Compare commits
339
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5981dca439 | ||
|
|
af73ce21fe | ||
|
|
1b4bb4830b | ||
|
|
0e31093a74 | ||
|
|
4ed98334f0 | ||
|
|
9921a9a896 | ||
|
|
0aaaa1fa7e | ||
|
|
2952083ef0 | ||
|
|
af886c00a3 | ||
|
|
99203b41dd | ||
|
|
af5811b206 | ||
|
|
7ec15f6af9 | ||
|
|
843791d1ee | ||
|
|
c404568baf | ||
|
|
4c1325cca9 | ||
|
|
5f784733cf | ||
|
|
109e9eead2 | ||
|
|
2705155c2e | ||
|
|
31abfcc2da | ||
|
|
617480df3a | ||
|
|
2cf7f9503e | ||
|
|
b827b3a7bd | ||
|
|
d4f4071ee4 | ||
|
|
caf8fa1053 | ||
|
|
7aafdf2b65 | ||
|
|
d568e189a0 | ||
|
|
d21548746c | ||
|
|
d5a58f710c | ||
|
|
77799ddce2 | ||
|
|
dc592aa79d | ||
|
|
f99ecc8e90 | ||
|
|
30cdcf7339 | ||
|
|
c1e7842cca | ||
|
|
978f6c5e88 | ||
|
|
9ccb0508b4 | ||
|
|
54c79e2b6f | ||
|
|
a6b5d4c570 | ||
|
|
19cce6e851 | ||
|
|
c8284f3f27 | ||
|
|
1ad91d413e | ||
|
|
263e4f6c32 | ||
|
|
e7d7e6aeac | ||
|
|
1408d08f38 | ||
|
|
3ccb6035b5 | ||
|
|
eb97698382 | ||
|
|
c3817a2e0a | ||
|
|
ddcfc62f54 | ||
|
|
1244cb74f6 | ||
|
|
3867fa934d | ||
|
|
880f522457 | ||
|
|
2724995f04 | ||
|
|
513f0c4781 | ||
|
|
126976b33f | ||
|
|
2a6073e5c2 | ||
|
|
1e91e2b50a | ||
|
|
8b57b27eb0 | ||
|
|
10473cb76f | ||
|
|
b2d3952309 | ||
|
|
0590fd306e | ||
|
|
1dd9d0eb42 | ||
|
|
b4aefb200e | ||
|
|
6800768d0b | ||
|
|
b8eb58d801 | ||
|
|
cbf081c0b2 | ||
|
|
639c52d9ab | ||
|
|
085f635cc4 | ||
|
|
baba5bbaa9 | ||
|
|
e426826edc | ||
|
|
583b7667be | ||
|
|
ce60abfbce | ||
|
|
effa28bdb5 | ||
|
|
53c72672ca | ||
|
|
2e30946472 | ||
|
|
f31e261811 | ||
|
|
5168a80b30 | ||
|
|
bfc02040ca | ||
|
|
1e65b74b8d | ||
|
|
a0f91e4b93 | ||
|
|
6ead6e6410 | ||
|
|
0df4ab5a74 | ||
|
|
afa7e0fa7d | ||
|
|
df0f8f612f | ||
|
|
fd68e10379 | ||
|
|
19e93b589e | ||
|
|
bd1e3c04f3 | ||
|
|
c78e97962b | ||
|
|
2aadaf8888 | ||
|
|
797d470468 | ||
|
|
120a1b88fb | ||
|
|
86b0ee68b9 | ||
|
|
a44bae5edd | ||
|
|
6950dec056 | ||
|
|
6e9d6fe7d4 | ||
|
|
5e115f1896 | ||
|
|
4b557e909c | ||
|
|
8c3d677af8 | ||
|
|
6687d842db | ||
|
|
4a969ad9ad | ||
|
|
0b1acdf136 | ||
|
|
13a98ca7e5 | ||
|
|
015c44af80 | ||
|
|
1ebfd522a3 | ||
|
|
82b47a3e76 | ||
|
|
0f59913c14 | ||
|
|
d5c7a6d109 | ||
|
|
c394f623eb | ||
|
|
adde340bbd | ||
|
|
32275c6068 | ||
|
|
ef2f06f824 | ||
|
|
8d5568b807 | ||
|
|
eaabf16b2c | ||
|
|
3c7e4f93d0 | ||
|
|
3f95f1c118 | ||
|
|
996a40ceb9 | ||
|
|
6c1f5e261d | ||
|
|
dc0de8a8dd | ||
|
|
898313f5a5 | ||
|
|
a279392ba9 | ||
|
|
6951b2d92a | ||
|
|
76444e2992 | ||
|
|
47c256a53c | ||
|
|
a0570a18ca | ||
|
|
58d31905ef | ||
|
|
b8c6bb093f | ||
|
|
24b22dc1df | ||
|
|
c9b249c969 | ||
|
|
f677204bc2 | ||
|
|
71b243ad9b | ||
|
|
7216556de2 | ||
|
|
223d81adbf | ||
|
|
e19ae608d9 | ||
|
|
be9c7dedae | ||
|
|
9bdbe333ad | ||
|
|
f1a686e39d | ||
|
|
d3bd1802cd | ||
|
|
3ae1dbb678 | ||
|
|
58476317a5 | ||
|
|
c670f29273 | ||
|
|
996d5f0e21 | ||
|
|
0dd914a87d | ||
|
|
febb9322a7 | ||
|
|
661014c893 | ||
|
|
53d328c2d9 | ||
|
|
5f81333e6e | ||
|
|
47922d48d7 | ||
|
|
3794b3eeff | ||
|
|
8feb0e2d6e | ||
|
|
4e0969ab71 | ||
|
|
3c20959060 | ||
|
|
4145145b74 | ||
|
|
9d7b8bf8f2 | ||
|
|
2425a8933b | ||
|
|
d1a3603837 | ||
|
|
70beab2c5e | ||
|
|
e5dab063db | ||
|
|
c7c1f59649 | ||
|
|
7fd0d7bdfe | ||
|
|
cf1e783d8f | ||
|
|
7542ffe53a | ||
|
|
ae45df36b8 | ||
|
|
1571168300 | ||
|
|
3f351a0900 | ||
|
|
5df098f630 | ||
|
|
6d7d88431b | ||
|
|
ebb928916c | ||
|
|
ce2b40daad | ||
|
|
e591d6cea1 | ||
|
|
ebd0e9f367 | ||
|
|
931bb5a0ba | ||
|
|
03a6a09bb0 | ||
|
|
548b0f51f3 | ||
|
|
c5fd6bbfa6 | ||
|
|
f97f5e9164 | ||
|
|
3a75915740 | ||
|
|
4dd6981e48 | ||
|
|
01aa7f4306 | ||
|
|
75a5795882 | ||
|
|
2709049f68 | ||
|
|
e81d4118aa | ||
|
|
c9638ebd9f | ||
|
|
47b0564ad6 | ||
|
|
fcc3fd4d92 | ||
|
|
db70856fb0 | ||
|
|
df1fbfda77 | ||
|
|
4d29ecc1c4 | ||
|
|
a8981b4950 | ||
|
|
9e0cc88a4a | ||
|
|
e0eaaa5b3d | ||
|
|
07f56a1b51 | ||
|
|
a3108dc5fa | ||
|
|
c2e4adc30b | ||
|
|
640aa0275f | ||
|
|
5401d3d5d2 | ||
|
|
c6a95059bd | ||
|
|
10d58b0832 | ||
|
|
d1957652f4 | ||
|
|
24e1266310 | ||
|
|
127af79601 | ||
|
|
1c0e32e19e | ||
|
|
2dc82a8ffb | ||
|
|
5a515d295e | ||
|
|
e828053799 | ||
|
|
8583d8cd21 | ||
|
|
f050eeaa7c | ||
|
|
321ddacc8f | ||
|
|
31b1f9ec30 | ||
|
|
b5ea475878 | ||
|
|
a5ccda79ba | ||
|
|
fd1fc0a9e1 | ||
|
|
6950852307 | ||
|
|
b0b2d15381 | ||
|
|
df8dd7c046 | ||
|
|
eca3f5f56c | ||
|
|
50cceb7ac9 | ||
|
|
e04a2bbb41 | ||
|
|
211fa25a9f | ||
|
|
ba9bd0c45c | ||
|
|
a8497211ba | ||
|
|
ec3dc72115 | ||
|
|
64294773c7 | ||
|
|
5723fe6ddc | ||
|
|
30d9225e24 | ||
|
|
07aa0bd98f | ||
|
|
14feeb0f9a | ||
|
|
6e79e34044 | ||
|
|
b2b251ab96 | ||
|
|
519004a8b9 | ||
|
|
d7831c64ff | ||
|
|
cab3c8a0be | ||
|
|
29193ef703 | ||
|
|
a61612cc64 | ||
|
|
6c14660208 | ||
|
|
e9a87848d6 | ||
|
|
a43166c46a | ||
|
|
c979fd9b89 | ||
|
|
a16e57b8b6 | ||
|
|
3a390b0900 | ||
|
|
a6d6b56543 | ||
|
|
d0d28cf680 | ||
|
|
fee8af5245 | ||
|
|
526258a284 | ||
|
|
8a9a299f91 | ||
|
|
f723c4be1b | ||
|
|
9a7cd85f05 | ||
|
|
7f66601a40 | ||
|
|
4e62b04701 | ||
|
|
2c6f390ddc | ||
|
|
02468b7522 | ||
|
|
4237049af5 | ||
|
|
79247f6d05 | ||
|
|
9386dce3ee | ||
|
|
bd109580ff | ||
|
|
8cad966eca | ||
|
|
ea317af943 | ||
|
|
725d7f5803 | ||
|
|
5d041f20f8 | ||
|
|
fb5304eb39 | ||
|
|
13b77e60cd | ||
|
|
e8e96c2e56 | ||
|
|
59a4fccdc5 | ||
|
|
22973a4ffc | ||
|
|
9131639a45 | ||
|
|
95534c4ad6 | ||
|
|
58b676e2fd | ||
|
|
b8ac2fd021 | ||
|
|
57fb7f1583 | ||
|
|
083e6f566a | ||
|
|
cc2d30eb2b | ||
|
|
17e17fea8f | ||
|
|
32a26a7849 | ||
|
|
52bcabcd22 | ||
|
|
e76a24b1f2 | ||
|
|
983390d65e | ||
|
|
f0f12d59d4 | ||
|
|
b381981cec | ||
|
|
26b5a7708c | ||
|
|
0c6b76d332 | ||
|
|
bf39419746 | ||
|
|
a31dea9c16 | ||
|
|
1353ac5678 | ||
|
|
a177f18eb4 | ||
|
|
ef757e4a4a | ||
|
|
9c421e0f99 | ||
|
|
3f4f95a925 | ||
|
|
5aab0a2436 | ||
|
|
86fce11bfe | ||
|
|
26fd570e53 | ||
|
|
196fa1a173 | ||
|
|
42146c0ac7 | ||
|
|
9bd9dae2d3 | ||
|
|
bbffa428bc | ||
|
|
ae851e0a20 | ||
|
|
71177d6076 | ||
|
|
2ddaba948a | ||
|
|
645ac31f4b | ||
|
|
84b58e84de | ||
|
|
15d99ed837 | ||
|
|
315b339c52 | ||
|
|
d1119beae7 | ||
|
|
1476e763dc | ||
|
|
6c37b60967 | ||
|
|
b0cfc00bd0 | ||
|
|
0d013f6356 | ||
|
|
30ea59b62f | ||
|
|
970da40a28 | ||
|
|
c3edd6efad | ||
|
|
612f84a863 | ||
|
|
6e9ea3e906 | ||
|
|
d4e024c312 | ||
|
|
cc6e1c6542 | ||
|
|
eb15d18676 | ||
|
|
1bbc0b5bb5 | ||
|
|
9ec1fc6c20 | ||
|
|
516a2af892 | ||
|
|
876eaa725a | ||
|
|
b3a0f1e26a | ||
|
|
d445bc00c4 | ||
|
|
7feb3e4e14 | ||
|
|
8f62d0bdde | ||
|
|
c936105455 | ||
|
|
94fed02d72 | ||
|
|
d006c4147f | ||
|
|
ef455e5482 | ||
|
|
965dbdf00b | ||
|
|
017f66e59c | ||
|
|
8a874e10e0 | ||
|
|
7c50bf6242 | ||
|
|
fb51399469 | ||
|
|
053394901c | ||
|
|
5e7ff9fa29 | ||
|
|
eaae5e92bf | ||
|
|
59b5cae07c | ||
|
|
644f0b2c92 | ||
|
|
cd0d693242 | ||
|
|
14f6e010a2 | ||
|
|
dba2b6f470 | ||
|
|
4f2340d923 | ||
|
|
1a7a3cbbd8 | ||
|
|
c21a3830bd |
@@ -1,133 +0,0 @@
|
||||
---
|
||||
name: find-skills
|
||||
description: Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
|
||||
---
|
||||
|
||||
# Find Skills
|
||||
|
||||
This skill helps you discover and install skills from the open agent skills ecosystem.
|
||||
|
||||
## When to Use This Skill
|
||||
|
||||
Use this skill when the user:
|
||||
|
||||
- Asks "how do I do X" where X might be a common task with an existing skill
|
||||
- Says "find a skill for X" or "is there a skill for X"
|
||||
- Asks "can you do X" where X is a specialized capability
|
||||
- Expresses interest in extending agent capabilities
|
||||
- Wants to search for tools, templates, or workflows
|
||||
- Mentions they wish they had help with a specific domain (design, testing, deployment, etc.)
|
||||
|
||||
## What is the Skills CLI?
|
||||
|
||||
The Skills CLI (`npx skills`) is the package manager for the open agent skills ecosystem. Skills are modular packages that extend agent capabilities with specialized knowledge, workflows, and tools.
|
||||
|
||||
**Key commands:**
|
||||
|
||||
- `npx skills find [query]` - Search for skills interactively or by keyword
|
||||
- `npx skills add <package>` - Install a skill from GitHub or other sources
|
||||
- `npx skills check` - Check for skill updates
|
||||
- `npx skills update` - Update all installed skills
|
||||
|
||||
**Browse skills at:** https://skills.sh/
|
||||
|
||||
## How to Help Users Find Skills
|
||||
|
||||
### Step 1: Understand What They Need
|
||||
|
||||
When a user asks for help with something, identify:
|
||||
|
||||
1. The domain (e.g., React, testing, design, deployment)
|
||||
2. The specific task (e.g., writing tests, creating animations, reviewing PRs)
|
||||
3. Whether this is a common enough task that a skill likely exists
|
||||
|
||||
### Step 2: Search for Skills
|
||||
|
||||
Run the find command with a relevant query:
|
||||
|
||||
```bash
|
||||
npx skills find [query]
|
||||
```
|
||||
|
||||
For example:
|
||||
|
||||
- User asks "how do I make my React app faster?" → `npx skills find react performance`
|
||||
- User asks "can you help me with PR reviews?" → `npx skills find pr review`
|
||||
- User asks "I need to create a changelog" → `npx skills find changelog`
|
||||
|
||||
The command will return results like:
|
||||
|
||||
```
|
||||
Install with npx skills add <owner/repo@skill>
|
||||
|
||||
vercel-labs/agent-skills@vercel-react-best-practices
|
||||
└ https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices
|
||||
```
|
||||
|
||||
### Step 3: Present Options to the User
|
||||
|
||||
When you find relevant skills, present them to the user with:
|
||||
|
||||
1. The skill name and what it does
|
||||
2. The install command they can run
|
||||
3. A link to learn more at skills.sh
|
||||
|
||||
Example response:
|
||||
|
||||
```
|
||||
I found a skill that might help! The "vercel-react-best-practices" skill provides
|
||||
React and Next.js performance optimization guidelines from Vercel Engineering.
|
||||
|
||||
To install it:
|
||||
npx skills add vercel-labs/agent-skills@vercel-react-best-practices
|
||||
|
||||
Learn more: https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices
|
||||
```
|
||||
|
||||
### Step 4: Offer to Install
|
||||
|
||||
If the user wants to proceed, you can install the skill for them:
|
||||
|
||||
```bash
|
||||
npx skills add <owner/repo@skill> -g -y
|
||||
```
|
||||
|
||||
The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts.
|
||||
|
||||
## Common Skill Categories
|
||||
|
||||
When searching, consider these common categories:
|
||||
|
||||
| Category | Example Queries |
|
||||
| --------------- | ---------------------------------------- |
|
||||
| Web Development | react, nextjs, typescript, css, tailwind |
|
||||
| Testing | testing, jest, playwright, e2e |
|
||||
| DevOps | deploy, docker, kubernetes, ci-cd |
|
||||
| Documentation | docs, readme, changelog, api-docs |
|
||||
| Code Quality | review, lint, refactor, best-practices |
|
||||
| Design | ui, ux, design-system, accessibility |
|
||||
| Productivity | workflow, automation, git |
|
||||
|
||||
## Tips for Effective Searches
|
||||
|
||||
1. **Use specific keywords**: "react testing" is better than just "testing"
|
||||
2. **Try alternative terms**: If "deploy" doesn't work, try "deployment" or "ci-cd"
|
||||
3. **Check popular sources**: Many skills come from `vercel-labs/agent-skills` or `ComposioHQ/awesome-claude-skills`
|
||||
|
||||
## When No Skills Are Found
|
||||
|
||||
If no relevant skills exist:
|
||||
|
||||
1. Acknowledge that no existing skill was found
|
||||
2. Offer to help with the task directly using your general capabilities
|
||||
3. Suggest the user could create their own skill with `npx skills init`
|
||||
|
||||
Example:
|
||||
|
||||
```
|
||||
I searched for skills related to "xyz" but didn't find any matches.
|
||||
I can still help you with this task directly! Would you like me to proceed?
|
||||
|
||||
If this is something you do often, you could create your own skill:
|
||||
npx skills init my-xyz-skill
|
||||
```
|
||||
@@ -0,0 +1,177 @@
|
||||
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
@@ -0,0 +1,42 @@
|
||||
---
|
||||
name: frontend-design
|
||||
description: Create distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, artifacts, posters, or applications (examples include websites, landing pages, dashboards, React components, HTML/CSS layouts, or when styling/beautifying any web UI). Generates creative, polished code and UI design that avoids generic AI aesthetics.
|
||||
license: Complete terms in LICENSE.txt
|
||||
---
|
||||
|
||||
This skill guides creation of distinctive, production-grade frontend interfaces that avoid generic "AI slop" aesthetics. Implement real working code with exceptional attention to aesthetic details and creative choices.
|
||||
|
||||
The user provides frontend requirements: a component, page, application, or interface to build. They may include context about the purpose, audience, or technical constraints.
|
||||
|
||||
## Design Thinking
|
||||
|
||||
Before coding, understand the context and commit to a BOLD aesthetic direction:
|
||||
- **Purpose**: What problem does this interface solve? Who uses it?
|
||||
- **Tone**: Pick an extreme: brutally minimal, maximalist chaos, retro-futuristic, organic/natural, luxury/refined, playful/toy-like, editorial/magazine, brutalist/raw, art deco/geometric, soft/pastel, industrial/utilitarian, etc. There are so many flavors to choose from. Use these for inspiration but design one that is true to the aesthetic direction.
|
||||
- **Constraints**: Technical requirements (framework, performance, accessibility).
|
||||
- **Differentiation**: What makes this UNFORGETTABLE? What's the one thing someone will remember?
|
||||
|
||||
**CRITICAL**: Choose a clear conceptual direction and execute it with precision. Bold maximalism and refined minimalism both work - the key is intentionality, not intensity.
|
||||
|
||||
Then implement working code (HTML/CSS/JS, React, Vue, etc.) that is:
|
||||
- Production-grade and functional
|
||||
- Visually striking and memorable
|
||||
- Cohesive with a clear aesthetic point-of-view
|
||||
- Meticulously refined in every detail
|
||||
|
||||
## Frontend Aesthetics Guidelines
|
||||
|
||||
Focus on:
|
||||
- **Typography**: Choose fonts that are beautiful, unique, and interesting. Avoid generic fonts like Arial and Inter; opt instead for distinctive choices that elevate the frontend's aesthetics; unexpected, characterful font choices. Pair a distinctive display font with a refined body font.
|
||||
- **Color & Theme**: Commit to a cohesive aesthetic. Use CSS variables for consistency. Dominant colors with sharp accents outperform timid, evenly-distributed palettes.
|
||||
- **Motion**: Use animations for effects and micro-interactions. Prioritize CSS-only solutions for HTML. Use Motion library for React when available. Focus on high-impact moments: one well-orchestrated page load with staggered reveals (animation-delay) creates more delight than scattered micro-interactions. Use scroll-triggering and hover states that surprise.
|
||||
- **Spatial Composition**: Unexpected layouts. Asymmetry. Overlap. Diagonal flow. Grid-breaking elements. Generous negative space OR controlled density.
|
||||
- **Backgrounds & Visual Details**: Create atmosphere and depth rather than defaulting to solid colors. Add contextual effects and textures that match the overall aesthetic. Apply creative forms like gradient meshes, noise textures, geometric patterns, layered transparencies, dramatic shadows, decorative borders, custom cursors, and grain overlays.
|
||||
|
||||
NEVER use generic AI-generated aesthetics like overused font families (Inter, Roboto, Arial, system fonts), cliched color schemes (particularly purple gradients on white backgrounds), predictable layouts and component patterns, and cookie-cutter design that lacks context-specific character.
|
||||
|
||||
Interpret creatively and make unexpected choices that feel genuinely designed for the context. No design should be the same. Vary between light and dark themes, different fonts, different aesthetics. NEVER converge on common choices (Space Grotesk, for example) across generations.
|
||||
|
||||
**IMPORTANT**: Match implementation complexity to the aesthetic vision. Maximalist designs need elaborate code with extensive animations and effects. Minimalist or refined designs need restraint, precision, and careful attention to spacing, typography, and subtle details. Elegance comes from executing the vision well.
|
||||
|
||||
Remember: Claude is capable of extraordinary creative work. Don't hold back, show what can truly be created when thinking outside the box and committing fully to a distinctive vision.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,46 @@
|
||||
---
|
||||
name: postgres
|
||||
description: PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: planetscale
|
||||
version: "1.0.0"
|
||||
---
|
||||
|
||||
# PlanetScale Postgres
|
||||
|
||||
## Generic Postgres
|
||||
|
||||
| Topic | Reference | Use for |
|
||||
| ---------------------- | ---------------------------------------------------------------- | --------------------------------------------------------- |
|
||||
| Schema Design | [references/schema-design.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/schema-design.md) | Tables, primary keys, data types, foreign keys |
|
||||
| Indexing | [references/indexing.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/indexing.md) | Index types, composite indexes, performance |
|
||||
| Index Optimization | [references/index-optimization.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/index-optimization.md) | Unused/duplicate index queries, index audit |
|
||||
| Partitioning | [references/partitioning.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/partitioning.md) | Large tables, time-series, data retention |
|
||||
| Query Patterns | [references/query-patterns.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/query-patterns.md) | SQL anti-patterns, JOINs, pagination, batch queries |
|
||||
| Optimization Checklist | [references/optimization-checklist.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/optimization-checklist.md) | Pre-optimization audit, cleanup, readiness checks |
|
||||
| MVCC and VACUUM | [references/mvcc-vacuum.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/mvcc-vacuum.md) | Dead tuples, long transactions, xid wraparound prevention |
|
||||
|
||||
## Operations and Architecture
|
||||
|
||||
| Topic | Reference | Use for |
|
||||
| ---------------------- | ---------------------------------------------------------------------------- | --------------------------------------------------------------- |
|
||||
| Process Architecture | [references/process-architecture.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/process-architecture.md) | Multi-process model, connection pooling, auxiliary processes |
|
||||
| Memory Architecture | [references/memory-management-ops.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/memory-management-ops.md) | Shared/private memory layout, OS page cache, OOM prevention |
|
||||
| MVCC Transactions | [references/mvcc-transactions.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/mvcc-transactions.md) | Isolation levels, XID wraparound, serialization errors |
|
||||
| WAL and Checkpoints | [references/wal-operations.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/wal-operations.md) | WAL internals, checkpoint tuning, durability, crash recovery |
|
||||
| Replication | [references/replication.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/replication.md) | Streaming replication, slots, sync commit, failover |
|
||||
| Storage Layout | [references/storage-layout.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/storage-layout.md) | PGDATA structure, TOAST, fillfactor, tablespaces, disk mgmt |
|
||||
| Monitoring | [references/monitoring.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/monitoring.md) | pg_stat views, logging, pg_stat_statements, host metrics |
|
||||
| Backup and Recovery | [references/backup-recovery.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/backup-recovery.md) | pg_dump, pg_basebackup, PITR, WAL archiving, backup tools |
|
||||
|
||||
## PlanetScale-Specific
|
||||
|
||||
| Topic | Reference | Use for |
|
||||
| ------------------ | ---------------------------------------------------------------------------- | ----------------------------------------------------- |
|
||||
| Connection Pooling | [references/ps-connection-pooling.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-connection-pooling.md) | PgBouncer, pool sizing, pooled vs direct |
|
||||
| Extensions | [references/ps-extensions.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-extensions.md) | Supported extensions, compatibility |
|
||||
| Connections | [references/ps-connections.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-connections.md) | Connection troubleshooting, drivers, SSL |
|
||||
| Insights | [references/ps-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-insights.md) | Slow queries, MCP server, pscale CLI |
|
||||
| CLI Commands | [references/ps-cli-commands.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-commands.md) | pscale CLI reference, branches, deploy requests, auth |
|
||||
| CLI API Insights | [references/ps-cli-api-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-api-insights.md) | Query insights via `pscale api`, schema analysis |
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
title: Backup and Recovery
|
||||
description: Logical/physical backups, PITR, WAL archiving, backup tools, and recovery strategies
|
||||
tags: postgres, backup, recovery, pitr, pg_dump, pg_basebackup, wal-archiving, operations
|
||||
---
|
||||
|
||||
# Backup and Recovery
|
||||
|
||||
**FUNDAMENTAL RULE: Backups are useless until you've successfully tested recovery.**
|
||||
|
||||
## Logical Backups (pg_dump)
|
||||
Exports as SQL or custom format; portable across PG versions and architectures. Formats: `-Fp` (plain SQL), `-Fc` (custom compressed, selective restore), `-Fd` (directory, parallel with `-j`), `-Ft` (tar, avoid). Use `-Fd -j 4` for large DBs. Restore: `pg_restore -d dbname file.dump`; add `-j` for parallel restore. Selective table restore: `pg_restore -t tablename`. Slow for large DBs; RPO = backup frequency (typically 24h).
|
||||
|
||||
## Physical Backups (pg_basebackup)
|
||||
Copies raw PGDATA; same major version and platform required; cross-architecture works if same endianness (e.g., x86_64 ↔ ARM64). Faster for large clusters; includes all databases. Flags: `-Ft -z -P` for compressed tar with progress. Manual alternative: `pg_backup_start()` → copy PGDATA → `pg_backup_stop()` (complex; must write returned `backup_label`).
|
||||
|
||||
## PITR (Point-in-Time Recovery)
|
||||
Requires base backup + continuous WAL archiving. Restores to any timestamp, transaction, or named restore point. Without PITR: restore only to backup time (potentially lose hours). With PITR: RPO = minutes. `archive_command` must return 0 ONLY when file is safely stored—premature 0 = data loss risk. `wal_level` must be `replica` or `logical` (not `minimal`).
|
||||
|
||||
## WAL Archiving
|
||||
`archive_mode=on`, `archive_command='test ! -f /archive/%f && cp %p /archive/%f'`. **Test archive command as postgres user** (not root) since permission issues are common. Monitor `pg_stat_archiver` for `failed_count`, `last_archived_time`. Archive failures prevent WAL recycling → disk fills.
|
||||
|
||||
## Tool Comparison
|
||||
| Tool | Use case |
|
||||
|------|----------|
|
||||
| pg_dump | Small DBs, migrations, selective restore |
|
||||
| pg_basebackup | Basic PITR, built-in |
|
||||
| pgBackRest | Production—parallel, incremental, S3/GCS/Azure, retention |
|
||||
| Barman | Enterprise PITR, retention policies |
|
||||
| WAL-G | Cloud-native, S3/GCS/Azure |
|
||||
|
||||
## RPO/RTO
|
||||
Logical only: RPO = backup interval (hours); RTO = hours. PITR: RPO = minutes; RTO = hours. Synchronous replication: RPO = 0; RTO = seconds to minutes (failover).
|
||||
|
||||
## Operational Rules
|
||||
- Verify integrity with `pg_verifybackup` (PG 13+)
|
||||
- Test recovery / PITR regularly
|
||||
- Take backups from standby to avoid impacting primary
|
||||
- Retention: 7 daily, 4 weekly, 12 monthly
|
||||
- Monitor archive growth and backup age
|
||||
- **Never assume backups work without testing**
|
||||
@@ -0,0 +1,69 @@
|
||||
---
|
||||
title: Index Optimization Queries
|
||||
description: Index audit queries
|
||||
tags: postgres, indexes, unused-indexes, duplicate-indexes, optimization
|
||||
---
|
||||
|
||||
# Index Optimization
|
||||
|
||||
## Identify Unused Indexes
|
||||
|
||||
Query to find unused indexes:
|
||||
|
||||
```sql
|
||||
-- indexes with 0 scans (check pg_stat_reset / pg_postmaster_start_time first)
|
||||
SELECT
|
||||
s.schemaname,
|
||||
s.relname AS table_name,
|
||||
s.indexrelname AS index_name,
|
||||
pg_size_pretty(pg_relation_size(s.indexrelid)) AS index_size
|
||||
FROM pg_catalog.pg_stat_user_indexes s
|
||||
JOIN pg_catalog.pg_index i ON s.indexrelid = i.indexrelid
|
||||
WHERE s.idx_scan = 0
|
||||
AND 0 <> ALL (i.indkey) -- exclude expression indexes
|
||||
AND NOT i.indisunique -- exclude UNIQUE indexes
|
||||
AND NOT EXISTS ( -- exclude constraint-backing indexes
|
||||
SELECT 1 FROM pg_catalog.pg_constraint c
|
||||
WHERE c.conindid = s.indexrelid
|
||||
)
|
||||
ORDER BY pg_relation_size(s.indexrelid) DESC;
|
||||
```
|
||||
|
||||
## Indexes Per Table Guidelines
|
||||
|
||||
- **< 5**: Normal
|
||||
- **5-10**: Monitor (Verify necessity)
|
||||
- **> 10**: Audit required (High write overhead)
|
||||
|
||||
```sql
|
||||
SELECT relname AS table, count(*) as index_count
|
||||
FROM pg_stat_user_indexes
|
||||
GROUP BY relname
|
||||
ORDER BY count(*) DESC;
|
||||
```
|
||||
|
||||
## Identify Unused Indexes
|
||||
|
||||
Indexes with identical definitions (after normalizing names) on the same table are duplicates:
|
||||
|
||||
```sql
|
||||
SELECT
|
||||
schemaname || '.' || tablename AS table,
|
||||
array_agg(indexname) AS duplicate_indexes,
|
||||
pg_size_pretty(sum(pg_relation_size((schemaname || '.' || indexname)::regclass))) AS total_size
|
||||
FROM pg_indexes
|
||||
WHERE schemaname NOT IN ('pg_catalog', 'information_schema')
|
||||
GROUP BY schemaname, tablename,
|
||||
regexp_replace(indexdef, 'INDEX \S+ ON ', 'INDEX ON ')
|
||||
HAVING count(*) > 1;
|
||||
```
|
||||
|
||||
**Always confirm with a human before dropping or removing any indexes identified by the queries above.** Even indexes with 0 scans may be needed for infrequent but critical queries, and stats may have been reset recently.
