fix(auth): drop nonexistent account_blocked column from login lookup
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m42s

getLoginUser selected users.account_blocked, which does not exist in the
DB (nor the Drizzle schema). Every credentials authorize() call threw a
SQL error -> NextAuth CallbackRouteError -> 'error=Configuration', so no
login could ever succeed. Remove the phantom column from the query and
LoginUser interface.

Also fix all remaining biome noNonNullAssertion / noExplicitAny lint
warnings so CI's check job (biome:lint) passes and the push deploy runs.
This commit is contained in:
openhands committed 2026-08-01 17:38:43 +02:00
1 parent 8275842e78
commit 22d455da7a
13 files changed
+71 -65

No files matched your search

+10 -2
View File
@@ -5,8 +5,16 @@ export interface StaffActivityFilters {
authorizationOnly?: boolean;
}
export function buildStaffActivityWhere(filters: StaffActivityFilters): any {
const where: any = {};
interface StaffActivityWhere {
OR?: Array<Record<string, { contains?: string }>>;
userId?: bigint;
action?: { startsWith: string } | { contains: string };
}
export function buildStaffActivityWhere(
filters: StaffActivityFilters,
): StaffActivityWhere {
const where: StaffActivityWhere = {};
if (filters.q?.trim())
where.OR = [
{ action: { contains: filters.q.trim() } },
+25 -25
View File
@@ -73,7 +73,8 @@ async function fetchCmsCandidates(
? [eq(WebsiteTicket.id, asId)]
: []),
];
conditions.push(or(...searchOr)!);
const searchFilter = or(...searchOr);
if (searchFilter) conditions.push(searchFilter);
}
const where = conditions.length > 0 ? and(...conditions) : undefined;
@@ -146,7 +147,8 @@ async function fetchHelpCandidates(
: []),
...(asId !== null ? [eq(WebsiteHelpCenterTickets.id, asId)] : []),
];
conditions.push(or(...searchOr)!);
const searchFilter = or(...searchOr);
if (searchFilter) conditions.push(searchFilter);
}
const where = conditions.length > 0 ? and(...conditions) : undefined;
@@ -210,16 +212,15 @@ async function countCms(search: string, openOnly: boolean): Promise<number> {
if (openOnly) conditions.push(ne(WebsiteTicket.status, "closed"));
if (search) {
const asId = Number(search);
conditions.push(
or(
like(WebsiteTicket.subject, `%${search}%`),
like(WebsiteTicket.category, `%${search}%`),
like(Creator.username, `%${search}%`),
...(Number.isFinite(asId) && asId > 0
? [eq(WebsiteTicket.id, asId)]
: []),
)!,
const searchFilter = or(
like(WebsiteTicket.subject, `%${search}%`),
like(WebsiteTicket.category, `%${search}%`),
like(Creator.username, `%${search}%`),
...(Number.isFinite(asId) && asId > 0
? [eq(WebsiteTicket.id, asId)]
: []),
);
if (searchFilter) conditions.push(searchFilter);
}
const where = conditions.length > 0 ? and(...conditions) : undefined;
const rows = await db
@@ -242,21 +243,20 @@ async function countHelp(search: string, openOnly: boolean): Promise<number> {
.where(like(User.username, `%${search}%`))
.limit(50)
.catch(() => []);
conditions.push(
or(
like(WebsiteHelpCenterTickets.title, `%${search}%`),
like(WebsiteHelpCenterTickets.content, `%${search}%`),
...(matchingUsers.length > 0
? [
inArray(
WebsiteHelpCenterTickets.userId,
matchingUsers.map((u) => u.id),
),
]
: []),
...(asId !== null ? [eq(WebsiteHelpCenterTickets.id, asId)] : []),
)!,
const searchFilter = or(
like(WebsiteHelpCenterTickets.title, `%${search}%`),
like(WebsiteHelpCenterTickets.content, `%${search}%`),
...(matchingUsers.length > 0
? [
inArray(
WebsiteHelpCenterTickets.userId,
matchingUsers.map((u) => u.id),
),
]
: []),
...(asId !== null ? [eq(WebsiteHelpCenterTickets.id, asId)] : []),
);
if (searchFilter) conditions.push(searchFilter);
}
const where = conditions.length > 0 ? and(...conditions) : undefined;
const rows = await db
+1 -6
View File
@@ -21,7 +21,6 @@ interface LoginUser {
mailVerified: string | null;
twoFactorConfirmedAt: string | null;
twoFactorSecret: string | null;
accountBlocked: string | null;
}
/**
@@ -41,13 +40,11 @@ async function getLoginUser(username: string): Promise<LoginUser | null> {
mail_verified: string | null;
two_factor_confirmed_at: string | null;
two_factor_secret: string | null;
account_blocked: string | null;
}>(sql`
SELECT id, username, password, rank, mail,
mail_verified,
two_factor_confirmed_at,
two_factor_secret,
account_blocked
two_factor_secret
FROM users
WHERE username = ${username}
LIMIT 1
@@ -61,7 +58,6 @@ async function getLoginUser(username: string): Promise<LoginUser | null> {
mail_verified: string | null;
two_factor_confirmed_at: string | null;
two_factor_secret: string | null;
account_blocked: string | null;
}>;
return rows.length > 0
? {
@@ -73,7 +69,6 @@ async function getLoginUser(username: string): Promise<LoginUser | null> {
mailVerified: rows[0].mail_verified,
twoFactorConfirmedAt: rows[0].two_factor_confirmed_at,
twoFactorSecret: rows[0].two_factor_secret,
accountBlocked: rows[0].account_blocked,
}
: null;
},