The database moved to a container of our own; the platform is gone. This takes out what was left of it — and, where the leftovers were load bearing, moves rather than deletes. Moved, not deleted: supabase/migrations/ -> db/migrations/ the schema's source of truth supabase/build-org.ts -> scripts/build-org.ts lib/supabase/types.ts -> lib/types.ts 52 import sites repointed The bookkeeping needed care. It lived in `supabase_migrations.schema_migrations`, and simply renaming the schema would have left the runner facing an empty table: it would have called all 67 migrations pending and replayed them against a database that is long since current. So the runner now creates `migrationen.schema_migrations` and, once, copies the old rows across — guarded so a second run does nothing and a fresh database skips it entirely. Only then does migration 20260907100000 drop the old schema. Deleted: the CLI config, the seed, the historical schema/function dumps (nothing read them), scripts/umzug-von-supabase.sh (the move is done), and both Supabase packages plus the CLI. Nothing in the application imported them — the build now succeeds with no environment variables at all, which is the proof. Integration tests: six of them signed in through Supabase Auth and asserted against the anon key and the service role. That model is gone, so the tests were not portable — they are deleted. session-context and employee-status-filter already ran on pg and are untouched; om-reporting is ported to a direct connection because it guards a real risk (the reporting line rule exists twice, once in SQL and once in TypeScript). CI: the integration job started a Supabase stack. It now runs a postgres service, applies deploy/db-init and every migration to an empty database — that was the valuable part, and it still holds — then checks that a second run is a no-op, which is what proves the bookkeeping works. Docs: security-review.md audited a service-role key, a cookie adapter and auth.users, none of which exist. Restating findings about removed components would suggest today's system had been reviewed; it has not. It now records what was removed and says a fresh review is due. data-model.md was already marked obsolete and described the pre-OM schema; azure-migration.md was a plan for a route not taken. Both deleted. Verified: npm ci, typecheck, lint, 445 tests, build — all clean without the packages. Integration tests skip cleanly with no database. Migration SQL and the runner are reviewed but NOT executed: no Docker here, and the old instance no longer resolves. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
159 lines
5.5 KiB
JavaScript
159 lines
5.5 KiB
JavaScript
#!/usr/bin/env node
|
|
// Guards lib/types.ts against drifting away from the migrations.
|
|
//
|
|
// That file is maintained by hand (its own header explains why: no DB
|
|
// Werkzeug erzeugt sie), so a new
|
|
// column reaches the database without the TypeScript side noticing — and
|
|
// `tsc` stays perfectly happy while the app reads a field that is typed but
|
|
// absent, or writes one that exists but is not typed.
|
|
//
|
|
// Reads the migrations rather than a live database on purpose: CI then needs
|
|
// no Postgres, and the migrations are the actual source of truth for what
|
|
// gets deployed.
|
|
|
|
import { readFileSync, readdirSync } from "node:fs";
|
|
import { dirname, join } from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const root = join(dirname(fileURLToPath(import.meta.url)), "..");
|
|
const migrationsDir = join(root, "db", "migrations");
|
|
|
|
// Columns are compared, not their types: the hand-written file deliberately
|
|
// uses richer unions than the SQL (`EmploymentStatus` for a text column with
|
|
// a check constraint), and flagging those would be noise.
|
|
const NON_COLUMN_START =
|
|
/^(constraint|check|primary|unique|foreign|exclude|like|inherits|partition|)$/i;
|
|
|
|
function stripComments(sql) {
|
|
return sql.replace(/--[^\n]*/g, "");
|
|
}
|
|
|
|
/** Splits on top-level commas only, so `numeric(10,2)` stays in one piece. */
|
|
function splitTopLevel(body) {
|
|
const parts = [];
|
|
let depth = 0;
|
|
let current = "";
|
|
for (const ch of body) {
|
|
if (ch === "(") depth++;
|
|
if (ch === ")") depth--;
|
|
if (ch === "," && depth === 0) {
|
|
parts.push(current);
|
|
current = "";
|
|
continue;
|
|
}
|
|
current += ch;
|
|
}
|
|
if (current.trim()) parts.push(current);
|
|
return parts;
|
|
}
|
|
|
|
function parseMigrations() {
|
|
const tables = new Map();
|
|
const files = readdirSync(migrationsDir).filter((f) => f.endsWith(".sql")).sort();
|
|
|
|
for (const file of files) {
|
|
const sql = stripComments(readFileSync(join(migrationsDir, file), "utf8"));
|
|
|
|
for (const match of sql.matchAll(/create table (?:if not exists )?(\w+)\s*\(/gi)) {
|
|
const name = match[1];
|
|
// Walk from the opening paren to its match so nested parens in column
|
|
// definitions do not end the table early.
