Skip to content

CodeLit's Platform based migration - #194

Open
rajat1saxena wants to merge 11 commits into
mainfrom
platform-based-rewrite
Open

rajat1saxena wants to merge 11 commits into
mainfrom
platform-based-rewrite

Conversation

@rajat1saxena

Copy link
Copy Markdown
Member

No description provided.

@rajat1saxena rajat1saxena self-assigned this Oct 2, 2026
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

if (
!process.env.CLOUD_BUCKET_NAME ||
!process.env.CLOUD_PUBLIC_BUCKET_NAME
) {

P1 Badge Configure the public bucket in the Compose deployment

The startup validation now requires CLOUD_PUBLIC_BUCKET_NAME, but the production docker-compose.yml only passes CLOUD_BUCKET_NAME to the API and has no way to forward the public bucket variable. Consequently, the documented Compose deployment exits during checkConfig() before serving requests, even when all of its currently required environment variables are supplied.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docker-compose.yml Outdated

services:
postgres:
image: postgres:16

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Mount persistent storage for Postgres

The new production Postgres service has no volumes entry, so all accounts, API keys, media metadata, sessions, and billing records live only in the container writable layer. Running docker compose down, recreating the database container, or moving the service to another host will start with an empty database and irreversibly orphan existing S3 objects.

Useful? React with 👍 / 👎.

Comment thread apps/api/src/index.ts
Comment on lines +146 to +155
const publicApiUrl = (
process.env.PUBLIC_API_URL ||
process.env.API_SERVER ||
`http://127.0.0.1:${port}`
).replace(/\/$/, "");
const webOrigin = (
process.env.WEB_ORIGIN ||
process.env.WEB_CLIENT ||
"http://localhost:3000"
).replace(/\/$/, "");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pass external auth origins to the Compose API

In the production Compose deployment, SITE_ADDRESS is supplied only to Caddy; neither PUBLIC_API_URL/API_SERVER nor WEB_ORIGIN/WEB_CLIENT reaches the API. The new auth initialization therefore advertises http://127.0.0.1:8000 as its issuer and seeds redirects to http://localhost:3000, so OAuth and dashboard sign-in redirects on an externally served Compose instance point at the visitor's local machine instead of the deployed site.

Useful? React with 👍 / 👎.

Lemon had no subscriptions. OSS mode and an empty Dodo configuration now build an engine with no providers, offers, or catalog revision. Paid checkout still requires the full cloud catalog.
Root lint was parsing every JavaScript file with next/babel, which does not resolve outside the Next app. The legacy token and revoke routes are now rate-limited, refresh tokens are checked before new tokens are issued, and userinfo reads the bearer credential without a backtracking expression.
CodeQL types better-auth's handler property as undefined, and a typeof guard does not change that. An optional call is skipped by that query and still returns 500 when the handler is missing.
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
CodeQL treats better-auth's handler property as undefined, including through a typeof guard and optional chaining. Reflect.apply keeps the called value a known function.
Comment thread apps/api/src/auth/legacy-oauth.ts Fixed
rajat1saxena and others added 6 commits October 3, 2026 14:07
CodeQL was reporting new Request as a call of undefined. The type-only Express import used the same name as the fetch constructor. The legacy forward path calls better-auth's handler directly again.
- Remove the scripts package’s duplicate database layer and migration files
- Require the API to apply migrations before running the Mongo import
- Add Drizzle migration config and metadata
- Run migrations via a dedicated command and Compose init service
- Document the migration workflow
- Adopt the Platform packages at 0.2.0 (billing, mcp-server-kit,
  oauth-server-kit, observability, platform, platform-conformance), the
  platform manifest, the managed conformance workflow, and Dependabot.
- Add `createApp` so production and tests serve the same HTTP stack, and a
  `test:conformance` suite that runs Platform MCP OAuth discovery against
  the real app on PGlite.
- Remove the legacy OAuth endpoints and self-signed JWTs, drop
  `legacy_revoked_tokens`, and replace `OAUTH_SIGNING_KEY` with a required
  `BETTER_AUTH_SECRET`. Deployments must set BETTER_AUTH_SECRET to the
  previous OAUTH_SIGNING_KEY value to keep existing sessions.
- Handle the `malformed` credential selection from @codelitdev/platform.
- Upgrade the AWS SDK so S3 XML parsing no longer depends on the
  overridden fast-xml-parser, which broke media sealing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants