refactor(db): migrate staff and app actions from Prisma facade to Drizzle

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-31 21:35:05 +02:00
1 parent 9854719cfd
commit ed9c23c702
85 files changed
+2612 -1832

No files matched your search

+17 -8
View File
@@ -1,10 +1,11 @@
"use server";
import { and, eq, sql } from "drizzle-orm";
import { auth, signOut } from "@/lib/auth";
import { invalidateJwtVersionCache } from "@/lib/auth/jwt-version-cache";
import { personalTokenScope } from "@/lib/auth/personal-token-scope";
import { db, PersonalAccessTokens, User } from "@/lib/db";
import { logger } from "@/lib/logger";
import { prisma } from "@/lib/prisma";
/**
* Invalidate every CMS JWT for the signed-in user by bumping website_jwt_version,
@@ -19,10 +20,12 @@ export async function signOutEverywhere(): Promise<void> {
}
try {
await prisma.user.update({
where: { id: userId },
data: { websiteJwtVersion: { increment: 1 } },
});
await db
.update(User)
.set({
websiteJwtVersion: sql`${User.websiteJwtVersion} + 1`,
})
.where(eq(User.id, userId));
await invalidateJwtVersionCache(userId);
} catch (err) {
logger.warn("Failed to bump JWT version during sign-out-everywhere", {
@@ -33,9 +36,15 @@ export async function signOutEverywhere(): Promise<void> {
// Revoke API bearer tokens (Sanctum / personal_access_tokens).
try {
await prisma.personalAccessTokens.deleteMany({
where: personalTokenScope(userId),
});
const scope = personalTokenScope(userId);
await db
.delete(PersonalAccessTokens)
.where(
and(
eq(PersonalAccessTokens.tokenableId, scope.tokenableId),
eq(PersonalAccessTokens.tokenableType, scope.tokenableType),
),
);
} catch (err) {
logger.warn(
"Failed to revoke personal access tokens during sign-out-everywhere",