Author SHA1 Message Date
jschoubben eab696ce42 Merge pull request 'fix(db): grant app user permissions on players and games tables' (#5) from fix/db-permissions into main 2026-07-09 19:48:53 +02:00
Warre (hal-developer) 1e7772ad29 fix(db): grant app user permissions on players and games tables
PostgreSQL 15+ revokes CREATE from non-superusers in public schema by default.
Child 1's migration created the tables as postgres superuser, leaving the
txt_game_scores app user with no privileges — causing "permission denied"
on every request in production.

Adds a numbered provision migration to GRANT SELECT/INSERT/UPDATE on players
and games, plus USAGE/SELECT on games_id_seq, to the app user.

Task: d1c49d59-57bd-4eba-9e22-f25a04157ad4
2026-07-09 19:46:14 +02:00
jschoubben 8c3c95916d Merge pull request 'feat(scores): persist scores in Postgres, add scoreboard UI' (#4) from feat/score-persistence into main 2026-07-09 19:37:32 +02:00
@@ -0,0 +1,29 @@
import pg from "pg";
const client = new pg.Client({
host: process.env.PROVISION_HOST,
port: parseInt(process.env.PROVISION_PORT ?? "5432"),
user: process.env.PROVISION_USER,
password: process.env.PROVISION_PASSWORD,
database: process.env.PROVISION_DATABASE,
});
await client.connect();
try {
// The HAL postgres provisioner names the app user identically to the database.
// PROVISION_DATABASE = "txt_game_scores" = the app user that server.mjs connects as.
const appUser = process.env.PROVISION_DATABASE as string;
await client.query(
`GRANT SELECT, INSERT, UPDATE ON TABLE players, games TO "${appUser}"`
);
await client.query(
`GRANT USAGE, SELECT ON SEQUENCE games_id_seq TO "${appUser}"`
);
console.log(`[txt-game migration-001] permissions granted to ${appUser}`);
} finally {
await client.end();
}