feat: Full project management application scaffold
Complete architecture for a ClickUp/Notion/Miro-class project management app:
- Turborepo monorepo with Next.js 15, TypeScript, PostgreSQL (Drizzle ORM)
- Object-centered database schema (everything is an Object: tasks, projects, docs, whiteboards)
- NextAuth v5 authentication with credentials + OAuth providers
- tRPC v11 API layer with full CRUD for objects, properties, relations, templates, search
- Three-panel UI: collapsible sidebar, center content area, push-in right panel
- Purple/teal theme with light/dark mode via Shadcn/ui + Tailwind CSS
- Multiple views: List, Kanban board (dnd-kit), Table (spreadsheet), Embedded iframe
- TipTap rich text editor with slash commands, custom blocks (callout, toggle, mention, embed, divider), AI block
- Real-time collaboration via Yjs + Hocuspocus with presence/cursors
- tldraw whiteboard with custom shape cards (task, document, project)
- MCP server exposing all app data/tools for AI agents
- AI chat panel, editor AI slash commands, Cmd+K command palette
- Template system with built-in templates (Bug Report, Meeting Notes, Sprint)
- Full-text search with result highlighting
- Docker Compose for full-stack deployment (web + collab + postgres + redis)
Made-with: Cursor
2026-03-26 23:39:16 -04:00
|
|
|
import NextAuth from "next-auth";
|
|
|
|
|
import type { DefaultSession, NextAuthConfig } from "next-auth";
|
feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:
App
- New routes: ai, forms, planner, settings (templates/types), teams,
doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
builder/renderer/responses, types manager, objects creation dialog,
card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in
Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
(uses CT 102 shared services), removes host port mappings, adds
Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
metadata title flipped to ECHODO
Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
credentials.*, *.key, *.crt, *.pem, ssh keys
Made-with: Cursor
2026-04-26 15:34:34 -04:00
|
|
|
import Authentik from "next-auth/providers/authentik";
|
feat: Full project management application scaffold
Complete architecture for a ClickUp/Notion/Miro-class project management app:
- Turborepo monorepo with Next.js 15, TypeScript, PostgreSQL (Drizzle ORM)
- Object-centered database schema (everything is an Object: tasks, projects, docs, whiteboards)
- NextAuth v5 authentication with credentials + OAuth providers
- tRPC v11 API layer with full CRUD for objects, properties, relations, templates, search
- Three-panel UI: collapsible sidebar, center content area, push-in right panel
- Purple/teal theme with light/dark mode via Shadcn/ui + Tailwind CSS
- Multiple views: List, Kanban board (dnd-kit), Table (spreadsheet), Embedded iframe
- TipTap rich text editor with slash commands, custom blocks (callout, toggle, mention, embed, divider), AI block
- Real-time collaboration via Yjs + Hocuspocus with presence/cursors
- tldraw whiteboard with custom shape cards (task, document, project)
- MCP server exposing all app data/tools for AI agents
- AI chat panel, editor AI slash commands, Cmd+K command palette
- Template system with built-in templates (Bug Report, Meeting Notes, Sprint)
- Full-text search with result highlighting
- Docker Compose for full-stack deployment (web + collab + postgres + redis)
Made-with: Cursor
2026-03-26 23:39:16 -04:00
|
|
|
import Credentials from "next-auth/providers/credentials";
|
|
|
|
|
import GitHub from "next-auth/providers/github";
|
|
|
|
|
import Google from "next-auth/providers/google";
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Optional: `pnpm add @auth/drizzle-adapter` then wire DrizzleAdapter + session strategy "database".
|
|
|
|
|
* Using JWT + Credentials/OAuth; `db` is loaded dynamically inside `authorize` (Node route handler only).
|
|
|
|
|
* User lookup uses the postgres.js client from Drizzle (`db.$client`) so we avoid a direct `drizzle-orm` import in this app.
|
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
declare module "next-auth" {
|
|
|
|
|
interface Session {
|
|
|
|
|
user: {
|
|
|
|
|
id: string;
|
|
|
|
|
} & DefaultSession["user"];
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const providers: NextAuthConfig["providers"] = [
|
|
|
|
|
Credentials({
|
|
|
|
|
name: "Email",
|
|
|
|
|
credentials: {
|
|
|
|
|
email: { label: "Email", type: "email" },
|
|
|
|
|
password: { label: "Password", type: "password" },
|
|
|
|
|
},
|
|
|
|
|
async authorize(credentials) {
|
|
|
|
|
const email = credentials?.email as string | undefined;
|
|
|
|
|
const password = credentials?.password as string | undefined;
|
|
|
|
|
if (!email?.trim() || !password) return null;
|
|
|
|
|
|
|
|
|
|
const devPassword = process.env.AUTH_DEV_PASSWORD;
|
|
|
|
|
if (!devPassword) {
|
|
|
|
|
console.warn("[auth] AUTH_DEV_PASSWORD is not set; credentials sign-in disabled.");
|
|
|
|
|
return null;
|
|
|
|
|
}
|
|
|
|
|
if (password !== devPassword) return null;
