a9df9c0cf4
Build and Push Docker Image / build (push) Successful in 2m26s
- Enforce task ownership on PATCH/DELETE /api/tasks (was: any signed-in user could edit or delete anyone's tasks) - Validate all API request bodies with zod; escape user content and restrict links to http(s) in the Drive export; block reverting a SUBMITTED report - Add @@unique([userId, date]) on Report with upsert to eliminate the duplicate-daily-report race; switch startup from `prisma db push --accept-data-loss` to `prisma migrate deploy` with automatic baselining of existing databases (dedup migration merges any pre-existing duplicates) - Autosave: re-queue and retry failed task saves with a visible saving/error indicator instead of silently dropping edits - Paginate and filter GET /api/reports (?date, ?mine, ?q, ?take, ?cursor); report form fetches only today's report, admin dashboard uses server-side search + Load more - Type the frontend and lib layer (DTOs in src/types/api.ts); zero eslint errors - Update README and Unraid guide for migrations, upgrade path, and API Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
46 lines
1.2 KiB
TypeScript
46 lines
1.2 KiB
TypeScript
import { NextAuthOptions } from "next-auth";
|
|
import GoogleProvider from "next-auth/providers/google";
|
|
import { PrismaAdapter } from "@next-auth/prisma-adapter";
|
|
import { prisma } from "@/lib/prisma";
|
|
|
|
export const authOptions: NextAuthOptions = {
|
|
adapter: PrismaAdapter(prisma),
|
|
session: {
|
|
strategy: "database",
|
|
},
|
|
providers: [
|
|
GoogleProvider({
|
|
clientId: process.env.GOOGLE_CLIENT_ID!,
|
|
clientSecret: process.env.GOOGLE_CLIENT_SECRET!,
|
|
authorization: {
|
|
params: {
|
|
scope: "openid email profile https://www.googleapis.com/auth/drive.file",
|
|
prompt: "consent",
|
|
access_type: "offline",
|
|
response_type: "code",
|
|
},
|
|
},
|
|
}),
|
|
],
|
|
callbacks: {
|
|
async session({ session, user }) {
|
|
if (session?.user && user) {
|
|
session.user.id = user.id;
|
|
session.user.role = user.role || 'EMPLOYEE';
|
|
}
|
|
return session;
|
|
},
|
|
},
|
|
events: {
|
|
async createUser({ user }) {
|
|
const userCount = await prisma.user.count();
|
|
if (userCount === 1) {
|
|
await prisma.user.update({
|
|
where: { id: user.id },
|
|
data: { role: 'ADMIN' },
|
|
});
|
|
}
|
|
},
|
|
},
|
|
};
|