Skip to content

Jadu Auth — where to look first

Monorepo (npm workspaces) for Studio Jadu's central authentication. Start with the doc that matches the area you are touching; each sub-project has its own conventions.

Workspaces

Path What it is Read first
be/ Express 5 + MongoDB auth backend: email/password, email OTP, SMS OTP, RBAC, admin API, Discord verification bot. be/conventions.md (layout, naming, static-method classes, error handling), then be/docs/ARCHITECTURE.md (folder map, bootstrap order, env vars), be/docs/CONTRIBUTION.md (adding a route/feature), be/docs/TESTS.md (how coverage is computed), be/README.md (endpoints, scripts, feature notes)
sso-fe/ Next.js centralized login surface that tenant apps redirect to. sso-fe/README.md
fe/ Next.js admin frontend for the auth service. fe/README.md
package/ @scenarix/jadu-auth SDK for React apps and Node backends. package/README.md
package/playground/ Example React app + Express API using the SDK. README.md (root)

Repo-wide docs

  • README.md — overview, root npm scripts (npm run dev, dev:be, build, …).
  • docs/ONBOARDING.md — local setup: env files, running the backend and playground.
  • docs/INFRA.md — how staging/production are deployed (ECR + App Runner for the backend, Pages for frontends); env vars are set manually in the host.
  • docs/SSO_CROSS_SITE_COOKIE_ISSUE.md — why the session cookie does not stick across *.pages.dev ↔ *.awsapprunner.com on staging, and the code-exchange fallback.

Ground rules that apply everywhere

  • Match the existing structure of the sub-project you are in before adding files. For be/ that structure is spelled out in be/conventions.md; do not create a new layout.
  • The backend has a 98% coverage gate in CI (be/vitest.config.integration.ts). Backend changes ship with tests in be/tests/suites/. Use c8 ignore only for genuinely unreachable branches, with a comment saying why; /* c8 ignore next */ must sit directly above the target line, not above a multi-line comment.
  • Secrets live in .env files that are never committed. New env vars get a commented entry in the relevant .env.example.
  • Keep comments and docs written for a reader who was not present when the code was written.