Skip to content

chore: update prod from main - #1205

Merged
fhennig merged 7 commits into
prodfrom
main
May 18, 2026
Merged

chore: update prod from main#1205
fhennig merged 7 commits into
prodfrom
main

Conversation

@github-actions

Copy link
Copy Markdown

This pull request updates the prod branch with the latest changes from the main branch.

Make sure to merge this creating a merge commit.

Do not squash-merge this PR. Do not rebase and merge.

…es (#1192)

Bumps the minorandpatch group in /backend with 2 updates: [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) and [gradle-wrapper](https://github.com/gradle/gradle).


Updates `org.postgresql:postgresql` from 42.7.10 to 42.7.11
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.7.10...REL42.7.11)

Updates `gradle-wrapper` from 9.4.1 to 9.5.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.4.1...v9.5.0)

---
updated-dependencies:
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: gradle-wrapper
  dependency-version: 9.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@vercel

vercel Bot commented May 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
dashboards Ready Ready Preview, Comment May 18, 2026 6:57am

Request Review

…15 updates (#1208)

Bumps the minorandpatch group with 13 updates in the /website directory:

| Package | From | To |
| --- | --- | --- |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.100.5` | `5.100.10` |
| [axios](https://github.com/axios/axios) | `1.15.2` | `1.16.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.5` | `19.2.6` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.5` | `19.2.6` |
| [yaml](https://github.com/eemeli/yaml) | `2.8.3` | `2.9.0` |
| [@astrojs/check](https://github.com/withastro/astro/tree/HEAD/packages/language-tools/astro-check) | `0.9.8` | `0.9.9` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.59.1` | `1.60.0` |
| [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite) | `4.2.4` | `4.3.0` |
| [@tanstack/eslint-plugin-query](https://github.com/TanStack/query/tree/HEAD/packages/eslint-plugin-query) | `5.100.5` | `5.100.10` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.59.1` | `8.59.3` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.59.1` | `8.59.3` |
| [msw](https://github.com/mswjs/msw) | `2.13.6` | `2.14.6` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.59.1` | `8.59.3` |



Updates `@tanstack/react-query` from 5.100.5 to 5.100.10
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/HEAD/packages/react-query)

Updates `axios` from 1.15.2 to 1.16.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.15.2...v1.16.0)

Updates `react` from 19.2.5 to 19.2.6
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react)

Updates `react-dom` from 19.2.5 to 19.2.6
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react-dom)

Updates `yaml` from 2.8.3 to 2.9.0
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.3...v2.9.0)

Updates `@astrojs/check` from 0.9.8 to 0.9.9
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/astro-check/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/check@0.9.9/packages/language-tools/astro-check)

Updates `@playwright/test` from 1.59.1 to 1.60.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.59.1...v1.60.0)

Updates `@tailwindcss/vite` from 4.2.4 to 4.3.0
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.0/packages/@tailwindcss-vite)

Updates `@tanstack/eslint-plugin-query` from 5.100.5 to 5.100.10
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/eslint-plugin-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/HEAD/packages/eslint-plugin-query)

Updates `@typescript-eslint/eslint-plugin` from 8.59.1 to 8.59.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.3/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.59.1 to 8.59.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.3/packages/parser)

Updates `msw` from 2.13.6 to 2.14.6
- [Release notes](https://github.com/mswjs/msw/releases)
- [Changelog](https://github.com/mswjs/msw/blob/main/CHANGELOG.md)
- [Commits](mswjs/msw@v2.13.6...v2.14.6)

Updates `playwright` from 1.59.1 to 1.60.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.59.1...v1.60.0)

Updates `tailwindcss` from 4.2.4 to 4.3.0
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.0/packages/tailwindcss)

Updates `typescript-eslint` from 8.59.1 to 8.59.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.3/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.100.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: axios
  dependency-version: 1.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: react
  dependency-version: 19.2.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: react-dom
  dependency-version: 19.2.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: "@astrojs/check"
  dependency-version: 0.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: "@playwright/test"
  dependency-version: 1.60.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: "@tailwindcss/vite"
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: "@tanstack/eslint-plugin-query"
  dependency-version: 5.100.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.59.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.59.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
- dependency-name: msw
  dependency-version: 2.14.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: playwright
  dependency-version: 1.60.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: tailwindcss
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
- dependency-name: typescript-eslint
  dependency-version: 8.59.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minorandpatch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minorandpatch group in /backend with 1 update: [org.jetbrains.kotlinx:kotlinx-datetime](https://github.com/Kotlin/kotlinx-datetime).


Updates `org.jetbrains.kotlinx:kotlinx-datetime` from 0.7.1-0.6.x-compat to 0.8.0-0.6.x-compat
- [Release notes](https://github.com/Kotlin/kotlinx-datetime/releases)
- [Changelog](https://github.com/Kotlin/kotlinx-datetime/blob/master/CHANGELOG.md)
- [Commits](Kotlin/kotlinx-datetime@v0.7.1-0.6.x-compat...v0.8.0-0.6.x-compat)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx:kotlinx-datetime
  dependency-version: 0.8.0-0.6.x-compat
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minorandpatch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…rrors (#1196)

Points VS Code at the project's TypeScript (website/node_modules/typescript)
so it respects allowImportingTsExtensions from the Astro tsconfig, silencing
false-positive ts(5097) errors on .ts import paths.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…ueryFilter (#1204)

