From 543e311b97366bb6c86c13b9437dd44242987f58 Mon Sep 17 00:00:00 2001 From: Vinicius Garcia Date: Fri, 9 Oct 2026 22:41:15 +0000 Subject: [PATCH 1/2] chore(ci): Dependabot e regra de lint contra @/db fora de src/server (auditoria COMP-007, 009) - dependabot semanal para npm (agrupando minor/patch) e github-actions, com alvo em develop - no-restricted-imports bloqueia @/db em app, components e lib (type-only liberado); painel de membros passa a usar src/server/workspace-auth-roles Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01VDxbrneS3TEAUmdgVmkKpQ --- .github/dependabot.yml | 24 ++++++++++++++++++++++++ eslint.config.mjs | 19 +++++++++++++++++++ src/app/(app)/cadastros/panels.tsx | 5 ++--- src/server/workspace-auth-roles.ts | 5 +++++ 4 files changed, 50 insertions(+), 3 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 src/server/workspace-auth-roles.ts diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..a6a86e8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,24 @@ +# Audit COMP-007: keep dependencies and CI actions current. Updates arrive as PRs through the normal flow (CI + review); +# `develop` is the production branch, so nothing here deploys on its own. +version: 2 +updates: + - package-ecosystem: npm + directory: / + target-branch: develop + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 5 + groups: + minor-and-patch: + update-types: [minor, patch] + commit-message: + prefix: "chore(deps)" + - package-ecosystem: github-actions + directory: / + target-branch: develop + schedule: + interval: weekly + day: monday + commit-message: + prefix: "chore(ci)" diff --git a/eslint.config.mjs b/eslint.config.mjs index 5248082..5cbe259 100644 --- a/eslint.config.mjs +++ b/eslint.config.mjs @@ -15,6 +15,25 @@ const eslintConfig = defineConfig([ // Plain service worker script served as-is "public/sw.js", ]), + // ADR-026: pages, components and libs reach the database only through src/server (the tenant layer). Type-only imports are fine. + { + files: ["src/app/**/*.{ts,tsx}", "src/components/**/*.{ts,tsx}", "src/lib/**/*.{ts,tsx}"], + ignores: ["**/*.test.{ts,tsx}"], + rules: { + "@typescript-eslint/no-restricted-imports": [ + "error", + { + patterns: [ + { + group: ["@/db", "@/db/*"], + allowTypeImports: true, + message: "Do not import the database outside src/server: go through getTenant() / createTenant() (ADR-026).", + }, + ], + }, + ], + }, + }, ]); export default eslintConfig; diff --git a/src/app/(app)/cadastros/panels.tsx b/src/app/(app)/cadastros/panels.tsx index 75ab16f..62f279b 100644 --- a/src/app/(app)/cadastros/panels.tsx +++ b/src/app/(app)/cadastros/panels.tsx @@ -4,8 +4,7 @@ import { Badge } from "@/components/ui/badge"; import { ActionButton } from "./entity-dialog"; import { setOrganizationArchived, setProjectArchived } from "./actions"; import { OrganizationDialog, ProjectDialog, TagDialog } from "./entity-dialogs"; -import { getDb } from "@/db"; -import { authRolesByUser } from "@/server/auth/member-roles"; +import { workspaceAuthRoles } from "@/server/workspace-auth-roles"; import { InviteMembersButton } from "./invite-members-button"; import { MemberAccessDialog } from "./member-access-dialog"; import { PendingInvitations } from "./pending-invitations"; @@ -157,7 +156,7 @@ export async function MembersPanel({ tenant, workspaceId, currentUserId }: { ten const [members, assignable, authRoles] = await Promise.all([ tenant.projectMembers.overview(), tenant.projectMembers.assignableProjects(), - authRolesByUser(getDb(), workspaceId), + workspaceAuthRoles(workspaceId), ]); return (
diff --git a/src/server/workspace-auth-roles.ts b/src/server/workspace-auth-roles.ts new file mode 100644 index 0000000..4485bbc --- /dev/null +++ b/src/server/workspace-auth-roles.ts @@ -0,0 +1,5 @@ +import { getDb } from "@/db"; +import { authRolesByUser } from "./auth/member-roles"; + +/** Better Auth roles of a workspace's members. Lives under src/server so pages never import the database directly. */ +export const workspaceAuthRoles = (workspaceId: string) => authRolesByUser(getDb(), workspaceId); From 467d73d0bd6c1ca83dca862b9835608987e3cf80 Mon Sep 17 00:00:00 2001 From: Vinicius Garcia Date: Fri, 9 Oct 2026 22:43:16 +0000 Subject: [PATCH 2/2] chore(ci): fixa actions/checkout e actions/setup-node por SHA (auditoria COMP-007) Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01VDxbrneS3TEAUmdgVmkKpQ --- .github/workflows/ci.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 65f899c..425d86f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,9 +19,9 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version-file: .nvmrc cache: npm