fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references) - Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates - Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts - Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force - Add structured JSON logger with levels (debug/info/warn/error) - Split 341-line HomePage into GuestView + UserView components - Add OpenAPI v3.1 spec at /api/openapi.json - Add LOG_LEVEL env var, regenerate Prisma client - Add mysql2 dependency for migration scripts - All 58 tests pass, typecheck clean
This commit is contained in:
1 parent
5c638cd6bc
commit
c5db7f5156
17 files changed
+1175
-449
No files matched your search
@@ -0,0 +1,136 @@
|
||||
import { createConnection } from "node:net";
|
||||
import { readFileSync, readdirSync } from "node:fs";
|
||||
import { resolve, dirname } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
|
||||
const __dirname = dirname(fileURLToPath(import.meta.url));
|
||||
const MIGRATIONS_DIR = resolve(__dirname, "../prisma/migrations");
|
||||
const TRACKING_TABLE = "cms_migrations";
|
||||
|
||||
interface MigrationFile {
|
||||
id: string;
|
||||
name: string;
|
||||
sql: string;
|
||||
}
|
||||
|
||||
function getDbConfig(): { url: string; database: string } {
|
||||
const url = process.env.DATABASE_URL;
|
||||
if (!url) throw new Error("DATABASE_URL is required");
|
||||
const dbName = url.split("/").pop()?.split("?")[0] ?? "atomcms";
|
||||
return { url, database: dbName };
|
||||
}
|
||||
|
||||
async function ensureConnection(): Promise<void> {
|
||||
const { database } = getDbConfig();
|
||||
const mysql = await import("mysql2/promise");
|
||||
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
|
||||
try {
|
||||
await conn.execute(
|
||||
`CREATE TABLE IF NOT EXISTS \`${TRACKING_TABLE}\` (
|
||||
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||
migration VARCHAR(255) NOT NULL UNIQUE,
|
||||
applied_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4`,
|
||||
);
|
||||
} finally {
|
||||
await conn.end();
|
||||
}
|
||||
}
|
||||
|
||||
async function getApplied(): Promise<Set<string>> {
|
||||
const mysql = await import("mysql2/promise");
|
||||
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
|
||||
try {
|
||||
const [rows] = await conn.execute(
|
||||
`SELECT migration FROM \`${TRACKING_TABLE}\` ORDER BY id`,
|
||||
);
|
||||
return new Set((rows as { migration: string }[]).map((r) => r.migration));
|
||||
} catch {
|
||||
return new Set();
|
||||
} finally {
|
||||
await conn.end();
|
||||
}
|
||||
}
|
||||
|
||||
function loadMigrations(): MigrationFile[] {
|
||||
const entries = readdirSync(MIGRATIONS_DIR, { withFileTypes: true });
|
||||
const files = entries
|
||||
.filter((e) => e.isFile() && e.name.endsWith(".sql"))
|
||||
.sort((a, b) => a.name.localeCompare(b.name));
|
||||
|
||||
return files.map((f) => {
|
||||
const id = f.name.replace(/\.sql$/, "");
|
||||
const sql = readFileSync(resolve(MIGRATIONS_DIR, f.name), "utf-8");
|
||||
return { id, name: f.name, sql };
|
||||
});
|
||||
}
|
||||
|
||||
async function apply(migration: MigrationFile): Promise<void> {
|
||||
const mysql = await import("mysql2/promise");
|
||||
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
|
||||
try {
|
||||
const statements = migration.sql
|
||||
.split(";")
|
||||
.map((s) => s.trim())
|
||||
.filter((s) => s.length > 0 && !s.startsWith("--"));
|
||||
|
||||
for (const stmt of statements) {
|
||||
await conn.execute(stmt);
|
||||
}
|
||||
|
||||
await conn.execute(
|
||||
`INSERT INTO \`${TRACKING_TABLE}\` (migration) VALUES (?)`,
|
||||
[migration.id],
|
||||
);
|
||||
console.log(`[migrate] Applied: ${migration.name}`);
|
||||
} finally {
|
||||
await conn.end();
|
||||
}
|
||||
}
|
||||
|
||||
async function main() {
|
||||
const flag = process.argv[2];
|
||||
|
||||
if (flag === "--status") {
|
||||
await ensureConnection();
|
||||
const applied = await getApplied();
|
||||
const all = loadMigrations();
|
||||
|
||||
console.log("\nMigration status:\n");
|
||||
for (const m of all) {
|
||||
const done = applied.has(m.id);
|
||||
console.log(` ${done ? "✓" : " "} ${m.name}${done ? "" : " [PENDING]"}`);
|
||||
}
|
||||
|
||||
const pending = all.filter((m) => !applied.has(m.id));
|
||||
const total = all.length;
|
||||
const done = total - pending.length;
|
||||
console.log(`\n${done}/${total} applied, ${pending.length} pending\n`);
|
||||
return;
|
||||
}
|
||||
|
||||
await ensureConnection();
|
||||
const applied = await getApplied();
|
||||
const pending = loadMigrations().filter((m) => !applied.has(m.id));
|
||||
|
||||
if (pending.length === 0) {
|
||||
console.log("[migrate] All migrations already applied.");
|
||||
return;
|
||||
}
|
||||
|
||||
console.log(`[migrate] Applying ${pending.length} migration(s)...\n`);
|
||||
for (const m of pending) {
|
||||
try {
|
||||
await apply(m);
|
||||
} catch (err) {
|
||||
console.error(`[migrate] FAILED: ${m.name}`, err);
|
||||
process.exit(1);
|
||||
}
|
||||
}
|
||||
console.log("\n[migrate] Done.");
|
||||
}
|
||||
|
||||
main().catch((err) => {
|
||||
console.error("[migrate] Fatal:", err);
|
||||
process.exit(1);
|
||||
});
|
||||
Reference in new issue
Block a user