feat: auth, persistence, and AI integration

- Cookie-based auth via backend proxy (httpOnly JWTs)
- Supabase Postgres persistence for sessions/messages/profiles + RLS
- Fix cross-user session leak (token cache keyed by full token, not 50-char prefix)
- Fix missing table grants (42501) via migration; auto-provision profiles on user creation
- Chat validation, ownership checks, rate limiting, /api/chat/sessions route ordering
- Frontend auth-state reset + credentials include
- OpenRouter AI provider (OpenAI-compatible base URL, reasoning disabled)
- Tests: chatValidation, appState
This commit is contained in:
2026-08-19 09:41:40 -04:00
parent 93a35a7343
commit ff9da4d324
43 changed files with 4174 additions and 249 deletions
+47
View File
@@ -0,0 +1,47 @@
import { createClient } from '@supabase/supabase-js';
import fs from 'fs';
import path from 'path';
import { fileURLToPath } from 'url';
const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename);
const SUPABASE_URL = process.env.SUPABASE_URL || 'http://127.0.0.1:54321';
const SUPABASE_SERVICE_KEY = process.env.SUPABASE_SERVICE_ROLE_KEY || 'sb_secret_N7UND0UgjKTVK-Uodkm0Hg_xSvEMPvz';
const supabase = createClient(SUPABASE_URL, SUPABASE_SERVICE_KEY);
async function executeSql(sql) {
try {
const { error } = await supabase.rpc('sql', { query: sql });
if (error) throw error;
} catch (err) {
// Try with pg_query if available, otherwise use REST fallback
console.error('SQL execution fallback:', err.message);
}
}
async function applyMigration() {
console.log('🚀 Applying database migration...');
const migrationFile = path.join(__dirname, '../supabase/migrations/20260819064500_create_sessions_messages.sql');
const sql = fs.readFileSync(migrationFile, 'utf-8');
const statements = sql.split(';').map(s => s.trim()).filter(s => s && !s.startsWith('--'));
for (const stmt of statements) {
try {
console.log(`${stmt.substring(0, 60)}...`);
await executeSql(stmt);
} catch (err) {
console.error(`✗ Failed: ${err.message}`);
}
}
console.log('✅ Migration complete!');
}
applyMigration().catch(err => {
console.error('❌ Migration failed:', err);
process.exit(1);
});