mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-08-13 22:37:29 +00:00
Adds apps/pwa: an Express + libSQL/Turso app that is now the home of team credential sharing, with the moshcode-style auth stack ported and reskinned to match logicsrc.com (light theme, Inter, green accent). apps/pwa - auth: email/password (scrypt), passkeys (WebAuthn), CoinPay OAuth, cookie sessions, and lsk_ API keys for the CLI via a loopback OAuth-PKCE flow (/cli/authorize + /cli/token). Ported from the moshcode PWA. - credshare API (/api/credshare/*): teams, members, invites, vaults, sealed grants, ciphertext secrets, audit — authed by session OR Bearer lsk_ key. Zero-knowledge: only ciphertext + sealed vault keys + public keys stored. - teams dashboard, accept-invite, and settings (API keys) pages, server-rendered in the LogicSRC brand (lib/html.mjs). - migrations (libSQL) 001_auth + 002_credshare, migrate-on-boot; Turso via TURSO_DATABASE_URL / TURSO_AUTH_TOKEN, or a local file db for dev. - trimmed moshcode-specific approvals/credits/push/deliver. CLI - `logicsrc login` now does browser loopback OAuth-PKCE against the app and stores an lsk_ token (email-OTP removed); --token for CI. Client repointed. Distribution - install.sh (served at logicsrc.com/install.sh) installs the CLI from the GitHub repo: tarball -> npm install -> `npm run build:cli` -> logicsrc wrapper. - root build:cli builds only the CLI's workspace chain (skips web/api/next). Cleanup - removed the commandboard-api credshare backend (superseded by the PWA) and its Supabase/Turso stores + libsql dep; commandboard-api tests green (40). - removed the Next.js /teams page (the PWA is the web UI now). Verified end-to-end: two accounts register on the PWA, mint lsk_ keys, CLI login uploads identity keys, owner pushes an encrypted .env, teammate invited -> accepted -> granted -> pulls the exact file. Server stores ciphertext only. Full workspace build + tests green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
1.5 KiB
JavaScript
33 lines
1.5 KiB
JavaScript
// Apply SQL migrations in order. Idempotent — tracks applied files in _migrations.
|
|
import fs from "node:fs";
|
|
import path from "node:path";
|
|
import { fileURLToPath, pathToFileURL } from "node:url";
|
|
import { db, run, all } from "./db.mjs";
|
|
|
|
const HERE = path.dirname(fileURLToPath(import.meta.url));
|
|
const DIR = path.join(HERE, "migrations");
|
|
|
|
export async function migrate() {
|
|
// Bootstrap the tracking table (the first migration also declares it IF NOT EXISTS).
|
|
await run(`CREATE TABLE IF NOT EXISTS _migrations (name TEXT PRIMARY KEY, applied_at INTEGER NOT NULL)`);
|
|
const done = new Set((await all(`SELECT name FROM _migrations`)).map((r) => r.name));
|
|
|
|
const files = fs.readdirSync(DIR).filter((f) => f.endsWith(".sql")).sort();
|
|
for (const file of files) {
|
|
if (done.has(file)) { console.log(`· ${file} (already applied)`); continue; }
|
|
const sql = fs.readFileSync(path.join(DIR, file), "utf8");
|
|
// libSQL executes one statement per call — split on semicolons at line ends.
|
|
const statements = sql.split(/;\s*(?:\n|$)/).map((s) => s.trim()).filter(Boolean);
|
|
for (const stmt of statements) await run(stmt);
|
|
await run(`INSERT INTO _migrations (name, applied_at) VALUES (?, ?)`, [file, Date.now()]);
|
|
console.log(`✓ ${file}`);
|
|
}
|
|
console.log("migrations up to date");
|
|
}
|
|
|
|
// Run directly (npm run migrate) — not when imported by the server.
|
|
if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) {
|
|
migrate()
|
|
.then(() => db.close?.())
|
|
.catch((e) => { console.error(e); process.exit(1); });
|
|
}
|