Closes the pick-a-name convoy. Applies D1-D5 + Risk 4 PRESERVE per
operator gate-1 ratification.
Infrastructure renames:
- lib/rate-limit.js: 5 Redis key prefixes tcgvault:* → deckhearth:* (D5).
One-time per-15-min / per-1-hour counter reset accepted; no user impact
because counter windows are short anyway. Existing rate-limit state in
Upstash will accumulate at the new prefix on first request.
- package.json: name field tcg-vault → deck-hearth (D2)
- package-lock.json: regenerated for the name change; STOP-on-churn
protocol confirmed only the two name lines changed (no dep churn)
- All three test users (admin/alice/bob) renamed to @deckhearth.com (D4)
- One-off migration script scripts/migrations/2026-05-24-rename-admin-
email.js (NEW): ESM, idempotent, UNIQUE-collision-safe. Per the
no-go-zones rule for new migrations. Operator MUST run post-deploy.
- README.md + TESTING_GUIDE.md operator-caveat blockquotes flagged
- pages/login.js demo-credential pre-fill updated
PRESERVED per Risk 4:
- test/lib/permission-middleware.test.js literal admin@tcgvault.com
with 7-line architect-authored "why" comment block. This is the
documented pre-fix-auth-bypass bug shape; the regression-lock
literal stays as historical truth.
Verification:
- npm run lint: 128 problems (baseline preserved)
- npm run test:run: 21/21 pass (preserved literal keeps green)
- Grep across full repo: 0 hits for TCG Vault / tcgvault / tcg-vault
except the explicit preserve in the test file + .convoys/ historical
- lib/rate-limit.js: 5 deckhearth: prefixes, 0 tcgvault: prefixes
- node --check on the new migration script: exit 0
- git diff package-lock.json: only the 2 "name": lines changed (no churn)
Operator post-merge action:
- Run `node scripts/migrations/2026-05-24-rename-admin-email.js` against
the production Neon DB. Order matters: migration FIRST, then any
subsequent `npm run setup-db` invocation. Migration script will refuse
to run if collision detected (means setup-db already ran post-rename).
Architect brief: .convoys/pick-a-name/brief-2-infrastructure-and-email-migration.md
Architect commit: 50ce9ab
Operator gate-1: D1-D5 + Risk 4 PRESERVE ratified.
Co-authored-by: Cursor <cursoragent@cursor.com>
44 lines
1.4 KiB
JavaScript
Executable file
44 lines
1.4 KiB
JavaScript
Executable file
#!/usr/bin/env node
|
||
|
||
import { config } from 'dotenv';
|
||
import { sql } from '@vercel/postgres';
|
||
import bcrypt from 'bcryptjs';
|
||
|
||
// Load environment variables
|
||
config({ path: '.env.local' });
|
||
|
||
async function createTestUsers() {
|
||
try {
|
||
console.log('<27><> Creating test users...\n');
|
||
|
||
// Create Alice (collaborator)
|
||
const alicePassword = await bcrypt.hash('alice123', 12);
|
||
await sql`
|
||
INSERT INTO users (email, password, role)
|
||
VALUES ('alice@deckhearth.com', ${alicePassword}, 'user')
|
||
ON CONFLICT (email) DO NOTHING
|
||
`;
|
||
console.log('✅ Created Alice (alice@deckhearth.com / alice123)');
|
||
|
||
// Create Bob (collaborator)
|
||
const bobPassword = await bcrypt.hash('bob123', 12);
|
||
await sql`
|
||
INSERT INTO users (email, password, role)
|
||
VALUES ('bob@deckhearth.com', ${bobPassword}, 'user')
|
||
ON CONFLICT (email) DO NOTHING
|
||
`;
|
||
console.log('✅ Created Bob (bob@deckhearth.com / bob123)');
|
||
|
||
console.log('\n🎉 Test users created successfully!');
|
||
console.log('\n👥 Available Test Accounts:');
|
||
console.log(' 1. admin@deckhearth.com / admin123 (Admin)');
|
||
console.log(' 2. alice@deckhearth.com / alice123 (User)');
|
||
console.log(' 3. bob@deckhearth.com / bob123 (User)');
|
||
|
||
} catch (error) {
|
||
console.error('❌ Failed to create test users:', error.message);
|
||
process.exit(1);
|
||
}
|
||
}
|
||
|
||
createTestUsers();
|