduleResolution": "bundler"
}
// Path aliases are handled by https://svelte.dev/docs/kit/configuration#alias
// except $lib which is handled by https://svelte.dev/docs/kit/configuration#files
//
// To make changes to top-level options such as include and exclude, we recommend extending
// the generated config; see https://svelte.dev/docs/kit/configuration#typescript
}

6
vite.config.ts Normal file
View File

@@ -0,0 +1,6 @@
import { sveltekit } from '@sveltejs/kit/vite';
import { defineConfig } from 'vite';
export default defineConfig({
plugins: [sveltekit()]
});