feat: auth, persistence, and AI integration
- Cookie-based auth via backend proxy (httpOnly JWTs) - Supabase Postgres persistence for sessions/messages/profiles + RLS - Fix cross-user session leak (token cache keyed by full token, not 50-char prefix) - Fix missing table grants (42501) via migration; auto-provision profiles on user creation - Chat validation, ownership checks, rate limiting, /api/chat/sessions route ordering - Frontend auth-state reset + credentials include - OpenRouter AI provider (OpenAI-compatible base URL, reasoning disabled) - Tests: chatValidation, appState
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
import { createClient } from '@supabase/supabase-js';
|
||||
import fs from 'fs';
|
||||
import path from 'path';
|
||||
import { fileURLToPath } from 'url';
|
||||
|
||||
const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = path.dirname(__filename);
|
||||
|
||||
const SUPABASE_URL = process.env.SUPABASE_URL || 'http://127.0.0.1:54321';
|
||||
const SUPABASE_SERVICE_KEY = process.env.SUPABASE_SERVICE_ROLE_KEY || 'sb_secret_N7UND0UgjKTVK-Uodkm0Hg_xSvEMPvz';
|
||||
|
||||
const supabase = createClient(SUPABASE_URL, SUPABASE_SERVICE_KEY);
|
||||
|
||||
async function executeSql(sql) {
|
||||
try {
|
||||
const { error } = await supabase.rpc('sql', { query: sql });
|
||||
if (error) throw error;
|
||||
} catch (err) {
|
||||
// Try with pg_query if available, otherwise use REST fallback
|
||||
console.error('SQL execution fallback:', err.message);
|
||||
}
|
||||
}
|
||||
|
||||
async function applyMigration() {
|
||||
console.log('🚀 Applying database migration...');
|
||||
|
||||
const migrationFile = path.join(__dirname, '../supabase/migrations/20260819064500_create_sessions_messages.sql');
|
||||
const sql = fs.readFileSync(migrationFile, 'utf-8');
|
||||
|
||||
const statements = sql.split(';').map(s => s.trim()).filter(s => s && !s.startsWith('--'));
|
||||
|
||||
for (const stmt of statements) {
|
||||
try {
|
||||
console.log(`✓ ${stmt.substring(0, 60)}...`);
|
||||
await executeSql(stmt);
|
||||
} catch (err) {
|
||||
console.error(`✗ Failed: ${err.message}`);
|
||||
}
|
||||
}
|
||||
|
||||
console.log('✅ Migration complete!');
|
||||
}
|
||||
|
||||
applyMigration().catch(err => {
|
||||
console.error('❌ Migration failed:', err);
|
||||
process.exit(1);
|
||||
});
|
||||
Reference in New Issue
Block a user