Skip to content
File

Blob: wrangler.jsonc

2.2 KB
1{
2 "$schema": "node_modules/wrangler/config-schema.json",
3 "name": "tessera",
4 "main": "src/worker/index.ts",
5 "compatibility_date": "2026-03-16",
6 // Better Auth 1.6.23 imports node:crypto at module scope. Keep bindings
7 // and secrets off process.env; tessera passes Env explicitly.
8 "compatibility_flags": [
9 "nodejs_compat",
10 "nodejs_compat_do_not_populate_process_env"
11 ],
12 "observability": {
13 "enabled": true,
14 },
15 "assets": {
16 "directory": "dist/client",
17 "binding": "ASSETS",
18 "not_found_handling": "single-page-application",
19 "run_worker_first": [
20 "/api/*",
21 "/.well-known/*",
22 "/healthz"
23 ],
24 },
25 "ratelimits": [
26 // Tight tier. Used for sign-in, invite, OAuth issuance, admin, and
27 // anything under /api/auth/* not in the loose set or exempt list.
28 {
29 "name": "RL_AUTH",
30 "namespace_id": "110001",
31 "simple": {
32 "limit": 10,
33 "period": 60,
34 },
35 },
36 // Loose tier. Used for high-volume reads served by the Better Auth
37 // catchall: session reads (/get-session, /update-session,
38 // /list-sessions, /list-accounts) and RP-backend OAuth reads
39 // (/oauth2/userinfo, /oauth2/introspect).
40 {
41 "name": "RL_API",
42 "namespace_id": "110002",
43 "simple": {
44 "limit": 300,
45 "period": 60,
46 },
47 },
48 ],
49 "d1_databases": [
50 {
51 "binding": "DB",
52 "database_name": "tessera-prod",
53 "database_id": "e2f541f9-781a-4d10-811a-82fc7b51df82",
54 "migrations_dir": "drizzle/d1",
55 },
56 ],
57 "vars": {
58 "LOG_LEVEL": "info",
59 // Production deployment: tessera answers on auth.limic.dev. The OIDC
60 // `iss` claim and Better Auth's cookie/baseURL all key off this.
61 // Override locally via .dev.vars (or leave it empty there to let the
62 // worker derive the base URL from the incoming request).
63 "BETTER_AUTH_URL": "https://auth.limic.dev",
64 "OIDC_ISSUER": "https://auth.limic.dev",
65 // OPERATOR_NAME and OPERATOR_CONTACT_EMAIL drive the operator
66 // identity rendered on /privacy and /terms. They are required at
67 // runtime — /api/config fails closed when either is empty — and are
68 // set per deployment via the Cloudflare dashboard (Workers →
69 // Settings → Variables) or locally via .dev.vars, not committed
70 // here.
71 },
72 "routes": [
73 {
74 "pattern": "auth.limic.dev",
75 "custom_domain": true,
76 },
77 ],
78}