fix: complete ORM port — token/oauth-client API mismatches, use published orm 0.2.8

- Use published @simpleworkjs/orm ^0.2.8 (fixes redis adapter write path)
  and model-redis ^1.6.0 instead of a local file: link that broke docker
  npm ci with a misleading "no lockfile" error.
- OtpToken.issue/verify: replace nonexistent find()/listDetail() with
  list({where}).
- routes/auth.js: ImpersonationToken.listDetail() -> list({where}).
- routes/token.js: drop listDetail() call; 404 on missing token instead
  of returning {results: null} with 200 (orm get() returns null, does
  not throw like model-redis Table.get did).
- OAuthClient: Resource has no is_valid column, so every client read as
  disabled and all /oauth/authorize requests 400'd — validity now lives
  in metadata (absent = valid). Also generate a unique slug on create
  (Resource.slug is required+unique) and use Resource.get() for lookup.
- User.login: 401 cleanly when neither uid nor username is supplied.
- models/index.js: log ORM init and surface init failures.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-23 02:20:49 -04:00
parent c4d7a1a8e9
commit 5dcc75195c
8 changed files with 1607 additions and 364 deletions
+2 -2
View File
@@ -95,7 +95,7 @@ class OtpToken extends Token {
}
static async issue(uid, method) {
const existing = await this.find({uid});
const existing = await this.list({where: {uid}});
for (const t of existing) {
if (t.is_valid) await t.update({is_valid: false});
}
@@ -104,7 +104,7 @@ class OtpToken extends Token {
}
static async verify(uid, code) {
const tokens = await this.listDetail({uid});
const tokens = await this.list({where: {uid}});
const match = tokens.find(t => t.is_valid && !t.isExpired && t.code === code);
if (!match) return null;
await match.update({is_valid: false});