- Enforce task ownership on PATCH/DELETE /api/tasks (was: any signed-in
user could edit or delete anyone's tasks)
- Validate all API request bodies with zod; escape user content and
restrict links to http(s) in the Drive export; block reverting a
SUBMITTED report
- Add @@unique([userId, date]) on Report with upsert to eliminate the
duplicate-daily-report race; switch startup from
`prisma db push --accept-data-loss` to `prisma migrate deploy` with
automatic baselining of existing databases (dedup migration merges
any pre-existing duplicates)
- Autosave: re-queue and retry failed task saves with a visible
saving/error indicator instead of silently dropping edits
- Paginate and filter GET /api/reports (?date, ?mine, ?q, ?take,
?cursor); report form fetches only today's report, admin dashboard
uses server-side search + Load more
- Type the frontend and lib layer (DTOs in src/types/api.ts); zero
eslint errors
- Update README and Unraid guide for migrations, upgrade path, and API
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
PrismaLibSql constructor takes a Config object (with url), not a
pre-created Client instance. Remove the unnecessary createClient call
and the @libsql/client direct dependency.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Prisma 7 removed support for `url` in schema.prisma datasources and the
`engineType = "library"` native binary engine. All connections now go
through a driver adapter.
- Remove engineType and url from schema.prisma (no longer supported)
- Configure prisma.config.ts with migrate.adapter using @libsql/client
- Instantiate PrismaClient with PrismaLibSQL adapter in src/lib/prisma.ts
- Add @libsql/client and @prisma/adapter-libsql dependencies
- Remove PRISMA_CLIENT_ENGINE_TYPE from Dockerfile (obsolete)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>