import type { FastifyInstance } from 'fastify';
import { loginHandler, sessionHandler, logoutHandler } from '../controllers/auth.controller.js';
import { loginSchema } from '../schemas/auth.schema.js';

export default async function authRoutes(fastify: FastifyInstance) {
  // Much stricter than the global rate limit — this is the one endpoint
  // where rapid repeated requests means someone is guessing passwords, not
  // just a legitimate burst of normal usage. Keyed by IP, so this also
  // acts as the account-lockout control: too many wrong passwords from one
  // source blocks further attempts for the window, without needing a
  // separate per-account lockout system (which has its own downside — an
  // attacker could otherwise lock a real user out just by guessing wrong).
  // Kept generous enough that a shared office IP with several staff mistyping
  // passwords doesn't lock everyone out.
  fastify.post(
    '/api/auth/login',
    { schema: loginSchema, config: { rateLimit: { max: 50, timeWindow: '5 minutes' } } },
    loginHandler,
  );
  fastify.get('/api/auth/session', sessionHandler);
  fastify.post('/api/auth/logout', logoutHandler);
}
