34 lines
2.1 KiB
Markdown
34 lines
2.1 KiB
Markdown
# Plumber — follow-ups
|
|
|
|
From the project review. Priority order within each section.
|
|
|
|
## Fix soon
|
|
|
|
- [x] **Persist sessions** — Sessions live in the app DB (`sessions` table): SQLite locally, `postgresstore` when `DATABASE_URL` is set. Opaque cookie unchanged; unused `SESSION_SECRET` removed from config / `.env.example`.
|
|
- [x] **Drop Dockerfile** — Deploying on DigitalOcean App Platform (buildpack from `go.mod`); no container image needed.
|
|
- [ ] **Rune-safe truncation** — `title[:120]`, `body[:8000]`, `city[:80]`, answer body, etc. can split multi-byte UTF-8. Truncate by runes (or safely).
|
|
- [x] **Admin bootstrap** — `ADMIN_USERNAME` seeds the first admin on register only when no admin exists. Promote/demote via `/admin/users` (admins only); roles stay in `users.role`.
|
|
|
|
## Docs & ops
|
|
|
|
- [ ] **README** — How to run locally, env vars (from `.env.example`), admin bootstrap, SQLite vs PlanetScale `DATABASE_URL`, App Platform notes (`PORT`, `SECURE_COOKIE=1`).
|
|
- [ ] **Migrations story** — Schema is applied on boot from `schema.sql` (+ sessions DDL). OK for v1; plan real migrations before schema drifts between SQLite and Postgres.
|
|
- [x] **App Platform listen port** — Prefers `PORT`, then `LISTEN`, then `:8080`.
|
|
- [x] **Prod DB = PlanetScale Postgres** — App already opens Postgres when `DATABASE_URL` is set; DSN cleanup strips PlanetScale/libpq-only params (`sslrootcert=system`, `sslnegotiation`). Use dashboard URI on **5432** for boot schema create; **6432** (PgBouncer) later if you need pooling.
|
|
|
|
## Smaller / later
|
|
|
|
- [ ] Rate-limit login/register (bcrypt helps; still open to brute-force).
|
|
- [ ] Graceful shutdown instead of bare `ListenAndServe`.
|
|
- [ ] More tests: vote HTMX paths, admin answer/hide, archive redirects; optional Postgres integration test.
|
|
- [ ] Watch dual-dialect schema — one SQL file works now; expect divergence later.
|
|
|
|
## Suggested order of attack
|
|
|
|
1. ~~Persist sessions~~ done.
|
|
2. ~~Drop Dockerfile~~ done (App Platform).
|
|
3. ~~Wire `PORT`~~ done.
|
|
4. ~~Admin roles page~~ done.
|
|
5. Short README (run, env, admin, App Platform + PlanetScale).
|
|
6. Rune-safe truncation + a couple of handler tests (vote, admin hide).
|