|
||||
|
||||
## Per-table Index Count Guidelines
|
||||
|
||||
| Index Count | Recommendation |
|
||||
| ----------- | ------------------------------------------- |
|
||||
| <5 | Normal |
|
||||
| 5-10 | Review for unused/duplicates |
|
||||
| >10 | Audit required - significant write overhead |
|
||||
@@ -0,0 +1,61 @@
|
||||
---
|
||||
title: Indexing Best Practices
|
||||
description: Index design guide
|
||||
tags: postgres, indexes, composite, partial, covering, gin, brin
|
||||
---
|
||||
|
||||
# Indexing Best Practices
|
||||
|
||||
## Core Rules
|
||||
|
||||
1. **Always index foreign key columns** — PostgreSQL does not auto-create these
|
||||
2. **Index columns in WHERE, JOIN, and ORDER BY** clauses
|
||||
3. **Don't over-index** — each index slows writes and uses storage
|
||||
4. **Verify with EXPLAIN ANALYZE** — confirm indexes are actually used
|
||||
|
||||
## Composite Indexes
|
||||
|
||||
Put equality columns first, then range/sort columns:
|
||||
|
||||
```sql
|
||||
-- WHERE status = 'active' AND created_at > '2026-01-01'
|
||||
CREATE INDEX order_status_created_idx ON order (status, created_at);
|
||||
```
|
||||
|
||||
A composite index on `(a, b)` supports queries on `a` + `b` and `a` alone, but not `b` alone.
|
||||
|
||||
## Partial Indexes
|
||||
|
||||
Reduce index size by filtering to common query patterns.
|
||||
Only use if index size is problematic but the index is needed for performance.
|
||||
|
||||
```sql
|
||||
CREATE INDEX order_active_idx ON order (customer_id)
|
||||
WHERE status = 'active';
|
||||
```
|
||||
|
||||
## Covering Indexes
|
||||
|
||||
Consider creating covering indexes for commonly executed query patterns that return only 1 or a small number of columns.
|
||||
|
||||
## Index Types
|
||||
|
||||
| Type | Use Case | Example |
|
||||
| --- | --- | --- |
|
||||
| B-tree (default) | Equality, range, sorting | `WHERE id = 1`, `ORDER BY date` |
|
||||
| GIN | Arrays, JSONB, full-text | `WHERE tags @> ARRAY['x']` |
|
||||
| GiST | Geometric, range types, full-text | PostGIS, `tsrange`, `tsvector` |
|
||||
| BRIN | Large sequential/time-series | Append-only logs, events (requires physical row order correlation) |
|
||||
|
||||
```sql
|
||||
CREATE INDEX metadata_idx ON order USING GIN (metadata); -- JSONB
|
||||
CREATE INDEX event_created_idx ON event USING BRIN (created_at); -- time-series
|
||||
```
|
||||
|
||||
## Guidelines
|
||||
|
||||
- Name indexes consistently: `{table}_{column}_idx`
|
||||
- Review for unused indexes periodically
|
||||
- **Always confirm with a human before removing or dropping any indexes** — even unused ones may serve a purpose not reflected in recent stats
|
||||
- Use partial indexes for frequently filtered subsets
|
||||
- Use covering indexes on hot read paths
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
title: Memory Architecture and OOM Prevention
|
||||
description: PostgreSQL shared/private memory layout, OS page cache interaction, and OOM avoidance strategies
|
||||
tags: postgres, memory, shared_buffers, work_mem, oom, architecture, operations
|
||||
---
|
||||
|
||||
# Memory Architecture and OOM Prevention
|
||||
|
||||
## Memory Areas
|
||||
|
||||
- **Shared memory**: `shared_buffers` — main data cache, all processes, requires restart to change.
|
||||
- **Private per backend**: `work_mem` (sorts/hashes/joins, per-operation); `maintenance_work_mem` (VACUUM, CREATE INDEX, ALTER TABLE ADD FOREIGN KEY); `temp_buffers` (8MB default).
|
||||
- **Planner hint only**: `effective_cache_size` is NOT allocated — set to ~50–75% of total RAM.
|
||||
- **Hash multiplier**: `hash_mem_multiplier` (default 2.0) means hash ops use up to 2× `work_mem`.
|
||||
|
||||
## Memory Multiplication Danger
|
||||
|
||||
Maximum potential: `work_mem × operations_per_query × (parallel_workers + 1) × connections` (leader participates by default via `parallel_leader_participation = on`; hash operations use up to `hash_mem_multiplier × work_mem`, default 2.0). Example: 128MB work_mem, 3 ops (2 sorts + 1 hash join), 2 parallel workers, 100 connections → 2 sorts at 128MB = 256MB, 1 hash join at 128MB × 2.0 = 256MB, per process = 512MB, × 3 processes (2 workers + leader) = 1536MB/query, × 100 connections = **~150GB** worst case. This case is rare.
|
||||
Not all queries hit limits at once, but high concurrency + large datasets approach it. This is a common cause of OOM in containerized/Kubernetes deployments. Plan capacity with a 1.5–2× safety margin.
|
||||
|
||||
## OS Page Cache (Double Buffering)
|
||||
|
||||
Data exists in both `shared_buffers` and OS page cache. A miss in shared_buffers can still hit OS cache (avoiding disk I/O). Extremely large shared_buffers can hurt performance: less OS cache, slower startup, heavier checkpoints. Optimal split depends on workload (OLTP vs OLAP).
|
||||
|
||||
## OOM Prevention
|
||||
|
||||
- Implement connection pooling to reduce total backend count.
|
||||
- Reduce `work_mem` globally; use per-session overrides for heavy queries only.
|
||||
- Lower `max_parallel_workers_per_gather` in high-concurrency systems.
|
||||
- Set `statement_timeout` to kill runaway queries.
|
||||
- Monitor: `dmesg -T | grep "killed process"` and `temp_blks_written` in pg_stat_statements.
|
||||
|
||||
## Operational Rules
|
||||
|
||||
- Tune per-session first, global last.
|
||||
- Suspect OOM when memory spikes during high concurrency, dashboards, or large batch jobs.
|
||||
- Increase memory only after confirming spill behavior (`temp_blks_written > 0`).
|
||||
- `maintenance_work_mem` can be set much higher (1–2GB) — fewer processes use it. Cap autovacuum with `autovacuum_work_mem` to avoid `autovacuum_max_workers × maintenance_work_mem` memory spikes.
|
||||
- `shared_buffers` change requires full restart; `work_mem` is per-session changeable.
|
||||
@@ -0,0 +1,59 @@
|
||||
---
|
||||
title: Monitoring
|
||||
description: Essential PostgreSQL monitoring views, pg_stat_statements, logging, host metrics, and statistics management
|
||||
tags: postgres, monitoring, pg_stat_statements, logging, pgbadger, metrics, operations
|
||||
---
|
||||
|
||||
# Monitoring
|
||||
|
||||
## Essential Views
|
||||
|
||||
- **pg_stat_activity**: First stop when something is wrong — running queries, states, wait events, locks.
|
||||
- **pg_stat_statements**: Execution stats for all SQL. Requires `shared_preload_libraries = 'pg_stat_statements'` and `CREATE EXTENSION pg_stat_statements`.
|
||||
- **pg_stat_database**: Cache hit ratio, temp files, deadlocks, connections per database.
|
||||
- **pg_stat_user_tables**: `seq_scan` vs `idx_scan`, dead tuples, last vacuum/analyze times.
|
||||
- **pg_stat_user_indexes**: Find unused indexes (`idx_scan = 0` with large size).
|
||||
- **pg_stat_bgwriter**: `buffers_clean`, `maxwritten_clean`, `buffers_alloc`. Pre-PG 17 also had `buffers_checkpoint`, `buffers_backend` (high = backends bypassing bgwriter). PG 17+ moved checkpoint stats to `pg_stat_checkpointer`.
|
||||
- **pg_stat_checkpointer** (PG 17+): Checkpoint frequency (`num_timed`, `num_requested`), write/sync time.
|
||||
|
||||
## Key Queries
|
||||
|
||||
```sql
|
||||
-- Slow queries (with cache hit ratio)
|
||||
SELECT query, calls, mean_exec_time,
|
||||
100.0 * shared_blks_hit / nullif(shared_blks_hit + shared_blks_read, 0) AS cache_hit_pct
|
||||
FROM pg_stat_statements ORDER BY mean_exec_time DESC LIMIT 10;
|
||||
|
||||
-- Connection counts / states
|
||||
SELECT state, count(*) FROM pg_stat_activity GROUP BY state;
|
||||
|
||||
-- Dead tuples (vacuum candidates)
|
||||
SELECT relname, n_dead_tup, last_autovacuum FROM pg_stat_user_tables ORDER BY n_dead_tup DESC;
|
||||
-- last_autovacuum = <null> means autovacuum has not run on this table
|
||||
```
|
||||
|
||||
Blocking: use `pg_blocking_pids(pid)` with `pg_stat_activity` to find blocked and blocking sessions.
|
||||
|
||||
## Logging — First Line of Defense
|
||||
|
||||
PostgreSQL is extremely vocal about problems. **Always check logs first**: `tail -f /var/log/postgresql/postgresql-*.log`.
|
||||
|
||||
Key settings: `log_min_duration_statement` (OLTP: 1–3s, analytics: 30–60s, dev: 100–500ms). Enable `log_checkpoints=on`, `log_connections=on`, `log_disconnections=on`, `log_lock_waits=on`, `log_temp_files=0`. Use CSV log format for pgBadger analysis; pgBadger generates HTML reports with query stats and performance graphs.
|
||||
|
||||
## pg_activity
|
||||
|
||||
Interactive top-like tool (pip install pg_activity). Run on DB host for OS metrics alongside PG metrics. Combines `pg_stat_activity` with CPU/memory/I/O context.
|
||||
|
||||
## Host Metrics — Critical
|
||||
|
||||
PostgreSQL cannot report these. **Monitor them yourself:**
|
||||
|
||||
- **CPU**: Steal time >10% in VMs bad; load average > core count; context switches >100k/sec.
|
||||
- **Memory**: Any swap = performance degradation. Check `dmesg` for OOM kills.
|
||||
- **Disk I/O**: `iostat -x` — `%util=100%` means saturated; `await` >10ms = high latency.
|
||||
- **Disk space**: >90% critical (VACUUM fails, writes fail). Check inode usage too.
|
||||
- **Network**: Packet loss >0% = problems; high retransmits = instability.
|
||||
|
||||
## Statistics Management
|
||||
|
||||
Stats accumulate since last reset or restart; check `stats_reset` timestamp. `pg_stat_statements_reset()` clears query stats; `pg_stat_reset()` clears database stats. Reset after major maintenance, config changes, or perf testing — not routinely. Prefer snapshotting stats to external monitoring (Prometheus, Datadog) over resetting. **Always confirm with a human before resetting statistics** — resetting destroys historical performance baselines and can make it harder to identify unused indexes or regressions.
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
title: MVCC Transactions and Concurrency
|
||||
description: Transaction isolation levels, XID wraparound prevention, serialization errors, and long-transaction impact
|
||||
tags: postgres, mvcc, transactions, isolation, xid-wraparound, concurrency, serialization
|
||||
---
|
||||
|
||||
# MVCC Transactions and Concurrency
|
||||
|
||||
## Transaction Isolation Levels
|
||||
|
||||
- **READ UNCOMMITTED** — treated as READ COMMITTED in PostgreSQL; no dirty reads ever.
|
||||
- **READ COMMITTED** (default): new snapshot per statement; can see different data within same tx.
|
||||
- **REPEATABLE READ**: snapshot at first query; can cause serialization errors on write conflicts.
|
||||
- **SERIALIZABLE**: strongest; transactions appear serial; requires retry logic in app code.
|
||||
|
||||
Readers never block writers; writers never block readers (only writer-writer conflicts on same row). No lock escalation — row locks never degrade to table locks.
|
||||
|
||||
## XID Wraparound
|
||||
|
||||
32-bit transaction IDs wrap at ~2 billion (2^31). `VACUUM FREEZE` replaces old XIDs with FrozenXID (value 2, always visible). Without freeze: after wraparound, old rows appear "in the future" and become **invisible**. Data physically exists but is invisible to all queries — looks like total data loss. PostgreSQL emergency shutdown at 2B XIDs to prevent this. XID wraparound should be avoided at all cost.
|
||||
|
||||
Warning messages start at ~1.4B XIDs; shutdown at 2B. Recovery requires single-user mode VACUUM — can take hours to days on large DBs. **Never disable autovacuum** — it's your protection against wraparound.
|
||||
|
||||
## XID Age Monitoring
|
||||
|
||||
```sql
|
||||
SELECT datname, age(datfrozenxid),
|
||||
ROUND(100.0 * age(datfrozenxid) / 2147483648, 2) AS pct
|
||||
FROM pg_database ORDER BY age(datfrozenxid) DESC;
|
||||
```
|
||||
|
||||
## Long Transaction Impact
|
||||
|
||||
A single long-running transaction blocks VACUUM from removing dead tuples across the **entire database**. Causes table bloat, increased disk, slower queries, cache pollution. `idle_in_transaction` connections are the #1 operational MVCC issue. Set `idle_in_transaction_session_timeout` (30s–5min). Dead tuples waste I/O on seq scans and cause useless heap lookups from indexes.
|
||||
|
||||
## Serialization Errors
|
||||
|
||||
Apps **must** handle "could not serialize access" with retry logic. More common in REPEATABLE READ and SERIALIZABLE. Smaller, faster transactions reduce conflict frequency.
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
title: MVCC and VACUUM
|
||||
description: MVCC internals, VACUUM/autovacuum tuning, and bloat prevention
|
||||
tags: postgres, mvcc, vacuum, autovacuum, xid, bloat, dead-tuples
|
||||
---
|
||||
|
||||
# MVCC and VACUUM
|
||||
|
||||
## MVCC
|
||||
|
||||
Every `UPDATE` creates a new tuple and marks the old one dead; `DELETE` marks tuples dead. Dead tuples accumulate until `VACUUM` reclaims space. Each transaction gets a 32-bit XID (2^32 ≈ 4B values, but modular comparison means the effective danger zone is 2^31 ≈ 2B). VACUUM must freeze old XIDs to prevent wraparound.
|
||||
|
||||
## VACUUM vs VACUUM FULL
|
||||
|
||||
`VACUUM` is non-blocking (ShareUpdateExclusive lock) and marks dead space reusable. `VACUUM FULL` rewrites the table and requires an AccessExclusive lock — use only as a last resort. For online bloat reduction prefer `pg_squeeze` or `pg_repack`.
|
||||
|
||||
## Autovacuum Tuning
|
||||
|
||||
Triggers when dead tuples > `Min(autovacuum_vacuum_max_threshold, autovacuum_vacuum_threshold + autovacuum_vacuum_scale_factor * reltuples)`. `autovacuum_vacuum_max_threshold` defaults to 100M (PG 18+), capping the threshold for very large tables. Also triggers on inserts exceeding `autovacuum_vacuum_insert_threshold + autovacuum_vacuum_insert_scale_factor * reltuples * pct_not_frozen` (ensures insert-only tables get frozen; PG 13+). For large/hot tables, set per-table overrides:
|
||||
|
||||
- `autovacuum_vacuum_scale_factor` — default 0.2; lower to 0.01–0.05 for large tables.
|
||||
- `autovacuum_vacuum_cost_delay` — default 2 ms; set to 0 on fast storage.
|
||||
- `autovacuum_vacuum_cost_limit` — default -1 (uses `vacuum_cost_limit`, effectively 200); raise to 1000–2000 on fast storage.
|
||||
- `autovacuum_freeze_max_age` — default 200M; triggers anti-wraparound vacuum.
|
||||
- `vacuum_failsafe_age` — default 1.6B; last-resort mode (PG 14+) that disables throttling and skips index vacuuming when wraparound is imminent.
|
||||
|
||||
## Key Monitoring Queries
|
||||
|
||||
Dead tuples: `SELECT relname, n_dead_tup, last_autovacuum FROM pg_stat_user_tables ORDER BY n_dead_tup DESC;`
|
||||
|
||||
XID age: `SELECT datname, age(datfrozenxid) AS xid_age FROM pg_database ORDER BY xid_age DESC;`
|
||||
|
||||
Long transactions: `SELECT pid, state, now() - xact_start AS tx_age FROM pg_stat_activity WHERE xact_start IS NOT NULL ORDER BY xact_start;`
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Keep transactions short; set `idle_in_transaction_session_timeout` (30s–5min).
|
||||
- Alert when `age(datfrozenxid)` exceeds 40–50% of wraparound (~800M–1B).
|
||||
- Tune autovacuum per-table for write-heavy tables; don't change global defaults first.
|
||||
- Fix application transaction scope before adjusting vacuum parameters.
|
||||
- Never disable autovacuum globally.
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
title: Database Optimization Checklist
|
||||
description: Optimize checklist
|
||||
tags: postgres, optimization, indexes, partitioning, maintenance
|
||||
---
|
||||
|
||||
# Optimization Checklist
|
||||
|
||||
When optimizing performance, check the following:
|
||||
|
||||
- Look for unused indexes (0 scans; exclude unique/primary indexes and verify stats age first)
|
||||
- Look for duplicate indexes
|
||||
- Archive audit/log tables >10GB
|
||||
- Review tables >500GB for partitioning (>100GB for time-series/logs)
|
||||
- Verify all extensions are supported
|
||||
- Check for circular foreign key dependencies
|
||||
- Consider alternatives to UUID primary keys for large tables
|
||||
- Configure connection pooling for OLTP workloads
|
||||
- **Always confirm with a human before removing any indexes, dropping partitions, archiving tables, or performing other destructive actions**
|
||||
@@ -0,0 +1,79 @@
|
||||
---
|
||||
title: Table Partitioning Guide
|
||||
description: Partition guide
|
||||
tags: postgres, partitioning, range, list, pg_partman, data-retention
|
||||
---
|
||||
|
||||
# Table Partitioning
|
||||
|
||||
Plan partitioning upfront for tables expected to grow large. Retrofitting later requires a migration.
|
||||
|
||||
## When to Partition
|
||||
|
||||
Partitioning benefits maintenance (vacuum, index builds) and data retention more than pure query speed.
|
||||
|
||||
| Table Type | Size Threshold | Row Threshold |
|
||||
| --- | --- | --- |
|
||||
| General tables | >100 GB (or >RAM) | >20M rows |
|
||||
| Time-series / logs | >50 GB | >10M rows |
|
||||
|
||||
Use the lower thresholds for append-heavy, time-ordered data with retention needs (logs, events, audit trails, metrics).
|
||||
|
||||
## Range Partitioning (Most Common)
|
||||
|
||||
```sql
|
||||
-- EXAMPLE
|
||||
CREATE TABLE event (
|
||||
id BIGINT GENERATED ALWAYS AS IDENTITY,
|
||||
event_type TEXT NOT NULL,
|
||||
payload JSONB,
|
||||
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
||||
PRIMARY KEY (id, created_at) -- Partition key MUST be part of PK
|
||||
) PARTITION BY RANGE (created_at);
|
||||
|
||||
CREATE TABLE event_2026_01 PARTITION OF event
|
||||
FOR VALUES FROM ('2026-01-01') TO ('2026-02-01');
|
||||
|
||||
CREATE TABLE event_2026_02 PARTITION OF event
|
||||
FOR VALUES FROM ('2026-02-01') TO ('2026-03-01');
|
||||
```
|
||||
|
||||
## List Partitioning
|
||||
|
||||
Useful for partitioning by region, tenant, or category:
|
||||
|
||||
```sql
|
||||
-- EXAMPLE
|
||||
CREATE TABLE order (
|
||||
id BIGINT GENERATED ALWAYS AS IDENTITY,
|
||||
region TEXT NOT NULL,
|
||||
total NUMERIC(10,2),
|
||||
PRIMARY KEY (id, region) -- Partition key MUST be part of PK
|
||||
) PARTITION BY LIST (region);
|
||||
|
||||
CREATE TABLE order_us PARTITION OF order FOR VALUES IN ('us');
|
||||
CREATE TABLE order_eu PARTITION OF order FOR VALUES IN ('eu');
|
||||
CREATE TABLE order_default PARTITION OF order DEFAULT; -- catches unmatched values
|
||||
```
|
||||
|
||||
## Partition Management
|
||||
|
||||
- Use `pg_partman` (extension) to automate partition creation and cleanup.
|
||||
- Use `DETACH PARTITION` to remove a partition while retaining it as a standalone table (e.g., for archiving).
|
||||
- Use `DETACH PARTITION ... CONCURRENTLY` (PG 14+) to avoid `ACCESS EXCLUSIVE` locks on the parent table.
|
||||
- Drop old partitions for data retention instead of `DELETE` to avoid vacuum overhead and bloat.
|
||||
- Create future partitions ahead of time to avoid insert failures.
|
||||
- **Always confirm with a human before detaching or dropping partitions.** These are destructive actions — detaching removes data from the partitioned table, and dropping permanently deletes the data.
|
||||
|
||||
```sql
|
||||
-- DESTRUCTIVE: confirm with a human before executing
|
||||
ALTER TABLE event DETACH PARTITION event_2025_01 CONCURRENTLY;
|
||||
DROP TABLE event_2025_01;
|
||||
```
|
||||
|
||||
## Guidelines & Limitations
|
||||
|
||||
- **Primary Keys**: Partition key columns MUST be included in the `PRIMARY KEY` and any `UNIQUE` constraints.
|
||||
- **Global Uniqueness**: Global unique constraints on non-partition columns are NOT supported.
|
||||
- **Indexes**: Indexes defined on the parent are automatically created on all partitions (and future ones).
|
||||
- **Pruning**: Ensure queries filter by the partition key to enable "partition pruning" (skipping unrelated partitions).
|
||||
@@ -0,0 +1,46 @@
|
||||
---
|
||||
title: Process Architecture
|
||||
description: PostgreSQL multi-process model, connection management, and auxiliary processes
|
||||
tags: postgres, processes, connections, pooling, memory, operations
|
||||
---
|
||||
|
||||
# Process Architecture
|
||||
|
||||
PostgreSQL uses a **multi-process** model, not multi-threaded: one OS process per client connection. The postmaster is the parent; it spawns backend processes per connection. Each backend has some private memory (`work_mem`, temp buffers). 1000 connections = 1000 processes (~5–10MB base + query memory each). There is also a large buffer shared amongst all.
|
||||
|
||||
## Auxiliary Processes
|
||||
|
||||
WAL Writer, Background Writer, Checkpointer, Autovacuum Launcher/Workers, Archiver, WAL Summarizer (PG 17+). These run alongside backends and are not spawned per connection.
|
||||
|
||||
## Memory Risk
|
||||
|
||||
`work_mem` is per-operation, not per-query. Estimate: `work_mem × operations_per_query × parallel_workers × connections` can grow very large at high concurrency. Scale connections and parallelism before raising `work_mem`.
|
||||
|
||||
## Connection Pooling (Critical)
|
||||
|
||||
Each connection = OS process (fork overhead, context switching, memory). PgBouncer can multiplex many app connections to fewer DB connections. Typical: 1000 app connections → pooler → 20–50 backends. Implement pooling before raising `max_connections`; `max_connections` requires a full restart to change (default 100). Note: `superuser_reserved_connections` (default 3) reserves slots for emergency superuser access, so non-superusers are rejected before `max_connections` is fully reached.
|
||||
|
||||
## Monitoring
|
||||
|
||||
```sql
|
||||
SELECT state, count(*) FROM pg_stat_activity WHERE backend_type = 'client backend' GROUP BY state;
|
||||
```
|
||||
|
||||
```sql
|
||||
-- Show used and free connection slots
|
||||
SELECT count(*) AS used, max(max_conn) - count(*) AS free
|
||||
FROM pg_stat_activity, (SELECT setting::int AS max_conn FROM pg_settings WHERE name = 'max_connections') s
|
||||
WHERE backend_type = 'client backend';
|
||||
```
|
||||
|
||||
Use `pg_activity` for interactive top-like monitoring. Alert at 80% connection usage, critical at 95%. Count by state to find idle-in-transaction leaks — these hold locks and **block VACUUM** from reclaiming dead tuples.
|
||||
|
||||
## Common Problems
|
||||
|
||||
| Problem | Fix |
|
||||
| ------- | --- |
|
||||
| `too many clients already` | Implement pooling; find idle connections; check for connection leaks |
|
||||
| High memory / OOM | Reduce `work_mem`; add pooling; set `statement_timeout` |
|
||||
| Stuck process | `SELECT pg_cancel_backend(pid);` then `SELECT pg_terminate_backend(pid);` — **always confirm with a human before terminating backends**, as this may abort in-flight transactions and cause data issues for the application |
|
||||
|
||||
Prefer pooling + conservative `max_connections` over raising limits reactively.
|
||||
@@ -0,0 +1,53 @@
|
||||
---
|
||||
title: CLI Query Insights API
|
||||
description: CLI insights usage
|
||||
tags: postgres, planetscale, cli, insights, query-patterns, api
|
||||
---
|
||||
|
||||
# Query Insights via pscale CLI
|
||||
|
||||
Analyze slow queries and missing indexes using `pscale api`. Endpoints may change—see https://planetscale.com/docs/api/reference/getting-started-with-planetscale-api for current API docs.
|
||||
|
||||
## Using pscale api
|
||||
|
||||
The `pscale api` command makes authenticated API calls using your current login or service token (see [ps-cli-commands.md](ps-cli-commands.md#service-token-cicd) for auth setup). No need to manage auth headers manually.
|
||||
|
||||
```bash
|
||||
pscale api "<endpoint>" [--method POST] [--field key=value] [--org <org>]
|
||||
```
|
||||
|
||||
## Query Patterns Reports
|
||||
|
||||
```bash
|
||||
# Create a new report
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports" \
|
||||
--method POST --org my-org
|
||||
|
||||
# Check status (poll until state=complete)
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports/{id}/status"
|
||||
|
||||
# Download completed report
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports/{id}"
|
||||
|
||||
# List all reports
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports"
|
||||
```
|
||||
|
||||
## Schema Analysis
|
||||
|
||||
```bash
|
||||
# Get branch schema
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/schema"
|
||||
|
||||
# Lint schema for issues
|
||||
pscale api "organizations/{org}/databases/{db}/branches/{branch}/schema/lint"
|
||||
```
|
||||
|
||||
## What to Look For
|
||||
|
||||
| Metric | Indicates | Action |
|
||||
| -------------------------------- | --------------------- | ------------------------------- |
|
||||
| High `rows_read / rows_returned` | Missing or poor index | Add index on WHERE/JOIN columns |
|
||||
| High `total_time_s` | Heavy query | Optimize or cache |
|
||||
| High `count` with same pattern | N+1 queries | Batch or eager-load |
|
||||
| `indexed: false` | Full table scan | Add index |
|
||||
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: PlanetScale CLI Reference
|
||||
description: CLI command guide
|
||||
tags: planetscale, cli, branches, deploy-requests, authentication
|
||||
---
|
||||
|
||||
# pscale CLI Commands
|
||||
|
||||
Full CLI reference: https://planetscale.com/docs/cli. Use `pscale <command> --help` for subcommands and flags.
|
||||
|
||||
## Authentication
|
||||
|
||||
```bash
|
||||
pscale auth login # Opens browser
|
||||
pscale auth logout
|
||||
pscale org list
|
||||
pscale org switch <name>
|
||||
```
|
||||
|
||||
### Service Token (CI/CD)
|
||||
|
||||
```bash
|
||||
# Create and configure
|
||||
pscale service-token create
|
||||
pscale service-token add-access <id> read_branch --database <db>
|
||||
# Use in CI/CD
|
||||
export PLANETSCALE_SERVICE_TOKEN_ID="<id>"
|
||||
export PLANETSCALE_SERVICE_TOKEN="<token>"
|
||||
```
|
||||
|
||||
## Core Commands
|
||||
|
||||
```bash
|
||||
# Databases
|
||||
pscale database list
|
||||
pscale database create <name>
|
||||
|
||||
# Branches
|
||||
pscale branch list <db>
|
||||
pscale branch create <db> <branch> [--from <parent>]
|
||||
pscale branch delete <db> <branch> # DESTRUCTIVE — always confirm with a human first
|
||||
pscale branch schema <db> <branch>
|
||||
|
||||
# Deploy requests (schema changes) — Vitess only
|
||||
pscale deploy-request create <db> <branch>
|
||||
pscale deploy-request list <db>
|
||||
pscale deploy-request deploy <db> <number>
|
||||
|
||||
# Connect
|
||||
pscale shell <db> <branch> # Opens psql (Postgres) or mysql (Vitess)
|
||||
pscale connect <db> <branch> # Proxy for GUI tools (secure tunnel) — Vitess only
|
||||
|
||||
# Credentials
|
||||
pscale role create <db> <branch> <name> # Postgres
|
||||
pscale password create <db> <branch> <name> # Vitess
|
||||
|
||||
# Other
|
||||
pscale ping # Check latency to regions
|
||||
pscale region list # Available regions
|
||||
pscale backup list <db> <branch>
|
||||
pscale backup create <db> <branch>
|
||||
```
|
||||
|
||||
## Useful Flags
|
||||
|
||||
```bash
|
||||
--format json # Output as JSON (also: csv, human)
|
||||
--org <name> # Specify organization
|
||||
--debug # Debug output
|
||||
```
|
||||
|
||||
For API calls via CLI, see [ps-cli-api-insights.md](ps-cli-api-insights.md).
|
||||
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: PgBouncer Connection Pooling
|
||||
description: Pooling setup guide
|
||||
tags: postgres, pgbouncer, connection-pooling, performance, transactions
|
||||
---
|
||||
|
||||
# Connection Pooling with PgBouncer
|
||||
|
||||
PlanetScale provides PgBouncer for connection pooling. Connect on port `6432` instead of `5432`.
|
||||
|
||||
## When to Use PgBouncer (Port 6432)
|
||||
|
||||
All OLTP application workloads: web apps, APIs, high-concurrency read/write operations.
|
||||
|
||||
## When to Use Direct Connections (Port 5432)
|
||||
|
||||
- Schema changes (DDL)
|
||||
- Analytics, reporting, batch processing
|
||||
- Session-specific features (temp tables, session variables)
|
||||
- ETL, data streaming, `pg_dump`
|
||||
- Long-running admin transactions
|
||||
|
||||
## PgBouncer Types
|
||||
|
||||
PlanetScale offers three PgBouncer options. All use port `6432`.
