Files
plumber/todo.md
T
codegirl007 afd2476f3c Harden sessions, uploads, admin demotion, and HTTP timeouts.
Address PR review findings: renew session tokens on auth, sniff/re-encode avatars, serialize last-admin checks, bound server timeouts, rune-safe truncation, and TEST_DATABASE_URL-only integration tests.
2026-08-22 07:24:39 -07:00

2.0 KiB

Plumber — follow-ups

From the project review. Priority order within each section.

Fix soon

  • Persist sessions — Sessions live in the app DB (sessions table) via postgresstore. Opaque cookie unchanged; unused SESSION_SECRET removed from config / .env.example.
  • Drop Dockerfile — Deploying on DigitalOcean App Platform (buildpack from go.mod); no container image needed.
  • Rune-safe truncationtitle[:120], body[:8000], city[:80], answer body, etc. can split multi-byte UTF-8. Truncate by runes (or safely).
  • Admin bootstrapADMIN_USERNAME seeds the first admin on register only when no admin exists. Promote/demote via /admin/users (admins only); roles stay in users.role.

Docs & ops

  • README — How to run locally, env vars (from .env.example), admin bootstrap, PlanetScale DATABASE_URL, App Platform notes (PORT, SECURE_COOKIE=1).
  • Migrations story — Schema is applied on boot from schema.sql (+ sessions DDL). OK for v1; plan real migrations before schema drifts.
  • App Platform listen port — Prefers PORT, then LISTEN, then :8080.
  • Prod DB = PlanetScale Postgres — App opens Postgres via required DATABASE_URL; DSN cleanup strips PlanetScale/libpq-only params (sslrootcert=system, sslnegotiation). Use dashboard URI on 5432 for boot schema create; 6432 (PgBouncer) later if you need pooling.

Smaller / later

  • Rate-limit login/register (bcrypt helps; still open to brute-force).
  • Graceful shutdown instead of bare ListenAndServe.
  • More tests: vote HTMX paths, admin answer/hide, archive redirects; optional Postgres integration test.

Suggested order of attack

  1. Persist sessions done.
  2. Drop Dockerfile done (App Platform).
  3. Wire PORT done.
  4. Admin roles page done.
  5. Short README (run, env, admin, App Platform + PlanetScale).
  6. Rune-safe truncation + a couple of handler tests (vote, admin hide).