Commit 0aa7603
authored
chore: upgrade Better Auth 1.7, unify deploys, guard db:push (#2181)
Better Auth 1.7 rekeys external identities, which is a required schema migration rather than a version bump. Working through it surfaced three rules the docs stated but nothing enforced — how a release deploys, where `db:push` may point, and which database role the workers run as — so each becomes a control.
New: scripts/deploy.ts (release path), db/scripts/guard-push.ts plus local-database.ts (push guard), db/scripts/grant-app-role.sql (least-privilege role), coverage config in vitest.config.ts.
Invariants to preserve when editing:
- An identity is keyed on `(issuer, accountId)`, never on `providerId`, which names only the local provider configuration. Do not restore `identity_provider_account_unique`: issuer is a function of providerId, so the new constraint implies it.
- `0000_init.sql` is regenerated in place under the squashed-init convention, never appended to. `0000_snapshot.json` must keep top-level `"version": "7"` — at `"1"` drizzle-kit rejects it, `db:generate` reports `data is malformed` and writes nothing, and `db:check` exits non-zero. The journal entry's own `version` is not read.
- `scripts/deploy.ts` is the only deploy path; deploy.yml calls it with `--skip-build`. Production is Wrangler's empty `--env` and the script owns that mapping, so do not inline `wrangler deploy` back into the workflow or spell the environment out twice.
- deploy.ts passes no `--env-file`. Wrangler already loads `.env` and `.env.local` from the cwd and merges them under `process.env`; listing them explicitly only suppresses `.env.<env>.local` on a staging deploy.
- `db:push` runs guard-push.ts first and refuses any non-loopback host. `ALLOW_REMOTE_DB_PUSH=1` is the sole bypass; widening the classifier in local-database.ts trains people to reach for it.
- grant-app-role.sql asserts database and `public` ownership before it creates anything, because Postgres answers an unauthorised REVOKE with a warning and exit 0. Removing the `DO` block makes a wrong-runner invocation report success with none of the boundary built.
- Tests run Vitest on Bun (`bun --bun vitest`); `coverage` runs it on Node. The inconsistency is deliberate — merging this suite's v8 coverage overflows Bun's stack inside `@bcoe/v8-coverage`.
- `coverage.include` must keep listing source globs. Without it an unimported module is absent from the total instead of reporting 0%, and excluding untested source to raise the number defeats the point.
- generate-auth-schema.ts must keep emitting table `indexes` and per-field `index`, `defaultValue` and `references.onDelete`. 1.7 moved the account identity key into exactly that metadata, and `/validate-auth-schema` reads this output as its source of truth.
Fixes the defect #2179 logged and left: `bun db:check` now passes. Also adds `ignoreRestSiblings` to `no-unused-vars`, so `const { password, ...rest }` is no longer an error.
Fresh clones run `bun db:push` after pulling. Forks syncing with `/merge-seed` will see it escalate on `0000_init.sql`, which is correct: keep local migration history and add `issuer` as a new migration with a backfill, since the column is NOT NULL with no default. docs/testing.md and docs/database/ carry the details.1 parent aceeb4f commit 0aa7603
38 files changed
Lines changed: 1134 additions & 517 deletions
File tree
- .claude/commands
- .github
- workflows
- apps
- api
- app
- web
- db
- migrations
- meta
- schema
- scripts
- docs
- auth
- database
- deployment
- getting-started
- security
- packages
- core
- ui
- ws-protocol
- scripts
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
67 | 71 | | |
68 | 72 | | |
69 | 73 | | |
| |||
168 | 172 | | |
169 | 173 | | |
170 | 174 | | |
171 | | - | |
172 | | - | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
179 | | - | |
180 | | - | |
181 | | - | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
34 | 35 | | |
35 | 36 | | |
36 | 37 | | |
37 | 38 | | |
38 | | - | |
| 39 | + | |
39 | 40 | | |
40 | 41 | | |
41 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
57 | | - | |
| 57 | + | |
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
| |||
172 | 172 | | |
173 | 173 | | |
174 | 174 | | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
179 | | - | |
180 | | - | |
181 | | - | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
182 | 178 | | |
183 | 179 | | |
| 180 | + | |
| 181 | + | |
184 | 182 | | |
185 | 183 | | |
186 | 184 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
22 | | - | |
| 21 | + | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | | - | |
41 | | - | |
| 40 | + | |
| 41 | + | |
42 | 42 | | |
43 | | - | |
44 | | - | |
| 43 | + | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
11 | | - | |
| 10 | + | |
12 | 11 | | |
13 | 12 | | |
14 | 13 | | |
15 | 14 | | |
16 | 15 | | |
17 | | - | |
18 | | - | |
| 16 | + | |
| 17 | + | |
19 | 18 | | |
20 | | - | |
21 | | - | |
| 19 | + | |
| 20 | + | |
22 | 21 | | |
23 | | - | |
| 22 | + | |
24 | 23 | | |
25 | | - | |
| 24 | + | |
26 | 25 | | |
27 | 26 | | |
28 | 27 | | |
| |||
32 | 31 | | |
33 | 32 | | |
34 | 33 | | |
35 | | - | |
36 | | - | |
| 34 | + | |
| 35 | + | |
37 | 36 | | |
38 | | - | |
| 37 | + | |
39 | 38 | | |
40 | 39 | | |
41 | | - | |
42 | | - | |
| 40 | + | |
| 41 | + | |
43 | 42 | | |
44 | 43 | | |
45 | 44 | | |
46 | | - | |
47 | | - | |
| 45 | + | |
| 46 | + | |
48 | 47 | | |
49 | 48 | | |
50 | 49 | | |
51 | | - | |
52 | | - | |
53 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
54 | 53 | | |
55 | 54 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | | - | |
19 | | - | |
| 18 | + | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
0 commit comments