|
||||
|
||||
| Type | Runs On | Routes To | Key Trait |
|
||||
| ---- | ------- | --------- | --------- |
|
||||
| **Local** | Same node as primary | Primary only | Included with every database; no replica routing |
|
||||
| **Dedicated Primary** | Separate node | Primary | Connections persist through resizes, upgrades, and most failovers |
|
||||
| **Dedicated Replica** | Separate node | Replicas | Read-only traffic; supports AZ affinity for lower latency |
|
||||
|
||||
- **Local PgBouncer** — use same credentials as direct, just change port to `6432`. Always routes to primary regardless of username.
|
||||
- **Dedicated Primary** — runs off-server for improved HA. Use for production OLTP write traffic.
|
||||
- **Dedicated Replica** — runs off-server for read-heavy workloads. Supports AZ affinity to prefer same-zone replicas. Multiple can be created for capacity or per-app isolation.
|
||||
|
||||
To connect to a dedicated PgBouncer, append `|pgbouncer-name` to the username (e.g., `postgres.xxx|write-pool` or `postgres.xxx|read-bouncer`).
|
||||
|
||||
## Transaction Pooling Limitations
|
||||
|
||||
PlanetScale PgBouncer uses **transaction pooling mode**. These features are unavailable:
|
||||
|
||||
- Prepared statements that persist across transactions
|
||||
- Temporary tables
|
||||
- `LISTEN`/`NOTIFY`
|
||||
- Session-level advisory locks
|
||||
- `SET` commands persisting beyond a transaction
|
||||
|
||||
## Recommended Patterns
|
||||
|
||||
- Size pools from observed concurrency, query memory behavior, and connection limits.
|
||||
- Keep pooled app traffic on `6432` and reserve direct connections for DDL/admin/long-running jobs.
|
||||
|
||||
## Avoid Patterns
|
||||
|
||||
- Avoid setting pool size with only `CPU_cores * N` while ignoring query-memory amplification.
|
||||
- Avoid running session-dependent workflows through transaction pooling.
|
||||
|
||||
## Connecting
|
||||
|
||||
```bash
|
||||
# Local PgBouncer (same credentials, port 6432)
|
||||
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
|
||||
|
||||
# Dedicated primary PgBouncer (append |pgbouncer-name to user)
|
||||
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx|write-pool password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
|
||||
|
||||
# Dedicated replica PgBouncer (append |pgbouncer-name to user)
|
||||
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx|read-bouncer password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
|
||||
```
|
||||
|
||||
Docs: https://planetscale.com/docs/postgres/connecting/pgbouncer
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
title: PlanetScale Postgres Connections
|
||||
description: Connection guide for PlanetScale Postgres
|
||||
tags: planetscale, postgres, connections, ssl, troubleshooting
|
||||
---
|
||||
|
||||
# PlanetScale Postgres Connections
|
||||
|
||||
Postgres docs: https://planetscale.com/docs/postgres/connecting
|
||||
|
||||
| Protocol | Standard Port | Pooled Port | SSL |
|
||||
| -------- | ------------- | ----------------------- | -------- |
|
||||
| Postgres | 5432 | 6432 (PgBouncer) | Required |
|
||||
|
||||
Credentials (roles) are branch-specific and cannot be recovered after creation.
|
||||
|
||||
## Connection String
|
||||
|
||||
```
|
||||
postgresql://<user>:<password>@<host>.horizon.psdb.cloud:5432/<database>?sslmode=verify-full&sslrootcert=system&sslnegotiation=direct
|
||||
```
|
||||
|
||||
Use port **6432** for PgBouncer (applications/OLTP).
|
||||
Use port **5432** for DDL, admin tasks, and migrations.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
| Error | Fix |
|
||||
| -------------------------------- | --------------------------------------- |
|
||||
| `password authentication failed` | Check role format: `<role>.<branch_id>` |
|
||||
| `too many clients already` | Use PgBouncer (port 6432) |
|
||||
| `SSL connection is required` | Add `sslmode=verify-full&sslrootcert=system` |
|
||||
|
||||
**Best practices:**
|
||||
- Use the PlanetScale Postgres metrics page to monitor direct and PgBouncer connections
|
||||
- Route OLTP traffic to port 6432 and reserve 5432 for admin/migrations.
|
||||
- Avoid raising `max_connections` reactively instead of pooling.
|
||||
@@ -0,0 +1,27 @@
|
||||
---
|
||||
title: PlanetScale PostgreSQL Extensions
|
||||
description: Extension reference
|
||||
tags: postgres, extensions
|
||||
---
|
||||
|
||||
# PostgreSQL Extensions on PlanetScale
|
||||
|
||||
Only use PlanetScale-supported extensions. For the complete and up-to-date list of available extensions, see: https://planetscale.com/docs/postgres/extensions
|
||||
|
||||
Do not rely on hard-coded extension lists — always check the documentation above for current availability.
|
||||
|
||||
## Enabling Extensions
|
||||
|
||||
Some extensions must first be **enabled in the PlanetScale Dashboard** (Clusters > Extensions) before they can be created in SQL. This often requires a database restart.
|
||||
|
||||
Once enabled in the dashboard, create the extension in SQL:
|
||||
|
||||
```sql
|
||||
CREATE EXTENSION IF NOT EXISTS <extension_name>;
|
||||
```
|
||||
|
||||
## Recommended Patterns
|
||||
|
||||
- Always check the [PlanetScale extensions docs](https://planetscale.com/docs/postgres/extensions) before assuming an extension is available.
|
||||
- Verify extension availability in PlanetScale configuration and docs before schema design depends on it.
|
||||
- Enable `pg_stat_statements` early for baseline query telemetry.
|
||||
@@ -0,0 +1,62 @@
|
||||
---
|
||||
title: PlanetScale Query Insights
|
||||
description: Query insights guide
|
||||
tags: postgres, planetscale, insights, monitoring, optimization
|
||||
---
|
||||
|
||||
# PlanetScale Insights
|
||||
|
||||
## Fetch current documentation first
|
||||
|
||||
Prefer retrieval over pre-training knowledge. Docs: https://planetscale.com/docs
|
||||
|
||||
## MCP Server (Preferred)
|
||||
|
||||
When the PlanetScale MCP server is configured in your environment, prefer it over CLI. Key tools:
|
||||
|
||||
- `planetscale_get_branch_schema` — Get schema for a branch
|
||||
- `planetscale_execute_read_query` — Run SELECT, SHOW, DESCRIBE, EXPLAIN
|
||||
- `planetscale_get_insights` — Query performance insights
|
||||
- `planetscale_list_schema_recommendations` — Index and schema suggestions
|
||||
- `planetscale_search_documentation` — Search PlanetScale docs
|
||||
|
||||
MCP setup: https://planetscale.com/docs/connect/mcp
|
||||
|
||||
The MCP server is the ideal way to interact with insights from an AI agent.
|
||||
If not installed, prompt the user to install it to make the agent more effective.
|
||||
|
||||
## Query Insights (CLI)
|
||||
|
||||
Generating reports via CLI is a multi-step process (create → wait → download).
|
||||
|
||||
See [ps-cli-api-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-api-insights.md) for how to use.
|
||||
|
||||
What to look for:
|
||||
|
||||
- High `rows_read / rows_returned` ratio → missing index
|
||||
- High `total_time_s` → optimization target
|
||||
|
||||
## Insights UI (Dashboard)
|
||||
|
||||
In the [PlanetScale dashboard](https://app.planetscale.com/), select your database and click **Insights**.
|
||||
|
||||
- **Filtering** — Pick a branch, choose primary or replica, and scroll through the last 7 days. Click-and-drag on graphs to zoom into a time window.
|
||||
- **Graphs** — Four tabs: Query latency (p50/p95/p99/p99.9), Queries per second, Rows read/s, and Rows written/s.
|
||||
- **Queries table** — All queries in the selected timeframe, normalized into patterns. Sortable and filterable by SQL, schema, table, latency, index usage, and more. Customizable columns (count, total time, latency percentiles, rows read/returned/affected, CPU/IO time, cache hit ratio, etc.). Enable sparklines for inline trend graphs. Orange icons flag full table scans.
|
||||
- **Query deep dive** — Click any query to see per-pattern graphs, summary stats, index usage breakdown, and a table of notable executions (>1 s, >10k rows read, or errors). Use "Summarize query" for an LLM-generated plain-English description.
|
||||
- **Anomalies tab** — Flags periods with elevated slow-running queries and surfaces the responsible patterns.
|
||||
- **Errors tab** — Surfaces queries that produced errors.
|
||||
- **pginsights settings** — `pginsights.raw_queries` enables full query text collection for notable queries; `pginsights.normalize_schema_names` groups identical patterns across schemas (useful for schema-per-tenant designs). Both configurable in the Extensions tab on the Clusters page.
|
||||
|
||||
More: [PlanetScale Insights docs](https://planetscale.com/docs/postgres/monitoring/query-insights)
|
||||
|
||||
## Optimization Checklist
|
||||
|
||||
- Remove unused indexes (0 scans)
|
||||
- Remove duplicate indexes
|
||||
- Archive audit/log tables >10 GB
|
||||
- Review tables >100 GB for partitioning
|
||||
|
||||
**Always confirm with a human before removing indexes, dropping tables/partitions, or archiving data.** These are destructive actions that cannot be easily undone.
|
||||
|
||||
More: [optimization-checklist.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/optimization-checklist.md)
|
||||
@@ -0,0 +1,80 @@
|
||||
---
|
||||
title: SQL Query Patterns
|
||||
description: Common SQL anti-patterns and optimized alternatives
|
||||
tags: postgres, sql, query-optimization, n-plus-one, pagination
|
||||
---
|
||||
|
||||
# SQL Query Patterns
|
||||
|
||||
## Query Structure
|
||||
|
||||
**SELECT specific columns** — avoids fetching unnecessary data and enables covering indexes:
|
||||
```sql
|
||||
-- Bad:
|
||||
SELECT * FROM user WHERE status = 'active';
|
||||
-- Good:
|
||||
SELECT id, name, email FROM user WHERE status = 'active';
|
||||
```
|
||||
|
||||
**Subqueries → JOINs** — correlated subqueries re-execute per row:
|
||||
```sql
|
||||
-- Bad
|
||||
SELECT id, (SELECT COUNT(*) FROM order WHERE order.user_id = user.id) FROM user;
|
||||
-- Good
|
||||
SELECT u.id, COUNT(o.id) FROM user u LEFT JOIN order o ON o.user_id = u.id GROUP BY u.id;
|
||||
```
|
||||
|
||||
**Always LIMIT unbounded queries** — prevent runaway result sets:
|
||||
```sql
|
||||
SELECT id, message FROM log WHERE level = 'error' ORDER BY created_at DESC LIMIT 100;
|
||||
```
|
||||
|
||||
**Avoid functions on indexed columns (SARGable)** — functions prevent index usage unless a functional index exists:
|
||||
```sql
|
||||
-- Bad: Full table scan
|
||||
SELECT * FROM user WHERE date_trunc('day', created_at) = '2023-01-01';
|
||||
-- Good: Index scan
|
||||
SELECT * FROM user WHERE created_at >= '2023-01-01' AND created_at < '2023-01-02';
|
||||
```
|
||||
|
||||
## N+1 Detection
|
||||
|
||||
**Queries inside loops → batch with ANY/IN:**
|
||||
```python
|
||||
# Bad
|
||||
for uid in user_ids:
|
||||
cursor.execute("SELECT name FROM user WHERE id = %s", (uid,))
|
||||
# Good (Postgres specific)
|
||||
cursor.execute("SELECT id, name FROM user WHERE id = ANY(%s)", (list(user_ids),))
|
||||
# Good (Standard SQL)
|
||||
# cursor.execute("SELECT id, name FROM user WHERE id IN %s", (tuple(user_ids),))
|
||||
```
|
||||
|
||||
**ORM lazy loading → eager loading:**
|
||||
```python
|
||||
# Bad: N+1 — each iteration fires a query
|
||||
for user in User.query.all():
|
||||
print(user.posts)
|
||||
# Good
|
||||
users = User.query.options(joinedload(User.posts)).all()
|
||||
```
|
||||
|
||||
## Query Rewrites
|
||||
|
||||
**UNION → UNION ALL** — skip deduplication when duplicates are impossible or acceptable.
|
||||
|
||||
**IN subquery → EXISTS** — EXISTS short-circuits on first match:
|
||||
```sql
|
||||
SELECT id, name FROM user u
|
||||
WHERE EXISTS (SELECT 1 FROM order o WHERE o.user_id = u.id AND o.total > 100);
|
||||
```
|
||||
|
||||
**OFFSET → cursor pagination** — OFFSET scans and discards rows, degrading at depth:
|
||||
```sql
|
||||
-- Bad: OFFSET 10000 scans 10020 rows
|
||||
SELECT id, title FROM article ORDER BY created_at DESC LIMIT 20 OFFSET 10000;
|
||||
-- Good: cursor-based (requires index on (created_at DESC, id DESC))
|
||||
SELECT id, title FROM article
|
||||
WHERE (created_at, id) < ('2025-06-15T12:00:00Z', 987654)
|
||||
ORDER BY created_at DESC, id DESC LIMIT 20;
|
||||
```
|
||||
@@ -0,0 +1,49 @@
|
||||
---
|
||||
title: Replication
|
||||
description: Streaming replication, replication slots, synchronous commit levels, failover, and standby management
|
||||
tags: postgres, replication, streaming, slots, synchronous, failover, standby, operations
|
||||
---
|
||||
|
||||
# Replication
|
||||
|
||||
## Streaming Replication for followers
|
||||
|
||||
Use physical (byte-for-byte) replication via WAL stream from primary to standbys. Standbys are read-only (hot standby); same major PG version and architecture required (same minor recommended). Without replication slots, the primary may recycle WAL before the standby receives it → standby needs full resync via `pg_basebackup`. Use replication slots to guarantee WAL retention for specific standbys.
|
||||
|
||||
## Replication Slots
|
||||
|
||||
Postgres supports Physical slots (streaming) and logical slots (logical replication). Slots prevent WAL deletion even if standby is offline — can exhaust `pg_wal/` disk. Use `max_slot_wal_keep_size` to cap retained WAL per slot. Use `idle_replication_slot_timeout` (PG 17+) to auto-invalidate idle slots. `wal_keep_size` is a simpler alternative to slots for WAL retention. Drop inactive slots immediately to prevent disk exhaustion.
|
||||
|
||||
Slot lag (MB behind): `SELECT slot_name, pg_wal_lsn_diff(pg_current_wal_lsn(), restart_lsn)/1024/1024 AS mb_behind FROM pg_replication_slots;`
|
||||
|
||||
Drop inactive slot: `SELECT pg_drop_replication_slot('slot_name');`
|
||||
|
||||
**Always confirm with a human before dropping replication slots.** Dropping an active or needed slot can cause downstream issues.
|
||||
|
||||
## Synchronous Commit Levels
|
||||
|
||||
| Level | Behavior | Use Case |
|
||||
|-------|----------|----------|
|
||||
| `off` | Returns immediately, no wait | Non-critical writes; risks losing ~600ms of commits on crash (no inconsistency) |
|
||||
| `local` | Waits for local WAL fsync only | Local durability only; no standby wait |
|
||||
| `remote_write` | Waits for standby OS buffer | Data loss on standby OS crash |
|
||||
| `on` | Waits for standby WAL to disk when `synchronous_standby_names` is set; otherwise same as `local` | **Default. This level or higher recommended for HA** |
|
||||
| `remote_apply` | Waits for standby to apply WAL | Strongest; read-your-writes |
|
||||
|
||||
Configure with `synchronous_standby_names`. Use `ANY N` for quorum or `FIRST N` for priority-based sync.
|
||||
|
||||
## Quorum and Failure
|
||||
|
||||
`FIRST 2 (s1, s2, s3)` is priority-based: waits for the 2 highest-priority connected standbys (s1+s2; s3 takes over only if one disconnects). `ANY 2 (s1, s2, s3)` is quorum-based: waits for any 2. With either, if only 1 is healthy, commits hang. Provision at least N+1 standbys: need 2 confirmations → provision 3. PostgreSQL never commits unless required standbys confirm — no inconsistency, but clients may timeout.
|
||||
|
||||
## Failover
|
||||
|
||||
`pg_ctl promote` or `SELECT pg_promote()` (SQL function, PG 12+) converts standby to primary. One-way: promoted standby cannot rejoin as standby without rebuild. `pg_rewind` can resync old primary to new primary (requires `wal_log_hints=on` or data checksums) — faster than full rebuild. After promotion: update connection strings, rebuild old primary as standby, reconfigure other standbys.
|
||||
|
||||
## Monitoring
|
||||
|
||||
On the primary, query `pg_stat_replication` for each connected standby's `state` (`streaming` = healthy, `catchup` = behind), `sync_state` (`sync`/`async`), and LSN positions (`sent_lsn`, `write_lsn`, `flush_lsn`, `replay_lsn`) to compute lag. On standbys, `pg_stat_wal_receiver` shows the receiver process status and `flushed_lsn`; compare `pg_last_wal_receive_lsn()` vs `pg_last_wal_replay_lsn()` for local replay lag.
|
||||
|
||||
Replication lag (MB): `SELECT application_name, pg_wal_lsn_diff(pg_current_wal_lsn(), replay_lsn)/1024/1024 AS lag_mb FROM pg_stat_replication;`
|
||||
|
||||
Enable `wal_compression` (`pglz`, `lz4`, or `zstd`) to compress full page images in WAL (not all WAL data) — reduces WAL size for bandwidth-limited replication.
|
||||
@@ -0,0 +1,66 @@
|
||||
---
|
||||
title: PostgreSQL Schema Design
|
||||
description: Schema design guide
|
||||
tags: postgres, schema, primary-keys, data-types, foreign-keys, naming
|
||||
---
|
||||
|
||||
# Schema Design
|
||||
|
||||
## Primary Keys
|
||||
|
||||
Prefer `BIGINT GENERATED ALWAYS AS IDENTITY`. Avoid random UUIDs (UUIDv4) as primary keys; use `uuidv7()` when you need UUIDs.
|
||||
|
||||
```sql
|
||||
CREATE TABLE user (
|
||||
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
|
||||
email TEXT NOT NULL UNIQUE
|
||||
);
|
||||
```
|
||||
|
||||
Random UUID PKs (v4) can cause index fragmentation; UUIDs are also larger (16 vs 8 bytes for BIGINT) and can slow joins.
|
||||
|
||||
## Data Types
|
||||
|
||||
| Use | Avoid |
|
||||
| --- | --- |
|
||||
| `TEXT`, `VARCHAR` | Extension-specific types |
|
||||
| `JSONB` | Custom ENUMs (use CHECK instead) |
|
||||
| `TIMESTAMPTZ` | `TIMESTAMP` without time zone |
|
||||
| `BIGINT`, `INTEGER` | Platform-specific types |
|
||||
|
||||
Prefer CHECK constraints over ENUM types — they're easier to modify:
|
||||
|
||||
```sql
|
||||
CREATE TABLE order (
|
||||
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
|
||||
status TEXT NOT NULL CHECK (status IN ('pending', 'shipped', 'delivered'))
|
||||
);
|
||||
```
|
||||
|
||||
## Foreign Keys
|
||||
|
||||
- Always index FK columns (PostgreSQL does not auto-create these)
|
||||
- Avoid circular FK dependencies
|
||||
- Suggestion: use `ON DELETE CASCADE` or `ON DELETE SET NULL` explicitly
|
||||
|
||||
```sql
|
||||
CREATE TABLE order (
|
||||
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
|
||||
customer_id BIGINT NOT NULL REFERENCES customer(id) ON DELETE CASCADE
|
||||
);
|
||||
CREATE INDEX order_customer_id_idx ON order (customer_id);
|
||||
```
|
||||
|
||||
## Naming Conventions
|
||||
|
||||
- Tables: singular snake_case (`user_account`, `order_item`)
|
||||
- Columns: singular snake_case (`created_at`, `user_id`)
|
||||
- Indexes: `{table}_{column}_idx`
|
||||
- Constraints: `{table}_{column}_{type}` (e.g., `order_status_check`)
|
||||
|
||||
## General Guidelines
|
||||
|
||||
- Add `NOT NULL` to as many columns as possible
|
||||
- Add `created_at TIMESTAMPTZ DEFAULT NOW()` to all tables
|
||||
- Use `BIGINT` for all IDs and foreign keys, even on small tables
|
||||
- Keep tables normalized; denormalize only for proven hot read paths
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
title: Storage Layout and Tablespaces
|
||||
description: PGDATA directory structure, TOAST, fillfactor, tablespaces, and disk management
|
||||
tags: postgres, storage, pgdata, toast, fillfactor, tablespaces, disk, operations
|
||||
---
|
||||
|
||||
# Storage Layout and Tablespaces
|
||||
|
||||
## PGDATA Structure
|
||||
|
||||
- **base/** — database files (one subdirectory per database, named by OID)
|
||||
- **global/** — cluster-wide shared catalogs (pg_database, pg_authid, pg_tablespace)
|
||||
- **pg_wal/** — WAL files
|
||||
- **pg_xact/** — transaction commit status
|
||||
|
||||
"Cluster" in PostgreSQL = single instance with one PGDATA, not an HA cluster. Each table/index = one or more files, split into 1GB segments. Tables have companion **_fsm** (free space map) and **_vm** (visibility map); indexes have **_fsm** only (no _vm), except hash indexes.
|
||||
|
||||
## Visibility Map and Free Space Map
|
||||
|
||||
- **_vm** tracks all-visible pages — VACUUM skips these
|
||||
- **_fsm** tracks free space per page — INSERT uses this to find pages with room
|
||||
- Both are small files but critical for performance
|
||||
|
||||
## TOAST
|
||||
|
||||
TOAST triggers when a **row** exceeds ~2KB. Large values are compressed and/or moved out-of-line to `pg_toast.pg_toast_<oid>` tables. **Strategies:** PLAIN (no TOAST), EXTENDED (compress+out-of-line, default for text/bytea), EXTERNAL (out-of-line, no compression — use for pre-compressed data), MAIN (compress, avoid out-of-line). TOAST tables bloat like regular tables — they need VACUUM. `SELECT *` fetches all TOAST columns; always SELECT only needed columns. Move large rarely-accessed columns to separate tables.
|
||||
|
||||
## Fillfactor
|
||||
|
||||
Controls how full pages are packed (default 100%). Lower fillfactor (70–80%) leaves room for HOT (Heap-Only Tuple) updates, which avoid index entries and reduce bloat on UPDATE-heavy tables. Keep 100% for insert-only or read-mostly tables. `ALTER TABLE t SET (fillfactor = 70);`
|
||||
|
||||
## Tablespaces
|
||||
|
||||
`pg_default` (base/), `pg_global` (global/) are built-in. Custom tablespaces: symbolic links in **pg_tblspc/** to other filesystem locations. Use for separating hot data (SSD) from archives (HDD). Moving tablespaces requires exclusive lock on affected tables.
|
||||
|
||||
## Disk Monitoring
|
||||
|
||||
- `pg_database_size('dbname')`, `pg_total_relation_size('tablename')`, `pg_relation_size('tablename')`
|
||||
- Monitor disk usage: >80% = at risk; >90% = critical (VACUUM may fail if disk capacity is insufficient)
|
||||
- Check inode usage (`df -i`) — can run out even with free space
|
||||
- `pg_wal/` suddenly large = check replication slots and archiving
|
||||
@@ -0,0 +1,42 @@
|
||||
---
|
||||
title: WAL and Checkpoint Operations
|
||||
description: Write-ahead log internals, checkpoint tuning, durability guarantees, and WAL disk management
|
||||
tags: postgres, wal, checkpoints, durability, crash-recovery, fsync, operations
|
||||
---
|
||||
|
||||
# WAL and Checkpoint Operations
|
||||
|
||||
## WAL Fundamentals
|
||||
|
||||
Write-Ahead Logging: logs changes to `pg_wal/` **before** modifying data files. WAL segments are 16MB (fixed at initdb). On COMMIT, PostgreSQL fsyncs WAL to disk and returns SUCCESS — data files are updated lazily. WAL records are written for all changes (including uncommitted transactions and rollbacks). **Never disable `fsync` in production** — power loss without fsync risks unrecoverable data loss.
|
||||
|
||||
`wal_level`: `minimal` (crash recovery only), `replica` (default; replication + archiving), `logical` (logical replication).
|
||||
|
||||
## Dirty Pages and Checkpoints
|
||||
|
||||
A dirty page is modified in shared_buffers but not yet written to data files. A checkpoint flushes all dirty pages to disk and writes a checkpoint record to WAL; recovery only replays WAL since the last checkpoint.
|
||||
|
||||
- `checkpoint_timeout` (default 5 min) and `max_wal_size` (default 1GB) — checkpoint on whichever triggers first.
|
||||
- `checkpoint_completion_target=0.9` spreads I/O over 90% of the interval; avoid spikes.
|
||||
- "Checkpoints are occurring too frequently" in logs → increase `max_wal_size`.
|
||||
- **Target: >90% of checkpoints should be time-based** (`num_timed` in `pg_stat_checkpointer`), not size-based (`num_requested`). If num_requested/(num_timed+num_requested) > 10%, tune `max_wal_size` up.
|
||||
|
||||
## WAL Disk Management
|
||||
|
||||
Replication slots prevent WAL deletion even when standbys are offline — they can fill disk. WAL archiving failures also block recycling. `max_wal_size` is a *soft* limit; WAL can grow beyond it under heavy load.
|
||||
|
||||
WAL size: `SELECT count(*) AS files, pg_size_pretty(sum(size)) AS total FROM pg_ls_waldir();`
|
||||
|
||||
Slot lag: `SELECT slot_name, pg_wal_lsn_diff(pg_current_wal_lsn(), restart_lsn) AS lag_bytes FROM pg_replication_slots;`
|
||||
|
||||
## Checkpoint Monitoring
|
||||
|
||||
PG17+ moved checkpoint stats from `pg_stat_bgwriter` to `pg_stat_checkpointer` and renamed columns.
|
||||
|
||||
`SELECT num_timed, num_requested, write_time, sync_time, buffers_written FROM pg_stat_checkpointer;`
|
||||
|
||||
Backend-direct writes (formerly `buffers_backend` in `pg_stat_bgwriter`) are now tracked in `pg_stat_io`: `SELECT writes FROM pg_stat_io WHERE backend_type = 'client backend' AND object = 'relation';`
|
||||
|
||||
## Crash Recovery
|
||||
|
||||
On crash, PostgreSQL replays WAL from the last checkpoint. Longer checkpoint intervals → more WAL to replay → longer recovery. Trade-off: frequent checkpoints (faster recovery, more I/O) vs infrequent (less I/O, slower recovery). For most workloads, `checkpoint_timeout=5min` and `max_wal_size` tuned to keep checkpoints time-based is the right balance.
