Read calendar event creators from the admin module, and archive the old ones (#14)
Jenkins Production Deployment
Jenkins Production Deployment
Reviewed-on: #14 Co-authored-by: Patrick Müller <mail@pmueller.me> Co-committed-by: Patrick Müller <mail@pmueller.me>
This commit was merged in pull request #14.
This commit is contained in:
@@ -33,7 +33,11 @@ const localhostOrigins = [
|
||||
'http://localhost:3000',
|
||||
'http://localhost:3001',
|
||||
'http://localhost:3002',
|
||||
'http://localhost:3003'
|
||||
'http://localhost:3003',
|
||||
// The Angular calendar frontend; `ng serve` defaults to 4200. Missing from
|
||||
// this list, sign-out from the calendar answers 403 in dev only, which is a
|
||||
// confusing thing to debug against a production config that is fine.
|
||||
'http://localhost:4200'
|
||||
];
|
||||
|
||||
const trustedOrigins = isProd
|
||||
|
||||
@@ -79,7 +79,8 @@ const parseList = (value: string | undefined, fallback: string[]): string[] => {
|
||||
* They feed better-auth's `trustedOrigins`, which is what lets the tickets and
|
||||
* feedback admin areas call /admin/auth/sign-out from their own origin. That
|
||||
* became load-bearing with the step 4 cutover: before it, the only browser
|
||||
* origin that ever reached /admin/auth was the admin app itself.
|
||||
* origin that ever reached /admin/auth was the admin app itself. The calendar
|
||||
* joined them with its own cutover (docs/calendar-auth-migration.md step 4).
|
||||
*
|
||||
* Hence the production default rather than an empty list. An origin missing
|
||||
* here fails in a way that is easy to misread - sign-in works, the app works,
|
||||
@@ -89,7 +90,8 @@ const parseList = (value: string | undefined, fallback: string[]): string[] => {
|
||||
*/
|
||||
const DEFAULT_APP_ORIGINS = [
|
||||
'https://tickets.nachklang.art',
|
||||
'https://feedback.nachklang.art'
|
||||
'https://feedback.nachklang.art',
|
||||
'https://calendar.nachklang.art'
|
||||
];
|
||||
|
||||
export const APP_ORIGINS = parseList(process.env.APP_ORIGINS, DEFAULT_APP_ORIGINS)
|
||||
|
||||
@@ -437,3 +437,30 @@ export const findUserByEmail = async (email: string): Promise<{id: string; email
|
||||
|
||||
return row ?? null;
|
||||
};
|
||||
|
||||
/**
|
||||
* Display names for a set of user ids, as an id -> name map. Ids that no
|
||||
* longer exist are simply absent from the map rather than mapping to a
|
||||
* placeholder, so callers can distinguish "deleted account" from "never had
|
||||
* one" and choose their own fallback.
|
||||
*
|
||||
* This exists for the calendar migration (docs/calendar-auth-migration.md
|
||||
* step 3): the calendar lives in a different database, so it cannot join
|
||||
* against `user` to render "created by". One lookup per result set keeps that
|
||||
* cheap without coupling the two schemas.
|
||||
*/
|
||||
export const findDisplayNames = async (ids: readonly string[]): Promise<Map<string, string>> => {
|
||||
const distinct = Array.from(new Set(ids.filter(id => id)));
|
||||
if (distinct.length === 0) {
|
||||
// Kysely renders `in ()` for an empty list, which MariaDB rejects.
|
||||
return new Map();
|
||||
}
|
||||
|
||||
const rows = await db
|
||||
.selectFrom('user')
|
||||
.select(['id', 'name'])
|
||||
.where('id', 'in', distinct)
|
||||
.execute();
|
||||
|
||||
return new Map(rows.map(row => [row.id, row.name]));
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user