Skip to content

Discord bot (1/2): server integration endpoints + account linking - #187

Merged
Anuraj-dev merged 2 commits into
mainfrom
feat/discord-integration-endpoints
Jul 23, 2026
Merged

Anuraj-dev merged 2 commits into
mainfrom
feat/discord-integration-endpoints

Conversation

@Anuraj-dev

Copy link
Copy Markdown
Owner

Implements ticket #185 — the server + client pieces the Discord bot (ticket #186) will consume. Spec: `docs/specs/2026-07-23-discord-bot-design.md`.

What's here

  • `DiscordLink` model — `{ discordId (unique), userId, createdAt }`; re-linking upserts on `discordId`.
  • Bot-API-key middleware (`requireBotAuth`) — timing-safe check of the `X-Bot-Api-Key` header against `DISCORD_BOT_API_KEY`; wired only onto `/api/integrations/discord/*`. Empty key disables the integration (rejects all). Never logged.
  • `POST /api/integrations/discord/link-token` (bot key) — mints a short-lived (`DISCORD_LINK_TOKEN_TTL`, default 10m) single-purpose token bound to the Discord ID. Signed with a key derived from `JWT_SECRET` (HMAC) + a `typ` claim, so an auth cookie JWT can't be used as a link token and vice-versa. Returns `{ token, linkUrl }`.
  • `POST /api/integrations/discord/link` (user cookie) — verifies token and cookie, upserts the mapping.
  • `POST /api/integrations/discord/rooms` (bot key) — unknown Discord ID → `404 { code: "not_linked" }`; linked → creates a room via the same `createUniqueRoom({ host, admin })` path as `POST /api/rooms`, returns `{ roomId }`.
  • Client `/link/discord` page (React + MUI, strict TS) — behind `ProtectedRoute` (unauthenticated visitors route through the normal auth flow and return here, token preserved); reads `?token=`, posts it, shows linked / expired-invalid / missing-token states.
  • Joi validation matching existing conventions; `server/.env.example` documents the new vars.

Tests (strict TDD)

  • Server: link-token mint/verify (expiry, wrong-type, tampered, cross-key), all three endpoints, bot-key vs user-cookie auth isolation, unknown Discord ID, re-link overwrite. (20 tests)
  • Client: page confirmation / expired / missing-token states. (3 tests)

Notes / deviations

  • Spec says "zod" for validation; the repo's actual convention is Joi (the `validate` middleware is Joi-based, no zod dependency). Followed the existing Joi convention — "matching existing conventions" was the stronger signal.
  • The room rate-limiter is intentionally not applied to the integration routes so a single bot-host IP isn't throttled creating meetings for a server; the bot-key gate is the protection.

Closes #185

Add the server + client pieces the Discord bot (ticket 2) will consume:

- DiscordLink model ({ discordId unique, userId, createdAt }), upsert on re-link
- bot-API-key middleware, wired ONLY onto /api/integrations/discord/* routes
- POST /api/integrations/discord/link-token (bot key) — mint a short-lived,
  single-purpose token bound to a Discord ID, signed with a key derived from
  JWT_SECRET so it is not interchangeable with the auth cookie JWT
- POST /api/integrations/discord/link (user cookie) — verify token + cookie,
  upsert the mapping
- POST /api/integrations/discord/rooms (bot key) — create an instant room hosted
  by the linked user; unknown Discord ID returns a distinct not_linked 404
- client /link/discord confirmation page (behind ProtectedRoute) + api helper
- zod-equivalent Joi validation matching existing conventions; env + .env.example

Closes #185
@vercel

vercel Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
a-meet Ready Ready Preview, Comment Jul 23, 2026 6:32am

pino-http serializes request headers, so the host-grade X-Bot-Api-Key would
otherwise leak into request-completion log lines. Add it to REDACT_PATHS and add
a behavioural test proving the value is censored (not just config membership).
@Anuraj-dev
Anuraj-dev merged commit e50fee1 into main Jul 23, 2026
14 checks passed
@Anuraj-dev
Anuraj-dev deleted the feat/discord-integration-endpoints branch July 23, 2026 07:11

This branch was successfully deployed

1 active deployment
Preview — 9dc19530 Deployed Jul 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Discord bot (1/2): server-side Discord integration endpoints + account linking

1 participant