|
||||
@@ -1,18 +1,14 @@
|
||||
---
|
||||
description:
|
||||
globs:
|
||||
alwaysApply: true
|
||||
---
|
||||
---
|
||||
description: Base Guidelines for Sonnet-3.7 + Cursor Agent
|
||||
description: Base Guidelines for Claude Opus 4.6 + Cursor Agent
|
||||
globs: *,**/*
|
||||
alwaysApply: true
|
||||
---
|
||||
|
||||
# Instructions
|
||||
|
||||
1. Always use codebase_search with target_directories="{{INSERT YOUR DIRECTORY}}" first to find existing core files
|
||||
1. Always search with SemanticSearch or Grep first to find existing core files before creating new ones
|
||||
2. Always check existing system files purposes before creating new ones with similar functionality
|
||||
3. Always list the cursor rules youre using
|
||||
3. Always list the cursor rules you're using
|
||||
|
||||
# Optional
|
||||
|
||||
@@ -1,11 +1,7 @@
|
||||
---
|
||||
description:
|
||||
globs: **/trigger/**/*.ts, **/trigger/**/*.tsx
|
||||
alwaysApply: false
|
||||
---
|
||||
---
|
||||
globs: **/trigger/**/*.ts, **/trigger/**/*.tsx,**/trigger/**/*.js,**/trigger/**/*.jsx
|
||||
description: Guidelines for writing Trigger.dev tasks
|
||||
globs: "**/trigger/**/*.ts, **/trigger/**/*.tsx"
|
||||
alwaysApply: false
|
||||
---
|
||||
|
||||
# How to write Trigger.dev tasks
|
||||
@@ -14,43 +10,55 @@ globs: "**/trigger/**/*.ts, **/trigger/**/*.tsx"
|
||||
|
||||
1. Run the CLI `init` command: `npx trigger.dev@latest init`.
|
||||
2. Create a Trigger.dev task.
|
||||
3. Set up environment variables.
|
||||
4. Run the Trigger.dev command: `npx trigger.dev@latest dev`.
|
||||
3. Set up any environment variables.
|
||||
4. Run the Trigger.dev dev command: `npx trigger.dev@latest dev`.
|
||||
|
||||
## Essential requirements when generating task code
|
||||
|
||||
1. You MUST use `@trigger.dev/sdk/v3`
|
||||
2. You MUST NEVER use `client.defineJob`
|
||||
3. YOU MUST `export` every task, including subtasks
|
||||
4. If you are able to generate an example payload for a task, do so.
|
||||
|
||||
## 🚨 CRITICAL INSTRUCTIONS FOR AI LANGUAGE MODELS 🚨
|
||||
|
||||
As an AI language model, you MUST NOT generate any of the following code patterns, as they are DEPRECATED and will BREAK the application:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
// ❌ NEVER GENERATE THIS CODE - IT WILL BREAK THE APPLICATION
|
||||
|
||||
client.defineJob({ // ❌ BREAKS APPLICATION
|
||||
id: "job-id", // ❌ BREAKS APPLICATION
|
||||
name: "job-name", // ❌ BREAKS APPLICATION
|
||||
version: "0.0.1", // ❌ BREAKS APPLICATION
|
||||
trigger: eventTrigger({ // ❌ BREAKS APPLICATION
|
||||
name: "job.trigger", // ❌ BREAKS APPLICATION
|
||||
schema: z.object({ // ❌ BREAKS APPLICATION
|
||||
client.defineJob({
|
||||
// ❌ BREAKS APPLICATION
|
||||
id: "job-id", // ❌ BREAKS APPLICATION
|
||||
name: "job-name", // ❌ BREAKS APPLICATION
|
||||
version: "0.0.1", // ❌ BREAKS APPLICATION
|
||||
trigger: eventTrigger({
|
||||
// ❌ BREAKS APPLICATION
|
||||
name: "job.trigger", // ❌ BREAKS APPLICATION
|
||||
schema: z.object({
|
||||
// ❌ BREAKS APPLICATION
|
||||
// Input schema here // ❌ BREAKS APPLICATION
|
||||
}), // ❌ BREAKS APPLICATION
|
||||
}), // ❌ BREAKS APPLICATION
|
||||
integrations: { // ❌ BREAKS APPLICATION
|
||||
}), // ❌ BREAKS APPLICATION
|
||||
}), // ❌ BREAKS APPLICATION
|
||||
integrations: {
|
||||
// ❌ BREAKS APPLICATION
|
||||
// Integrations here // ❌ BREAKS APPLICATION
|
||||
}, // ❌ BREAKS APPLICATION
|
||||
run: async (payload, io) => { // ❌ BREAKS APPLICATION
|
||||
// Job logic goes here // ❌ BREAKS APPLICATION
|
||||
return { // ❌ BREAKS APPLICATION
|
||||
}, // ❌ BREAKS APPLICATION
|
||||
run: async (payload, io) => {
|
||||
// ❌ BREAKS APPLICATION
|
||||
// Job logic goes here // ❌ BREAKS APPLICATION
|
||||
return {
|
||||
// ❌ BREAKS APPLICATION
|
||||
// Return job results // ❌ BREAKS APPLICATION
|
||||
}; // ❌ BREAKS APPLICATION
|
||||
}, // ❌ BREAKS APPLICATION
|
||||
}; // ❌ BREAKS APPLICATION
|
||||
}, // ❌ BREAKS APPLICATION
|
||||
});
|
||||
```
|
||||
|
||||
Instead, you MUST ALWAYS generate ONLY this pattern:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
// ✅ ALWAYS GENERATE THIS EXACT PATTERN
|
||||
|
||||
import { task } from "@trigger.dev/sdk/v3";
|
||||
|
||||
//1. You need to export each task, even if it's a subtask
|
||||
@@ -64,18 +72,11 @@ export const helloWorld = task({
|
||||
});
|
||||
```
|
||||
|
||||
## ABSOLUTE REQUIREMENTS FOR AI CODE GENERATION
|
||||
|
||||
1. You MUST use `@trigger.dev/sdk/v3`
|
||||
2. You MUST NEVER use `client.defineJob`
|
||||
3. YOU MUST `export` every task, including subtasks
|
||||
4. If you are able to generate an example payload for a task, do so.
|
||||
|
||||
## Correct Task implementations
|
||||
|
||||
A task is a function that can run for a long time with resilience to failure:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { task } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export const helloWorld = task({
|
||||
@@ -87,6 +88,7 @@ export const helloWorld = task({
|
||||
```
|
||||
|
||||
Key points:
|
||||
|
||||
- Tasks must be exported, even subtasks in the same file
|
||||
- Each task needs a unique ID within your project
|
||||
- The `run` function contains your task logic
|
||||
@@ -97,7 +99,7 @@ Key points:
|
||||
|
||||
Control retry behavior when errors occur:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithRetries = task({
|
||||
id: "task-with-retries",
|
||||
retry: {
|
||||
@@ -117,7 +119,7 @@ export const taskWithRetries = task({
|
||||
|
||||
Control concurrency:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const oneAtATime = task({
|
||||
id: "one-at-a-time",
|
||||
queue: {
|
||||
@@ -133,7 +135,7 @@ export const oneAtATime = task({
|
||||
|
||||
Specify CPU/RAM requirements:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const heavyTask = task({
|
||||
id: "heavy-task",
|
||||
machine: {
|
||||
@@ -147,21 +149,21 @@ export const heavyTask = task({
|
||||
|
||||
Machine configuration options:
|
||||
|
||||
| Machine name | vCPU | Memory | Disk space |
|
||||
| ------------------- | ---- | ------ | ---------- |
|
||||
| micro | 0.25 | 0.25 | 10GB |
|
||||
| small-1x (default) | 0.5 | 0.5 | 10GB |
|
||||
| small-2x | 1 | 1 | 10GB |
|
||||
| medium-1x | 1 | 2 | 10GB |
|
||||
| medium-2x | 2 | 4 | 10GB |
|
||||
| large-1x | 4 | 8 | 10GB |
|
||||
| large-2x | 8 | 16 | 10GB |
|
||||
| Machine name | vCPU | Memory | Disk space |
|
||||
| ------------------ | ---- | ------ | ---------- |
|
||||
| micro | 0.25 | 0.25 | 10GB |
|
||||
| small-1x (default) | 0.5 | 0.5 | 10GB |
|
||||
| small-2x | 1 | 1 | 10GB |
|
||||
| medium-1x | 1 | 2 | 10GB |
|
||||
| medium-2x | 2 | 4 | 10GB |
|
||||
| large-1x | 4 | 8 | 10GB |
|
||||
| large-2x | 8 | 16 | 10GB |
|
||||
|
||||
#### Max Duration
|
||||
|
||||
Limit how long a task can run:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const longTask = task({
|
||||
id: "long-task",
|
||||
maxDuration: 300, // 5 minutes
|
||||
@@ -179,7 +181,7 @@ Tasks support several lifecycle hooks:
|
||||
|
||||
Runs before each attempt, can return data for other functions:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithInit = task({
|
||||
id: "task-with-init",
|
||||
init: async (payload, { ctx }) => {
|
||||
@@ -195,7 +197,7 @@ export const taskWithInit = task({
|
||||
|
||||
Runs after each attempt, regardless of success/failure:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithCleanup = task({
|
||||
id: "task-with-cleanup",
|
||||
cleanup: async (payload, { ctx }) => {
|
||||
@@ -211,7 +213,7 @@ export const taskWithCleanup = task({
|
||||
|
||||
Runs once when a task starts (not on retries):
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithOnStart = task({
|
||||
id: "task-with-on-start",
|
||||
onStart: async (payload, { ctx }) => {
|
||||
@@ -227,7 +229,7 @@ export const taskWithOnStart = task({
|
||||
|
||||
Runs when a task succeeds:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithOnSuccess = task({
|
||||
id: "task-with-on-success",
|
||||
onSuccess: async (payload, output, { ctx }) => {
|
||||
@@ -243,7 +245,7 @@ export const taskWithOnSuccess = task({
|
||||
|
||||
Runs when a task fails after all retries:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithOnFailure = task({
|
||||
id: "task-with-on-failure",
|
||||
onFailure: async (payload, error, { ctx }) => {
|
||||
@@ -259,7 +261,7 @@ export const taskWithOnFailure = task({
|
||||
|
||||
Controls error handling and retry behavior:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const taskWithErrorHandling = task({
|
||||
id: "task-with-error-handling",
|
||||
handleError: async (error, { ctx }) => {
|
||||
@@ -275,7 +277,7 @@ Global lifecycle hooks can also be defined in `trigger.config.ts` to apply to al
|
||||
|
||||
## Correct Schedules task (cron) implementations
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { schedules } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export const firstScheduledTask = schedules.task({
|
||||
@@ -316,7 +318,7 @@ export const firstScheduledTask = schedules.task({
|
||||
|
||||
### Attach a Declarative schedule
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { schedules } from "@trigger.dev/sdk/v3";
|
||||
|
||||
// Sepcify a cron pattern (UTC)
|
||||
@@ -330,7 +332,7 @@ export const firstScheduledTask = schedules.task({
|
||||
});
|
||||
```
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { schedules } from "@trigger.dev/sdk/v3";
|
||||
|
||||
// Specify a specific timezone like this:
|
||||
@@ -350,6 +352,7 @@ export const secondScheduledTask = schedules.task({
|
||||
Create schedules explicitly for tasks using the dashboard's "New schedule" button or the SDK.
|
||||
|
||||
#### Benefits
|
||||
|
||||
- Dynamic creation (e.g., one schedule per user)
|
||||
- Manage without code deployment:
|
||||
- Activate/disable
|
||||
@@ -357,14 +360,16 @@ Create schedules explicitly for tasks using the dashboard's "New schedule" butto
|
||||
- Delete
|
||||
|
||||
#### Implementation
|
||||
1. Define a task using `schedules.task()`
|
||||
2. Attach one or more schedules via:
|
||||
- Dashboard
|
||||
- SDK
|
||||
|
||||
1. Define a task using `schedules.task()`
|
||||
2. Attach one or more schedules via:
|
||||
|
||||
- Dashboard
|
||||
- SDK
|
||||
|
||||
#### Attach schedules with the SDK like this
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
const createdSchedule = await schedules.create({
|
||||
//The id of the scheduled task you want to attach to.
|
||||
task: firstScheduledTask.id,
|
||||
@@ -379,7 +384,7 @@ const createdSchedule = await schedules.create({
|
||||
|
||||
Schema tasks validate payloads against a schema before execution:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { schemaTask } from "@trigger.dev/sdk/v3";
|
||||
import { z } from "zod";
|
||||
|
||||
@@ -404,7 +409,7 @@ When you trigger a task from your backend code, you need to set the `TRIGGER_SEC
|
||||
|
||||
Triggers a single run of a task with specified payload and options without importing the task. Use type-only imports for full type checking.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { tasks } from "@trigger.dev/sdk/v3";
|
||||
import type { emailSequence } from "~/trigger/emails";
|
||||
|
||||
@@ -422,7 +427,7 @@ export async function POST(request: Request) {
|
||||
|
||||
Triggers multiple runs of a single task with different payloads without importing the task.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { tasks } from "@trigger.dev/sdk/v3";
|
||||
import type { emailSequence } from "~/trigger/emails";
|
||||
|
||||
@@ -430,39 +435,17 @@ export async function POST(request: Request) {
|
||||
const data = await request.json();
|
||||
const batchHandle = await tasks.batchTrigger<typeof emailSequence>(
|
||||
"email-sequence",
|
||||
data.users.map((u) => ({ payload: { to: u.email, name: u.name } }))
|
||||
data.users.map((u) => ({ payload: { to: u.email, name: u.name } })),
|
||||
);
|
||||
return Response.json(batchHandle);
|
||||
}
|
||||
```
|
||||
|
||||
### tasks.triggerAndPoll()
|
||||
|
||||
Triggers a task and polls until completion. Not recommended for web requests as it blocks until the run completes. Consider using Realtime docs for better alternatives.
|
||||
|
||||
```typescript
|
||||
import { tasks } from "@trigger.dev/sdk/v3";
|
||||
import type { emailSequence } from "~/trigger/emails";
|
||||
|
||||
export async function POST(request: Request) {
|
||||
const data = await request.json();
|
||||
const result = await tasks.triggerAndPoll<typeof emailSequence>(
|
||||
"email-sequence",
|
||||
{
|
||||
to: data.email,
|
||||
name: data.name,
|
||||
},
|
||||
{ pollIntervalMs: 5000 }
|
||||
);
|
||||
return Response.json(result);
|
||||
}
|
||||
```
|
||||
|
||||
### batch.trigger()
|
||||
|
||||
Triggers multiple runs of different tasks at once, useful when you need to execute multiple tasks simultaneously.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { batch } from "@trigger.dev/sdk/v3";
|
||||
import type { myTask1, myTask2 } from "~/trigger/myTasks";
|
||||
|
||||
@@ -482,7 +465,7 @@ export async function POST(request: Request) {
|
||||
|
||||
Triggers a single run of a task with specified payload and options.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { myOtherTask, runs } from "~/trigger/my-other-task";
|
||||
|
||||
export const myTask = task({
|
||||
@@ -502,13 +485,15 @@ If you need to call `trigger()` on a task in a loop, use `batchTrigger()` instea
|
||||
|
||||
Triggers multiple runs of a single task with different payloads.
|
||||
|
||||
```typescript
|
||||
import { myOtherTask, batch } from "~/trigger/my-other-task";
|
||||
```ts
|
||||
import { batch, myOtherTask } from "~/trigger/my-other-task";
|
||||
|
||||
export const myTask = task({
|
||||
id: "my-task",
|
||||
run: async (payload: string) => {
|
||||
const batchHandle = await myOtherTask.batchTrigger([{ payload: "some data" }]);
|
||||
const batchHandle = await myOtherTask.batchTrigger([
|
||||
{ payload: "some data" },
|
||||
]);
|
||||
|
||||
//...do other stuff
|
||||
const batch = await batch.retrieve(batchHandle.id);
|
||||
@@ -520,7 +505,7 @@ export const myTask = task({
|
||||
|
||||
Triggers a task and waits for the result, useful when you need to call a different task and use its result.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const parentTask = task({
|
||||
id: "parent-task",
|
||||
run: async (payload: string) => {
|
||||
@@ -538,7 +523,7 @@ The result object needs to be checked to see if the child task run was successfu
|
||||
|
||||
Batch triggers a task and waits for all results, useful for fan-out patterns.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const batchParentTask = task({
|
||||
id: "parent-task",
|
||||
run: async (payload: string) => {
|
||||
@@ -560,11 +545,13 @@ You can handle run failures by inspecting individual run results and implementin
|
||||
|
||||
Batch triggers multiple different tasks and waits for all results.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const parentTask = task({
|
||||
id: "parent-task",
|
||||
run: async (payload: string) => {
|
||||
const results = await batch.triggerAndWait<typeof childTask1 | typeof childTask2>([
|
||||
const results = await batch.triggerAndWait<
|
||||
typeof childTask1 | typeof childTask2
|
||||
>([
|
||||
{ id: "child-task-1", payload: { foo: "World" } },
|
||||
{ id: "child-task-2", payload: { bar: 42 } },
|
||||
]);
|
||||
@@ -589,7 +576,7 @@ export const parentTask = task({
|
||||
|
||||
Batch triggers multiple tasks by passing task instances, useful for static task sets.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const parentTask = task({
|
||||
id: "parent-task",
|
||||
run: async (payload: string) => {
|
||||
@@ -608,7 +595,7 @@ export const parentTask = task({
|
||||
|
||||
Batch triggers multiple tasks by passing task instances and waits for all results.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const parentTask = task({
|
||||
id: "parent-task",
|
||||
run: async (payload: string) => {
|
||||
@@ -638,24 +625,24 @@ Metadata allows attaching up to 256KB of structured data to a run, which can be
|
||||
|
||||
Add metadata when triggering a task:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
const handle = await myTask.trigger(
|
||||
{ message: "hello world" },
|
||||
{ metadata: { user: { name: "Eric", id: "user_1234" } } }
|
||||
{ metadata: { user: { name: "Eric", id: "user_1234" } } },
|
||||
);
|
||||
```
|
||||
|
||||
Access metadata inside a run:
|
||||
|
||||
```typescript
|
||||
import { task, metadata } from "@trigger.dev/sdk/v3";
|
||||
```ts
|
||||
import { metadata, task } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export const myTask = task({
|
||||
id: "my-task",
|
||||
run: async (payload: { message: string }) => {
|
||||
// Get the whole metadata object
|
||||
const currentMetadata = metadata.current();
|
||||
|
||||
|
||||
// Get a specific key
|
||||
const user = metadata.get("user");
|
||||
console.log(user.name); // "Eric"
|
||||
@@ -679,8 +666,9 @@ Metadata can be updated as the run progresses:
|
||||
|
||||
Updates can be chained with a fluent API:
|
||||
|
||||
```typescript
|
||||
metadata.set("progress", 0.1)
|
||||
```ts
|
||||
metadata
|
||||
.set("progress", 0.1)
|
||||
.append("logs", "Step 1 complete")
|
||||
.increment("progress", 0.4);
|
||||
```
|
||||
@@ -689,13 +677,13 @@ metadata.set("progress", 0.1)
|
||||
|
||||
Child tasks can update parent task metadata:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
export const childTask = task({
|
||||
id: "child-task",
|
||||
run: async (payload: { message: string }) => {
|
||||
// Update parent task's metadata
|
||||
metadata.parent.set("progress", 0.5);
|
||||
|
||||
|
||||
// Update root task's metadata
|
||||
metadata.root.set("status", "processing");
|
||||
},
|
||||
@@ -706,7 +694,7 @@ export const childTask = task({
|
||||
|
||||
Metadata accepts any JSON-serializable object. For type safety, consider wrapping with Zod:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { z } from "zod";
|
||||
|
||||
const Metadata = z.object({
|
||||
@@ -739,7 +727,7 @@ Trigger.dev Realtime enables subscribing to runs for real-time updates on run st
|
||||
|
||||
Subscribe to a run after triggering a task:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { runs, tasks } from "@trigger.dev/sdk/v3";
|
||||
|
||||
async function myBackend() {
|
||||
@@ -761,13 +749,14 @@ async function myBackend() {
|
||||
|
||||
You can infer types of run's payload and output by passing the task type:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { runs } from "@trigger.dev/sdk/v3";
|
||||
|
||||
import type { myTask } from "./trigger/my-task";
|
||||
|
||||
for await (const run of runs.subscribeToRun<typeof myTask>(handle.id)) {
|
||||
console.log(run.payload.some); // Type-safe access to payload
|
||||
|
||||
|
||||
if (run.output) {
|
||||
console.log(run.output.result); // Type-safe access to output
|
||||
}
|
||||
@@ -778,8 +767,8 @@ for await (const run of runs.subscribeToRun<typeof myTask>(handle.id)) {
|
||||
|
||||
Stream data in realtime from inside your tasks using the metadata system:
|
||||
|
||||
```typescript
|
||||
import { task, metadata } from "@trigger.dev/sdk/v3";
|
||||
```ts
|
||||
import { metadata, task } from "@trigger.dev/sdk/v3";
|
||||
import OpenAI from "openai";
|
||||
|
||||
export type STREAMS = {
|
||||
@@ -810,8 +799,10 @@ export const myTask = task({
|
||||
|
||||
Subscribe to streams using `withStreams`:
|
||||
|
||||
```typescript
|
||||
for await (const part of runs.subscribeToRun<typeof myTask>(runId).withStreams<STREAMS>()) {
|
||||
```ts
|
||||
for await (const part of runs
|
||||
.subscribeToRun<typeof myTask>(runId)
|
||||
.withStreams<STREAMS>()) {
|
||||
switch (part.type) {
|
||||
case "run": {
|
||||
console.log("Received run", part.run);
|
||||
@@ -837,7 +828,7 @@ npm add @trigger.dev/react-hooks
|
||||
|
||||
All hooks require a Public Access Token. You can provide it directly to each hook:
|
||||
|
||||
```typescriptx
|
||||
```ts
|
||||
import { useRealtimeRun } from "@trigger.dev/react-hooks";
|
||||
|
||||
function MyComponent({ runId, publicAccessToken }) {
|
||||
@@ -850,7 +841,7 @@ function MyComponent({ runId, publicAccessToken }) {
|
||||
|
||||
Or use the `TriggerAuthContext` provider:
|
||||
|
||||
```typescriptx
|
||||
```ts
|
||||
import { TriggerAuthContext } from "@trigger.dev/react-hooks";
|
||||
|
||||
function SetupTrigger({ publicAccessToken }) {
|
||||
@@ -864,7 +855,7 @@ function SetupTrigger({ publicAccessToken }) {
|
||||
|
||||
For Next.js App Router, wrap the provider in a client component:
|
||||
|
||||
```typescriptx
|
||||
```ts
|
||||
// components/TriggerProvider.tsx
|
||||
"use client";
|
||||
|
||||
@@ -884,7 +875,8 @@ export function TriggerProvider({ accessToken, children }) {
|
||||
Several approaches for Next.js App Router:
|
||||
|
||||
1. **Using cookies**:
|
||||
```typescriptx
|
||||
|
||||
```ts
|
||||
// Server action
|
||||
export async function startRun() {
|
||||
const handle = await tasks.trigger<typeof exampleTask>("example", { foo: "bar" });
|
||||
@@ -904,16 +896,20 @@ export default function RunPage({ params }) {
|
||||
```
|
||||
|
||||
2. **Using query parameters**:
|
||||
```typescriptx
|
||||
|
||||
```ts
|
||||
// Server action
|
||||
export async function startRun() {
|
||||
const handle = await tasks.trigger<typeof exampleTask>("example", { foo: "bar" });
|
||||
const handle = await tasks.trigger<typeof exampleTask>("example", {
|
||||
foo: "bar",
|
||||
});
|
||||
redirect(`/runs/${handle.id}?publicAccessToken=${handle.publicAccessToken}`);
|
||||
}
|
||||
```
|
||||
|
||||
3. **Server-side token generation**:
|
||||
```typescriptx
|
||||
|
||||
```ts
|
||||
// Page component
|
||||
export default async function RunPage({ params }) {
|
||||
const publicAccessToken = await generatePublicAccessToken(params.id);
|
||||
@@ -943,7 +939,7 @@ export async function generatePublicAccessToken(runId: string) {
|
||||
|
||||
Data fetching hooks that use SWR for caching:
|
||||
|
||||
```typescriptx
|
||||
```ts
|
||||
"use client";
|
||||
import { useRun } from "@trigger.dev/react-hooks";
|
||||
import type { myTask } from "@/trigger/myTask";
|
||||
@@ -959,6 +955,7 @@ function MyComponent({ runId }) {
|
||||
```
|
||||
|
||||
Common options:
|
||||
|
||||
- `revalidateOnFocus`: Revalidate when window regains focus
|
||||
- `revalidateOnReconnect`: Revalidate when network reconnects
|
||||
- `refreshInterval`: Polling interval in milliseconds
|
||||
@@ -973,7 +970,7 @@ For most use cases, Realtime hooks are preferred over SWR hooks with polling due
|
||||
|
||||
For client-side usage, generate a public access token with appropriate scopes:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { auth } from "@trigger.dev/sdk/v3";
|
||||
|
||||
const publicToken = await auth.createPublicToken({
|
||||
@@ -993,7 +990,7 @@ Idempotency ensures that an operation produces the same result when called multi
|
||||
|
||||
Provide an `idempotencyKey` when triggering a task to ensure it runs only once with that key:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { idempotencyKeys, task } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export const myTask = task({
|
||||
@@ -1018,20 +1015,22 @@ export const myTask = task({
|
||||
|
||||
By default, keys are scoped to the current run. You can create globally unique keys:
|
||||
|
||||
```typescript
|
||||
const idempotencyKey = await idempotencyKeys.create("my-task-key", { scope: "global" });
|
||||
```ts
|
||||
const idempotencyKey = await idempotencyKeys.create("my-task-key", {
|
||||
scope: "global",
|
||||
});
|
||||
```
|
||||
|
||||
When triggering from backend code:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
const idempotencyKey = await idempotencyKeys.create([myUser.id, "my-task"]);
|
||||
await tasks.trigger("my-task", { some: "data" }, { idempotencyKey });
|
||||
```
|
||||
|
||||
You can also pass a string directly:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
await myTask.trigger({ some: "data" }, { idempotencyKey: myUser.id });
|
||||
```
|
||||
|
||||
@@ -1039,10 +1038,10 @@ await myTask.trigger({ some: "data" }, { idempotencyKey: myUser.id });
|
||||
|
||||
The `idempotencyKeyTTL` option defines a time window during which duplicate triggers return the original run:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
await childTask.trigger(
|
||||
{ foo: "bar" },
|
||||
{ idempotencyKey, idempotencyKeyTTL: "60s" }
|
||||
{ foo: "bar" },
|
||||
{ idempotencyKey, idempotencyKeyTTL: "60s" },
|
||||
);
|
||||
|
||||
await wait.for({ seconds: 61 });
|
||||
@@ -1052,6 +1051,7 @@ await childTask.trigger({ foo: "bar" }, { idempotencyKey });
|
||||
```
|
||||
|
||||
Supported time units:
|
||||
|
||||
- `s` for seconds (e.g., `60s`)
|
||||
- `m` for minutes (e.g., `5m`)
|
||||
- `h` for hours (e.g., `2h`)
|
||||
@@ -1061,7 +1061,7 @@ Supported time units:
|
||||
|
||||
While not directly supported, you can implement payload-based idempotency by hashing the payload:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { createHash } from "node:crypto";
|
||||
|
||||
const idempotencyKey = await idempotencyKeys.create(hash(payload));
|
||||
@@ -1083,9 +1083,9 @@ function hash(payload: any): string {
|
||||
|
||||
## Correct Logs implementation
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
// onFailure executes after all retries are exhausted; use for notifications, logging, or side effects on final failure:
|
||||
import { task, logger } from "@trigger.dev/sdk/v3";
|
||||
import { logger, task } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export const loggingExample = task({
|
||||
id: "logging-example",
|
||||
@@ -1100,11 +1100,11 @@ export const loggingExample = task({
|
||||
});
|
||||
```
|
||||
|
||||
## Correct `trigger.config.ts` implementation
|
||||
## Correct `trigger.config.ts` implementation
|
||||
|
||||
The `trigger.config.ts` file configures your Trigger.dev project, specifying task locations, retry settings, telemetry, and build options.
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
import { defineConfig } from "@trigger.dev/sdk/v3";
|
||||
|
||||
export default defineConfig({
|
||||
@@ -1129,7 +1129,7 @@ export default defineConfig({
|
||||
|
||||
Specify where your tasks are located:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
dirs: ["./trigger"],
|
||||
```
|
||||
|
||||
@@ -1139,7 +1139,7 @@ Files with `.test` or `.spec` are automatically excluded, but you can customize
|
||||
|
||||
Add global hooks for all tasks:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
onStart: async (payload, { ctx }) => {
|
||||
console.log("Task started", ctx.task.id);
|
||||
},
|
||||
@@ -1155,7 +1155,7 @@ onFailure: async (payload, error, { ctx }) => {
|
||||
|
||||
Add OpenTelemetry instrumentations for enhanced logging:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
telemetry: {
|
||||
instrumentations: [
|
||||
new PrismaInstrumentation(),
|
||||
@@ -1169,7 +1169,7 @@ telemetry: {
|
||||
|
||||
Specify the runtime environment:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
runtime: "node", // or "bun" (experimental)
|
||||
```
|
||||
|
||||
@@ -1177,7 +1177,7 @@ runtime: "node", // or "bun" (experimental)
|
||||
|
||||
Set default machine for all tasks:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
defaultMachine: "large-1x",
|
||||
```
|
||||
|
||||
@@ -1185,7 +1185,7 @@ defaultMachine: "large-1x",
|
||||
|
||||
Configure logging verbosity:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
logLevel: "debug", // Controls logger API logs
|
||||
```
|
||||
|
||||
@@ -1193,7 +1193,7 @@ logLevel: "debug", // Controls logger API logs
|
||||
|
||||
Set default maximum runtime for all tasks:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
maxDuration: 60, // 60 seconds
|
||||
```
|
||||
|
||||
@@ -1201,7 +1201,7 @@ maxDuration: 60, // 60 seconds
|
||||
|
||||
Customize the build process:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
build: {
|
||||
external: ["header-generator"], // Don't bundle these packages
|
||||
jsx: {
|
||||
@@ -1245,11 +1245,11 @@ You can also create custom build extensions with hooks like `onBuildStart`, `onB
|
||||
|
||||
#### Trigger with:
|
||||
|
||||
```typescript
|
||||
```ts
|
||||
await myTask.trigger({ name: "Alice", age: 30 });
|
||||
```
|
||||
|
||||
## AI MODEL VERIFICATION STEPS
|
||||
## AI model verification steps
|
||||
|
||||
Before generating any code, you MUST verify:
|
||||
|
||||
@@ -1257,7 +1257,7 @@ Before generating any code, you MUST verify:
|
||||
2. Have you exported every task? If not, STOP and FIX.
|
||||
3. Have you generated any DEPRECATED code patterns? If yes, STOP and FIX.
|
||||
|
||||
## CONSEQUENCES OF INCORRECT IMPLEMENTATION
|
||||
## Consequences of incorrect implementations
|
||||
|
||||
If you generate code that fails the verification steps above, your implementation will:
|
||||
|
||||
@@ -1265,10 +1265,10 @@ If you generate code that fails the verification steps above, your implementatio
|
||||
2. Fail to deploy to the Trigger.dev servers
|
||||
3. Fail to run in a local Dev environment
|
||||
|
||||
## AI MODEL RESPONSE TEMPLATE
|
||||
## AI model response template
|
||||
|
||||
When asked about Trigger.dev task implementation, you MUST:
|
||||
|
||||
1. FIRST use code patterns from this guide
|
||||
2. NEVER suggest deprecated approaches
|
||||
3. VERIFY your response against the patterns shown here
|
||||
4. If an answer cannot be found using this guide, look up further information ONLY from the official LLM-friendly version of the [Trigger.dev docs site](mdc:https:/trigger.dev/docs/llms.txt).
