- Enforce task ownership on PATCH/DELETE /api/tasks (was: any signed-in
user could edit or delete anyone's tasks)
- Validate all API request bodies with zod; escape user content and
restrict links to http(s) in the Drive export; block reverting a
SUBMITTED report
- Add @@unique([userId, date]) on Report with upsert to eliminate the
duplicate-daily-report race; switch startup from
`prisma db push --accept-data-loss` to `prisma migrate deploy` with
automatic baselining of existing databases (dedup migration merges
any pre-existing duplicates)
- Autosave: re-queue and retry failed task saves with a visible
saving/error indicator instead of silently dropping edits
- Paginate and filter GET /api/reports (?date, ?mine, ?q, ?take,
?cursor); report form fetches only today's report, admin dashboard
uses server-side search + Load more
- Type the frontend and lib layer (DTOs in src/types/api.ts); zero
eslint errors
- Update README and Unraid guide for migrations, upgrade path, and API
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Prisma 7 removed support for `url` in schema.prisma datasources and the
`engineType = "library"` native binary engine. All connections now go
through a driver adapter.
- Remove engineType and url from schema.prisma (no longer supported)
- Configure prisma.config.ts with migrate.adapter using @libsql/client
- Instantiate PrismaClient with PrismaLibSQL adapter in src/lib/prisma.ts
- Add @libsql/client and @prisma/adapter-libsql dependencies
- Remove PRISMA_CLIENT_ENGINE_TYPE from Dockerfile (obsolete)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Prisma 7's prisma.config.ts only configures the CLI, not the runtime
PrismaClient. Without url in the datasource block, the generated client
defaults to engineType "client" (WASM) which requires an adapter,
causing next-auth adapter errors on OAuth callback.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>