Commit graph

1 commit

Author SHA1 Message Date
Randall Stillwell
cd4ba35356 architect(drop-public-setup): plan + brief 1 (env-var admin password)
Single-brief convoy. ~25 LOC net across 2 files (scripts/setup-neon-db.js,
README.md). No fan-out; single PR.

Decisions:
  A1 — going-forward only (matches JWT_SECRET pattern from
       fix-auth-bypass Brief 1). Existing weak-hash admin rows in
       deployed envs are NOT rotated; operators rotate manually
       via the app after merge. Queue rotate-default-admin follow-up
       if a real audit finds a deploy still on the weak hash.
  B  — operational change to setup-neon-db.js is allowed; no-go-zones
       rule prohibits SCHEMA edits, not env-var gating.
  C1 — no vitest coverage. Fail-loud path is validated by manual smoke
       (the brief mandates pasting fail-loud + happy-path output into
       the PR description).

Key risks tracked: R1 (existing weak hash), R2 (unhelpful error),
R3 (stdout password leak — delete the console.log lines, do NOT
interpolate the env-var), R4 (silent rotation if ON CONFLICT changed
to DO UPDATE), R5 (README env block omits the new var), R6 (3 sibling
files still have admin123 — out of scope per convoy spec).

Flagged-but-deferred:
  - CommonJS in ESM package (setup-neon-db.js) → convert-setup-db-to-esm
  - admin123 in reset-db.js, create-test-users.js, TESTING_GUIDE.md
    → purge-weak-creds-from-helpers (or fold into launch-polish)
  - admin@tcgvault.com hardcoded email → pick-a-name convoy

addresses: P0 #3 from .convoys/ship-readiness.md
parent: ship-readiness
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-23 12:32:52 -05:00