Skip to content

✨ logging in and logging out pages and logic - #75

Open
miasua wants to merge 7 commits into
stagingfrom
miasua/user-login
Open

miasua wants to merge 7 commits into
stagingfrom
miasua/user-login

Conversation

@miasua

@miasua miasua commented Oct 5, 2026

Copy link
Copy Markdown

No description provided.

@miasua
miasua requested a review from synmux October 5, 2026 07:41
Comment thread server/api/user/stats.get.ts Dismissed
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
affirm-staging bab8a1d Commit Preview URL

Branch Preview URL
Oct 05 2026, 07:33 PM

@miasua miasua changed the title DRAFT: ✨ logging in and logging out pages and logic ✨ logging in and logging out pages and logic Oct 5, 2026
synmux added 3 commits October 5, 2026 18:46
- Add 7-day cooldown and reassign dependabot updates to synmux
  for both the github-actions and npm ecosystems
- Replace blanket `read-all` permissions in ci.yaml with a scoped
  block granting only the needed actions, checks, contents,
  id-token, issues, pull-requests and security-events scopes
- Grant `checks: write` in devskim.yaml and reorder the `on`
  triggers in both workflows for consistency
- Bump trunk linters: oxlint 1.87.0, checkov 3.3.23,
  trufflehog 3.98.0, oxfmt 0.72.0
- Revert over-eager bumps of @nuxt/scripts, @unhead/vue, daisyui,
  @types/node, node-gyp, vitest, vue-tsc and wrangler to the
  previously tested versions
- Alphabetise the VS Code extension recommendations
- Use `const` for the mutated-but-never-reassigned `message`
  object in server/api/login.post.ts

pnpm-lock.yaml is regenerated to match the adjusted pins.
- Add `reset` npm script that removes pnpm-lock.yaml and
  node_modules via rimraf, then runs `pnpm install`
- Add rimraf ^6.1.3 as a devDependency
- Regenerate pnpm-lock.yaml for rimraf and its transitive
  dependencies
@synmux

synmux commented Oct 5, 2026

Copy link
Copy Markdown
Member

typecheck output:

ℹ Nuxt Icon server bundle mode is set to remote
app/layouts/nuxt.config.ts(2,16): error TS2552: Cannot find name 'defineNuxtConfig'. Did you mean 'defineNitroConfig'?
app/pages/me.vue(23,31): error TS2339: Property 'name' does not exist on type 'User'.
server/api/login.post.ts(34,14): error TS2790: The operand of a 'delete' operator must be optional.
server/api/login.post.ts(40,14): error TS2352: Conversion of type '{ status: number; error: false; message: { id: number; email: string; username: string; name: string; password: string; businessRepresentative: boolean | null; business: number | null; verified: boolean | null; createdAt: Date; updatedAt: Date; }; }' to type 'ApiResponse' may be a mistake because neither type sufficiently overlaps with the other. If this was intentional, convert the expression to 'unknown' first.
  Types of property 'message' are incompatible.
    Type '{ id: number; email: string; username: string; name: string; password: string; businessRepresentative: boolean | null; business: number | null; verified: boolean | null; createdAt: Date; updatedAt: Date; }' is not comparable to type 'string'.
server/api/register.post.ts(40,44): error TS2769: No overload matches this call.
  Overload 1 of 2, '(value: { email: string | SQL<unknown> | Placeholder<string, any>; password: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: Date | ... 2 more ... | undefined; }): SQLiteInsertBase<...>', gave the following error.
    Argument of type '{ name: any; email: any; password: string; }' is not assignable to parameter of type '{ email: string | SQL<unknown> | Placeholder<string, any>; password: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: Date | ... 2 more ... | undefined; }'.
      Property 'username' is missing in type '{ name: any; email: any; password: string; }' but required in type '{ email: string | SQL<unknown> | Placeholder<string, any>; password: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: Date | ... 2 more ... | undefined; }'.
  Overload 2 of 2, '(values: { email: string | SQL<unknown> | Placeholder<string, any>; password: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: Date | ... 2 more ... | undefined; }[]): SQLiteInsertBase<...>', gave the following error.
    Object literal may only specify known properties, and 'name' does not exist in type '{ email: string | SQL<unknown> | Placeholder<string, any>; password: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: Date | ... 2 more ... | undefined; }[]'.
server/api/login.post.ts(34,14): error TS2790: The operand of a 'delete' operator must be optional.
server/api/login.post.ts(40,14): error TS2352: Conversion of type '{ status: number; error: false; message: { id: number; email: string; username: string; name: string; password: string; businessRepresentative: boolean | null; business: number | null; verified: boolean | null; createdAt: Date; updatedAt: Date; }; }' to type 'ApiResponse' may be a mistake because neither type sufficiently overlaps with the other. If this was intentional, convert the expression to 'unknown' first.
  Types of property 'message' are incompatible.
    Type '{ id: number; email: string; username: string; name: string; password: string; businessRepresentative: boolean | null; business: number | null; verified: boolean | null; createdAt: Date; updatedAt: Date; }' is not comparable to type 'string'.
server/api/register.post.ts(40,44): error TS2769: No overload matches this call.
  Overload 1 of 2, '(value: { email: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<string, any>; name: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: SQL<...> | ... 2 more ... | undefined; }): SQLiteInsertBase<...>', gave the following error.
    Argument of type '{ name: any; email: any; password: string; }' is not assignable to parameter of type '{ email: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<string, any>; name: string | SQL<unknown> | Placeholder<string, any>; ... 6 more ...; updatedAt?: SQL<...> | ... 2 more ... | undefined; }'.
      Property 'username' is missing in type '{ name: any; email: any; password: string; }' but required in type '{ email: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<string, any>; name: string | SQL<unknown> | Placeholder<string, any>; ... 6 more ...; updatedAt?: SQL<...> | ... 2 more ... | undefined; }'.
  Overload 2 of 2, '(values: { email: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<string, any>; name: string | SQL<unknown> | Placeholder<...>; ... 6 more ...; updatedAt?: SQL<...> | ... 2 more ... | undefined; }[]): SQLiteInsertBase<...>', gave the following error.
    Object literal may only specify known properties, and 'name' does not exist in type '{ email: string | SQL<unknown> | Placeholder<string, any>; username: string | SQL<unknown> | Placeholder<string, any>; name: string | SQL<unknown> | Placeholder<string, any>; ... 6 more ...; updatedAt?: SQL<...> | ... 2 more ... | undefined; }[]'.

