{"version":3,"file":"code.mjs","names":[],"sources":["../../../../../../src/astro/routes/api/oauth/device/code.ts"],"sourcesContent":["/**\n * POST /_emdash/api/oauth/device/code\n *\n * Issue a device code + user code for the OAuth Device Flow.\n * This is an unauthenticated endpoint (the CLI doesn't have a token yet).\n *\n * Rate limited: 10 requests per minute per IP.\n */\n\nimport type { APIRoute } from \"astro\";\nimport { z } from \"zod\";\n\nimport { apiError, handleError, unwrapResult } from \"#api/error.js\";\nimport { handleDeviceCodeRequest } from \"#api/handlers/device-flow.js\";\nimport { isParseError, parseBody } from \"#api/parse.js\";\nimport { getPublicOrigin } from \"#api/public-url.js\";\nimport { checkRateLimit, getClientIp, rateLimitResponse } from \"#auth/rate-limit.js\";\nimport { getTrustedProxyHeaders } from \"#auth/trusted-proxy.js\";\n\nexport const prerender = false;\n\nconst deviceCodeSchema = z.object({\n\tclient_id: z.string().optional(),\n\tscope: z.string().optional(),\n});\n\nexport const POST: APIRoute = async ({ request, locals, url }) => {\n\tconst { emdash } = locals;\n\n\tif (!emdash?.db) {\n\t\treturn apiError(\"NOT_CONFIGURED\", \"EmDash is not initialized\", 500);\n\t}\n\n\ttry {\n\t\tconst body = await parseBody(request, deviceCodeSchema);\n\t\tif (isParseError(body)) return body;\n\n\t\t// Rate limit: 10 requests per 60 seconds per IP\n\t\tconst ip = getClientIp(request, getTrustedProxyHeaders(emdash.config));\n\t\tconst rateLimit = await checkRateLimit(emdash.db, ip, \"device/code\", 10, 60);\n\t\tif (!rateLimit.allowed) {\n\t\t\treturn rateLimitResponse(60);\n\t\t}\n\n\t\t// Build the verification URI — device page lives inside the admin SPA\n\t\tconst verificationUri = new URL(\n\t\t\t\"/_emdash/admin/device\",\n\t\t\tgetPublicOrigin(url, emdash?.config),\n\t\t).toString();\n\n\t\tconst result = await handleDeviceCodeRequest(emdash.db, body, verificationUri);\n\t\treturn unwrapResult(result);\n\t} catch (error) {\n\t\treturn handleError(error, \"Failed to create device code\", \"DEVICE_CODE_ERROR\");\n\t}\n};\n"],"mappings":";;;;;;;;;;;;;;;AAmBA,MAAa,YAAY;AAEzB,MAAM,mBAAmB,EAAE,OAAO;CACjC,WAAW,EAAE,QAAQ,CAAC,UAAU;CAChC,OAAO,EAAE,QAAQ,CAAC,UAAU;CAC5B,CAAC;AAEF,MAAa,OAAiB,OAAO,EAAE,SAAS,QAAQ,UAAU;CACjE,MAAM,EAAE,WAAW;AAEnB,KAAI,CAAC,QAAQ,GACZ,QAAO,SAAS,kBAAkB,6BAA6B,IAAI;AAGpE,KAAI;EACH,MAAM,OAAO,MAAM,UAAU,SAAS,iBAAiB;AACvD,MAAI,aAAa,KAAK,CAAE,QAAO;EAG/B,MAAM,KAAK,YAAY,SAAS,uBAAuB,OAAO,OAAO,CAAC;AAEtE,MAAI,EADc,MAAM,eAAe,OAAO,IAAI,IAAI,eAAe,IAAI,GAAG,EAC7D,QACd,QAAO,kBAAkB,GAAG;EAI7B,MAAM,kBAAkB,IAAI,IAC3B,yBACA,gBAAgB,KAAK,QAAQ,OAAO,CACpC,CAAC,UAAU;AAGZ,SAAO,aADQ,MAAM,wBAAwB,OAAO,IAAI,MAAM,gBAAgB,CACnD;UACnB,OAAO;AACf,SAAO,YAAY,OAAO,gCAAgC,oBAAoB"}