( rsLive: Layer.Layer<DbService | UserStoreService | WorkOsMirror | MemberDirectory>, )
| 67 | // handler reads it for the free-organizations-per-user limit gate — one of the |
| 68 | // few app-only billing touchpoints. (It is NOT on the neutral boot core.) |
| 69 | export const makeNonProtectedApiLive = ( |
| 70 | rsLive: Layer.Layer<DbService | UserStoreService | WorkOsMirror | MemberDirectory>, |
| 71 | ) => |
| 72 | HttpApiBuilder.layer(NonProtectedApi).pipe( |
| 73 | Layer.provide(Layer.mergeAll(CloudAuthPublicHandlers, CloudSessionAuthHandlers)), |
| 74 | Layer.provide(requestScopedMiddleware(rsLive).layer), |
| 75 | Layer.provideMerge(SessionAuthLive), |
| 76 | Layer.provideMerge(AutumnService.Default), |
| 77 | ); |
| 78 | |
| 79 | // Cloud-only WorkOS domain-verification routes. Auth is enforced by a router |
| 80 | // middleware that resolves the URL org selector header before falling back to |
no test coverage detected