Path-A first task: get the repo's two repo-wide quality gates passing.
Both were failing from a clean clone in ways that were silently hiding
each other.
Headline fixes:
* apps/web: add an eslint 9 flat config (eslint.config.mjs) using
FlatCompat against next/core-web-vitals + next/typescript, and switch
the `lint` script from `next lint` to `eslint .`. Previously `next
lint` fell into its interactive setup prompt because there was no
config at all in apps/web, which made `pnpm lint` permanently fail
before any rule ever ran.
* packages/shared/src/utils/id.ts: replace `randomUUID` from `node:crypto`
with `globalThis.crypto.randomUUID`. `@tasks/shared` is forbidden from
using Node-only APIs (per AGENTS.md / repo-overview.mdc) because it
has to be importable from the browser bundle.
Adjacent fixes pulled in to make the gates actually green:
* apps/mcp-server/tsconfig.json: drop vestigial rootDir / declaration*
/ outDir / sourceMap (build is via tsup, not tsc emit) and add
allowImportingTsExtensions. The MCP server uses `.ts`-extension
re-export shims (db.ts / schema.ts / shared-types.ts) so tsup can
inline workspace .ts sources into the bundle.
* apps/collab-server/tsconfig.json: same simplification.
* apps/mcp-server/package.json: add @types/node so `process.env` in
packages/database/src/client.ts (transitively pulled into the MCP
server's type-check) resolves.
* apps/web/components/ui/input.tsx: empty `interface InputProps extends
React.InputHTMLAttributes<HTMLInputElement> {}` -> `type` alias.
* apps/web/server/lib/workspace-guard.ts: `from(args.table as any)` ->
`as unknown as PgTable` with a comment. Standard drizzle escape
hatch for structural generic tables.
* apps/web/components/whiteboard/shapes/{document,project,task}-card.tsx:
`BaseBoxShapeUtil<any>` -> `BaseBoxShapeUtil<{Shape}>` plus inline
`declare module "@tldraw/tlschema"` augmentation of
TLGlobalShapePropsMap. Required adding @tldraw/tlschema as a direct
devDep of apps/web so the augmentation target resolves; previously
it was only present transitively under tldraw's own deps.
Result: `pnpm lint && pnpm type-check` exits 0 across all 6 packages.
16 unused-import / exhaustive-deps warnings remain; they're pre-existing
housekeeping and out of scope for this task.
Closes plans/Plan-daily-driver-finish/Epic-shipping-the-shell/
Task-fix-lint-and-shared-types.md (status: done).
Co-authored-by: Cursor <cursoragent@cursor.com>
Three pieces of authentication work that need to land together so OAuth
sign-ins produce a usable session.
* `ensureUserIdByEmail` upserts a `users` row on every OAuth sign-in
matched case-insensitively on email, then stamps `token.id` with the
resulting UUID so workspace-scoped tRPC procedures can resolve
membership. Credentials sign-in already returned the DB id from
`authorize`; OAuth now does the equivalent.
* `ensureUserHasWorkspace` mints a personal workspace (and `owner`
member row) on first sign-in for any user that doesn't already
belong to one, so fresh OAuth accounts don't land in the app with
no tenant scope. Idempotent; slug collisions retry with a random
suffix and cap at 5 attempts.
* Migration 0004 adds a `UNIQUE (lower(email))` index on `users` to
match the lookup pattern and prevent two providers from minting
rows that differ only in casing. Existing rows are normalized to
lowercase first; the column-level UNIQUE catches any pre-existing
duplicates so they get resolved by a human rather than silently
merged.
Sign-in / sign-up pages add an Authentik SSO button (gated on
`AUTH_AUTHENTIK_*` env vars). Layout switches to GitHub+Google on top
with Authentik full-width below.
Co-authored-by: Cursor <cursoragent@cursor.com>
Block A of the EchoDo plan. Workspaces used to live as `objects(type='workspace')`,
which made it impossible to put a real RLS-friendly tenant boundary on the schema
or to give each workspace a stable URL slug. This commit:
- Adds a top-level `workspaces` table (slug unique, owner FK, plan_tier hook).
