# AIRI Server Auth UI Auth UI for the hosted AIRI server. It is a Vue/Vite app deployed separately from `server/apps/api` and used for Better Auth sign-in, email verification, password reset, profile, and Electron OIDC callback relay flows. ## Use When - Building user-facing auth pages backed by server `/api/auth/*` endpoints. - Updating login, sign-up, verification, reset-password, account profile, or Electron auth relay UX. - Deploying the auth surface to Cloudflare Workers Static Assets. ## Do Not Use When - Building the main stage app sign-in callback pages that consume OIDC tokens. - Adding admin-only operational pages. Those belong in the standalone `proj-airi` admin repository. ## Commands ```sh pnpm -F @proj-airi/ui-server-auth dev pnpm -F @proj-airi/ui-server-auth typecheck pnpm -F @proj-airi/ui-server-auth build ``` ## Deployment `pnpm -F @proj-airi/ui-server-auth build` writes to `apps/ui-server-auth/dist`. Vue Router owns `/ui/*`, while Vite assets are served from root `/assets-v2/*` so Cloudflare Pages can serve static files without rewriting nested asset paths. The versioned namespace moves existing clients away from previously poisoned `/assets/*` browser cache entries. Both namespaces use `Cache-Control: public, no-cache`, allowing browsers to retain files only when Pages revalidates them. `public/_redirects` scopes the SPA rewrite to `/ui/*`, and the top-level `public/404.html` keeps missing assets and other unknown paths as HTTP 404 responses. The production GitHub Actions workflow deploys this app to the Cloudflare Pages project `moeru-ai-airi-auth` with separate auth-account credentials: ```sh AUTH_CLOUDFLARE_ACCOUNT_ID=... AUTH_CLOUDFLARE_API_TOKEN=... ``` `apps/ui-server-auth/wrangler.toml` remains available for Workers Static Assets deployments, but production CI uses Cloudflare Pages direct upload. Production expects: ```sh VITE_SERVER_URL=https://api.airi.build ``` The server redirects historical `/auth/*` URLs to `AUTH_UI_URL`, which defaults to `https://accounts.airi.build/ui`. The `server-dev` workflow deploys a Cloudflare Pages branch build at `https://server-dev.airi-server-auth.pages.dev/ui/` with `VITE_SERVER_URL=https://airi-server-dev.up.railway.app`. Set the server-dev API environment variable `AUTH_UI_URL=https://server-dev.airi-server-auth.pages.dev/ui` when the full dev auth redirect chain should stay on server-dev.