96043efe46
Passkey-Login wie in ausgaben-next/werte-next: auf der Login-Seite "Mit Passkey anmelden", Verwaltung der eigenen Passkeys unter /einstellungen (Button oben rechts). Das Passwort bleibt als Alternative bestehen. - lib/webauthn.ts, lib/passkeys.ts sowie API-Routen unter /api/passkey - proxy.ts: /api/passkey/authenticate ohne Session erreichbar - Styles als eigene CSS-Klassen in globals.css (kein Tailwind in diesem Projekt), passend zum vorhandenen login-*/app-*-Schema - Tabelle tabletten_passkeys in der DB medizin: app-spezifischer Name, damit sich Apps desselben Stacks nicht gegenseitig Passkeys anzeigen oder loeschen - RP-Konfiguration ueber TABLETTEN_RP_*, da sich die .env auf dem Server mit anderen Apps teilt, die RP_ID/RP_ORIGIN bereits belegen Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
56 lines
2.6 KiB
Markdown
56 lines
2.6 KiB
Markdown
This is a [Next.js](https://nextjs.org) project bootstrapped with [`create-next-app`](https://nextjs.org/docs/app/api-reference/cli/create-next-app).
|
|
|
|
## Getting Started
|
|
|
|
First, run the development server:
|
|
|
|
```bash
|
|
npm run dev
|
|
# or
|
|
yarn dev
|
|
# or
|
|
pnpm dev
|
|
# or
|
|
bun dev
|
|
```
|
|
|
|
Open [http://localhost:3000](http://localhost:3000) with your browser to see the result.
|
|
|
|
You can start editing the page by modifying `app/page.tsx`. The page auto-updates as you edit the file.
|
|
|
|
This project uses [`next/font`](https://nextjs.org/docs/app/building-your-application/optimizing/fonts) to automatically optimize and load [Geist](https://vercel.com/font), a new font family for Vercel.
|
|
|
|
## Learn More
|
|
|
|
To learn more about Next.js, take a look at the following resources:
|
|
|
|
- [Next.js Documentation](https://nextjs.org/docs) - learn about Next.js features and API.
|
|
- [Learn Next.js](https://nextjs.org/learn) - an interactive Next.js tutorial.
|
|
|
|
You can check out [the Next.js GitHub repository](https://github.com/vercel/next.js) - your feedback and contributions are welcome!
|
|
|
|
## Deploy on Vercel
|
|
|
|
The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js.
|
|
|
|
Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details.
|
|
|
|
## Anmeldung & Passkeys
|
|
|
|
Benutzer und bcrypt-Passworthashes stehen in `AUTH_USERS` (Format `name:hash,name2:hash2`),
|
|
die Session ist ein JWT-Cookie (`AUTH_SECRET`).
|
|
|
|
Zusätzlich kann sich jeder Benutzer per **Passkey** anmelden (Fingerabdruck,
|
|
Gesichtserkennung oder Geräte-PIN). Das Passwort bleibt als Alternative bestehen.
|
|
|
|
- **Registrieren**: nach der Anmeldung oben rechts auf *Einstellungen* → „Passkey hinzufügen".
|
|
- **Anmelden**: auf der Login-Seite „Mit Passkey anmelden".
|
|
- **Speicherung**: Tabelle `tabletten_passkeys` in der Datenbank `medizin`; sie wird beim
|
|
ersten Zugriff automatisch angelegt, falls der DB-Benutzer CREATE-Rechte hat. Der
|
|
app-spezifische Name verhindert Kollisionen mit anderen Apps desselben Stacks.
|
|
- **Konfiguration**: Im Container `RP_ID` (nur der Host), `RP_ORIGIN` (volle URL) und
|
|
`RP_NAME`. In den Compose-Dateien werden diese aus `TABLETTEN_RP_*` befüllt, weil sich
|
|
die `.env` auf dem Server mit anderen Apps teilt, die `RP_ID`/`RP_ORIGIN` bereits belegen.
|
|
- **Wichtig**: WebAuthn funktioniert nur über **HTTPS** oder auf `localhost`. Ändert sich
|
|
`RP_ID`, werden bereits registrierte Passkeys ungültig.
|