learn
apps/

HTTP server

Authenticated HTTP API for scenes, rooms, invites, files, and private library items.

Routes live under /scenes, /library, and /room, all behind authentication, plus health and account endpoints. Rooms also issue the presence tickets the browser uses to open its WebSocket connection. Shared room checks live in the route utils; the write path itself lives in backend-common.

What it owns

  • Scene CRUD and guest import
  • Room CRUD, presence tickets, files, and scene patching
  • Room invitations, join codes, and member management
  • Private library item CRUD

Files

File list and purposes from the folder README.

FilePurpose
src/app.tsRoute mounting and middleware wiring.
src/middleware.tsRequest authentication.
src/invitationRateLimit.tsInvite request rate limits.
src/routes/scenes.tsScene routes.
src/routes/rooms.tsRoom routes.
src/routes/roomInvites.tsInvite, join-code, and member management routes.
src/routes/roomRouteUtils.tsShared room authorization, join-code, and rate-limit helpers.
src/routes/library.tsLibrary routes.
src/routes/guestImport.tsGuest import routes.
src/services/Reserved folder holding only its README for now.

Dependencies

LibraryVersion rangeWhy it is used here
CORS2.8.5Enables cross-origin requests from the web app.
Express^5.2.1HTTP server behind the scenes, rooms, and library APIs.
Zod^4.6.4Validates guest-import payloads.
Development and tooling (4)
LibraryVersion rangeWhy it is used here
@types/cors2.8.19Type declarations for CORS.
@types/express^5.0.6Type declarations for Express.
@types/node26.4.1Type declarations for Node.js built-ins.
tsx^4.23.13Runs and watches TypeScript sources for development and tests.

Dependencies as of commit b0026d9.

http-server folder
BrowserAPIRealtimeCacheDatabaseShareddurableephemeral

Talks to

Sources: apps/http-server/README.md, apps/http-server/src/README.md, apps/http-server/src/routes/README.md, apps/http-server/src/routes/scenes.ts, apps/http-server/src/routes/rooms.ts, apps/http-server/src/routes/roomInvites.ts (documented at commit b0026d9)

On this page