synmux added 3 commits October 5, 2026 20:26
- Add .github/copilot-instructions.md with a pointer block that
  routes diagram creation, editing, and visualization requests to
  the detailed Mermaid instructions
- Add .github/instructions/mermaid.instructions.md describing the
  workflow for generating, validating, and previewing .mmd files
- Document required LM tool calls (mermaid-diagram-validator,
  mermaid-diagram-preview, get-syntax-docs-mermaid)
- Catalog VS Code extension commands, Mermaid cloud login/sync
  commands, the GitHub Sync review flow, and @Mermaid-Chart slash
  commands
- Spell out rules so AI agents validate before showing, preview
  after generating, warn before spending AI-repair credits, and
  leave sync-managed diagrams untouched
- Rename `bg-gradient-to-*` classes to `bg-linear-to-*` in the blank
  layout and the account page, matching Tailwind v4 naming
- Add a `userName` computed in `me.vue` that casts `user` safely and
  falls back to "there", so the welcome heading never renders a blank
  or undefined name
- Polish Copilot docs: add a `# Copilot Instructions` title, drop a
  stray blank line after the mermaid frontmatter, and widen the slash
  command table separator so the columns align

@synmux synmux left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mergeable once typing issues are resolved

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Authentication behavior, response handling, type safety, accessibility, dependencies, and workflow permissions contain unresolved issues.

11 open findings
What changed in this PR

Adds session-based login/logout flows, protected account UI, and related repository configuration updates.

Changes:

  • Creates authenticated session, profile, logout, and route-guard flows.
  • Adds example layout/page and protected user endpoint.
  • Updates developer tooling, CI permissions, Dependabot, and Mermaid guidance.
File Description
server/​api/​user/​stats.get.ts Adds protected user endpoint.
server/​api/​login.post.ts Creates sessions after login.
drizzle.config.ts Loads environment variables.
app/​pages/​me.vue Adds profile/logout page.
app/​pages/​login.vue Refreshes session and redirects.
app/​pages/​login-example.vue Adds example login route.
app/​middleware/​authenticated.ts Protects authenticated routes.
app/​layouts/​nuxt.config.ts Adds nested Nuxt configuration.
app/​layouts/​blank.vue Adds blank layout.
app/​components/​AppHeader.vue Adds session-aware navigation.
.vscode/​extensions.json Updates extension recommendations.
.trunk/​trunk.yaml Updates tool versions.
.github/​workflows/​devskim.yaml Changes workflow permissions.
.github/​workflows/​ci.yaml Changes CI permissions.
.github/​instructions/​mermaid.instructions.md Adds Mermaid instructions.
.github/​dependabot.yml Updates cooldowns and assignees.
.github/​copilot-instructions.md References Mermaid guidance.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread .github/workflows/ci.yaml
Comment on lines +5 to +12
permissions:
actions: read
checks: write
contents: read
id-token: write
issues: write
pull-requests: write
security-events: write
Comment thread drizzle.config.ts
@@ -1,4 +1,7 @@
import { defineConfig } from "drizzle-kit";
import dotenv from "dotenv";
Comment thread server/api/login.post.ts
});
if (check) {
const message = { ...result };
delete message.password;
<li>
<NuxtLink to="/list" class="link link-hover" active-class="menu-active">List</NuxtLink>
</li>
<li v-if="loggedIn">
Comment on lines +19 to +25
const res = await $fetch("/api/login", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: { email: email.value, password: password.value },
});
console.log("Fetch Complete");
console.log(res);
Comment thread server/api/login.post.ts
status: 200,
error: false,
message: `${body.email} logged in`,
message,
Comment thread server/api/login.post.ts
}
}
return {
status: 401,
Comment on lines +6 to +8
// TODO: Fetch some stats based on the user

return { ...user };
Comment on lines +2 to +3
export default defineNuxtConfig({
modules: ["nuxt-auth-utils"],
Comment thread app/pages/login.vue
class="fieldset bg-base-200 border-base-300 border rounded-box w-full p-4 flex flex-col justify-stretch gap-4"
>
<legend class="sr-only">Login Page</legend>
<main class="flex-1 py-12">

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants