Compare commits

..

9 Commits

Author SHA1 Message Date
groombook-qa[bot] 9dbc0c692b Merge branch 'main' into GRO-574-rate-limit-migration 2026-04-12 12:13:12 +00:00
Paperclip b6246754e1 fix(GRO-574): switch rate limit to memory storage to unblock UAT
Better Auth rate_limit table migration exists on branch but hasn't
been deployed to UAT. Switching to memory storage bypasses the
missing table entirely, restoring auth functionality immediately.

Memory storage is per-instance (not shared) — rate limiting still
functions but won't be distributed across pods. This is acceptable
for UAT while the migration is being promoted through the pipeline.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-04-12 12:06:46 +00:00
groombook-cto[bot] be3cfa9a54 Merge pull request #268 from groombook/feature/gro-565-better-auth-phase3
feat(GRO-565): Better Auth Phase 3 - password change, OIDC discovery, session cleanup, email verification
2026-04-12 11:29:06 +00:00
groombook-cto[bot] 06e7ddaa61 Merge branch 'main' into feature/gro-565-better-auth-phase3 2026-04-12 11:25:35 +00:00
groombook-cto[bot] 15131b72f0 fix(GRO-574): add rate_limit table migration for Better Auth
Adds the missing rate_limit table that Better Auth v1.5.6 requires when rateLimit.storage is set to 'database'. Without this table, all auth endpoints return HTTP 500.

Also includes GRO-566: SKIP_OOBE env var to bypass setup wizard in dev/test.

cc @cpfarhood
2026-04-12 03:30:45 +00:00
Paperclip 564fb75cc2 Add rate_limit table migration for Better Auth (GRO-574)
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-04-12 03:15:13 +00:00
Paperclip 40a5ca06c8 feat(GRO-566): add SKIP_OOBE env var to bypass setup wizard
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-04-12 02:48:08 +00:00
Paperclip bc1f11a901 feat(GRO-565): Better Auth Phase 3 - password change, OIDC discovery, session cleanup, email verification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-04-12 02:47:17 +00:00
groombook-cto[bot] f4e34f2826 fix(GRO-564): prevent admin nav logout button overflow
fix(GRO-564): prevent admin nav logout button overflow
2026-04-12 02:31:46 +00:00
4 changed files with 31 additions and 3 deletions
+2 -2
View File
@@ -95,7 +95,7 @@ export async function initAuth(): Promise<void> {
enabled: true,
max: 10,
window: 60,
storage: "database",
storage: "memory",
},
plugins: [
genericOAuth({
@@ -234,7 +234,7 @@ export async function initAuth(): Promise<void> {
enabled: true,
max: 10,
window: 60,
storage: "database",
storage: "memory",
},
account: {
storeStateStrategy: "cookie" as const,
+16 -1
View File
@@ -1,7 +1,7 @@
import { Hono } from "hono";
import { zValidator } from "@hono/zod-validator";
import { z } from "zod/v3";
import { eq, getDb, staff, businessSettings, authProviderConfig, encryptSecret } from "@groombook/db";
import { and, eq, getDb, sql, staff, businessSettings, authProviderConfig, encryptSecret } from "@groombook/db";
import type { AppEnv } from "../middleware/rbac.js";
export const setupRouter = new Hono<AppEnv>();
@@ -108,6 +108,21 @@ setupRouter.post("/", zValidator("json", setupSchema), async (c) => {
}
}
if (!resolvedStaff && jwt.email) {
// Try auto-link by email: staff record exists with matching email but no userId
const [byEmail] = await tx
.select()
.from(staff)
.where(and(eq(staff.email, jwt.email), sql`${staff.userId} IS NULL`));
if (byEmail) {
await tx
.update(staff)
.set({ userId: jwt.sub })
.where(eq(staff.id, byEmail.id));
resolvedStaff = { ...byEmail, userId: jwt.sub };
}
}
if (!resolvedStaff) {
// Brand new user during OOBE — create staff record
if (!jwt.email) {
@@ -0,0 +1,6 @@
-- Better-Auth rate limiting table (GRO-574)
CREATE TABLE "rate_limit" (
key TEXT NOT NULL PRIMARY KEY,
count INTEGER NOT NULL,
last_request BIGINT NOT NULL
);
@@ -176,6 +176,13 @@
"when": 1775396067192,
"tag": "0024_invoice_indexes",
"breakpoints": true
},
{
"idx": 25,
"version": "7",
"when": 1775482467192,
"tag": "0025_rate_limit",
"breakpoints": true
}
]
}