Task 15 of the authz permissions plan: proves db store + cache + catalog + middleware + audit compose correctly, wires a real (non-dangling) example into auth-showcase, and documents the declaration/registration/precedence surface in the package README.
Authentication showcase
Run from the monorepo root:
bun run auth:dev
The showcase uses package-owned /api/auth/* routes, automatic browser schemas, auth-session middleware, components, styles, and runtime. It intentionally contains no copied default API handlers or app/schemas files.
It demonstrates registration, password login and recovery, passwordless OTP, magic-link requests, two-factor verification, authenticator setup, passkeys, sessions, invitations, account state, and impersonation safety UI.
Development delivery messages are retained in the in-memory outbox. Console output reports only the template and destination; it does not print OTP codes, raw tokens, or reset URLs. Replace the memory store, development secret, and delivery implementation before production use.