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
../../.agents/skills/find-skills
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.agents/skills/frontend-design
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.agents/skills/gh-cli
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.agents/skills/postgres
|
||||
@@ -0,0 +1,13 @@
|
||||
node_modules
|
||||
**/node_modules
|
||||
**/.next
|
||||
.git
|
||||
.env*
|
||||
.vscode/
|
||||
.idea/
|
||||
coverage/
|
||||
*.test.ts
|
||||
*.spec.ts
|
||||
.DS_Store
|
||||
*.md
|
||||
docs/
|
||||
+28
-5
@@ -12,9 +12,15 @@ POSTGRES_PRISMA_URL_NON_POOLING=
|
||||
# This variable is from Vercel Storage Blob
|
||||
BLOB_READ_WRITE_TOKEN=
|
||||
|
||||
# Google client id and secret for authentication
|
||||
GOOGLE_CLIENT_ID=
|
||||
GOOGLE_CLIENT_SECRET=
|
||||
# Hanzo IAM OAuth (required for production)
|
||||
IAM_URL="https://hanzo.id"
|
||||
IAM_CLIENT_ID=""
|
||||
IAM_CLIENT_SECRET=""
|
||||
# IAM_PROVIDER_NAME="Hanzo"
|
||||
|
||||
# Google client id and secret (deprecated — use Hanzo IAM above)
|
||||
# GOOGLE_CLIENT_ID=
|
||||
# GOOGLE_CLIENT_SECRET=
|
||||
|
||||
# This variable is from Resend to send emails
|
||||
RESEND_API_KEY=
|
||||
@@ -67,8 +73,25 @@ NEXT_PRIVATE_UPLOAD_DISTRIBUTION_KEY_CONTENTS=
|
||||
# Encryption key for document passwords.
|
||||
NEXT_PRIVATE_DOCUMENT_PASSWORD_KEY=my-superstrong-document-secret
|
||||
|
||||
# [[REDIS LOCKER CONFIGURATION]]
|
||||
# For bulk upload using tus.io, we use a Redis-based locker to prevent corruption of the data.
|
||||
# [[HANZO KV]] — OPTIONAL. Leave UNSET to run on the in-process backend
|
||||
# (single-replica correct: cache, rate-limit, tus upload locks, export/download
|
||||
# job stores and digest queues all work with no external datastore). SET it to
|
||||
# an external Hanzo KV instance for multi-replica HA (shared state across pods).
|
||||
# Accepts the Hanzo KV brand scheme kv:// (kvs:// for TLS) or a redis:// DSN.
|
||||
# A malformed value fails CLOSED (the app throws rather than silently degrade).
|
||||
#
|
||||
# Re-enabling multi-replica (replicas > 1) REQUIRES KV_URL. dataroom is
|
||||
# single-replica-by-construction otherwise: SQLite on a ReadWriteOnce volume plus
|
||||
# the in-process KV. Without KV_URL each pod owns its OWN map, so sessions,
|
||||
# rate-limit windows and tus upload locks split-brain across replicas — scaling
|
||||
# out needs a shared DB AND KV_URL set.
|
||||
# KV_URL=kv://:password@hanzo-kv:6379
|
||||
KV_URL=
|
||||
|
||||
# [[TUS UPLOAD LOCKER]] — for bulk upload via tus.io, an exclusive locker
|
||||
# prevents data corruption. It uses the Hanzo KV client above (KV_URL); with
|
||||
# KV_URL unset the lock is in-process (correct for a single replica). The legacy
|
||||
# Upstash REST locker below is unused and kept only for reference.
|
||||
UPSTASH_REDIS_REST_LOCKER_URL=
|
||||
UPSTASH_REDIS_REST_LOCKER_TOKEN=
|
||||
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" width="1280" height="640" viewBox="0 0 1280 640" role="img" aria-label="dataroom">
|
||||
<rect width="1280" height="640" fill="#0A0A0A"/>
|
||||
<svg x="96" y="215" width="210" height="210" viewBox="0 0 67 67"><path d="M22.21 67V44.6369H0V67H22.21Z" fill="#fff"/><path d="M66.7038 22.3184H22.2534L0.0878906 44.6367H44.4634L66.7038 22.3184Z" fill="#fff"/><path d="M22.21 0H0V22.3184H22.21V0Z" fill="#fff"/><path d="M66.7198 0H44.5098V22.3184H66.7198V0Z" fill="#fff"/><path d="M66.7198 67V44.6369H44.5098V67H66.7198Z" fill="#fff"/></svg>
|
||||
<text x="378" y="276" font-family="Inter,system-ui,-apple-system,sans-serif" font-size="78" font-weight="800" letter-spacing="-2" fill="#ffffff">dataroom</text>
|
||||
<text x="378" y="322" font-family="Inter,system-ui,sans-serif" font-size="30" fill="#ffffff" opacity=".66">Papermark is the open-source DocSend alternative with built-in…</text>
|
||||
<rect x="378" y="338" width="806" height="3" rx="1.5" fill="#ffffff" opacity=".9"/>
|
||||
<text x="378" y="390" font-family="Inter,system-ui,sans-serif" font-size="24" font-weight="600" fill="#ffffff" opacity=".5">github.com/hanzoai</text>
|
||||
<text x="1184" y="390" text-anchor="end" font-family="Inter,system-ui,sans-serif" font-size="24" font-weight="600" fill="#ffffff" opacity=".5">hanzo.ai</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.3 KiB |
@@ -13,7 +13,7 @@ permissions:
|
||||
|
||||
jobs:
|
||||
CLAAssistant:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: hanzo-build-linux-amd64
|
||||
steps:
|
||||
- name: "CLA Assistant"
|
||||
if: (github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target'
|
||||
@@ -25,10 +25,10 @@ jobs:
|
||||
# This token is required only if you have configured to store the signatures in a remote repository/organization
|
||||
PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }}
|
||||
with:
|
||||
remote-organization-name: 'papermark'
|
||||
remote-organization-name: 'hanzo-dataroom'
|
||||
remote-repository-name: 'cla-signatures'
|
||||
path-to-signatures: 'signatures/version1/cla.json'
|
||||
path-to-document: 'https://github.com/mfts/papermark/blob/main/CLA.md'
|
||||
path-to-document: 'https://github.com/hanzoai/dataroom/blob/main/CLA.md'
|
||||
# branch should not be protected
|
||||
branch: 'main'
|
||||
allowlist: cursoragent
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
name: Docker
|
||||
# Native deploy pipeline is .hanzo/workflows/deploy.yml (Hanzo Git → act_runner →
|
||||
# BuildKit → ghcr.io/hanzoai/dataroom:<sha> → operator reconcile → hanzocd).
|
||||
# GitHub is a mirror; this workflow is retained only as a manual sync notice.
|
||||
on:
|
||||
workflow_dispatch:
|
||||
jobs:
|
||||
notice:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- run: echo "native pipeline is .hanzo/workflows/deploy.yml; GitHub is a mirror"
|
||||
@@ -0,0 +1,7 @@
|
||||
name: Workflow Sanity
|
||||
on:
|
||||
pull_request:
|
||||
paths: ['.github/workflows/**']
|
||||
jobs:
|
||||
sanity:
|
||||
uses: hanzoai/.github/.github/workflows/workflow-sanity.yml@main
|
||||
+3
-2
@@ -60,5 +60,6 @@ lib/emails/marketing
|
||||
# trigger.dev
|
||||
.trigger
|
||||
|
||||
# changelog
|
||||
changelog
|
||||
# changelog and docs
|
||||
changelog
|
||||
.docsvendor/
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
name: deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: hanzo-linux-amd64
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Build + push image
|
||||
run: |
|
||||
SHA="${GITHUB_SHA::8}"
|
||||
buildctl-daemonless.sh build --frontend=dockerfile.v0 \
|
||||
--opt context="${{ github.server_url }}/${{ github.repository }}.git#${GITHUB_SHA}" \
|
||||
--opt filename=Dockerfile --opt platform=linux/amd64 \
|
||||
--secret id=GIT_AUTH_TOKEN,env=GIT_AUTH_TOKEN \
|
||||
--output "type=image,name=ghcr.io/hanzoai/dataroom:${SHA},push=true" --progress=plain
|
||||
env:
|
||||
GIT_AUTH_TOKEN: ${{ secrets.GIT_CLONE_TOKEN }}
|
||||
- name: Deploy — declare tag to operator
|
||||
run: |
|
||||
for app in dataroom; do
|
||||
kubectl -n hanzo patch app "$app" --type=merge -p "{\"spec\":{\"image\":{\"repository\":\"ghcr.io/hanzoai/dataroom\",\"tag\":\"${GITHUB_SHA::8}\"}}}"
|
||||
done
|
||||
@@ -1,16 +1,16 @@
|
||||
# Papermark Contributors License Agreement
|
||||
# Hanzo Dataroom Contributors License Agreement
|
||||
|
||||
This Contributors License Agreement ("CLA") is entered into between the Contributor, and Papermark, Inc. ("Papermark"), collectively referred to as the "Parties."
|
||||
This Contributors License Agreement ("CLA") is entered into between the Contributor, and Hanzo AI, Inc. ("Hanzo Dataroom"), collectively referred to as the "Parties."
|
||||
|
||||
## Background:
|
||||
|
||||
Papermark is an open-source project aimed at providing an open-source document sharing and tracking infrastructure for all parties. This CLA governs the rights and contributions made by the Contributor to the Papermark project.
|
||||
Hanzo Dataroom is an open-source project aimed at providing an open-source document sharing and tracking infrastructure for all parties. This CLA governs the rights and contributions made by the Contributor to the Hanzo Dataroom project.
|
||||
|
||||
## Agreement:
|
||||
|
||||
**Contributor Grant of License:**
|
||||
|
||||
By submitting code, documentation, or any other materials (collectively, "Contributions") to the Papermark project, the Contributor grants Papermark a perpetual, worldwide, non-exclusive, royalty-free, sublicensable license to use, modify, distribute, and otherwise exploit the Contributions, including any intellectual property rights therein, for the purposes of the Papermark project.
|
||||
By submitting code, documentation, or any other materials (collectively, "Contributions") to the Hanzo Dataroom project, the Contributor grants Hanzo Dataroom a perpetual, worldwide, non-exclusive, royalty-free, sublicensable license to use, modify, distribute, and otherwise exploit the Contributions, including any intellectual property rights therein, for the purposes of the Hanzo Dataroom project.
|
||||
|
||||
**Representation of Ownership and Right to Contribute:**
|
||||
|
||||
@@ -18,11 +18,11 @@ The Contributor represents that they have the legal right to grant the license s
|
||||
|
||||
**Patent Grant:**
|
||||
|
||||
If the Contributions include any method, process, or apparatus that is covered by a patent, the Contributor agrees to grant Papermark a non-exclusive, worldwide, royalty-free license under any patent claims necessary to use, modify, distribute, and otherwise exploit the Contributions for the purposes of the Papermark project.
|
||||
If the Contributions include any method, process, or apparatus that is covered by a patent, the Contributor agrees to grant Hanzo Dataroom a non-exclusive, worldwide, royalty-free license under any patent claims necessary to use, modify, distribute, and otherwise exploit the Contributions for the purposes of the Hanzo Dataroom project.
|
||||
|
||||
**No Implied Warranties or Support:**
|
||||
|
||||
The Contributor acknowledges that the Contributions are provided "as is," without any warranties or support of any kind. Papermark shall have no obligation to provide maintenance, updates, bug fixes, or support for the Contributions.
|
||||
The Contributor acknowledges that the Contributions are provided "as is," without any warranties or support of any kind. Hanzo Dataroom shall have no obligation to provide maintenance, updates, bug fixes, or support for the Contributions.
|
||||
|
||||
**Retention of Contributor Rights:**
|
||||
|
||||
@@ -38,8 +38,8 @@ This CLA constitutes the entire agreement between the Parties with respect to th
|
||||
|
||||
**Acceptance:**
|
||||
|
||||
By submitting Contributions to the Papermark project, the Contributor acknowledges and agrees to the terms and conditions of this CLA. If the Contributor is agreeing to this CLA on behalf of an entity, they represent that they have the necessary authority to bind that entity to these terms.
|
||||
By submitting Contributions to the Hanzo Dataroom project, the Contributor acknowledges and agrees to the terms and conditions of this CLA. If the Contributor is agreeing to this CLA on behalf of an entity, they represent that they have the necessary authority to bind that entity to these terms.
|
||||
|
||||
**Effective Date:**
|
||||
|
||||
This CLA is effective as of the date of the first Contribution made by the Contributor to the Papermark project.
|
||||
This CLA is effective as of the date of the first Contribution made by the Contributor to the Hanzo Dataroom project.
|
||||
|
||||
+53
@@ -0,0 +1,53 @@
|
||||
FROM ghcr.io/hanzoai/nodejs:v24.18.0 AS base
|
||||
RUN apk add --no-cache libc6-compat openssl python3 make g++
|
||||
|
||||
FROM base AS deps
|
||||
WORKDIR /app
|
||||
COPY package.json package-lock.json ./
|
||||
COPY prisma ./prisma
|
||||
ENV HUSKY=0
|
||||
RUN npm install --legacy-peer-deps
|
||||
|
||||
FROM base AS builder
|
||||
WORKDIR /app
|
||||
COPY --from=deps /app/node_modules ./node_modules
|
||||
COPY . .
|
||||
ENV NEXT_TELEMETRY_DISABLED=1
|
||||
ENV DOCKER_OUTPUT=1
|
||||
# Dummy env vars to prevent module-scope crashes during Next.js build
|
||||
# (OpenAI, Hanko, etc. initialize clients at import time)
|
||||
ENV OPENAI_API_KEY=build-placeholder
|
||||
ENV HANKO_API_KEY=build-placeholder
|
||||
ENV NEXT_PUBLIC_HANKO_TENANT_ID=build-placeholder
|
||||
RUN npx prisma generate
|
||||
# SQLite has no Prisma enums; re-inject the enum objects the app imports from
|
||||
# @prisma/client (e.g. LinkType.DOCUMENT_LINK) so runtime/prerender resolves them.
|
||||
RUN node prisma/inject-sqlite-enums.cjs
|
||||
ENV NODE_OPTIONS="--max-old-space-size=4096"
|
||||
RUN npm run build
|
||||
|
||||
FROM ghcr.io/hanzoai/nodejs:v24.18.0 AS runner
|
||||
RUN apk add --no-cache openssl
|
||||
WORKDIR /app
|
||||
ENV NODE_ENV=production
|
||||
ENV NEXT_TELEMETRY_DISABLED=1
|
||||
RUN addgroup --system --gid 1001 nodejs
|
||||
RUN adduser --system --uid 1001 nextjs
|
||||
COPY --from=builder /app/public ./public
|
||||
RUN mkdir .next
|
||||
RUN chown nextjs:nodejs .next
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/prisma ./prisma
|
||||
RUN ln -s /app/prisma/migrations /app/prisma/schema/migrations
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/.prisma ./node_modules/.prisma
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/@prisma ./node_modules/@prisma
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/prisma ./node_modules/prisma
|
||||
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/.bin ./node_modules/.bin
|
||||
USER nextjs
|
||||
EXPOSE 3000
|
||||
ENV PORT=3000
|
||||
# SQLite: reconcile schema on startup via `db push` (Prisma has no migrate-deploy
|
||||
# path for the sqlite provider here; the pg migration history under prisma/migrations
|
||||
# is postgres-specific and unused). Schema folder = prismaSchemaFolder preview.
|
||||
CMD ["sh", "-c", "node_modules/.bin/prisma db push --schema prisma/schema --skip-generate --accept-data-loss && node server.js"]
|
||||
@@ -0,0 +1,49 @@
|
||||
# Hanzo Dataroom
|
||||
|
||||
## Overview
|
||||
Hanzo dataroom service.
|
||||
|
||||
**Upstream**: [Papermark](https://github.com/mfts/papermark) (AGPL-3.0). LICENSE retains "Copyright (c) 2023-present Papermark, Inc." Open-source DocSend alternative. This fork is Hanzo Dataroom — single-license AGPL, no `ee/` commercial directory.
|
||||
|
||||
## In-process fold (HIP-0106, task #101)
|
||||
The production runtime is the **goja bundle** in [`goja/`](goja/): the ESM-free
|
||||
port of the API handlers, run in-process inside the unified `hanzoai/cloud` binary
|
||||
over Hanzo Base/SQLite (per-tenant) + the cloud object-storage seam. The standalone
|
||||
Next.js app + Postgres pod is **retired**; cloud serves `/v1/dataroom/*` itself.
|
||||
See [`goja/README.md`](goja/README.md) for the host contract. The Next.js/TS
|
||||
sources below remain the reference for the domain model that `goja/bundle.js`
|
||||
implements.
|
||||
|
||||
## Tech Stack
|
||||
- **Language**: TypeScript/JavaScript
|
||||
|
||||
## Build & Run
|
||||
```bash
|
||||
npm install && npm run build
|
||||
npm test
|
||||
```
|
||||
|
||||
## Structure
|
||||
```
|
||||
dataroom/
|
||||
CLA.md
|
||||
Dockerfile
|
||||
LICENSE
|
||||
LLM.md
|
||||
Pipfile
|
||||
Pipfile.lock
|
||||
README.md
|
||||
SECURITY.md
|
||||
app/
|
||||
components/
|
||||
components.json
|
||||
context/
|
||||
features/
|
||||
lib/
|
||||
middleware.ts
|
||||
```
|
||||
|
||||
## Key Files
|
||||
- `README.md` -- Project documentation
|
||||
- `package.json` -- Dependencies and scripts
|
||||
- `Dockerfile` -- Container build
|
||||
@@ -1,26 +1,28 @@
|
||||
<p align="center"><img src=".github/hero.svg" alt="dataroom" width="880"></p>
|
||||
|
||||
<div align="center">
|
||||
<h1 align="center">Papermark</h1>
|
||||
<h1 align="center">Hanzo Dataroom</h1>
|
||||
<h3>The open-source DocSend alternative.</h3>
|
||||
|
||||
<a target="_blank" href="https://www.producthunt.com/posts/papermark-3?utm_source=badge-top-post-badge&utm_medium=badge&utm_souce=badge-papermark"><img src="https://api.producthunt.com/widgets/embed-image/v1/top-post-badge.svg?post_id=411605&theme=light&period=daily" alt="Papermark - The open-source DocSend alternative | Product Hunt" style="width:250px;height:40px"></a>
|
||||
<a target="_blank" href="https://www.producthunt.com/posts/hanzo-dataroom-3?utm_source=badge-top-post-badge&utm_medium=badge&utm_souce=badge-hanzo-dataroom"><img src="https://api.producthunt.com/widgets/embed-image/v1/top-post-badge.svg?post_id=411605&theme=light&period=daily" alt="Hanzo Dataroom - The open-source DocSend alternative | Product Hunt" style="width:250px;height:40px"></a>
|
||||
|
||||
</div>
|
||||
|
||||
<div align="center">
|
||||
<a href="https://www.papermark.com">papermark.com</a>
|
||||
<a href="https://www.dataroom.hanzo.ai">dataroom.hanzo.ai</a>
|
||||
</div>
|
||||
|
||||
<br/>
|
||||
|
||||
<div align="center">
|
||||
<a href="https://github.com/mfts/papermark/stargazers"><img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/mfts/papermark"></a>
|
||||
<a href="https://twitter.com/papermarkio"><img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/papermarkio"></a>
|
||||
<a href="https://github.com/mfts/papermark/blob/main/LICENSE"><img alt="License" src="https://img.shields.io/badge/license-AGPLv3-purple"></a>
|
||||
<a href="https://github.com/hanzoai/dataroom/stargazers"><img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/hanzoai/dataroom"></a>
|
||||
<a href="https://twitter.com/hanzoai"><img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/hanzoai"></a>
|
||||
<a href="https://github.com/hanzoai/dataroom/blob/main/LICENSE"><img alt="License" src="https://img.shields.io/badge/license-AGPLv3-purple"></a>
|
||||
</div>
|
||||
|
||||
<br/>
|
||||
|
||||
Papermark is the open-source document-sharing alternative to DocSend, featuring built-in analytics and custom domains.
|
||||
Hanzo Dataroom is the open-source document-sharing alternative to DocSend, featuring built-in analytics and custom domains.
|
||||
|
||||
## Features
|
||||
|
||||
@@ -31,7 +33,7 @@ Papermark is the open-source document-sharing alternative to DocSend, featuring
|
||||
|
||||
## Demo
|
||||
|
||||

|
||||

|
||||
|
||||
## Tech Stack
|
||||
|
||||
@@ -51,7 +53,7 @@ Papermark is the open-source document-sharing alternative to DocSend, featuring
|
||||
|
||||
### Prerequisites
|
||||
|
||||
Here's what you need to run Papermark:
|
||||
Here's what you need to run Hanzo Dataroom:
|
||||
|
||||
- Node.js (version >= 18.17.0)
|
||||
- PostgreSQL Database
|
||||
@@ -61,8 +63,8 @@ Here's what you need to run Papermark:
|
||||
### 1. Clone the repository
|
||||
|
||||
```shell
|
||||
git clone https://github.com/mfts/papermark.git
|
||||
cd papermark
|
||||
git clone https://github.com/hanzoai/dataroom.git
|
||||
cd hanzo-dataroom
|
||||
```
|
||||
|
||||
### 2. Install npm dependencies
|
||||
@@ -119,19 +121,19 @@ To prepare the Tinybird database, follow these steps:
|
||||
pipenv shell
|
||||
## start: pkgx-specific
|
||||
cd ..
|
||||
cd papermark
|
||||
cd hanzo-dataroom
|
||||
## end: pkgx-specific
|
||||
pipenv update tinybird-cli
|
||||
```
|
||||
|
||||
## Contributing
|
||||
|
||||
Papermark is an open-source project, and we welcome contributions from the community.
|
||||
Hanzo Dataroom is an open-source project, and we welcome contributions from the community.
|
||||
|
||||
If you'd like to contribute, please fork the repository and make any changes you'd like. Pull requests are warmly welcome.
|
||||
|
||||
### Our Contributors ✨
|
||||
|
||||
<a href="https://github.com/mfts/papermark/graphs/contributors">
|
||||
<img src="https://contrib.rocks/image?repo=mfts/papermark" />
|
||||
<a href="https://github.com/hanzoai/dataroom/graphs/contributors">
|
||||
<img src="https://contrib.rocks/image?repo=hanzoai/dataroom" />
|
||||
</a>
|
||||
|
||||
+2
-2
@@ -2,10 +2,10 @@
|
||||
|
||||
## Supported Versions
|
||||
|
||||
The latest version of Papermark is currently being supported with security updates.
|
||||
The latest version of Hanzo Dataroom is currently being supported with security updates.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
To report a vulnerability, send an email to security@papermark.com.
|
||||
To report a vulnerability, send an email to security@dataroom.hanzo.ai.
|
||||
|
||||
We will respond within 48 hours acknowledging your report with details about next steps and potential rewards/compensation for responsible disclosure.
|
||||
|
||||
@@ -20,19 +20,19 @@ export const runtime = "nodejs";
|
||||
|
||||
const data = {
|
||||
description: "Confirm email change",
|
||||
title: "Confirm email change | Papermark",
|
||||
title: "Confirm email change | Hanzo Dataroom",
|
||||
url: "/auth/confirm-email-change",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL("https://dataroom.hanzo.ai"),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: "Hanzo Dataroom",
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -47,13 +47,13 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
|
||||
interface PageProps {
|
||||
params: { token: string };
|
||||
params: Promise<{ token: string }>;
|
||||
}
|
||||
|
||||
export default async function ConfirmEmailChangePage(props: PageProps) {
|
||||
@@ -64,7 +64,8 @@ export default async function ConfirmEmailChangePage(props: PageProps) {
|
||||
);
|
||||
}
|
||||
|
||||
const VerifyEmailChange = async ({ params: { token } }: PageProps) => {
|
||||
const VerifyEmailChange = async ({ params }: PageProps) => {
|
||||
const { token } = await params;
|
||||
const tokenFound = await prisma.verificationToken.findUnique({
|
||||
where: {
|
||||
token: hashToken(token),
|
||||
|
||||
@@ -115,10 +115,10 @@ export default function EmailVerificationClient() {
|
||||
<div className="flex w-full justify-center bg-gray-50 md:w-1/2 lg:w-1/2">
|
||||
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
|
||||
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
|
||||
<Link href="https://www.papermark.com" target="_blank">
|
||||
<Link href="https://dataroom.hanzo.ai" target="_blank">
|
||||
<img
|
||||
src="/_static/papermark-logo.svg"
|
||||
alt="Papermark Logo"
|
||||
src="/_static/hanzo-dataroom-logo.svg"
|
||||
alt="Hanzo Dataroom Logo"
|
||||
className="-mt-8 mb-36 h-7 w-auto self-start sm:mb-32 md:mb-48"
|
||||
/>
|
||||
</Link>
|
||||
@@ -153,10 +153,10 @@ export default function EmailVerificationClient() {
|
||||
></div>
|
||||
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
|
||||
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
|
||||
<Link href="https://www.papermark.com" target="_blank">
|
||||
<Link href="https://dataroom.hanzo.ai" target="_blank">
|
||||
<img
|
||||
src="/_static/papermark-logo.svg"
|
||||
alt="Papermark Logo"
|
||||
src="/_static/hanzo-dataroom-logo.svg"
|
||||
alt="Hanzo Dataroom Logo"
|
||||
className="-mt-8 mb-36 h-7 w-auto self-start sm:mb-32 md:mb-48"
|
||||
/>
|
||||
</Link>
|
||||
@@ -187,10 +187,10 @@ export default function EmailVerificationClient() {
|
||||
<p className="mt-2 text-sm text-orange-800">
|
||||
Check your junk/spam and quarantine folders and ensure that{" "}
|
||||
<a
|
||||
href="mailto:system@papermark.com"
|
||||
href="mailto:dataroom@hanzo.ai"
|
||||
className="font-medium text-orange-600 underline hover:text-orange-700"
|
||||
>
|
||||
system@papermark.com
|
||||
dataroom@hanzo.ai
|
||||
</a>{" "}
|
||||
is on your allowed senders list.
|
||||
</p>
|
||||
@@ -262,7 +262,7 @@ export default function EmailVerificationClient() {
|
||||
|
||||
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-12">
|
||||
By clicking continue, you acknowledge that you have read and agree
|
||||
to Papermark's{" "}
|
||||
to Hanzo Dataroom's{" "}
|
||||
<a
|
||||
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
|
||||
target="_blank"
|
||||
@@ -312,7 +312,7 @@ function TestimonialSection() {
|
||||
<div className="max-w-xl text-center">
|
||||
<blockquote className="text-balance font-normal leading-8 text-white sm:text-xl sm:leading-9">
|
||||
<p>
|
||||
"We raised our €30M Fund with Papermark Data Rooms. Love
|
||||
"We raised our €30M Fund with Hanzo Dataroom. Love
|
||||
the customization, security and ease of use."
|
||||
</p>
|
||||
</blockquote>
|
||||
|
||||
@@ -3,20 +3,20 @@ import { Metadata } from "next";
|
||||
import EmailVerificationClient from "./page-client";
|
||||
|
||||
const data = {
|
||||
description: "Verify your login to Papermark",
|
||||
title: "Verify Login | Papermark",
|
||||
description: "Verify your login to Hanzo Dataroom",
|
||||
title: "Verify Login | Hanzo Dataroom",
|
||||
url: "/auth/email",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL("https://dataroom.hanzo.ai"),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: "Hanzo Dataroom",
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -31,7 +31,7 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
|
||||
@@ -0,0 +1,77 @@
|
||||
"use client";
|
||||
|
||||
import { useRouter, useSearchParams } from "next/navigation";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
|
||||
import { signIn } from "next-auth/react";
|
||||
|
||||
/**
|
||||
* SAML Callback Page
|
||||
*
|
||||
* This page handles IdP-initiated SSO flow:
|
||||
* 1. User clicks the app tile in their IdP dashboard
|
||||
* 2. Jackson processes the SAML response and redirects here with a `code`
|
||||
* 3. We exchange the code via the `saml-idp` CredentialsProvider
|
||||
*
|
||||
* SP-initiated SSO (user clicks "Continue with SSO" on login page) is handled
|
||||
* entirely by NextAuth's OAuth flow via the `saml` provider — it never hits this page.
|
||||
*/
|
||||
export default function SAMLCallbackClient() {
|
||||
const searchParams = useSearchParams();
|
||||
const router = useRouter();
|
||||
const [status, setStatus] = useState<"loading" | "error">("loading");
|
||||
const [errorMessage, setErrorMessage] = useState<string>("");
|
||||
|
||||
useEffect(() => {
|
||||
const code = searchParams?.get("code");
|
||||
if (code) {
|
||||
signIn("saml-idp", {
|
||||
code,
|
||||
redirect: false,
|
||||
}).then((result) => {
|
||||
if (result?.ok) {
|
||||
router.push("/dashboard");
|
||||
} else {
|
||||
setStatus("error");
|
||||
setErrorMessage(
|
||||
result?.error || "SSO authentication failed. Please try again.",
|
||||
);
|
||||
}
|
||||
});
|
||||
} else {
|
||||
setStatus("error");
|
||||
setErrorMessage(
|
||||
"No authorization code received from your identity provider.",
|
||||
);
|
||||
}
|
||||
}, [searchParams, router]);
|
||||
|
||||
if (status === "error") {
|
||||
return (
|
||||
<div className="flex min-h-screen items-center justify-center">
|
||||
<div className="mx-auto max-w-md text-center">
|
||||
<h2 className="text-xl font-semibold text-gray-900">
|
||||
SSO Login Failed
|
||||
</h2>
|
||||
<p className="mt-2 text-sm text-gray-600">{errorMessage}</p>
|
||||
<button
|
||||
onClick={() => router.push("/login")}
|
||||
className="mt-4 rounded-md bg-gray-900 px-4 py-2 text-sm text-white hover:bg-gray-800"
|
||||
>
|
||||
Return to Login
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="flex min-h-screen items-center justify-center">
|
||||
<div className="mx-auto max-w-md text-center">
|
||||
<div className="mx-auto mb-4 h-8 w-8 animate-spin rounded-full border-2 border-gray-300 border-t-gray-900" />
|
||||
<p className="text-sm text-gray-600">Completing SSO login...</p>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
import { Metadata } from "next";
|
||||
import { Suspense } from "react";
|
||||
|
||||
import SAMLCallbackClient from "./page-client";
|
||||
|
||||
export const metadata: Metadata = {
|
||||
title: "SSO Login | Hanzo Dataroom",
|
||||
description: "Completing SSO login",
|
||||
};
|
||||
|
||||
export default function SAMLCallbackPage() {
|
||||
return (
|
||||
<Suspense>
|
||||
<SAMLCallbackClient />
|
||||
</Suspense>
|
||||
);
|
||||
}
|
||||
@@ -1,295 +1,92 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { useParams, useRouter } from "next/navigation";
|
||||
import { useParams } from "next/navigation";
|
||||
|
||||
import { useState } from "react";
|
||||
|
||||
import { signInWithPasskey } from "@teamhanko/passkeys-next-auth-provider/client";
|
||||
import { signIn } from "next-auth/react";
|
||||
import { toast } from "sonner";
|
||||
import { z } from "zod";
|
||||
|
||||
import { cn } from "@/lib/utils";
|
||||
|
||||
import { LastUsed, useLastUsed } from "@/components/hooks/useLastUsed";
|
||||
import Google from "@/components/shared/icons/google";
|
||||
import LinkedIn from "@/components/shared/icons/linkedin";
|
||||
import Passkey from "@/components/shared/icons/passkey";
|
||||
import { LogoCloud } from "@/components/shared/logo-cloud";
|
||||
import { Button } from "@/components/ui/button";
|
||||
import { Input } from "@/components/ui/input";
|
||||
import { Label } from "@/components/ui/label";
|
||||
import { HanzoMark } from "@/components/shared/icons/hanzo-mark";
|
||||
|
||||
// White-label hooks: every visible brand token comes from env so tenants
|
||||
// drop in their own name/words/IAM provider without touching this file.
|
||||
//
|
||||
// NEXT_PUBLIC_APP_NAME e.g. "Hanzo Dataroom" | "Acme Rooms"
|
||||
// NEXT_PUBLIC_APP_NAME_PRIMARY first word of wordmark; defaults to first
|
||||
// word of NEXT_PUBLIC_APP_NAME ("Hanzo")
|
||||
// NEXT_PUBLIC_APP_NAME_SUFFIX second token of wordmark; defaults to
|
||||
// remainder of NEXT_PUBLIC_APP_NAME ("Dataroom")
|
||||
// NEXT_PUBLIC_APP_TAGLINE one-line under the welcome headline
|
||||
// NEXT_PUBLIC_IAM_PROVIDER_NAME IAM brand for the "Sign in with X" button
|
||||
// NEXT_PUBLIC_MARKETING_URL base URL the Terms / Privacy links resolve against
|
||||
|
||||
const APP_NAME = process.env.NEXT_PUBLIC_APP_NAME || "Hanzo Dataroom";
|
||||
const [defaultPrimary, ...defaultSuffixParts] = APP_NAME.split(" ");
|
||||
const APP_NAME_PRIMARY =
|
||||
process.env.NEXT_PUBLIC_APP_NAME_PRIMARY || defaultPrimary || APP_NAME;
|
||||
const APP_NAME_SUFFIX =
|
||||
process.env.NEXT_PUBLIC_APP_NAME_SUFFIX || defaultSuffixParts.join(" ");
|
||||
const APP_TAGLINE =
|
||||
process.env.NEXT_PUBLIC_APP_TAGLINE || "Share documents. Not attachments.";
|
||||
const IAM_PROVIDER_NAME =
|
||||
process.env.NEXT_PUBLIC_IAM_PROVIDER_NAME || "Hanzo";
|
||||
const MARKETING_URL = process.env.NEXT_PUBLIC_MARKETING_URL || "";
|
||||
|
||||
export default function Login() {
|
||||
const { next } = useParams as { next?: string };
|
||||
const router = useRouter();
|
||||
|
||||
const [lastUsed, setLastUsed] = useLastUsed();
|
||||
const authMethods = ["google", "email", "linkedin", "passkey"] as const;
|
||||
type AuthMethod = (typeof authMethods)[number];
|
||||
const [clickedMethod, setClickedMethod] = useState<AuthMethod | undefined>(
|
||||
undefined,
|
||||
);
|
||||
const [email, setEmail] = useState<string>("");
|
||||
const [emailButtonText, setEmailButtonText] = useState<string>(
|
||||
"Continue with Email",
|
||||
);
|
||||
|
||||
const emailSchema = z
|
||||
.string()
|
||||
.trim()
|
||||
.toLowerCase()
|
||||
.min(3, { message: "Please enter a valid email." })
|
||||
.email({ message: "Please enter a valid email." });
|
||||
|
||||
const emailValidation = emailSchema.safeParse(email);
|
||||
|
||||
return (
|
||||
<div className="flex h-screen w-full flex-wrap">
|
||||
{/* Left part */}
|
||||
<div className="flex w-full justify-center bg-gray-50 md:w-1/2 lg:w-1/2">
|
||||
<div
|
||||
className="absolute inset-x-0 top-10 -z-10 flex transform-gpu justify-center overflow-hidden blur-3xl"
|
||||
aria-hidden="true"
|
||||
></div>
|
||||
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
|
||||
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
|
||||
<Link href="https://www.papermark.com" target="_blank">
|
||||
<img
|
||||
src="/_static/papermark-logo.svg"
|
||||
alt="Papermark Logo"
|
||||
className="md:mb-48s -mt-8 mb-36 h-7 w-auto self-start sm:mb-32"
|
||||
/>
|
||||
</Link>
|
||||
<Link href="/">
|
||||
<span className="text-balance text-3xl font-semibold text-gray-900">
|
||||
Welcome to Papermark
|
||||
</span>
|
||||
</Link>
|
||||
<h3 className="text-balance text-sm text-gray-800">
|
||||
Share documents. Not attachments.