|
|
|
|
|
|
|
|
|
|
const { db } = await import("@tasks/database/client");
|
|
|
|
|
const sql = (db as { $client: (t: TemplateStringsArray, ...v: unknown[]) => Promise<unknown[]> })
|
|
|
|
|
.$client;
|
|
|
|
|
const rows = (await sql`
|
|
|
|
|
SELECT id, email, name, avatar_url AS "avatarUrl"
|
|
|
|
|
FROM users
|
|
|
|
|
WHERE lower(email) = lower(${email.trim()})
|
|
|
|
|
LIMIT 1
|
|
|
|
|
`) as { id: string; email: string; name: string | null; avatarUrl: string | null }[];
|
|
|
|
|
const user = rows[0];
|
|
|
|
|
if (!user) return null;
|
|
|
|
|
|
|
|
|
|
return {
|
|
|
|
|
id: user.id,
|
|
|
|
|
email: user.email,
|
|
|
|
|
name: user.name ?? undefined,
|
|
|
|
|
image: user.avatarUrl ?? undefined,
|
|
|
|
|
};
|
|
|
|
|
},
|
|
|
|
|
}),
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
if (process.env.AUTH_GITHUB_ID && process.env.AUTH_GITHUB_SECRET) {
|
|
|
|
|
providers.push(
|
|
|
|
|
GitHub({
|
|
|
|
|
clientId: process.env.AUTH_GITHUB_ID,
|
|
|
|
|
clientSecret: process.env.AUTH_GITHUB_SECRET,
|
|
|
|
|
}),
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (process.env.AUTH_GOOGLE_ID && process.env.AUTH_GOOGLE_SECRET) {
|
|
|
|
|
providers.push(
|
|
|
|
|
Google({
|
|
|
|
|
clientId: process.env.AUTH_GOOGLE_ID,
|
|
|
|
|
clientSecret: process.env.AUTH_GOOGLE_SECRET,
|
|
|
|
|
}),
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
|
feat: ECHODO app shell, Coolify deploy, Authentik + Umami
Bundles in-flight ECHODO work with the Coolify deployment configuration:
App
- New routes: ai, forms, planner, settings (templates/types), teams,
doc detail, whiteboard detail
- New components: app shell rework (icon-rail, top-header), forms
builder/renderer/responses, types manager, objects creation dialog,
card primitive, form + overview views
- New tRPC routers: favorites, forms, types, workspaces; updates to
health and objects routers
- Markdown backlog sync (packages/database) + cursor-sync schema/migrations
- Schema additions: forms, types, favorites, markdown_backlog, cursor_sync
- Initial Drizzle migrations checked in
Deployment
- docker/docker-compose.coolify.yml: drops bundled Postgres/Redis
(uses CT 102 shared services), removes host port mappings, adds
Coolify SERVICE_FQDN_* magic vars for web + collab
- .env.example rewritten as the full ECHODO/Coolify variable manifest
- NextAuth gains an Authentik OIDC provider (gated on env presence)
- Root layout injects Umami tracking script when configured;
metadata title flipped to ECHODO
Security
- .gitignore expanded to exclude AGENT-DEPLOY.md, .env.*, secrets/,
credentials.*, *.key, *.crt, *.pem, ssh keys
Made-with: Cursor
2026-04-26 15:34:34 -04:00
|
|
|
if (
|
|
|
|
|
process.env.AUTH_AUTHENTIK_ID &&
|
|
|
|
|
process.env.AUTH_AUTHENTIK_SECRET &&
|
|
|
|
|
process.env.AUTH_AUTHENTIK_ISSUER
|
|
|
|
|
) {
|
|
|
|
|
providers.push(
|
|
|
|
|
Authentik({
|
|
|
|
|
clientId: process.env.AUTH_AUTHENTIK_ID,
|
|
|
|
|
clientSecret: process.env.AUTH_AUTHENTIK_SECRET,
|
|
|
|
|
issuer: process.env.AUTH_AUTHENTIK_ISSUER,
|
|
|
|
|
}),
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
|
feat: Full project management application scaffold
Complete architecture for a ClickUp/Notion/Miro-class project management app:
- Turborepo monorepo with Next.js 15, TypeScript, PostgreSQL (Drizzle ORM)
- Object-centered database schema (everything is an Object: tasks, projects, docs, whiteboards)
- NextAuth v5 authentication with credentials + OAuth providers
- tRPC v11 API layer with full CRUD for objects, properties, relations, templates, search
- Three-panel UI: collapsible sidebar, center content area, push-in right panel
- Purple/teal theme with light/dark mode via Shadcn/ui + Tailwind CSS
- Multiple views: List, Kanban board (dnd-kit), Table (spreadsheet), Embedded iframe
- TipTap rich text editor with slash commands, custom blocks (callout, toggle, mention, embed, divider), AI block
- Real-time collaboration via Yjs + Hocuspocus with presence/cursors
- tldraw whiteboard with custom shape cards (task, document, project)
- MCP server exposing all app data/tools for AI agents
- AI chat panel, editor AI slash commands, Cmd+K command palette
- Template system with built-in templates (Bug Report, Meeting Notes, Sprint)
- Full-text search with result highlighting
- Docker Compose for full-stack deployment (web + collab + postgres + redis)
Made-with: Cursor
2026-03-26 23:39:16 -04:00
|
|
|
export const { handlers, auth, signIn, signOut } = NextAuth({
|
|
|
|
|
session: { strategy: "jwt" },
|
|
|
|
|
pages: {
|
|
|
|
|
signIn: "/sign-in",
|
|
|
|
|
},
|
|
|
|
|
providers,
|
|
|
|
|
callbacks: {
|
|
|
|
|
async jwt({ token, user }) {
|
|
|
|
|
if (user?.id) {
|
|
|
|
|
token.id = user.id;
|
|
|
|
|
}
|
|
|
|
|
return token;
|
|
|
|
|
},
|
|
|
|
|
async session({ session, token }) {
|
|
|
|
|
if (session.user && token.id) {
|
|
|
|
|
session.user.id = token.id as string;
|
|
|
|
|
}
|
|
|
|
|
return session;
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
trustHost: true,
|
|
|
|
|
});
|