Skip to content
← Public packages

@kentcdodds/audible

Personal Audible library app — browser re-auth, library, wishlist, NAS archive stub.

src/auth-status.ts

62 lines · 2.1 KB · TypeScript
import {
	AUDIBLE_AUTH_SECRET,
	audibleAuthSetupUrl,
	authPublicSummary,
	loadAuthFromSecret,
} from './auth.ts'
import { AUTH_RELATED_HOSTS, resolveLocale } from './locales.ts'

/**
 * Report whether ADP signing auth is available in package storage
 * (`audible-auth-v1`) and whether signing / bearer tokens look fresh —
 * without returning any secret values. Opaque `audibleAuth` mounts alone are
 * not enough after the opaque-secrets change. Use as the first smoke check
 * after Connect / complete-auth.
 *
 * @param _input - Reserved for future options
 * @returns Status metadata and setup URL / Connect guidance when pending
 *
 * @example
 * import authStatus from 'kody:@kentcdodds/audible/auth-status'
 *
 * const status = await authStatus()
 * // { pendingSecret: true, setupUrl } or { pendingSecret: false, signingReady: true, ... }
 */
export default async function authStatus(_input: Record<string, never> = {}) {
	const loaded = await loadAuthFromSecret()
	if (!loaded.ok) {
		return {
			ok: true,
			pendingSecret: true as const,
			secretName: AUDIBLE_AUTH_SECRET,
			signingReady: false,
			setupUrl: loaded.setupUrl,
			reason: loaded.reason,
			hostsToApprove: AUTH_RELATED_HOSTS,
			reauth: {
				app: 'Open the package app Connect tab, or call ./start-auth then ./complete-auth with the maplanding URL.',
				exports: ['./start-auth', './complete-auth'],
			},
		}
	}

	const summary = authPublicSummary(loaded.auth)
	const locale = resolveLocale(summary.locale)
	return {
		ok: true,
		pendingSecret: false as const,
		secretName: AUDIBLE_AUTH_SECRET,
		signingReady: summary.hasAdpToken && summary.hasDevicePrivateKey,
		locale: locale.countryCode,
		apiHost: locale.apiHost,
		marketPlaceId: locale.marketPlaceId,
		...summary,
		setupUrl: audibleAuthSetupUrl(),
		hostsToApprove: AUTH_RELATED_HOSTS,
		reauth: {
			when: 'Only when the virtual device is invalidated or package storage auth is cleared. After opaque-secrets platform change, one Connect re-auth is required so keys live in package storage.',
			app: 'Package app Connect tab → Amazon login → paste maplanding URL.',
			exports: ['./start-auth', './complete-auth'],
		},
	}
}