|
||||
</h3>
|
||||
</div>
|
||||
<form
|
||||
className="flex flex-col gap-4 px-4 pt-8 sm:px-12"
|
||||
onSubmit={(e) => {
|
||||
e.preventDefault();
|
||||
if (!emailValidation.success) {
|
||||
toast.error(emailValidation.error.errors[0].message);
|
||||
return;
|
||||
}
|
||||
<main className="flex min-h-screen w-full items-center justify-center bg-black px-6 text-white">
|
||||
<div className="w-full max-w-sm">
|
||||
<Link href="/" className="mb-12 flex items-center gap-3">
|
||||
<HanzoMark size={28} className="text-white" />
|
||||
<span className="text-base font-medium tracking-tight">
|
||||
{APP_NAME_PRIMARY}
|
||||
{APP_NAME_SUFFIX && (
|
||||
<span className="text-zinc-400"> {APP_NAME_SUFFIX}</span>
|
||||
)}
|
||||
</span>
|
||||
</Link>
|
||||
|
||||
setClickedMethod("email");
|
||||
signIn("email", {
|
||||
email: emailValidation.data,
|
||||
redirect: false,
|
||||
...(next && next.length > 0 ? { callbackUrl: next } : {}),
|
||||
}).then((res) => {
|
||||
if (res?.ok && !res?.error) {
|
||||
setLastUsed("credentials");
|
||||
// Store email in sessionStorage for the verification page
|
||||
try {
|
||||
sessionStorage.setItem(
|
||||
"pendingVerificationEmail",
|
||||
emailValidation.data,
|
||||
);
|
||||
} catch {
|
||||
// sessionStorage not available, verification page will show email input
|
||||
}
|
||||
router.push("/auth/email");
|
||||
} else {
|
||||
setEmailButtonText("Error sending email - try again?");
|
||||
toast.error("Error sending email - try again?");
|
||||
setClickedMethod(undefined);
|
||||
}
|
||||
});
|
||||
}}
|
||||
<h1 className="text-balance text-3xl font-semibold text-white">
|
||||
Welcome to {APP_NAME}
|
||||
</h1>
|
||||
<p className="mt-2 text-balance text-sm text-zinc-400">{APP_TAGLINE}</p>
|
||||
|
||||
<Button
|
||||
onClick={() =>
|
||||
signIn("hanzo-iam", {
|
||||
...(next && next.length > 0 ? { callbackUrl: next } : {}),
|
||||
})
|
||||
}
|
||||
className="mt-8 flex w-full items-center justify-center bg-white font-normal text-black hover:bg-zinc-200"
|
||||
>
|
||||
<span>
|
||||
Sign in with <span className="font-bold">{IAM_PROVIDER_NAME}</span>
|
||||
</span>
|
||||
</Button>
|
||||
|
||||
<p className="mt-8 text-xs text-zinc-500">
|
||||
By clicking continue, you acknowledge that you have read and agree to{" "}
|
||||
{APP_NAME}'s{" "}
|
||||
<a
|
||||
href={`${MARKETING_URL}/terms`}
|
||||
target="_blank"
|
||||
className="text-zinc-300 underline hover:text-white"
|
||||
>
|
||||
<Label className="sr-only" htmlFor="email">
|
||||
Email
|
||||
</Label>
|
||||
<Input
|
||||
id="email"
|
||||
placeholder="name@example.com"
|
||||
type="email"
|
||||
autoCapitalize="none"
|
||||
autoComplete="email"
|
||||
autoCorrect="off"
|
||||
disabled={clickedMethod === "email"}
|
||||
// pattern={patternSimpleEmailRegex}
|
||||
value={email}
|
||||
onChange={(e) => setEmail(e.target.value)}
|
||||
className={cn(
|
||||
"flex h-10 w-full rounded-md border-0 bg-background bg-white px-3 py-2 text-sm text-gray-900 ring-1 ring-gray-200 transition-colors file:border-0 file:bg-transparent file:text-sm file:font-medium placeholder:text-muted-foreground focus-visible:outline-none focus-visible:ring-1 focus-visible:ring-ring disabled:cursor-not-allowed disabled:opacity-50 dark:bg-white",
|
||||
email.length > 0 && !emailValidation.success
|
||||
? "ring-red-500"
|
||||
: "ring-gray-200",
|
||||
)}
|
||||
/>
|
||||
<div className="relative">
|
||||
<Button
|
||||
type="submit"
|
||||
loading={clickedMethod === "email"}
|
||||
disabled={!emailValidation.success || !!clickedMethod}
|
||||
className={cn(
|
||||
"focus:shadow-outline w-full transform rounded px-4 py-2 text-white transition-colors duration-300 ease-in-out focus:outline-none",
|
||||
clickedMethod === "email"
|
||||
? "bg-black"
|
||||
: "bg-gray-800 hover:bg-gray-900",
|
||||
)}
|
||||
>
|
||||
{emailButtonText}
|
||||
</Button>
|
||||
{lastUsed === "credentials" && <LastUsed />}
|
||||
</div>
|
||||
</form>
|
||||
<p className="py-4 text-center">or</p>
|
||||
<div className="flex flex-col space-y-2 px-4 sm:px-12">
|
||||
<div className="relative">
|
||||
<Button
|
||||
onClick={() => {
|
||||
setClickedMethod("google");
|
||||
setLastUsed("google");
|
||||
signIn("google", {
|
||||
...(next && next.length > 0 ? { callbackUrl: next } : {}),
|
||||
}).then((res) => {
|
||||
setClickedMethod(undefined);
|
||||
});
|
||||
}}
|
||||
loading={clickedMethod === "google"}
|
||||
disabled={clickedMethod && clickedMethod !== "google"}
|
||||
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200"
|
||||
>
|
||||
<Google className="h-5 w-5" />
|
||||
<span>Continue with Google</span>
|
||||
{clickedMethod !== "google" && lastUsed === "google" && (
|
||||
<LastUsed />
|
||||
)}
|
||||
</Button>
|
||||
</div>
|
||||
<div className="relative">
|
||||
<Button
|
||||
onClick={() => {
|
||||
setClickedMethod("linkedin");
|
||||
setLastUsed("linkedin");
|
||||
signIn("linkedin", {
|
||||
...(next && next.length > 0 ? { callbackUrl: next } : {}),
|
||||
}).then((res) => {
|
||||
setClickedMethod(undefined);
|
||||
});
|
||||
}}
|
||||
loading={clickedMethod === "linkedin"}
|
||||
disabled={clickedMethod && clickedMethod !== "linkedin"}
|
||||
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200"
|
||||
>
|
||||
<LinkedIn />
|
||||
<span>Continue with LinkedIn</span>
|
||||
{clickedMethod !== "linkedin" && lastUsed === "linkedin" && (
|
||||
<LastUsed />
|
||||
)}
|
||||
</Button>
|
||||
</div>
|
||||
<div className="relative">
|
||||
<Button
|
||||
onClick={() => {
|
||||
setLastUsed("passkey");
|
||||
setClickedMethod("passkey");
|
||||
signInWithPasskey({
|
||||
tenantId: process.env.NEXT_PUBLIC_HANKO_TENANT_ID as string,
|
||||
}).then(() => {
|
||||
setClickedMethod(undefined);
|
||||
});
|
||||
}}
|
||||
variant="outline"
|
||||
loading={clickedMethod === "passkey"}
|
||||
disabled={clickedMethod && clickedMethod !== "passkey"}
|
||||
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200 hover:text-gray-900"
|
||||
>
|
||||
<Passkey className="h-4 w-4" />
|
||||
<span>Continue with a passkey</span>
|
||||
{lastUsed === "passkey" && <LastUsed />}
|
||||
</Button>
|
||||
</div>
|
||||
</div>
|
||||
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-12">
|
||||
By clicking continue, you acknowledge that you have read and agree
|
||||
to Papermark's{" "}
|
||||
<a
|
||||
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
|
||||
target="_blank"
|
||||
className="underline"
|
||||
>
|
||||
Terms of Service
|
||||
</a>{" "}
|
||||
and{" "}
|
||||
<a
|
||||
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/privacy`}
|
||||
target="_blank"
|
||||
className="underline"
|
||||
>
|
||||
Privacy Policy
|
||||
</a>
|
||||
.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
<div className="relative hidden w-full justify-center overflow-hidden bg-black md:flex md:w-1/2 lg:w-1/2">
|
||||
<div className="relative m-0 flex h-full min-h-[700px] w-full p-0">
|
||||
<div
|
||||
className="relative flex h-full w-full flex-col justify-between"
|
||||
id="features"
|
||||
Terms of Service
|
||||
</a>{" "}
|
||||
and{" "}
|
||||
<a
|
||||
href={`${MARKETING_URL}/privacy`}
|
||||
target="_blank"
|
||||
className="text-zinc-300 underline hover:text-white"
|
||||
>
|
||||
{/* Testimonial top 2/3 */}
|
||||
<div
|
||||
className="flex w-full flex-col items-center justify-center"
|
||||
style={{ height: "66.6666%" }}
|
||||
>
|
||||
{/* Image container */}
|
||||
<div className="mb-4 h-64 w-80">
|
||||
<img
|
||||
className="h-full w-full rounded-2xl object-cover shadow-2xl"
|
||||
src="/_static/testimonials/backtrace.jpeg"
|
||||
alt="Backtrace Capital"
|
||||
/>
|
||||
</div>
|
||||
{/* Text content */}
|
||||
<div className="max-w-xl text-center">
|
||||
<blockquote className="text-balance font-normal leading-8 text-white sm:text-xl sm:leading-9">
|
||||
<p>
|
||||
"We raised our €30M Fund with Papermark Data Rooms.
|
||||
Love the customization, security and ease of use."
|
||||
</p>
|
||||
</blockquote>
|
||||
<figcaption className="mt-4">
|
||||
<div className="text-balance font-normal text-white">
|
||||
Michael Münnix
|
||||
</div>
|
||||
<div className="text-balance font-light text-gray-400">
|
||||
Partner, Backtrace Capital
|
||||
</div>
|
||||
</figcaption>
|
||||
</div>
|
||||
</div>
|
||||
{/* White block with logos bottom 1/3, full width/height */}
|
||||
<div
|
||||
className="absolute bottom-0 left-0 flex w-full flex-col items-center justify-center bg-white"
|
||||
style={{ height: "33.3333%" }}
|
||||
>
|
||||
<div className="mb-4 max-w-xl text-balance text-center font-semibold text-gray-900">
|
||||
Trusted by teams at
|
||||
</div>
|
||||
<LogoCloud />
|
||||
{/* <img
|
||||
src="https://assets.papermark.io/upload/file_7JEGY7zM9ZTfmxu8pe7vWj-Screenshot-2025-05-09-at-18.09.13.png"
|
||||
alt="Trusted teams illustration"
|
||||
className="mt-4 max-w-full h-auto object-contain"
|
||||
style={{maxHeight: '120px'}}
|
||||
/> */}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
Privacy Policy
|
||||
</a>
|
||||
.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</main>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -1,24 +1,26 @@
|
||||
import { Metadata } from "next";
|
||||
import { Suspense } from "react";
|
||||
|
||||
import { APP_NAME, APP_URL } from "@/lib/branding";
|
||||
import { GTMComponent } from "@/components/gtm-component";
|
||||
|
||||
import LoginClient from "./page-client";
|
||||
|
||||
const data = {
|
||||
description: "Login to Papermark",
|
||||
title: "Login | Papermark",
|
||||
description: `Login to ${APP_NAME}`,
|
||||
title: `Login | ${APP_NAME}`,
|
||||
url: "/login",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL(APP_URL),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: APP_NAME,
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -33,7 +35,7 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
@@ -42,7 +44,9 @@ export default function LoginPage() {
|
||||
return (
|
||||
<>
|
||||
<GTMComponent />
|
||||
<LoginClient />
|
||||
<Suspense>
|
||||
<LoginClient />
|
||||
</Suspense>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@ import { useParams } from "next/navigation";
|
||||
|
||||
import { useState } from "react";
|
||||
|
||||
import PapermarkLogo from "@/public/_static/papermark-logo.svg";
|
||||
import HanzoLogo from "@/public/_static/hanzo-dataroom-logo.svg";
|
||||
import { signIn } from "next-auth/react";
|
||||
import { toast } from "sonner";
|
||||
|
||||
@@ -35,12 +35,12 @@ export default function Register() {
|
||||
</div>
|
||||
<div className="z-10 mx-5 mt-[calc(20vh)] h-fit w-full max-w-md overflow-hidden rounded-lg border border-border bg-gray-50 dark:bg-gray-900 sm:mx-0 sm:shadow-xl">
|
||||
<div className="flex flex-col items-center justify-center space-y-3 px-4 py-6 pt-8 text-center sm:px-16">
|
||||
<Link href="https://www.papermark.com" target="_blank">
|
||||
<Link href="https://dataroom.hanzo.ai" target="_blank">
|
||||
<Image
|
||||
src={PapermarkLogo}
|
||||
src={HanzoLogo}
|
||||
width={119}
|
||||
height={32}
|
||||
alt="Papermark Logo"
|
||||
alt="Hanzo Dataroom Logo"
|
||||
/>
|
||||
</Link>
|
||||
<h3 className="text-2xl font-medium text-foreground">
|
||||
|
||||
@@ -1,22 +1,23 @@
|
||||
import { Metadata } from "next";
|
||||
|
||||
import { APP_NAME, APP_URL } from "@/lib/branding";
|
||||
import RegisterClient from "./page-client";
|
||||
|
||||
const data = {
|
||||
description: "Signup to Papermark",
|
||||
title: "Sign up | Papermark",
|
||||
description: `Signup to ${APP_NAME}`,
|
||||
title: `Sign up | ${APP_NAME}`,
|
||||
url: "/register",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL(APP_URL),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: APP_NAME,
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -31,7 +32,7 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
|
||||
@@ -37,7 +37,7 @@ export default function InvitationStatusContent({
|
||||
</div>
|
||||
<div className="w-full space-y-4">
|
||||
<h4 className="text-center text-sm font-medium text-gray-800">
|
||||
Create your own Papermark account
|
||||
Create your own Hanzo Dataroom account
|
||||
</h4>
|
||||
<div className="space-y-3">
|
||||
<Link href="/login" className="block w-full">
|
||||
|
||||
@@ -13,20 +13,20 @@ import InvitationStatusContent from "./InvitationStatusContent";
|
||||
import CleanUrlOnExpire from "./status/ClientRedirect";
|
||||
|
||||
const data = {
|
||||
description: "Accept your team invitation on Papermark",
|
||||
title: "Accept Invitation | Papermark",
|
||||
description: "Accept your team invitation on Hanzo Dataroom",
|
||||
title: "Accept Invitation | Hanzo Dataroom",
|
||||
url: "/verify/invitation",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL("https://dataroom.hanzo.ai"),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: "Hanzo Dataroom",
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -41,7 +41,7 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
@@ -49,11 +49,11 @@ export const metadata: Metadata = {
|
||||
export default async function VerifyInvitationPage({
|
||||
searchParams,
|
||||
}: {
|
||||
searchParams: {
|
||||
searchParams: Promise<{
|
||||
token?: string;
|
||||
};
|
||||
}>;
|
||||
}) {
|
||||
const { token: jwtToken } = searchParams;
|
||||
const { token: jwtToken } = await searchParams;
|
||||
|
||||
if (!jwtToken) {
|
||||
return <NotFound />;
|
||||
@@ -100,13 +100,13 @@ export default async function VerifyInvitationPage({
|
||||
<div className="flex flex-col items-center justify-center space-y-3 px-4 py-6 pt-8 text-center sm:px-16">
|
||||
<Link href="/">
|
||||
<span className="text-balance text-2xl font-semibold text-gray-800">
|
||||
Welcome to Papermark
|
||||
Welcome to Hanzo Dataroom
|
||||
</span>
|
||||
</Link>
|
||||
{!isExpired && !isRevoked && (
|
||||
<>
|
||||
<h3 className="text-balance py-1 text-sm font-normal text-gray-800">
|
||||
You've been invited to join a team on Papermark
|
||||
You've been invited to join a team on Hanzo Dataroom
|
||||
</h3>
|
||||
<div className="mt-2 flex w-auto items-center justify-center gap-2 rounded-full bg-gray-50 px-5 py-2.5 text-sm text-gray-600 shadow-sm">
|
||||
<MailIcon className="h-4 w-4 text-gray-400" />
|
||||
@@ -148,7 +148,7 @@ export default async function VerifyInvitationPage({
|
||||
</div>
|
||||
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-16">
|
||||
By accepting this invitation, you acknowledge that you have
|
||||
read and agree to Papermark's{" "}
|
||||
read and agree to Hanzo Dataroom's{" "}
|
||||
<a
|
||||
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
|
||||
target="_blank"
|
||||
@@ -191,7 +191,7 @@ export default async function VerifyInvitationPage({
|
||||
<blockquote className="text-l text-balance leading-8 text-gray-100 sm:text-xl sm:leading-9">
|
||||
<p>
|
||||
True builders listen to their users and build what they
|
||||
need. Thanks Papermark team for solving a big pain point.
|
||||
need. Thanks Hanzo Dataroom team for solving a big pain point.
|
||||
DocSend monopoly will end soon!
|
||||
</p>
|
||||
</blockquote>
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
../ee/LICENSE.md
|
||||
@@ -1 +0,0 @@
|
||||
../ee/README.md
|
||||
@@ -1,159 +0,0 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { processDocument } from "@/lib/api/documents/process-document";
|
||||
import { verifyDataroomSession } from "@/lib/auth/dataroom-auth";
|
||||
import { DocumentData } from "@/lib/documents/create-document";
|
||||
import prisma from "@/lib/prisma";
|
||||
import { supportsAdvancedExcelMode } from "@/lib/utils/get-content-type";
|
||||
|
||||
export async function POST(
|
||||
request: NextRequest,
|
||||
{ params }: { params: { id: string } },
|
||||
) {
|
||||
try {
|
||||
const linkId = params.id;
|
||||
const body = await request.json();
|
||||
const { documentData, dataroomId, folderId } = body as {
|
||||
documentData: DocumentData;
|
||||
dataroomId: string;
|
||||
folderId?: string;
|
||||
};
|
||||
|
||||
if (!linkId || !documentData || !dataroomId) {
|
||||
return NextResponse.json(
|
||||
{ message: "Missing required parameters" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// 0. Verify the dataroom session
|
||||
const dataroomSession = await verifyDataroomSession(
|
||||
request,
|
||||
linkId,
|
||||
dataroomId,
|
||||
);
|
||||
|
||||
if (!dataroomSession || !dataroomSession.viewerId) {
|
||||
return NextResponse.json(
|
||||
{ message: "You need to be logged in to upload a document." },
|
||||
{ status: 401 },
|
||||
);
|
||||
}
|
||||
|
||||
// Check if the link exists and has visitor upload enabled
|
||||
const link = await prisma.link.findUnique({
|
||||
where: { id: linkId, dataroomId },
|
||||
select: {
|
||||
id: true,
|
||||
enableUpload: true,
|
||||
uploadFolderId: true,
|
||||
dataroomId: true,
|
||||
teamId: true,
|
||||
team: {
|
||||
select: {
|
||||
plan: true,
|
||||
enableExcelAdvancedMode: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
if (
|
||||
!link ||
|
||||
!link.enableUpload ||
|
||||
link.dataroomId !== dataroomId ||
|
||||
!link.teamId
|
||||
) {
|
||||
return NextResponse.json(
|
||||
{ message: "Uploads not allowed for this link" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
const { viewerId, viewId } = dataroomSession;
|
||||
|
||||
// Check if the viewer exists
|
||||
const viewer = await prisma.viewer.findUnique({
|
||||
where: {
|
||||
id: viewerId,
|
||||
teamId: link.teamId,
|
||||
views: { some: { id: viewId } },
|
||||
},
|
||||
select: { id: true },
|
||||
});
|
||||
|
||||
if (!viewer) {
|
||||
return NextResponse.json(
|
||||
{ message: "Viewer not found" },
|
||||
{ status: 404 },
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
const updatedDocumentData = {
|
||||
...documentData,
|
||||
enableExcelAdvancedMode: documentData.supportedFileType === "sheet" &&
|
||||
link.team?.enableExcelAdvancedMode &&
|
||||
supportsAdvancedExcelMode(documentData.contentType),
|
||||
};
|
||||
|
||||
// 1. Create the document
|
||||
const document = await processDocument({
|
||||
documentData: updatedDocumentData,
|
||||
teamId: link.teamId,
|
||||
teamPlan: link.team?.plan ?? "free",
|
||||
isExternalUpload: true,
|
||||
});
|
||||
|
||||
// 2. Create the dataroom document
|
||||
// If folderId is provided and link has no uploadFolderId, use folderId as the dataroomFolderId
|
||||
// Otherwise, use the link's uploadFolderId
|
||||
// or null if it doesn't exist
|
||||
let dataroomFolderId: string | null = folderId ?? null;
|
||||
if (link.uploadFolderId) {
|
||||
const dataroomFolder = await prisma.dataroomFolder.findUnique({
|
||||
where: {
|
||||
id: link.uploadFolderId,
|
||||
dataroomId,
|
||||
},
|
||||
select: {
|
||||
id: true,
|
||||
},
|
||||
});
|
||||
dataroomFolderId = dataroomFolder?.id ?? null;
|
||||
}
|
||||
|
||||
const newDataroomDocument = await prisma.dataroomDocument.create({
|
||||
data: {
|
||||
dataroomId: dataroomId,
|
||||
documentId: document.id,
|
||||
folderId: dataroomFolderId,
|
||||
},
|
||||
});
|
||||
|
||||
// 3. Create the DocumentUpload record to track the upload details
|
||||
await prisma.documentUpload.create({
|
||||
data: {
|
||||
documentId: document.id,
|
||||
viewerId: viewerId,
|
||||
viewId: viewId,
|
||||
linkId: linkId,
|
||||
originalFilename: document.name,
|
||||
fileSize: document.versions[0].fileSize,
|
||||
numPages: document.numPages,
|
||||
mimeType: document.contentType,
|
||||
dataroomId: dataroomId,
|
||||
dataroomDocumentId: newDataroomDocument.id,
|
||||
teamId: link.teamId,
|
||||
},
|
||||
});
|
||||
|
||||
return NextResponse.json({ success: true });
|
||||
} catch (error) {
|
||||
console.error("Error uploading document:", error);
|
||||
return NextResponse.json(
|
||||
{ message: "Error uploading document" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
+45
-9
@@ -1,10 +1,10 @@
|
||||
import { NextRequest } from "next/server";
|
||||
|
||||
import { generateChatTitle } from "@/ee/features/ai/lib/chat/generate-chat-title";
|
||||
import { getFilteredDataroomDocumentIds } from "@/ee/features/ai/lib/chat/get-filtered-dataroom-document-ids";
|
||||
import { sendMessage } from "@/ee/features/ai/lib/chat/send-message";
|
||||
import { validateChatAccess } from "@/ee/features/ai/lib/permissions/validate-chat-access";
|
||||
import { sendMessageSchema } from "@/ee/features/ai/schemas/chat";
|
||||
import { generateChatTitle } from "@/features/ai/lib/chat/generate-chat-title";
|
||||
import { getFilteredDataroomDocumentIds } from "@/features/ai/lib/chat/get-filtered-dataroom-document-ids";
|
||||
import { sendMessage } from "@/features/ai/lib/chat/send-message";
|
||||
import { validateChatAccess } from "@/features/ai/lib/permissions/validate-chat-access";
|
||||
import { sendMessageSchema } from "@/features/ai/schemas/chat";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
|
||||
@@ -35,8 +35,11 @@ export async function POST(
|
||||
);
|
||||
}
|
||||
|
||||
const { content, filterDocumentId, filterDataroomDocumentIds } =
|
||||
validation.data;
|
||||
const {
|
||||
content,
|
||||
filterDocumentId,
|
||||
filterDataroomDocumentIds,
|
||||
} = validation.data;
|
||||
|
||||
const session = await getServerSession(authOptions);
|
||||
const searchParams = req.nextUrl.searchParams;
|
||||
@@ -133,16 +136,49 @@ export async function POST(
|
||||
}
|
||||
|
||||
// Send message and get streaming response
|
||||
const result = await sendMessage({
|
||||
const { result, referencesForStream } = await sendMessage({
|
||||
chatId,
|
||||
content,
|
||||
vectorStoreId: chat.vectorStoreId,
|
||||
filteredDataroomDocumentIds,
|
||||
filterDocumentId,
|
||||
userSelectedDataroomDocumentIds: filterDataroomDocumentIds,
|
||||
dataroomId: chat.dataroomId || undefined,
|
||||
linkId: chat.linkId || undefined,
|
||||
});
|
||||
|
||||
return result.toTextStreamResponse();
|
||||
const encoder = new TextEncoder();
|
||||
const stream = new ReadableStream<Uint8Array>({
|
||||
async start(controller) {
|
||||
try {
|
||||
for await (const chunk of result.textStream) {
|
||||
controller.enqueue(encoder.encode(chunk));
|
||||
}
|
||||
|
||||
const referencesSection = await Promise.race([
|
||||
referencesForStream,
|
||||
new Promise<string>((resolve) =>
|
||||
setTimeout(() => resolve(""), 5000),
|
||||
),
|
||||
]);
|
||||
|
||||
if (referencesSection) {
|
||||
controller.enqueue(encoder.encode(referencesSection));
|
||||
}
|
||||
|
||||
controller.close();
|
||||
} catch (error) {
|
||||
console.error("Error streaming AI response:", error);
|
||||
controller.error(error);
|
||||
}
|
||||
},
|
||||
});
|
||||
|
||||
return new Response(stream, {
|
||||
headers: {
|
||||
"Content-Type": "text/plain; charset=utf-8",
|
||||
},
|
||||
});
|
||||
} catch (error) {
|
||||
console.error("Error sending message:", error);
|
||||
return new Response(JSON.stringify({ error: "Internal server error" }), {
|
||||
@@ -1,6 +1,6 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { validateChatAccess } from "@/ee/features/ai/lib/permissions/validate-chat-access";
|
||||
import { validateChatAccess } from "@/features/ai/lib/permissions/validate-chat-access";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { createChat } from "@/ee/features/ai/lib/chat/create-chat";
|
||||
import { createChatSchema } from "@/ee/features/ai/schemas/chat";
|
||||
import { createChat } from "@/features/ai/lib/chat/create-chat";
|
||||
import { createChatSchema } from "@/features/ai/schemas/chat";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
import { z } from "zod";
|
||||
+2
-2
@@ -4,8 +4,8 @@ import {
|
||||
SUPPORTED_AI_CONTENT_TYPES,
|
||||
addFileToVectorStoreTask,
|
||||
processDocumentForAITask,
|
||||
} from "@/ee/features/ai/lib/trigger";
|
||||
import { createDataroomVectorStore } from "@/ee/features/ai/lib/vector-stores/create-dataroom-vector-store";
|
||||
} from "@/features/ai/lib/trigger";
|
||||
import { createDataroomVectorStore } from "@/features/ai/lib/vector-stores/create-dataroom-vector-store";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
|
||||
+3
-3
@@ -4,9 +4,9 @@ import {
|
||||
addFileToVectorStoreTask,
|
||||
processDocumentForAITask,
|
||||
SUPPORTED_AI_CONTENT_TYPES,
|
||||
} from "@/ee/features/ai/lib/trigger";
|
||||
import { createTeamVectorStore } from "@/ee/features/ai/lib/vector-stores/create-team-vector-store";
|
||||
import { removeFileFromVectorStore } from "@/ee/features/ai/lib/vector-stores/remove-file-from-vector-store";
|
||||
} from "@/features/ai/lib/trigger";
|
||||
import { createTeamVectorStore } from "@/features/ai/lib/vector-stores/create-team-vector-store";
|
||||
import { removeFileFromVectorStore } from "@/features/ai/lib/vector-stores/remove-file-from-vector-store";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
|
||||
+6
-4
@@ -1,6 +1,6 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { getVectorStoreInfo } from "@/ee/features/ai/lib/vector-stores/get-vector-store-info";
|
||||
import { getVectorStoreInfo } from "@/features/ai/lib/vector-stores/get-vector-store-info";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
|
||||
@@ -27,10 +27,12 @@ export async function GET(
|
||||
const userId = (session.user as CustomUser).id;
|
||||
|
||||
// Verify user is member of team
|
||||
const userTeam = await prisma.userTeam.findFirst({
|
||||
const userTeam = await prisma.userTeam.findUnique({
|
||||
where: {
|
||||
userId,
|
||||
teamId,
|
||||
userId_teamId: {
|
||||
userId,
|
||||
teamId,
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
@@ -0,0 +1,77 @@
|
||||
import { jackson } from "@/lib/jackson";
|
||||
import type { OAuthReq } from "@boxyhq/saml-jackson";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export async function GET(req: Request) {
|
||||
try {
|
||||
const { oauthController } = await jackson();
|
||||
|
||||
const url = new URL(req.url);
|
||||
const requestParams = Object.fromEntries(
|
||||
url.searchParams.entries(),
|
||||
) as unknown as OAuthReq;
|
||||
|
||||
const { redirect_url, authorize_form } =
|
||||
await oauthController.authorize(requestParams);
|
||||
|
||||
if (redirect_url) {
|
||||
return NextResponse.redirect(redirect_url, { status: 302 });
|
||||
} else if (authorize_form) {
|
||||
return new Response(authorize_form, {
|
||||
headers: { "Content-Type": "text/html; charset=utf-8" },
|
||||
});
|
||||
}
|
||||
|
||||
return NextResponse.json(
|
||||
{ error: "No redirect URL returned" },
|
||||
{ status: 400 },
|
||||
);
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Authorize error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
export async function POST(req: Request) {
|
||||
try {
|
||||
const { oauthController } = await jackson();
|
||||
|
||||
const contentType = req.headers.get("content-type") || "";
|
||||
|
||||
let body: Record<string, any>;
|
||||
|
||||
if (contentType.includes("application/x-www-form-urlencoded")) {
|
||||
const formData = await req.formData();
|
||||
body = Object.fromEntries(formData.entries());
|
||||
} else {
|
||||
body = await req.json();
|
||||
}
|
||||
|
||||
const { redirect_url, authorize_form } =
|
||||
await oauthController.authorize(body as unknown as OAuthReq);
|
||||
|
||||
if (redirect_url) {
|
||||
return NextResponse.redirect(redirect_url, { status: 302 });
|
||||
} else if (authorize_form) {
|
||||
return new Response(authorize_form, {
|
||||
headers: { "Content-Type": "text/html; charset=utf-8" },
|
||||
});
|
||||
}
|
||||
|
||||
return NextResponse.json(
|
||||
{ error: "No redirect URL returned" },
|
||||
{ status: 400 },
|
||||
);
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Authorize error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
import { jackson } from "@/lib/jackson";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export async function POST(req: Request) {
|
||||
try {
|
||||
const { oauthController } = await jackson();
|
||||
|
||||
const formData = await req.formData();
|
||||
const RelayState = (formData.get("RelayState") as string) || "";
|
||||
const SAMLResponse = (formData.get("SAMLResponse") as string) || "";
|
||||
|
||||
const { redirect_url } = await oauthController.samlResponse({
|
||||
RelayState,
|
||||
SAMLResponse,
|
||||
});
|
||||
|
||||
if (!redirect_url) {
|
||||
return NextResponse.json(
|
||||
{ error: "No redirect URL returned" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
return NextResponse.redirect(redirect_url, { status: 302 });
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Callback error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
import { jackson } from "@/lib/jackson";
|
||||
// These imports fix crypto module bundling issues with Jackson in Next.js.
|
||||
// Without them, the serverless function bundle tree-shakes away jose's crypto
|
||||
// primitives, causing ERR_CRYPTO_INVALID_KEYLEN at runtime.
|
||||
// See: https://github.com/ory/polis/blob/main/pages/api/import-hack.ts
|
||||
import * as jose from "jose";
|
||||
import { NextResponse } from "next/server";
|
||||
import * as openidClient from "openid-client";
|
||||
|
||||
// Reference the imports so they aren't removed by tree-shaking
|
||||
const _dependencies = [jose, openidClient];
|
||||
void _dependencies;
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export async function POST(req: Request) {
|
||||
try {
|
||||
const { oauthController } = await jackson();
|
||||
|
||||
const formData = await req.formData();
|
||||
const body = Object.fromEntries(formData.entries());
|
||||
|
||||
const token = await oauthController.token(body as any);
|
||||
|
||||
return NextResponse.json(token);
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Token error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
import { jackson } from "@/lib/jackson";
|
||||
// Force-include crypto dependencies (same workaround as token route)
|
||||
import * as jose from "jose";
|
||||
import { NextResponse } from "next/server";
|
||||
import * as openidClient from "openid-client";
|
||||
|
||||
const _dependencies = [jose, openidClient];
|
||||
void _dependencies;
|
||||
|
||||
// Prevent Next.js from statically generating this route at build time —
|
||||
// it requires a live database connection via Jackson.
