Harden API, data layer, and autosave; add validation, pagination, migrations
Build and Push Docker Image / build (push) Successful in 2m26s

- Enforce task ownership on PATCH/DELETE /api/tasks (was: any signed-in
  user could edit or delete anyone's tasks)
- Validate all API request bodies with zod; escape user content and
  restrict links to http(s) in the Drive export; block reverting a
  SUBMITTED report
- Add @@unique([userId, date]) on Report with upsert to eliminate the
  duplicate-daily-report race; switch startup from
  `prisma db push --accept-data-loss` to `prisma migrate deploy` with
  automatic baselining of existing databases (dedup migration merges
  any pre-existing duplicates)
- Autosave: re-queue and retry failed task saves with a visible
  saving/error indicator instead of silently dropping edits
- Paginate and filter GET /api/reports (?date, ?mine, ?q, ?take,
  ?cursor); report form fetches only today's report, admin dashboard
  uses server-side search + Load more
- Type the frontend and lib layer (DTOs in src/types/api.ts); zero
  eslint errors
- Update README and Unraid guide for migrations, upgrade path, and API

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-01 19:43:36 -05:00
parent d8efa71992
commit a9df9c0cf4
22 changed files with 636 additions and 148 deletions
+7 -1
View File
@@ -70,5 +70,11 @@ For the application to work, you must configure your Google Cloud Project:
1. **Authorized Redirect URIs**: `http://[your-unraid-ip]:3000/api/auth/callback/google`
2. **Scopes**: Enable `Google Drive API` and ensure `auth/drive.file` scope is requested.
## Database & Upgrades
The database schema is managed by Prisma Migrate: every container start runs `prisma migrate deploy`, which applies any pending schema migrations automatically before the server boots.
**Upgrading from a version prior to migrations** (i.e. a database created by the old `db push` startup): the first boot after the upgrade will log a one-time `P3005` error followed by `Migration 0_init marked as applied.` — this is the automatic baseline step and is expected. No manual action is required, and your data is preserved. Any duplicate reports for the same user and day (a bug in older versions) are merged automatically during this migration.
## Support
The database is a single SQLite file located at `/mnt/user/appdata/wfh-daily-report/data/dev.db`. You can back this file up directly.
The database is a single SQLite file located at `/mnt/user/appdata/wfh-daily-report/data/dev.db`. You can back this file up directly (ideally while the container is stopped, or copy the file atomically).