- Migrates the 8 anchor tables (objects, workspace_members, object_type_defs,
property_definitions, templates, forms, markdown_backlog_items,
cursor_sync_mappings) to FK into `workspaces.id` instead of `objects.id`,
with a hand-augmented data-copy migration that preserves IDs and slug-collision-
proofs on backfill.
- Introduces a `workspaceProcedure` tRPC middleware + `resolveWorkspace` helper
that take a UUID-or-slug `workspace` handle and expose `ctx.workspace`. All
tenant-scoped routers (objects, types, properties, templates, forms, search,
ai, relations, favorites) now flow through it.
- Updates the web app to pass `workspace` slugs from the URL (or store) instead
of the old `workspaceId`, including a workspace-sync layer that rewrites
/<UUID>/... links to /<slug>/...
- Updates the MCP tools (list_objects, create_object, search_objects) and the
workspace://{handle}/tree resource to accept either a slug or UUID so existing
agents keep working.
- Adds a Create Workspace dialog and a Workspace Settings page (rename + slug
rename with redirect, owner-only archive).
Verified locally against a fresh Postgres: migration applies cleanly, slug
uniqueness holds, tenant data is isolated by workspace_id, slug↔UUID resolution
works in both directions, and ON DELETE CASCADE cleans up child rows in the
correct workspace only.
Co-authored-by: Cursor <cursoragent@cursor.com>
The collab server was using createRequire() with hardcoded relative paths
(../../../packages/database/package.json, ../node_modules/@hocuspocus/server/...)
to grab `eq` from drizzle-orm and `Forbidden` from @hocuspocus/common. That
worked under tsx in dev but fell apart in the bundled prod image because
those paths don't exist there and pnpm's symlink topology in the runtime
node_modules wasn't reachable from inside the bundled dist file.
Result at runtime: Cannot find module '@hocuspocus/common' on every
collab restart, infinite crash loop.
Switch both to plain ESM imports — tsup bundles them into dist/index.mjs
directly, no runtime resolution needed. Add @hocuspocus/common and
drizzle-orm as explicit deps so they're properly tracked.
Verified locally: bundle now resolves cleanly with no createRequire calls
(actually shrinks from 304 KB to 102 KB after dead-code elimination).
Made-with: Cursor
@tasks/database (and @tasks/shared) export raw .ts files via "main" /
"exports", which works fine for tsx/dev but blows up at runtime in the
production image:
ERR_UNKNOWN_FILE_EXTENSION: Unknown file extension ".ts" for
/app/packages/database/src/client.ts
tsup was leaving those workspace imports as externals in the output, so
the deployed dist/index.mjs still tried to resolve them at startup.
Switch each app to a tsup.config.ts that sets noExternal: [/^@tasks\\//],
which inlines workspace packages into the bundle while keeping
node_modules deps (postgres, drizzle-orm, hocuspocus, mcp-sdk, etc.)
external.
Verified locally: collab-server bundle size goes from 7 KB to 304 KB,
confirming @tasks/database is now compiled in. Also fixed the collab
start script to point at index.mjs (tsup ESM output) instead of .js.
Made-with: Cursor
The Next.js standalone runtime stage copies apps/web/public into the image,
but the directory was never committed since the project hasn't shipped any
static assets. BuildKit fails with "not found" on the COPY. Adding an empty
.gitkeep guarantees the directory exists at build time and lets future static
assets drop in without further build changes.
Made-with: Cursor
Two AI components were importing from ../../../../packages/ai/src using
relative paths that escape the workspace root. This worked locally because
all packages are siblings on disk, but failed in Docker where Dockerfile.web
only copies apps/web, packages/database, and packages/shared into the
build context — packages/ai never made it in.
Changes:
- Add @tasks/ai as a workspace dependency in apps/web/package.json
- Switch both imports (command-palette.tsx, ai-block.tsx) to "@tasks/ai"
- Add @tasks/ai to transpilePackages in next.config.ts and the docker variant
- Copy packages/ai into the Docker build context (Dockerfile.web)
- Refresh pnpm-lock.yaml for the new workspace edge
Verified locally: web builds compile cleanly past the previously failing
"Module not found" errors. (Local final step hits an unrelated ENOSPC on
the dev disk; Coolify's volume has plenty of headroom.)
Made-with: Cursor