* feat(website): make error tooltip direction configurable in AdvancedQueryFilter

Adds an optional `errorTooltipClass` prop to `AdvancedQueryFilter` (and
the internal `ErrorIconWithTooltip`) so callers can control which
direction the validation error tooltip opens. Defaults to the original
`tooltip-left lg:tooltip-right` so existing usages are unchanged.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* format

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…enced in the AdvancedQueryFilter (#1195)

* initial implementation

* format

* fix(website): use type-only import for SiloFilterExpression in spec

Required by verbatimModuleSyntax.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* format

* test(website): implement allowedFields browser tests for AdvancedQueryFilter

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(website): deduplicate usedFields and clean up spec type annotation

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* format

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat(website): replace auth-astro with better-auth

Replaces auth-astro + @auth/core with better-auth, running in stateless
mode (no database, JWT-based sessions). Removes the custom patch that
was required for auth-astro TypeScript compatibility.

- Add better-auth config (src/auth.ts) with GitHub OAuth and trustedProxyHeaders
- Add catch-all API route at /api/auth/[...all] to handle auth requests
- Replace getSession() calls across all pages and backendProxy with auth.api.getSession()
- Replace signIn() in LoginButton with authClient.signIn.social()
- Replace custom logout implementation with auth.api.signOut()
- Update E2E test helper to use better-auth cookie name and JWT format
- Remove auth-astro Astro integration from astro.config.mjs
- Remove patches/auth-astro+4.2.0.patch and patch-package

NOTE: session.user.id must be verified to contain the GitHub numeric user
ID after a real login — see TODO in src/auth.ts. The E2E test token
format is also a best-guess pending verification — see TODO in
tests/helpers/auth.ts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(website): pass asResponse: true to better-auth signOut

auth.api.signOut() returns typed data, not a Response object, so
calling .headers.getSetCookie() on it threw a 500. The asResponse
option makes it return a proper Response with Set-Cookie headers.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(website): resolve GitHub user ID from account instead of session

better-auth's session.user.id is a randomly generated internal ID, not
the GitHub numeric ID the backend uses for ownership checks. Adds a
getGitHubUserId() helper that retrieves the correct ID via
auth.api.listUserAccounts() and updates backendProxy and the two
collection pages that do ownership comparisons.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): centralise auth in Astro middleware, store GitHub ID as user field

Replaces per-page auth calls with a single middleware that runs once per
request and populates Astro.locals. The GitHub numeric user ID is now stored
as a dedicated `githubId` additionalField on the user object via
`mapProfileToUser`, so it is available directly on `session.user` without
any secondary lookups.

- Add `authMiddleware` that calls `getSession` once and sets
  `context.locals.user` and `context.locals.session`
- Configure `user.additionalFields.githubId` + `mapProfileToUser` in
  `auth.ts` to populate it from the GitHub profile at login time
- Remove `getGitHubUserId` helper (no longer needed)
- Update `backendProxy` to read `context.locals.user?.githubId` via
  `APIContext` instead of re-deriving the ID from headers
- Update all pages/components to read from `Astro.locals` instead of
  calling `auth.api.getSession` directly
- Update `App.Locals` types to use the inferred auth user type so
  `githubId` is typed correctly everywhere
- Remove unused `jose` devDependency and E2E test auth helper

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): add E2E auth cookie helper and set cookie prefix

Adds tests/helpers/auth.ts with createAuthCookies() and setupAuthCookie()
that craft valid better-auth session cookies for Playwright tests without
needing a real OAuth flow. Also sets cookiePrefix to 'gen-spectrum' in auth
config (required for the helper to match what the server sets).

Note: E2E cookie injection is untested — cookieCache also needs to be
enabled in auth.ts before getSession will accept the crafted session_data
cookie without a store lookup.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* format

* asdfasdf

* fix check-types

* fix(website): remove patches dir from Dockerfile COPY

The patches/ directory was deleted when auth-astro was replaced with
better-auth, causing the Docker build to fail.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): enable cookieCache and wire up E2E auth cookies

Enables better-auth cookieCache (JWE, 1hr) so getSession can validate
crafted session cookies without an in-memory store lookup. This makes
the E2E auth helper work across the separate test/server processes.

Also aligns the E2E test GitHub ID with the seeded collection's userId
so ownership checks pass on the edit page.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* format

* fix(website): coerce GitHub user ID to string in mapProfileToUser

profile.id from GitHub is a number but githubId is declared as string.
Without String(), the stored value is a number and ownership checks
(currentUserId === collection.ownedBy) fail due to type mismatch.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(website): suppress eslint warning on String(profile.id) coercion

The type says string but GitHub returns a number at runtime.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): harden better-auth session and cookie config

- Set 7-day session expiry explicitly
- Add refreshCache: true so stateless JWE cookie stays fresh
- Enable storeAccountCookie for fully stateless operation
- Fix cookie prefix from 'gen-spectrum' to 'genspectrum'

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* let better-auth read secret automatically; document it.

* use const ID

* fix(website): raise error when AUTH_SECRET is missing in E2E helpers

Also fix cookie prefix to match auth.ts ('genspectrum').

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor(website): use App.AuthUser type in UserDropdown, rename prop to user

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): configure trustedOrigins for better-auth from application YAML

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat(website): add better-auth logging via instance logger

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* foo

* foo

* foo

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@fhennig
fhennig merged commit a8c9ee2 into prod May 18, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant