CarterPerez-dev
|
697f4909d7
|
fix(canary-phase1): clear all post-phase-1 audit observations + header normalization
No 'logged for later' — every non-blocking finding from the Phase 1 audits
is fixed now, in this commit, before declaring the phase truly closed.
Code cleanups (5 items):
1. Database.SQLDB() *sql.DB accessor on core.Database; main.go uses
db.SQLDB() instead of the awkward db.DB.DB triple-chain.
2. Hoisted list-default literals (50, 20) to package-level
defaultListLimit consts in token + event repositories. MEMORY.md
'no magic numbers' rule honored.
3. Moved ptr[T any] helper to internal/testutil/ptr.go as testutil.Ptr;
removed local copies from token + event repository_test.go.
4. Renamed CHECK constraints in 0001_create_tokens.sql to match spec
text exactly: chk_token_type → chk_type, chk_alert_channel → chk_channel.
Spec was the original contract; impl now aligns.
5. Resolved APP_ENVIRONMENT vs ENVIRONMENT divergence per spec §12.1:
- compose.yml: ENVIRONMENT=production → APP_ENVIRONMENT=production
- dev.compose.yml: ENVIRONMENT=development → APP_ENVIRONMENT=development
- config.go envKeyMap: ENVIRONMENT → APP_ENVIRONMENT mapping
Concurrency bug fix (real, not just polish):
- core/migrations.go: added sync.Mutex around goose calls. goose's
package-level state (SetBaseFS, SetDialect) raced under t.Parallel()
testcontainers tests. Race detector caught it under -race after
parallel test counts climbed. Mutex serializes goose invocation
globally; testcontainer-parallelism otherwise unaffected.
Header normalization (50 files):
- Bulk-normalized every project file's header to canonical
'©AngelaMos | 2026' (no space, with © glyph, year 2026) per MEMORY.md
style rule. Eliminated 4 distinct non-canonical variants: '// AngelaMos',
'// ©AngelaMos | 2025', '// © AngelaMos | 202X', '# AngelaMos'.
- Verified clean: grep returns zero non-canonical headers across the
whole project tree (excluding gitignored docs/ and node_modules/).
Backlog discipline:
- Created docs/plans/BACKLOG.md with strict format: open items only,
HIGH/MEDIUM/LOW severity, must-clear-before-ship contract.
- BACKLOG currently has zero open items — every observation was fixed
here, not deferred. Closed-items section logs what was cleared.
Verification:
- go build ./... clean
- go vet ./... clean
- go test -tags=integration -race ./internal/token/... 11/11 PASS
- go test -tags=integration -race ./internal/event/... 9/9 PASS
- docker compose -f compose.yml config parses
- docker compose -f dev.compose.yml config parses
- grep for non-canonical headers zero matches
|
2026-05-10 06:15:26 -04:00 |
CarterPerez-dev
|
a2d6f09ab3
|
feat(canary): add project-root .env.example + idempotent init.sh
.env.example covers every env var the canary stack reads:
- Public: APP_NAME, NGINX_HOST_PORT, PUBLIC_BASE_URL, VITE_APP_TITLE, VITE_API_URL
- Anti-bot: TURNSTILE_SITE_KEY/SECRET + VITE_TURNSTILE_SITE_KEY (frontend mirror)
- Operator: OPERATOR_TOKEN (admin endpoints)
- DB: POSTGRES_PASSWORD + POSTGRES_DEV_PORT
- Cache: REDIS_DEV_PORT
- GeoIP: MAXMIND_ACCOUNT_ID/LICENSE_KEY (optional)
- Webhooks: WEBHOOK_HMAC_SECRET (optional)
- Fake MySQL: MYSQL_FAKE_ENABLED + MYSQL_HOST_PORT (optional, off by default)
- Logging: LOG_LEVEL, LOG_FORMAT
- Telemetry: OTEL_ENABLED, OTEL_EXPORTER_OTLP_ENDPOINT + Jaeger ports
- Tunnel: CLOUDFLARE_TUNNEL_TOKEN (for cloudflared.compose.yml)
scripts/init.sh rewritten as idempotent setup helper:
- Copies .env.example -> .env on first run
- Generates POSTGRES_PASSWORD + OPERATOR_TOKEN via openssl rand -hex 32 if blank
- Skips already-set values (idempotent)
- Conditionally fetches GeoLite2-City.mmdb when MAXMIND creds present
- All sed usage is operator-side (script run-time), not Claude tool-time
scripts/randomize-ports.sh kept as-is (operator helper for spinning up
sibling projects on non-conflicting ports).
|
2026-05-10 05:27:30 -04:00 |