(
store: ReturnType<typeof makeSelfHostMcpSessionStore>,
betterAuth: BetterAuthHandle,
)
| 114 | */ |
| 115 | const makeApprovalHandler = |
| 116 | ( |
| 117 | store: ReturnType<typeof makeSelfHostMcpSessionStore>, |
| 118 | betterAuth: BetterAuthHandle, |
| 119 | ): ((request: Request) => Promise<Response>) => |
| 120 | async (request) => { |
| 121 | // A malformed cookie must read as unauthenticated, not 500. |
| 122 | const session = await Effect.runPromise( |
| 123 | Effect.tryPromise({ |
| 124 | try: () => betterAuth.auth.api.getSession({ headers: request.headers }), |
| 125 | catch: () => "session lookup failed", |
| 126 | }).pipe(Effect.orElseSucceed(() => null)), |
| 127 | ); |
| 128 | if (!session) return jsonResponse({ error: "Unauthorized" }, 401); |
| 129 | const principal = await Effect.runPromise( |
| 130 | principalFromSession(session, betterAuth, request.headers), |
| 131 | ); |
| 132 | |
| 133 | return ( |
| 134 | (await store.handlePausedRequest(request, principal)) ?? |
| 135 | (await store.handleApprovalRequest(request, principal)) ?? |
| 136 | jsonResponse({ error: "Not found" }, 404) |
| 137 | ); |
| 138 | }; |
| 139 | |
| 140 | /** |
| 141 | * Build the self-host MCP serving seams over the long-lived DB handle. The auth |
no test coverage detected