|
|
let depth = 0;
|
|
let end = match.index + match[0].length - 1;
|
|
for (let i = end; i < sql.length; i++) {
|
|
if (sql[i] === "(") depth++;
|
|
else if (sql[i] === ")") {
|
|
depth--;
|
|
if (depth === 0) {
|
|
end = i;
|
|
break;
|
|
}
|
|
}
|
|
}
|
|
const body = sql.slice(match.index + match[0].length, end);
|
|
const columns = new Set();
|
|
for (const part of splitTopLevel(body)) {
|
|
const first = part.trim().split(/\s+/)[0] ?? "";
|
|
if (!first || NON_COLUMN_START.test(first)) continue;
|
|
columns.add(first.toLowerCase());
|
|
}
|
|
tables.set(name, columns);
|
|
}
|
|
|
|
for (const m of sql.matchAll(/alter table (?:if exists )?(\w+)\s+add column (?:if not exists )?(\w+)/gi)) {
|
|
tables.get(m[1])?.add(m[2].toLowerCase());
|
|
}
|
|
for (const m of sql.matchAll(/alter table (?:if exists )?(\w+)\s+drop column (?:if exists )?(\w+)/gi)) {
|
|
tables.get(m[1])?.delete(m[2].toLowerCase());
|
|
}
|
|
for (const m of sql.matchAll(/alter table (?:if exists )?(\w+)\s+rename column (\w+) to (\w+)/gi)) {
|
|
const t = tables.get(m[1]);
|
|
if (t?.delete(m[2].toLowerCase())) t.add(m[3].toLowerCase());
|
|
}
|
|
for (const m of sql.matchAll(/drop table (?:if exists )?(\w+)/gi)) {
|
|
tables.delete(m[1]);
|
|
}
|
|
}
|
|
return tables;
|
|
}
|
|
|
|
function parseTypes() {
|
|
const source = readFileSync(join(root, "lib", "types.ts"), "utf8");
|
|
const start = source.indexOf("Tables: {");
|
|
if (start === -1) throw new Error("Tables block not found in lib/types.ts");
|
|
|
|
const tables = new Map();
|
|
// Each entry looks like `name: NoRelationships & { Row: { … } … }`; the Row
|
|
// block is the one that has to match the database.
|
|
const entry = /^ {6}(\w+): /gm;
|
|
for (const m of source.slice(start).matchAll(entry)) {
|
|
const rest = source.slice(start + m.index);
|
|
const rowAt = rest.indexOf("Row: {");
|
|
if (rowAt === -1) continue;
|
|
let depth = 0;
|
|
let end = rowAt + "Row: ".length;
|
|
for (let i = end; i < rest.length; i++) {
|
|
if (rest[i] === "{") depth++;
|
|
else if (rest[i] === "}") {
|
|
depth--;
|
|
if (depth === 0) {
|
|
end = i;
|
|
break;
|
|
}
|
|
}
|
|
}
|
|
const body = rest.slice(rowAt + "Row: {".length, end);
|
|
const columns = new Set();
|
|
for (const f of body.matchAll(/(\w+)\s*\??\s*:/g)) columns.add(f[1].toLowerCase());
|
|
tables.set(m[1], columns);
|
|
}
|
|
return tables;
|
|
}
|
|
|
|
const sqlTables = parseMigrations();
|
|
const tsTables = parseTypes();
|
|
const problems = [];
|
|
|
|
for (const [name, columns] of tsTables) {
|
|
const sqlColumns = sqlTables.get(name);
|
|
if (!sqlColumns) {
|
|
problems.push(`Tabelle "${name}" ist in types.ts typisiert, existiert aber in keiner Migration.`);
|
|
continue;
|
|
}
|
|
for (const c of columns) {
|
|
if (!sqlColumns.has(c)) problems.push(`${name}.${c}: in types.ts typisiert, in den Migrationen nicht vorhanden.`);
|
|
}
|
|
for (const c of sqlColumns) {
|
|
if (!columns.has(c)) problems.push(`${name}.${c}: in den Migrationen vorhanden, in types.ts nicht typisiert.`);
|
|
}
|
|
}
|
|
|
|
if (problems.length > 0) {
|
|
console.error("Schema-Drift zwischen db/migrations und lib/types.ts:\n");
|
|
for (const p of problems.sort()) console.error(" - " + p);
|
|
console.error(`\n${problems.length} Abweichung(en). types.ts entsprechend nachziehen.`);
|
|
process.exit(1);
|
|
}
|
|
|
|
console.log(`Kein Schema-Drift: ${tsTables.size} typisierte Tabellen stimmen mit den Migrationen überein.`);
|