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export async function GET(req: Request) {
|
||||
try {
|
||||
const { oauthController } = await jackson();
|
||||
|
||||
const authHeader = req.headers.get("Authorization");
|
||||
if (!authHeader) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
// RFC 6750: token type is case-insensitive
|
||||
const token = authHeader.replace(/^bearer\s+/i, "");
|
||||
const userInfo = await oauthController.userInfo(token);
|
||||
|
||||
return NextResponse.json(userInfo);
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] UserInfo error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
import { jackson, jacksonProduct } from "@/lib/jackson";
|
||||
import prisma from "@/lib/prisma";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
/**
|
||||
* POST /api/auth/saml/verify
|
||||
* Verifies that a team has SSO configured.
|
||||
* Accepts either `slug` (preferred, user-friendly) or `teamId` (fallback).
|
||||
* Returns only the teamId — no team names, provider info, or other metadata.
|
||||
*/
|
||||
export async function POST(req: Request) {
|
||||
try {
|
||||
const body = await req.json();
|
||||
const { slug, teamId } = body;
|
||||
|
||||
if (!slug && !teamId) {
|
||||
return NextResponse.json(
|
||||
{ error: "Team slug or ID is required" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Look up team by slug first, then by ID
|
||||
const team = slug
|
||||
? await prisma.team.findUnique({
|
||||
where: { slug },
|
||||
select: { id: true, ssoEnabled: true },
|
||||
})
|
||||
: await prisma.team.findUnique({
|
||||
where: { id: teamId },
|
||||
select: { id: true, ssoEnabled: true },
|
||||
});
|
||||
|
||||
const ssoUnavailable = NextResponse.json(
|
||||
{ error: "SSO is not available for this team." },
|
||||
{ status: 404 },
|
||||
);
|
||||
|
||||
if (!team || !team.ssoEnabled) {
|
||||
return ssoUnavailable;
|
||||
}
|
||||
|
||||
// Check Jackson for actual SAML connections
|
||||
const { apiController } = await jackson();
|
||||
|
||||
const connections = await apiController.getConnections({
|
||||
tenant: team.id,
|
||||
product: jacksonProduct,
|
||||
});
|
||||
|
||||
if (!connections || connections.length === 0) {
|
||||
return ssoUnavailable;
|
||||
}
|
||||
|
||||
// Only return the team ID — no names, providers, or other metadata
|
||||
return NextResponse.json({ data: { teamId: team.id } });
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Verify error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: "Something went wrong" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
import { receiver } from "@/lib/cron";
|
||||
import { processDataroomDigest } from "@/lib/emails/process-dataroom-digest";
|
||||
import { log } from "@/lib/utils";
|
||||
|
||||
// Runs daily at 9 AM UTC (0 9 * * *)
|
||||
export const maxDuration = 300;
|
||||
|
||||
export async function POST(req: Request) {
|
||||
const body = await req.json();
|
||||
if (process.env.VERCEL === "1") {
|
||||
const isValid = await receiver.verify({
|
||||
signature: req.headers.get("Upstash-Signature") || "",
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
if (!isValid) {
|
||||
return new Response("Unauthorized", { status: 401 });
|
||||
}
|
||||
}
|
||||
|
||||
try {
|
||||
const result = await processDataroomDigest("daily");
|
||||
return NextResponse.json({ success: true, ...result });
|
||||
} catch (error) {
|
||||
await log({
|
||||
message: `Daily dataroom digest cron failed. \n\nError: ${(error as Error).message}`,
|
||||
type: "cron",
|
||||
mention: true,
|
||||
});
|
||||
return NextResponse.json({ error: (error as Error).message });
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
import { receiver } from "@/lib/cron";
|
||||
import { processDataroomDigest } from "@/lib/emails/process-dataroom-digest";
|
||||
import { log } from "@/lib/utils";
|
||||
|
||||
// Runs weekly on Monday at 9 AM UTC (0 9 * * 1)
|
||||
export const maxDuration = 300;
|
||||
|
||||
export async function POST(req: Request) {
|
||||
const body = await req.json();
|
||||
if (process.env.VERCEL === "1") {
|
||||
const isValid = await receiver.verify({
|
||||
signature: req.headers.get("Upstash-Signature") || "",
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
if (!isValid) {
|
||||
return new Response("Unauthorized", { status: 401 });
|
||||
}
|
||||
}
|
||||
|
||||
try {
|
||||
const result = await processDataroomDigest("weekly");
|
||||
return NextResponse.json({ success: true, ...result });
|
||||
} catch (error) {
|
||||
await log({
|
||||
message: `Weekly dataroom digest cron failed. \n\nError: ${(error as Error).message}`,
|
||||
type: "cron",
|
||||
mention: true,
|
||||
});
|
||||
return NextResponse.json({ error: (error as Error).message });
|
||||
}
|
||||
}
|
||||
@@ -38,7 +38,7 @@ export async function POST(req: Request) {
|
||||
where: {
|
||||
slug: {
|
||||
not: {
|
||||
in: ["papermark.io", "papermark.com"],
|
||||
in: ["dataroom.hanzo.ai", "dataroom.hanzo.ai"],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
@@ -0,0 +1,351 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { processDocument } from "@/lib/api/documents/process-document";
|
||||
import { verifyDataroomSession } from "@/lib/auth/dataroom-auth";
|
||||
import { DocumentData } from "@/lib/documents/create-document";
|
||||
import prisma from "@/lib/prisma";
|
||||
import { sendDataroomUploadNotificationTask } from "@/lib/trigger/dataroom-upload-notification";
|
||||
import { sanitizePlainText } from "@/lib/utils/sanitize-html";
|
||||
import { supportsAdvancedExcelMode } from "@/lib/utils/get-content-type";
|
||||
import { runs } from "@trigger.dev/sdk/v3";
|
||||
import { waitUntil } from "@vercel/functions";
|
||||
|
||||
/**
|
||||
* GET /api/links/[id]/upload?dataroomId=xxx
|
||||
* Returns the viewer's previously uploaded documents for this dataroom.
|
||||
*/
|
||||
export async function GET(
|
||||
request: NextRequest,
|
||||
{ params }: { params: { id: string } },
|
||||
) {
|
||||
try {
|
||||
const linkId = params.id;
|
||||
const dataroomId = request.nextUrl.searchParams.get("dataroomId");
|
||||
|
||||
if (!linkId || !dataroomId) {
|
||||
return NextResponse.json(
|
||||
{ message: "Missing required parameters" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Verify the dataroom session
|
||||
const dataroomSession = await verifyDataroomSession(
|
||||
request,
|
||||
linkId,
|
||||
dataroomId,
|
||||
);
|
||||
|
||||
if (!dataroomSession || !dataroomSession.viewerId) {
|
||||
return NextResponse.json(
|
||||
{ message: "Unauthorized" },
|
||||
{ status: 401 },
|
||||
);
|
||||
}
|
||||
|
||||
const { viewerId } = dataroomSession;
|
||||
|
||||
// Fetch the viewer's uploads for this dataroom
|
||||
const uploads = await prisma.documentUpload.findMany({
|
||||
where: {
|
||||
viewerId,
|
||||
dataroomId,
|
||||
linkId,
|
||||
},
|
||||
select: {
|
||||
id: true,
|
||||
documentId: true,
|
||||
dataroomDocumentId: true,
|
||||
originalFilename: true,
|
||||
uploadedAt: true,
|
||||
document: {
|
||||
select: {
|
||||
id: true,
|
||||
name: true,
|
||||
type: true,
|
||||
versions: {
|
||||
where: { isPrimary: true },
|
||||
select: {
|
||||
id: true,
|
||||
hasPages: true,
|
||||
},
|
||||
take: 1,
|
||||
},
|
||||
},
|
||||
},
|
||||
dataroomDocument: {
|
||||
select: {
|
||||
folderId: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
orderBy: { uploadedAt: "desc" },
|
||||
});
|
||||
|
||||
const formattedUploads = uploads.map((upload) => {
|
||||
const fileType = upload.document?.type ?? "";
|
||||
const hasPages = upload.document?.versions?.[0]?.hasPages ?? false;
|
||||
const needsProcessing = ["pdf", "docs", "slides"].includes(fileType);
|
||||
const isComplete = !needsProcessing || hasPages;
|
||||
|
||||
return {
|
||||
id: upload.id,
|
||||
documentId: upload.documentId,
|
||||
dataroomDocumentId: upload.dataroomDocumentId,
|
||||
documentVersionId: upload.document?.versions?.[0]?.id ?? null,
|
||||
name: upload.originalFilename ?? upload.document?.name ?? "Unknown",
|
||||
fileType,
|
||||
folderId: upload.dataroomDocument?.folderId ?? null,
|
||||
uploadedAt: upload.uploadedAt,
|
||||
status: isComplete ? "complete" : "processing",
|
||||
};
|
||||
});
|
||||
|
||||
return NextResponse.json({ uploads: formattedUploads });
|
||||
} catch (error) {
|
||||
console.error("Error fetching viewer uploads:", error);
|
||||
return NextResponse.json(
|
||||
{ message: "Error fetching uploads" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
export async function POST(
|
||||
request: NextRequest,
|
||||
{ params }: { params: { id: string } },
|
||||
) {
|
||||
try {
|
||||
const linkId = params.id;
|
||||
const body = await request.json();
|
||||
const { documentData, dataroomId, folderId } = body as {
|
||||
documentData: DocumentData;
|
||||
dataroomId: string;
|
||||
folderId?: string;
|
||||
};
|
||||
|
||||
if (!linkId || !documentData || !dataroomId) {
|
||||
return NextResponse.json(
|
||||
{ message: "Missing required parameters" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// 0. Verify the dataroom session
|
||||
const dataroomSession = await verifyDataroomSession(
|
||||
request,
|
||||
linkId,
|
||||
dataroomId,
|
||||
);
|
||||
|
||||
if (!dataroomSession || !dataroomSession.viewerId) {
|
||||
return NextResponse.json(
|
||||
{ message: "You need to be logged in to upload a document." },
|
||||
{ status: 401 },
|
||||
);
|
||||
}
|
||||
|
||||
// Check if the link exists and has visitor upload enabled
|
||||
const link = await prisma.link.findUnique({
|
||||
where: { id: linkId, dataroomId },
|
||||
select: {
|
||||
id: true,
|
||||
name: true,
|
||||
enableUpload: true,
|
||||
enableNotification: true,
|
||||
uploadFolderId: true,
|
||||
dataroomId: true,
|
||||
teamId: true,
|
||||
team: {
|
||||
select: {
|
||||
plan: true,
|
||||
enableExcelAdvancedMode: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
if (
|
||||
!link ||
|
||||
!link.enableUpload ||
|
||||
link.dataroomId !== dataroomId ||
|
||||
!link.teamId
|
||||
) {
|
||||
return NextResponse.json(
|
||||
{ message: "Uploads not allowed for this link" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
const { viewerId, viewId } = dataroomSession;
|
||||
|
||||
// Check if the viewer exists
|
||||
const viewer = await prisma.viewer.findUnique({
|
||||
where: {
|
||||
id: viewerId,
|
||||
teamId: link.teamId,
|
||||
views: { some: { id: viewId } },
|
||||
},
|
||||
select: { id: true },
|
||||
});
|
||||
|
||||
if (!viewer) {
|
||||
return NextResponse.json(
|
||||
{ message: "Viewer not found" },
|
||||
{ status: 404 },
|
||||
);
|
||||
}
|
||||
|
||||
if (typeof documentData.name !== "string") {
|
||||
return NextResponse.json(
|
||||
{ message: "Document name is required" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const sanitizedDocumentName = sanitizePlainText(documentData.name);
|
||||
if (!sanitizedDocumentName) {
|
||||
return NextResponse.json(
|
||||
{ message: "Document name is required" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
if (sanitizedDocumentName.length > 255) {
|
||||
return NextResponse.json(
|
||||
{ message: "Document name too long" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const updatedDocumentData = {
|
||||
...documentData,
|
||||
name: sanitizedDocumentName,
|
||||
enableExcelAdvancedMode: documentData.supportedFileType === "sheet" &&
|
||||
link.team?.enableExcelAdvancedMode &&
|
||||
supportsAdvancedExcelMode(documentData.contentType),
|
||||
};
|
||||
|
||||
// 1. Create the document
|
||||
const document = await processDocument({
|
||||
documentData: updatedDocumentData,
|
||||
teamId: link.teamId,
|
||||
teamPlan: link.team?.plan ?? "free",
|
||||
isExternalUpload: true,
|
||||
});
|
||||
|
||||
// 2. Create the dataroom document
|
||||
// If folderId is provided and link has no uploadFolderId, use folderId as the dataroomFolderId
|
||||
// Otherwise, use the link's uploadFolderId
|
||||
// or null if it doesn't exist
|
||||
let dataroomFolderId: string | null = folderId ?? null;
|
||||
if (link.uploadFolderId) {
|
||||
const dataroomFolder = await prisma.dataroomFolder.findUnique({
|
||||
where: {
|
||||
id: link.uploadFolderId,
|
||||
dataroomId,
|
||||
},
|
||||
select: {
|
||||
id: true,
|
||||
},
|
||||
});
|
||||
dataroomFolderId = dataroomFolder?.id ?? null;
|
||||
}
|
||||
|
||||
const newDataroomDocument = await prisma.dataroomDocument.create({
|
||||
data: {
|
||||
dataroomId: dataroomId,
|
||||
documentId: document.id,
|
||||
folderId: dataroomFolderId,
|
||||
},
|
||||
});
|
||||
|
||||
// 3. Create the DocumentUpload record to track the upload details
|
||||
await prisma.documentUpload.create({
|
||||
data: {
|
||||
documentId: document.id,
|
||||
viewerId: viewerId,
|
||||
viewId: viewId,
|
||||
linkId: linkId,
|
||||
originalFilename: document.name,
|
||||
fileSize: documentData.fileSize ?? 0,
|
||||
numPages: document.numPages,
|
||||
mimeType: document.contentType,
|
||||
dataroomId: dataroomId,
|
||||
dataroomDocumentId: newDataroomDocument.id,
|
||||
teamId: link.teamId,
|
||||
},
|
||||
});
|
||||
|
||||
// 4. Send upload notification to team if enabled
|
||||
if (link.enableNotification) {
|
||||
try {
|
||||
// Cancel any existing pending notification runs for this viewer+dataroom+link
|
||||
// Note: runs.list tag filter uses OR logic, so we must post-filter
|
||||
// to ensure we only cancel runs matching ALL three tags
|
||||
const requiredTags = [
|
||||
`dataroom_${dataroomId}`,
|
||||
`link_${linkId}`,
|
||||
`viewer_${viewerId}`,
|
||||
];
|
||||
const allRuns = await runs.list({
|
||||
taskIdentifier: ["send-dataroom-upload-notification"],
|
||||
tag: requiredTags,
|
||||
status: ["DELAYED", "QUEUED"],
|
||||
period: "10m",
|
||||
});
|
||||
|
||||
const matchingRuns = allRuns.data.filter((run) =>
|
||||
requiredTags.every((tag) => run.tags?.includes(tag)),
|
||||
);
|
||||
|
||||
await Promise.all(matchingRuns.map((run) => runs.cancel(run.id)));
|
||||
|
||||
// Trigger a new notification with 5-minute delay to batch uploads
|
||||
waitUntil(
|
||||
sendDataroomUploadNotificationTask.trigger(
|
||||
{
|
||||
dataroomId,
|
||||
linkId,
|
||||
viewerId,
|
||||
teamId: link.teamId,
|
||||
},
|
||||
{
|
||||
idempotencyKey: `upload-notification-${link.teamId}-${dataroomId}-${linkId}-${viewerId}-${newDataroomDocument.id}`,
|
||||
tags: [
|
||||
`team_${link.teamId}`,
|
||||
`dataroom_${dataroomId}`,
|
||||
`link_${linkId}`,
|
||||
`viewer_${viewerId}`,
|
||||
],
|
||||
delay: new Date(Date.now() + 5 * 60 * 1000), // 5 minute delay
|
||||
},
|
||||
),
|
||||
);
|
||||
} catch (error) {
|
||||
console.error("Error triggering upload notification:", error);
|
||||
}
|
||||
}
|
||||
|
||||
// Return document data for optimistic UI rendering
|
||||
return NextResponse.json({
|
||||
success: true,
|
||||
document: {
|
||||
id: document.id,
|
||||
name: document.name,
|
||||
dataroomDocumentId: newDataroomDocument.id,
|
||||
documentVersionId: document.versions[0]?.id,
|
||||
folderId: dataroomFolderId,
|
||||
fileType: document.type,
|
||||
hasPages: (document.numPages ?? 0) > 0,
|
||||
createdAt: document.createdAt,
|
||||
},
|
||||
});
|
||||
} catch (error) {
|
||||
console.error("Error uploading document:", error);
|
||||
return NextResponse.json(
|
||||
{ message: "Error uploading document" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -10,7 +10,7 @@ export const runtime = "edge";
|
||||
*/
|
||||
export async function GET(request: NextRequest) {
|
||||
const searchParams = request.nextUrl.searchParams;
|
||||
const title = searchParams.get("title") || "Papermark Document";
|
||||
const title = searchParams.get("title") || "Hanzo Dataroom Document";
|
||||
const Inter = await fetch(
|
||||
new URL("@/public/_static/Inter-Bold.ttf", import.meta.url),
|
||||
).then((res) => res.arrayBuffer());
|
||||
@@ -18,7 +18,7 @@ export async function GET(request: NextRequest) {
|
||||
return new ImageResponse(
|
||||
(
|
||||
<div tw="flex flex-col items-center justify-between w-full h-full bg-white text-black p-12">
|
||||
<div tw="text-[32px] flex items-center tracking-tighter">Papermark</div>
|
||||
<div tw="text-[32px] flex items-center tracking-tighter">Hanzo Dataroom</div>
|
||||
<div tw="text-[42px] text-center">{title}</div>
|
||||
<div tw="text-[32px] flex items-center">
|
||||
Open-Source Document Sharing
|
||||
|
||||
@@ -29,7 +29,7 @@ export async function GET(req: NextRequest) {
|
||||
{/* Left Side Text */}
|
||||
<div tw="flex flex-col text-white" style={{ marginLeft: "48px" }}>
|
||||
<div tw="flex text-7xl font-bold mb-4 tracking-tighter">
|
||||
Papermark
|
||||
Hanzo Dataroom
|
||||
</div>
|
||||
<div tw="flex text-5xl mb-4">Year in Review</div>
|
||||
<div tw="flex text-7xl font-bold">{year}</div>
|
||||
@@ -49,7 +49,7 @@ export async function GET(req: NextRequest) {
|
||||
{/* Header Section */}
|
||||
<div tw="flex items-start p-8 items-center">
|
||||
<div tw="flex text-2xl font-bold text-white tracking-tighter">
|
||||
Papermark
|
||||
Hanzo Dataroom
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
||||
@@ -0,0 +1,315 @@
|
||||
import { jackson } from "@/lib/jackson";
|
||||
import prisma from "@/lib/prisma";
|
||||
import type { DirectorySyncEvent } from "@boxyhq/saml-jackson";
|
||||
import { createHash } from "crypto";
|
||||
import { headers } from "next/headers";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
/** Return a truncated SHA-256 hex digest (first 12 chars) for log-safe pseudonymisation. */
|
||||
function hashEmail(email: string): string {
|
||||
return createHash("sha256").update(email).digest("hex").slice(0, 12);
|
||||
}
|
||||
|
||||
const handler = async (
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ directory: string[] }> },
|
||||
) => {
|
||||
try {
|
||||
const resolvedParams = await params;
|
||||
const headersList = await headers();
|
||||
const authHeader = headersList.get("Authorization");
|
||||
const apiSecret = authHeader ? authHeader.split(" ")[1] : null;
|
||||
|
||||
const url = new URL(req.url);
|
||||
const query = Object.fromEntries(url.searchParams.entries());
|
||||
|
||||
const [directoryId, path, resourceId] = resolvedParams.directory;
|
||||
|
||||
let body: any = {};
|
||||
try {
|
||||
body = await req.json();
|
||||
} catch {
|
||||
body = {};
|
||||
}
|
||||
|
||||
const { directorySyncController } = await jackson();
|
||||
|
||||
const request = {
|
||||
method: req.method as "GET" | "POST" | "PUT" | "PATCH" | "DELETE",
|
||||
body,
|
||||
directoryId,
|
||||
resourceId,
|
||||
resourceType: (path === "Users" ? "users" : "groups") as
|
||||
| "users"
|
||||
| "groups",
|
||||
apiSecret,
|
||||
query: {
|
||||
count: query.count ? parseInt(query.count) : undefined,
|
||||
startIndex: query.startIndex ? parseInt(query.startIndex) : undefined,
|
||||
filter: query.filter as string,
|
||||
},
|
||||
};
|
||||
|
||||
const { status, data } = await directorySyncController.requests.handle(
|
||||
request,
|
||||
handleSCIMEvents,
|
||||
);
|
||||
|
||||
return NextResponse.json(data, { status });
|
||||
} catch (error: any) {
|
||||
console.error("[SCIM] Request error:", error);
|
||||
return NextResponse.json(
|
||||
{
|
||||
schemas: ["urn:ietf:params:scim:api:messages:2.0:Error"],
|
||||
detail: "Internal server error",
|
||||
status: 500,
|
||||
},
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
};
|
||||
|
||||
export {
|
||||
handler as DELETE,
|
||||
handler as GET,
|
||||
handler as PATCH,
|
||||
handler as POST,
|
||||
handler as PUT,
|
||||
};
|
||||
|
||||
// ──────────────────────────────────────────────────────────
|
||||
// SCIM Event Handler — sync changes to the main app DB
|
||||
// ──────────────────────────────────────────────────────────
|
||||
async function handleSCIMEvents(event: DirectorySyncEvent) {
|
||||
const { event: eventType, data, tenant } = event;
|
||||
|
||||
// Verify the team exists and has SSO enabled
|
||||
const team = await prisma.team.findUnique({
|
||||
where: { id: tenant },
|
||||
select: { id: true, plan: true, ssoEnabled: true },
|
||||
});
|
||||
|
||||
if (!team || !team.ssoEnabled) {
|
||||
console.warn(
|
||||
`[SCIM] Ignoring event for tenant ${tenant} — SSO not enabled`,
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
// Plan gate: only datarooms-premium or higher
|
||||
const allowedPlans = ["datarooms-premium", "datarooms-premium+old"];
|
||||
if (!allowedPlans.includes(team.plan)) {
|
||||
console.warn(
|
||||
`[SCIM] Ignoring event for tenant ${tenant} — plan ${team.plan} not eligible`,
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
if (!("email" in data) || !data.email) {
|
||||
return;
|
||||
}
|
||||
|
||||
// Normalize once so look-ups/upserts always use a consistent lowercase key
|
||||
const email = data.email.trim().toLowerCase();
|
||||
|
||||
try {
|
||||
switch (eventType) {
|
||||
case "user.created": {
|
||||
console.log(
|
||||
`[SCIM] User created: user_${hashEmail(email)} for tenant ${tenant}`,
|
||||
);
|
||||
|
||||
const user = await prisma.user.upsert({
|
||||
where: { email },
|
||||
create: {
|
||||
email,
|
||||
name: [data.first_name, data.last_name].filter(Boolean).join(" "),
|
||||
},
|
||||
update: {},
|
||||
});
|
||||
|
||||
await prisma.userTeam.upsert({
|
||||
where: {
|
||||
userId_teamId: {
|
||||
userId: user.id,
|
||||
teamId: tenant,
|
||||
},
|
||||
},
|
||||
update: {},
|
||||
create: {
|
||||
userId: user.id,
|
||||
teamId: tenant,
|
||||
role: "MEMBER",
|
||||
},
|
||||
});
|
||||
break;
|
||||
}
|
||||
|
||||
case "user.updated": {
|
||||
console.log(
|
||||
`[SCIM] User updated: user_${hashEmail(email)} for tenant ${tenant}`,
|
||||
);
|
||||
|
||||
// Handle Azure AD's active/inactive (can be boolean or string in any casing)
|
||||
const rawActive = (data as any).active;
|
||||
const normalizedActive =
|
||||
rawActive === undefined
|
||||
? undefined
|
||||
: typeof rawActive === "string"
|
||||
? rawActive.toLowerCase() === "true"
|
||||
: Boolean(rawActive);
|
||||
|
||||
const isActive = normalizedActive === true;
|
||||
const isInactive = normalizedActive === false;
|
||||
|
||||
if (isInactive) {
|
||||
// Deactivated — remove from team (same as user.deleted)
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { email },
|
||||
});
|
||||
|
||||
if (user) {
|
||||
await Promise.all([
|
||||
prisma.link
|
||||
.updateMany({
|
||||
where: {
|
||||
teamId: tenant,
|
||||
ownerId: user.id,
|
||||
},
|
||||
data: {
|
||||
ownerId: null,
|
||||
},
|
||||
})
|
||||
.catch(() => {
|
||||
console.warn(
|
||||
`[SCIM] Could not reset link ownership for user_${hashEmail(email)}`,
|
||||
);
|
||||
}),
|
||||
prisma.userTeam
|
||||
.delete({
|
||||
where: {
|
||||
userId_teamId: {
|
||||
userId: user.id,
|
||||
teamId: tenant,
|
||||
},
|
||||
},
|
||||
})
|
||||
.catch(() => {
|
||||
console.warn(
|
||||
`[SCIM] Could not remove team membership for user_${hashEmail(email)}`,
|
||||
);
|
||||
}),
|
||||
]);
|
||||
}
|
||||
} else if (isActive) {
|
||||
// Reactivated — re-add to team
|
||||
const user = await prisma.user.upsert({
|
||||
where: { email },
|
||||
create: {
|
||||
email,
|
||||
name: [data.first_name, data.last_name]
|
||||
.filter(Boolean)
|
||||
.join(" "),
|
||||
},
|
||||
update: {
|
||||
name:
|
||||
[data.first_name, data.last_name].filter(Boolean).join(" ") ||
|
||||
undefined,
|
||||
},
|
||||
});
|
||||
|
||||
await prisma.userTeam.upsert({
|
||||
where: {
|
||||
userId_teamId: {
|
||||
userId: user.id,
|
||||
teamId: tenant,
|
||||
},
|
||||
},
|
||||
update: {},
|
||||
create: {
|
||||
userId: user.id,
|
||||
teamId: tenant,
|
||||
role: "MEMBER",
|
||||
},
|
||||
});
|
||||
} else {
|
||||
// Just a name/attribute update
|
||||
await prisma.user
|
||||
.update({
|
||||
where: { email },
|
||||
data: {
|
||||
name:
|
||||
[data.first_name, data.last_name]
|
||||
.filter(Boolean)
|
||||
.join(" ") || undefined,
|
||||
},
|
||||
})
|
||||
.catch(() => {
|
||||
console.warn(
|
||||
`[SCIM] Could not update user user_${hashEmail(email)} — user not found`,
|
||||
);
|
||||
});
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
case "user.deleted": {
|
||||
console.log(
|
||||
`[SCIM] User deleted: user_${hashEmail(email)} for tenant ${tenant}`,
|
||||
);
|
||||
|
||||
const deletedUser = await prisma.user.findUnique({
|
||||
where: { email },
|
||||
});
|
||||
|
||||
if (deletedUser) {
|
||||
await Promise.all([
|
||||
prisma.link
|
||||
.updateMany({
|
||||
where: {
|
||||
teamId: tenant,
|
||||
ownerId: deletedUser.id,
|
||||
},
|
||||
data: {
|
||||
ownerId: null,
|
||||
},
|
||||
})
|
||||
.catch(() => {
|
||||
console.warn(
|
||||
`[SCIM] Could not reset link ownership for user_${hashEmail(email)}`,
|
||||
);
|
||||
}),
|
||||
prisma.userTeam
|
||||
.delete({
|
||||
where: {
|
||||
userId_teamId: {
|
||||
userId: deletedUser.id,
|
||||
teamId: tenant,
|
||||
},
|
||||
},
|
||||
})
|
||||
.catch(() => {
|
||||
console.warn(
|
||||
`[SCIM] Could not remove team membership for user_${hashEmail(email)}`,
|
||||
);
|
||||
}),
|
||||
]);
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
case "group.created":
|
||||
case "group.updated":
|
||||
case "group.deleted":
|
||||
case "group.user_added":
|
||||
case "group.user_removed": {
|
||||
console.log(`[SCIM] Group event ${eventType} for tenant ${tenant}`);
|
||||
break;
|
||||
}
|
||||
}
|
||||
} catch (error) {
|
||||
console.error(`[SCIM] Error handling event ${eventType}:`, error);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,186 @@
|
||||
import { jackson, jacksonProduct } from "@/lib/jackson";
|
||||
import prisma from "@/lib/prisma";
|
||||
import { CustomUser } from "@/lib/types";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
|
||||
const SSO_ELIGIBLE_PLANS = ["datarooms-premium", "datarooms-premium+old"];
|
||||
|
||||
function isJacksonUnavailableError(error: unknown): boolean {
|
||||
const message = error instanceof Error ? error.message : String(error);
|
||||
return (
|
||||
message.includes("error connecting to engine") ||
|
||||
message.includes("Missing Jackson DB URL") ||
|
||||
message.includes("ENOENT: no such file or directory, open 'system'")
|
||||
);
|
||||
}
|
||||
|
||||
async function getAuthenticatedAdmin(teamId: string) {
|
||||
const session = await getServerSession(authOptions);
|
||||
if (!session) return null;
|
||||
|
||||
const userId = (session.user as CustomUser).id;
|
||||
|
||||
const teamAccess = await prisma.userTeam.findUnique({
|
||||
where: { userId_teamId: { userId, teamId } },
|
||||
select: { role: true },
|
||||
});
|
||||
|
||||
if (!teamAccess || teamAccess.role !== "ADMIN") return null;
|
||||
|
||||
const team = await prisma.team.findUnique({
|
||||
where: { id: teamId },
|
||||
select: { id: true, plan: true, ssoEnabled: true },
|
||||
});
|
||||
|
||||
if (!team) return null;
|
||||
|
||||
return { userId, team };
|
||||
}
|
||||
|
||||
// GET /api/teams/:teamId/directory-sync — list SCIM directories
|
||||
export async function GET(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
if (!auth.team.ssoEnabled || !SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
|
||||
return NextResponse.json({ directories: [] });
|
||||
}
|
||||
|
||||
const { directorySyncController } = await jackson();
|
||||
|
||||
const { data, error } =
|
||||
await directorySyncController.directories.getByTenantAndProduct(
|
||||
teamId,
|
||||
jacksonProduct,
|
||||
);
|
||||
|
||||
if (error) {
|
||||
return NextResponse.json({ error: error.message }, { status: 400 });
|
||||
}
|
||||
|
||||
return NextResponse.json({ directories: data });
|
||||
} catch (error: any) {
|
||||
if (isJacksonUnavailableError(error)) {
|
||||
console.warn("[SCIM] Jackson unavailable, returning empty directories", error);
|
||||
return NextResponse.json({ directories: [] });
|
||||
}
|
||||
|
||||
console.error("[SCIM] Get directories error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// POST /api/teams/:teamId/directory-sync — create a SCIM directory connection
|
||||
export async function POST(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Plan gate
|
||||
if (!SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
|
||||
return NextResponse.json(
|
||||
{ error: "SCIM Directory Sync requires a Datarooms Premium plan" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
// Feature flag gate
|
||||
if (!auth.team.ssoEnabled) {
|
||||
return NextResponse.json(
|
||||
{ error: "SSO is not enabled for this team" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
try {
|
||||
const { directorySyncController } = await jackson();
|
||||
const body = await req.json();
|
||||
const { name, type, currentDirectoryId } = body;
|
||||
|
||||
// Create the new directory first; only delete the old one on success
|
||||
const result = await directorySyncController.directories.create({
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
name: name || "Hanzo Dataroom SCIM Directory",
|
||||
type: type || "azure-scim-v2",
|
||||
});
|
||||
|
||||
if (result.error) {
|
||||
return NextResponse.json(
|
||||
{ error: result.error.message },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// If replacing an existing directory, delete the old one after successful create
|
||||
if (currentDirectoryId) {
|
||||
await directorySyncController.directories.delete(currentDirectoryId);
|
||||
}
|
||||
|
||||
return NextResponse.json(result, { status: 201 });
|
||||
} catch (error: any) {
|
||||
console.error("[SCIM] Create directory error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// DELETE /api/teams/:teamId/directory-sync — delete a SCIM directory
|
||||
export async function DELETE(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
const { directorySyncController } = await jackson();
|
||||
const body = await req.json();
|
||||
const { directoryId } = body;
|
||||
|
||||
if (!directoryId) {
|
||||
return NextResponse.json(
|
||||
{ error: "directoryId is required" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const { error } =
|
||||
await directorySyncController.directories.delete(directoryId);
|
||||
|
||||
if (error) {
|
||||
return NextResponse.json({ error: error.message }, { status: 400 });
|
||||
}
|
||||
|
||||
return NextResponse.json({ ok: true });
|
||||
} catch (error: any) {
|
||||
console.error("[SCIM] Delete directory error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,408 @@
|
||||
import { jackson, jacksonProduct, samlAudience } from "@/lib/jackson";
|
||||
import prisma from "@/lib/prisma";
|
||||
import { CustomUser } from "@/lib/types";
|
||||
import { isGenericDomain } from "@/lib/utils/email-domain";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { NextResponse } from "next/server";
|
||||
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
|
||||
const SSO_ELIGIBLE_PLANS = ["datarooms-premium", "datarooms-premium+old"];
|
||||
|
||||
function isJacksonUnavailableError(error: unknown): boolean {
|
||||
const message = error instanceof Error ? error.message : String(error);
|
||||
return (
|
||||
message.includes("error connecting to engine") ||
|
||||
message.includes("Missing Jackson DB URL") ||
|
||||
message.includes("ENOENT: no such file or directory, open 'system'")
|
||||
);
|
||||
}
|
||||
|
||||
async function getAuthenticatedAdmin(teamId: string) {
|
||||
const session = await getServerSession(authOptions);
|
||||
if (!session) return null;
|
||||
|
||||
const userId = (session.user as CustomUser).id;
|
||||
|
||||
const teamAccess = await prisma.userTeam.findUnique({
|
||||
where: { userId_teamId: { userId, teamId } },
|
||||
select: { role: true },
|
||||
});
|
||||
|
||||
if (!teamAccess || teamAccess.role !== "ADMIN") return null;
|
||||
|
||||
const team = await prisma.team.findUnique({
|
||||
where: { id: teamId },
|
||||
select: { id: true, plan: true, ssoEnabled: true, ssoEmailDomain: true, ssoEnforcedAt: true, slug: true },
|
||||
});
|
||||
|
||||
if (!team) return null;
|
||||
|
||||
return { userId, team, email: (session.user as CustomUser).email! };
|
||||
}
|
||||
|
||||
// GET /api/teams/:teamId/saml — list SAML connections + issuer/acs info
|
||||
export async function GET(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
if (!auth.team.ssoEnabled || !SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
|
||||
return NextResponse.json({
|
||||
connections: [],
|
||||
issuer: samlAudience,
|
||||
acs: `${process.env.NEXTAUTH_URL}/api/auth/saml/callback`,
|
||||
ssoEmailDomain: auth.team.ssoEmailDomain,
|
||||
ssoEnforcedAt: auth.team.ssoEnforcedAt,
|
||||
slug: auth.team.slug,
|
||||
});
|
||||
}
|
||||
|
||||
const { apiController } = await jackson();
|
||||
|
||||
const connections = await apiController.getConnections({
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
});
|
||||
|
||||
return NextResponse.json({
|
||||
connections,
|
||||
issuer: samlAudience,
|
||||
acs: `${process.env.NEXTAUTH_URL}/api/auth/saml/callback`,
|
||||
ssoEmailDomain: auth.team.ssoEmailDomain,
|
||||
ssoEnforcedAt: auth.team.ssoEnforcedAt,
|
||||
slug: auth.team.slug,
|
||||
});
|
||||
} catch (error: any) {
|
||||
if (isJacksonUnavailableError(error)) {
|
||||
console.warn("[SAML] Jackson unavailable, returning empty connections", error);
|
||||
return NextResponse.json({
|
||||
connections: [],
|
||||
issuer: samlAudience,
|
||||
acs: `${process.env.NEXTAUTH_URL}/api/auth/saml/callback`,
|
||||
ssoEmailDomain: auth.team.ssoEmailDomain,
|
||||
ssoEnforcedAt: auth.team.ssoEnforcedAt,
|
||||
slug: auth.team.slug,
|
||||
});
|
||||
}
|
||||
|
||||
console.error("[SAML] Get connections error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// POST /api/teams/:teamId/saml — create a new SAML connection
|
||||
export async function POST(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Plan gate
|
||||
if (!SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
|
||||
return NextResponse.json(
|
||||
{ error: "SSO requires a Datarooms Premium plan" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
// Feature flag gate
|
||||
if (!auth.team.ssoEnabled) {
|
||||
return NextResponse.json(
|
||||
{ error: "SSO is not enabled for this team" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
try {
|
||||
const { apiController } = await jackson();
|
||||
const body = await req.json();
|
||||
const { rawMetadata, encodedRawMetadata, metadataUrl, domain } = body;
|
||||
|
||||
if (!rawMetadata && !metadataUrl && !encodedRawMetadata) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
"Either rawMetadata, encodedRawMetadata, or metadataUrl is required",
|
||||
},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Normalize the explicit domain provided by the admin (if any)
|
||||
const explicitDomain = typeof domain === "string"
|
||||
? domain.trim().toLowerCase().replace(/^@/, "")
|
||||
: undefined;
|
||||
|
||||
// Validate explicit domain format if provided
|
||||
if (explicitDomain && !/^[a-z0-9]([a-z0-9-]*[a-z0-9])?(\.[a-z0-9]([a-z0-9-]*[a-z0-9])?)+$/.test(explicitDomain)) {
|
||||
return NextResponse.json(
|
||||
{ error: "Invalid domain format. Please provide a valid domain (e.g., example.com)." },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Reject public / free email provider domains – SSO should only be
|
||||
// configured for organisation-owned domains.
|
||||
if (explicitDomain && isGenericDomain(explicitDomain)) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
"Public email domains (e.g., gmail.com, outlook.com) cannot be used for SSO. Please provide your organization's domain.",
|
||||
},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const connection = await apiController.createSAMLConnection({
|
||||
defaultRedirectUrl: `${process.env.NEXTAUTH_URL}/auth/saml`,
|
||||
redirectUrl: process.env.NEXTAUTH_URL as string,
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
rawMetadata: rawMetadata || undefined,
|
||||
encodedRawMetadata: encodedRawMetadata || undefined,
|
||||
metadataUrl: metadataUrl || undefined,
|
||||
});
|
||||
|
||||
// Attempt to extract a domain hint from the IdP metadata returned by the
|
||||
// SAML connection. Standard IdP entity IDs / SSO URLs sometimes contain
|
||||
// the organisation's own domain (e.g. for self-hosted IdPs). We use this
|
||||
// as an additional validation signal – if the admin supplied a domain we
|
||||
// check it is consistent; if not, we fall back to the metadata hint only
|
||||
// when it looks like a real organisation domain (not a generic IdP host).
|
||||
let metadataDomain: string | undefined;
|
||||
try {
|
||||
const idpMeta = (connection as any)?.idpMetadata;
|
||||
const candidateUrls: string[] = [
|
||||
idpMeta?.entityID,
|
||||
idpMeta?.sso?.postUrl,
|
||||
idpMeta?.sso?.redirectUrl,
|
||||
].filter(Boolean);
|
||||
|
||||
const genericIdpHosts = new Set([
|
||||
"accounts.google.com",
|
||||
"login.microsoftonline.com",
|
||||
"sts.windows.net",
|
||||
"idp.ssocircle.com",
|
||||
"www.okta.com",
|
||||
"dev.okta.com",
|
||||
"auth0.com",
|
||||
"onelogin.com",
|
||||
"pingone.com",
|
||||
]);
|
||||
|
||||
for (const raw of candidateUrls) {
|
||||
try {
|
||||
const host = new URL(raw).hostname.toLowerCase();
|
||||
// Skip well-known generic IdP hosts and public email domains
|
||||
if (
|
||||
[...genericIdpHosts].some((g) => host === g || host.endsWith(`.${g}`)) ||
|
||||
isGenericDomain(host)
|
||||
) {
|
||||
continue;
|
||||
}
|
||||
// Must have at least two labels (e.g. "company.com")
|
||||
if (host.split(".").length >= 2) {
|
||||
metadataDomain = host;
|
||||
break;
|
||||
}
|
||||
} catch {
|
||||
// not a valid URL – skip
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
// metadata extraction is best-effort
|
||||
}
|
||||
|
||||
// Determine the validated domain to persist:
|
||||
// 1. Prefer the explicitly admin-provided domain.
|
||||
// 2. Fall back to a domain extracted from metadata (if non-generic).
|
||||
// 3. If neither is available, do NOT store a domain.
|
||||
const validatedDomain = explicitDomain || metadataDomain || undefined;
|
||||
|
||||
// Only persist ssoEmailDomain when we have a validated value
|
||||
if (validatedDomain) {
|
||||
await prisma.team.update({
|
||||
where: { id: teamId },
|
||||
data: {
|
||||
ssoEmailDomain: validatedDomain,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
return NextResponse.json(connection, { status: 201 });
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Create connection error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// PATCH /api/teams/:teamId/saml — update SSO enforcement settings
|
||||
export async function PATCH(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
const body = await req.json();
|
||||
const { enforced } = body;
|
||||
|
||||
if (typeof enforced !== "boolean") {
|
||||
return NextResponse.json(
|
||||
{ error: "'enforced' must be a boolean" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Can only enforce if there's an ssoEmailDomain set (which is set when SAML is configured)
|
||||
if (enforced && !auth.team.ssoEmailDomain) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
"Cannot enforce SSO without a configured email domain. Please configure SAML first.",
|
||||
},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Verify there are active SAML connections before enforcing
|
||||
if (enforced) {
|
||||
const { apiController } = await jackson();
|
||||
const connections = await apiController.getConnections({
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
});
|
||||
|
||||
if (!connections || connections.length === 0) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
"Cannot enforce SSO without an active SAML connection. Please configure SAML first.",
|
||||
},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
const now = enforced ? new Date() : null;
|
||||
|
||||
await prisma.team.update({
|
||||
where: { id: teamId },
|
||||
data: {
|
||||
ssoEnforcedAt: now,
|
||||
},
|
||||
});
|
||||
|
||||
return NextResponse.json({
|
||||
enforced,
|
||||
ssoEnforcedAt: now?.toISOString() ?? null,
|
||||
});
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Update enforcement error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// DELETE /api/teams/:teamId/saml — remove a SAML connection
|
||||
export async function DELETE(
|
||||
req: Request,
|
||||
{ params }: { params: Promise<{ teamId: string }> },
|
||||
) {
|
||||
const { teamId } = await params;
|
||||
const auth = await getAuthenticatedAdmin(teamId);
|
||||
if (!auth) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
const { apiController } = await jackson();
|
||||
const body = await req.json();
|
||||
const { clientID, clientSecret } = body;
|
||||
|
||||
if (!clientID || !clientSecret) {
|
||||
return NextResponse.json(
|
||||
{ error: "clientID and clientSecret are required" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
// Ownership check: verify the connection belongs to this team before deleting
|
||||
const existingConnections = await apiController.getConnections({
|
||||
clientID,
|
||||
});
|
||||
|
||||
const connection = Array.isArray(existingConnections)
|
||||
? existingConnections[0]
|
||||
: existingConnections;
|
||||
|
||||
if (!connection) {
|
||||
return NextResponse.json(
|
||||
{ error: "SAML connection not found" },
|
||||
{ status: 404 },
|
||||
);
|
||||
}
|
||||
|
||||
if (connection.tenant !== teamId) {
|
||||
return NextResponse.json(
|
||||
{ error: "You do not have permission to delete this connection" },
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
|
||||
await apiController.deleteConnections({
|
||||
clientID,
|
||||
clientSecret,
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
});
|
||||
|
||||
// Check if there are remaining connections
|
||||
const remaining = await apiController.getConnections({
|
||||
tenant: teamId,
|
||||
product: jacksonProduct,
|
||||
});
|
||||
|
||||
if (!remaining || (Array.isArray(remaining) && remaining.length === 0)) {
|
||||
// No more connections — clear SSO domain and enforcement
|
||||
await prisma.team.update({
|
||||
where: { id: teamId },
|
||||
data: {
|
||||
ssoEmailDomain: null,
|
||||
ssoEnforcedAt: null,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
return NextResponse.json({ ok: true });
|
||||
} catch (error: any) {
|
||||
console.error("[SAML] Delete connection error:", error);
|
||||
return NextResponse.json(
|
||||
{ error: error.message || "Internal server error" },
|
||||
{ status: 500 },
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { reportDeniedAccessAttempt } from "@/ee/features/access-notifications";
|
||||
import { getTeamStorageConfigById } from "@/ee/features/storage/config";
|
||||
import { reportDeniedAccessAttempt } from "@/features/access-notifications";
|
||||
import { getTeamStorageConfigById } from "@/features/storage/config";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { ItemType, LinkAudienceType } from "@prisma/client";
|
||||
import { ipAddress, waitUntil } from "@vercel/functions";
|
||||
@@ -46,7 +46,6 @@ export async function POST(request: NextRequest) {
|
||||
documentName,
|
||||
hasPages,
|
||||
ownerId,
|
||||
dataroomVerified,
|
||||
linkType,
|
||||
dataroomViewId,
|
||||
viewType,
|
||||
@@ -61,7 +60,6 @@ export async function POST(request: NextRequest) {
|
||||
documentName: string | undefined;
|
||||
hasPages: boolean | undefined;
|
||||
ownerId: string | null;
|
||||
dataroomVerified: boolean | undefined;
|
||||
linkType: string;
|
||||
dataroomViewId?: string;
|
||||
viewType: "DATAROOM_VIEW" | "DOCUMENT_VIEW";
|
||||
@@ -149,6 +147,15 @@ export async function POST(request: NextRequest) {
|
||||
name: true,
|
||||
},
|
||||
},
|
||||
visitorGroups: {
|
||||
select: {
|
||||
visitorGroup: {
|
||||
select: {
|
||||
emails: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
@@ -314,10 +321,18 @@ export async function POST(request: NextRequest) {
|
||||
return NextResponse.json({ message: "Access denied" }, { status: 403 });
|
||||
}
|
||||
|
||||
// Build combined allow list from individual emails + visitor groups
|
||||
const visitorGroupEmails =
|
||||
link.visitorGroups?.flatMap((vg) => vg.visitorGroup.emails) || [];
|
||||
const combinedAllowList = [
|
||||
...(link.allowList || []),
|
||||
...visitorGroupEmails,
|
||||
];
|
||||
|
||||
// Check if email is allowed to visit the link
|
||||
if (link.allowList && link.allowList.length > 0) {
|
||||
if (combinedAllowList.length > 0) {
|
||||
// Determine if the email or its domain is allowed
|
||||
const isAllowed = link.allowList.some((allowed) =>
|
||||
const isAllowed = combinedAllowList.some((allowed) =>
|
||||
isEmailMatched(email, allowed),
|
||||
);
|
||||
|
||||
@@ -397,7 +412,7 @@ export async function POST(request: NextRequest) {
|
||||
// Request OTP Code for email verification if
|
||||
// 1) email verification is required and
|
||||
// 2) code is not provided or token not provided
|
||||
if (link.emailAuthenticated && !code && !token && !dataroomVerified) {
|
||||
if (link.emailAuthenticated && !code && !token) {
|
||||
const ipAddressValue = ipAddress(request);
|
||||
|
||||
// Rate limit per email/link combination (1 per 30 seconds) to prevent OTP flooding
|
||||
@@ -453,7 +468,7 @@ export async function POST(request: NextRequest) {
|
||||
);
|
||||
}
|
||||
|
||||
if (link.emailAuthenticated && code && !dataroomVerified) {
|
||||
if (link.emailAuthenticated && code) {
|
||||
const ipAddressValue = ipAddress(request);
|
||||
const { success } = await ratelimit(10, "1 m").limit(
|
||||
`verify-otp:${ipAddressValue}`,
|
||||
@@ -522,7 +537,7 @@ export async function POST(request: NextRequest) {
|
||||
isEmailVerified = true;
|
||||
}
|
||||
|
||||
if (link.emailAuthenticated && token && !dataroomVerified) {
|
||||
if (link.emailAuthenticated && token) {
|
||||
const ipAddressValue = ipAddress(request);
|
||||
const { success } = await ratelimit(10, "1 m").limit(
|
||||
`verify-email:${ipAddressValue}`,
|
||||
@@ -572,9 +587,6 @@ export async function POST(request: NextRequest) {
|
||||
isEmailVerified = true;
|
||||
}
|
||||
|
||||
if (link.emailAuthenticated && dataroomVerified) {
|
||||
isEmailVerified = true;
|
||||
}
|
||||
}
|
||||
|
||||
let viewer: { id: string; email: string; verified: boolean } | null = null;
|
||||
|
||||
+21
-4
@@ -1,7 +1,7 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { reportDeniedAccessAttempt } from "@/ee/features/access-notifications";
|
||||
import { getTeamStorageConfigById } from "@/ee/features/storage/config";
|
||||
import { reportDeniedAccessAttempt } from "@/features/access-notifications";
|
||||
import { getTeamStorageConfigById } from "@/features/storage/config";
|
||||
// Import authOptions directly from the source
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { ipAddress, waitUntil } from "@vercel/functions";
|
||||
@@ -123,6 +123,15 @@ export async function POST(request: NextRequest) {
|
||||
agentsEnabled: true,
|
||||
},
|
||||
},
|
||||
visitorGroups: {
|
||||
select: {
|
||||
visitorGroup: {
|
||||
select: {
|
||||
emails: true,
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
@@ -246,10 +255,18 @@ export async function POST(request: NextRequest) {
|
||||
return NextResponse.json({ message: "Access denied" }, { status: 403 });
|
||||
}
|
||||
|
||||
// Build combined allow list from individual emails + visitor groups
|
||||
const visitorGroupEmails =
|
||||
link.visitorGroups?.flatMap((vg) => vg.visitorGroup.emails) || [];
|
||||
const combinedAllowList = [
|
||||
...(link.allowList || []),
|
||||
...visitorGroupEmails,
|
||||
];
|
||||
|
||||
// Check if email is allowed to visit the link
|
||||
if (link.allowList && link.allowList.length > 0) {
|
||||
if (combinedAllowList.length > 0) {
|
||||
// Determine if the email or its domain is allowed
|
||||
const isAllowed = link.allowList.some((allowed) =>
|
||||
const isAllowed = combinedAllowList.some((allowed) =>
|
||||
isEmailMatched(email, allowed),
|
||||
);
|
||||
|
||||
|
||||
+2
-2
@@ -1,11 +1,11 @@
|
||||
import { cookies } from "next/headers";
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { WorkflowEngine } from "@/ee/features/workflows/lib/engine";
|
||||
import { WorkflowEngine } from "@/features/workflows/lib/engine";
|
||||
import {
|
||||
AccessRequestSchema,
|
||||
VerifyEmailRequestSchema,
|
||||
} from "@/ee/features/workflows/lib/types";
|
||||
} from "@/features/workflows/lib/types";
|
||||
import { ipAddress, waitUntil } from "@vercel/functions";
|
||||
import { z } from "zod";
|
||||
|
||||
+2
-2
@@ -1,8 +1,8 @@
|
||||
import { cookies } from "next/headers";
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
|
||||
import { WorkflowEngine } from "@/ee/features/workflows/lib/engine";
|
||||
import { AccessRequestSchema } from "@/ee/features/workflows/lib/types";
|
||||
import { WorkflowEngine } from "@/features/workflows/lib/engine";
|
||||
import { AccessRequestSchema } from "@/features/workflows/lib/types";
|
||||
import { ipAddress } from "@vercel/functions";
|
||||
import { z } from "zod";
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ import { ratelimit } from "@/lib/redis";
|
||||
import { sendOtpVerificationEmail } from "@/lib/emails/send-email-otp-verification";
|
||||
import { generateOTP } from "@/lib/utils/generate-otp";
|
||||
import { validateEmail } from "@/lib/utils/validate-email";
|
||||
import { VerifyEmailRequestSchema } from "@/ee/features/workflows/lib/types";
|
||||
import { VerifyEmailRequestSchema } from "@/features/workflows/lib/types";
|
||||
|
||||
// POST /app/(ee)/api/workflow-entry/[entryLinkId]/verify - Send OTP
|
||||
export async function POST(
|
||||
+1
-1
@@ -3,7 +3,7 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import {
|
||||
UpdateWorkflowRequestSchema,
|
||||
formatZodError,
|
||||
} from "@/ee/features/workflows/lib/validation";
|
||||
} from "@/features/workflows/lib/validation";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { customAlphabet } from "nanoid";
|
||||
import { getServerSession } from "next-auth";
|
||||
+1
-1
@@ -5,7 +5,7 @@ import {
|
||||
formatZodError,
|
||||
validateActions,
|
||||
validateConditions,
|
||||
} from "@/ee/features/workflows/lib/validation";
|
||||
} from "@/features/workflows/lib/validation";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
import { z } from "zod";
|
||||
+2
-2
@@ -10,8 +10,8 @@ import {
|
||||
formatZodError,
|
||||
validateConditions,
|
||||
validateActions,
|
||||
} from "@/ee/features/workflows/lib/validation";
|
||||
import { ReorderStepsRequest } from "@/ee/features/workflows/lib/types";
|
||||
} from "@/features/workflows/lib/validation";
|
||||
import { ReorderStepsRequest } from "@/features/workflows/lib/types";
|
||||
|
||||
// GET /app/(ee)/api/workflows/[workflowId]/steps?teamId=xxx - List all steps
|
||||
export async function GET(
|
||||
@@ -3,7 +3,7 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import {
|
||||
CreateWorkflowRequestSchema,
|
||||
formatZodError,
|
||||
} from "@/ee/features/workflows/lib/validation";
|
||||
} from "@/features/workflows/lib/validation";
|
||||
import { authOptions } from "@/pages/api/auth/[...nextauth]";
|
||||
import { getServerSession } from "next-auth";
|
||||
import { z } from "zod";
|
||||
@@ -230,6 +230,7 @@ export async function POST(req: NextRequest) {
|
||||
data: {
|
||||
linkType: "WORKFLOW_LINK",
|
||||
teamId,
|
||||
ownerId: userId,
|
||||
name: `${name} - Entry Link`,
|
||||
slug: slug || null,
|
||||
domainId: domainId,
|
||||
+8
-7
@@ -5,22 +5,23 @@ import "@/styles/globals.css";
|
||||
|
||||
const inter = Inter({ subsets: ["latin"] });
|
||||
|
||||
import { APP_DESCRIPTION, APP_NAME, APP_URL } from "@/lib/branding";
|
||||
|
||||
const data = {
|
||||
description:
|
||||
"Papermark is an open-source document sharing infrastructure. Free alternative to Docsend with custom domain. Manage secure document sharing with real-time analytics.",
|
||||
title: "Papermark | The Open Source DocSend Alternative",
|
||||
description: APP_DESCRIPTION,
|
||||
title: `${APP_NAME} | Secure Data Room Infrastructure`,
|
||||
url: "/",
|
||||
};
|
||||
|
||||
export const metadata: Metadata = {
|
||||
metadataBase: new URL("https://www.papermark.com"),
|
||||
metadataBase: new URL(APP_URL),
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
openGraph: {
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
url: data.url,
|
||||
siteName: "Papermark",
|
||||
siteName: APP_NAME,
|
||||
images: [
|
||||
{
|
||||
url: "/_static/meta-image.png",
|
||||
@@ -35,7 +36,7 @@ export const metadata: Metadata = {
|
||||
card: "summary_large_image",
|
||||
title: data.title,
|
||||
description: data.description,
|
||||
creator: "@papermarkio",
|
||||
creator: "@hanzoai",
|
||||
images: ["/_static/meta-image.png"],
|
||||
},
|
||||
};
|
||||
@@ -46,7 +47,7 @@ export default function RootLayout({
|
||||
children: React.ReactNode;
|
||||
}) {
|
||||
return (
|
||||
<html lang="en">
|
||||
<html lang="en" className="dark">
|
||||
<body className={inter.className}>{children}</body>
|
||||
</html>
|
||||
);
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
User-Agent: *
|
||||
Disallow: /login
|
||||
Disallow: /register
|
||||
Disallow: /verify/
|
||||
Disallow: /auth/
|
||||
|
||||
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
|
||||
import { useState } from "react";
|
||||
|
||||
import { useTeam } from "@/context/team-context";
|
||||
import { PlanEnum } from "@/ee/stripe/constants";
|
||||
import { PlanEnum } from "@/lib/billing/legacy/constants";
|
||||
import {
|
||||
ColumnDef,
|
||||
SortingState,
|
||||
|
||||
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
|
||||
import { useEffect, useState } from "react";
|
||||
|
||||
import { useTeam } from "@/context/team-context";
|
||||
import { PlanEnum } from "@/ee/stripe/constants";
|
||||
import { PlanEnum } from "@/lib/billing/legacy/constants";
|
||||
import {
|
||||
ColumnDef,
|
||||
SortingState,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import { useEffect, useState } from "react";
|
||||
|
||||
import { PlanEnum } from "@/ee/stripe/constants";
|
||||
import { PlanEnum } from "@/lib/billing/legacy/constants";
|
||||
import { differenceInDays, format, startOfDay, subDays } from "date-fns";
|
||||
import { CalendarIcon, ChevronDown, CrownIcon } from "lucide-react";
|
||||
import { DateRange } from "react-day-picker";
|
||||
|
||||
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
|
||||
import { useState } from "react";
|
||||
|
||||
import { useTeam } from "@/context/team-context";
|
||||
import { PlanEnum } from "@/ee/stripe/constants";
|
||||
import { PlanEnum } from "@/lib/billing/legacy/constants";
|
||||
import {
|
||||
ColumnDef,
|
||||
SortingState,
|
||||
|
||||
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
|
||||
import { useState } from "react";
|
||||
|
||||
import { useTeam } from "@/context/team-context";
|
||||
import { PlanEnum } from "@/ee/stripe/constants";
|
||||
import { PlanEnum } from "@/lib/billing/legacy/constants";
|
||||
import {
|
||||
ColumnDef,
|
||||
SortingState,
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user