dorfteich/.gitea/workflows/ci.yml
Claude Fable 5 36608177f6 Add user, identity, session, and auth-support data model
Prisma models per data-model.md: users (status enum, site-admin flag),
user_identities (password provider now, OIDC later — subject is the
stable user id), sessions (hashed ids), auth_tokens (hashed, single-
use), plus rate_limits and mail_outbox for the upcoming M1 stories.
UsersService creates accounts transactionally with Argon2id-hashed
password identities (OWASP parameters, rehash detection) and maps
uniqueness violations to field-level conflicts. Database-backed suites
run when TEST_DATABASE_URL is set — locally against the dev db, in CI
via a new postgres service container; shared auth schemas (username,
password policy incl. common-password blocklist) ship with tests.

Closes #10

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 00:42:22 +02:00

78 lines
2.2 KiB
YAML

# CI: every pull request and every push to main must pass these checks
# (ADR 0014). The deploy pipeline (CD) lives in cd.yml and only runs on
# main after this workflow's quality bar.
#
# Runner requirements: an act_runner with the `ubuntu-latest` label and
# Docker access (see deploy/stages.md, issue #9).
name: CI
on:
pull_request:
push:
branches: [main]
jobs:
checks:
name: Lint, typecheck, test
runs-on: ubuntu-latest
services:
postgres:
image: postgres:17.5-alpine
env:
POSTGRES_USER: test
POSTGRES_PASSWORD: test
POSTGRES_DB: test
env:
# Enables the database-backed test suites (vitest.global-setup.ts).
TEST_DATABASE_URL: postgresql://test:test@postgres:5432/test
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up pnpm
uses: pnpm/action-setup@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
# Build first: package type checks resolve @dorfteich/shared through
# its built dist, and i18n:check imports the built helpers.
- name: Build all packages
run: pnpm build
- name: Lint (ESLint + Prettier)
run: pnpm lint
- name: Typecheck
run: pnpm typecheck
- name: Unit and integration tests
run: pnpm test
- name: Translation key parity (de/en)
run: pnpm i18n:check
images:
name: Build container images
# PR-only: on main the CD workflow builds and pushes the same images —
# building twice would waste the runner (ADR 0014: build once, promote).
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
# PRs prove the Dockerfiles still build; pushing happens in cd.yml.
- name: Build web image
run: docker build -f apps/web/Dockerfile --build-arg APP_VERSION=${{ github.sha }} -t dorfteich-web:ci .
- name: Build api image
run: docker build -f apps/api/Dockerfile --build-arg APP_VERSION=${{ github.sha }} -t dorfteich-api:ci .