Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Audit COMP-007: keep dependencies and CI actions current. Updates arrive as PRs through the normal flow (CI + review);
# `develop` is the production branch, so nothing here deploys on its own.
version: 2
updates:
- package-ecosystem: npm
directory: /
target-branch: develop
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 5
groups:
minor-and-patch:
update-types: [minor, patch]
commit-message:
prefix: "chore(deps)"
- package-ecosystem: github-actions
directory: /
target-branch: develop
schedule:
interval: weekly
day: monday
commit-message:
prefix: "chore(ci)"
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- uses: actions/setup-node@v4
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version-file: .nvmrc
cache: npm
Expand Down
19 changes: 19 additions & 0 deletions eslint.config.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,25 @@ const eslintConfig = defineConfig([
// Plain service worker script served as-is
"public/sw.js",
]),
// ADR-026: pages, components and libs reach the database only through src/server (the tenant layer). Type-only imports are fine.
{
files: ["src/app/**/*.{ts,tsx}", "src/components/**/*.{ts,tsx}", "src/lib/**/*.{ts,tsx}"],
ignores: ["**/*.test.{ts,tsx}"],
rules: {
"@typescript-eslint/no-restricted-imports": [
"error",
{
patterns: [
{
group: ["@/db", "@/db/*"],
allowTypeImports: true,
message: "Do not import the database outside src/server: go through getTenant() / createTenant() (ADR-026).",
},
],
},
],
},
},
]);

export default eslintConfig;
5 changes: 2 additions & 3 deletions src/app/(app)/cadastros/panels.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@ import { Badge } from "@/components/ui/badge";
import { ActionButton } from "./entity-dialog";
import { setOrganizationArchived, setProjectArchived } from "./actions";
import { OrganizationDialog, ProjectDialog, TagDialog } from "./entity-dialogs";
import { getDb } from "@/db";
import { authRolesByUser } from "@/server/auth/member-roles";
import { workspaceAuthRoles } from "@/server/workspace-auth-roles";
import { InviteMembersButton } from "./invite-members-button";
import { MemberAccessDialog } from "./member-access-dialog";
import { PendingInvitations } from "./pending-invitations";
Expand Down Expand Up @@ -157,7 +156,7 @@ export async function MembersPanel({ tenant, workspaceId, currentUserId }: { ten
const [members, assignable, authRoles] = await Promise.all([
tenant.projectMembers.overview(),
tenant.projectMembers.assignableProjects(),
authRolesByUser(getDb(), workspaceId),
workspaceAuthRoles(workspaceId),
]);
return (
<div className="flex flex-col gap-3">
Expand Down
5 changes: 5 additions & 0 deletions src/server/workspace-auth-roles.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
import { getDb } from "@/db";
import { authRolesByUser } from "./auth/member-roles";

/** Better Auth roles of a workspace's members. Lives under src/server so pages never import the database directly. */
export const workspaceAuthRoles = (workspaceId: string) => authRolesByUser(getDb(), workspaceId);
Loading