ac6c834525
- main.ts awaits DatabaseInitService.init() before app.listen(), ensuring
migrations + seed run before the HTTP server accepts traffic.
- AppModule now uses NestModule with consumer.apply() no longer needed for
CSRF (registered globally via app.use after body parsers in main.ts).
- JwtAuthGuard extended from AuthGuard('jwt') so protected endpoints
actually validate the bearer token.
- Admin controller now uses Zod-validated DTOs for body/path/query:
createUser, updateUserRole, userIdParam, listUsersQuery; with @Public
/ @Roles decorators and AdminGuard applied.
- Multer upload module + controller (POST /api/v1/uploads/category-icon
and /challenge-file) with safe-filename strategy, configured
UPLOAD_SIZE_LIMIT, admin-only via AdminGuard, served via /uploads
static handler.
- ThemeLoaderService now requires all 10 canonical theme ids at startup,
backfilling missing themes from built-ins with a warning; validates the
configured themeKey setting and falls back to 'classic' if invalid;
gracefully tolerates missing setting table during early boot.
- Test suite expanded to 76 tests / 17 suites; new specs:
admin-validation, uploads, theme-required, database-init.
11 lines
492 B
TypeScript
11 lines
492 B
TypeScript
import { INestApplication } from '@nestjs/common';
|
|
import { DatabaseInitService } from '../../backend/src/database/database-init.service';
|
|
|
|
/**
|
|
* Await database initialization (migrations + seed verification) on the
|
|
* given Nest app. Without this, integration tests that hit controllers
|
|
* will hit a fresh `:memory:` SQLite database with no tables.
|
|
*/
|
|
export async function initDb(app: INestApplication): Promise<void> {
|
|
await app.get<DatabaseInitService>(DatabaseInitService).init();
|
|
} |