Skip to content

feat(db): move from Turso/libSQL to Postgres via @profullstack/libsql-pg - #120

Merged
ralyodio merged 3 commits into
masterfrom
port/libsql-pg
Sep 25, 2026
Merged

ralyodio merged 3 commits into
masterfrom
port/libsql-pg

Conversation

@ralyodio

Copy link
Copy Markdown
Collaborator

Second pass of the dev2 migration: the database leaves Turso for the shared Postgres cluster on dev2.

  • DATABASE_URL=postgres://... is read through @profullstack/libsql-pg (the @libsql/client surface; SQLite idioms rewritten per statement; the CREATE TABLEs in initSchema go through its schema converter, which needed 0.1.3 for DEFAULT 'x' CHECK (...) and datetime('now','+7 days') defaults). file: still works locally and in the tests (@libsql/client becomes a devDependency, loaded lazily; TURSO_DATABASE_URL still names a file: URL). libsql:// is refused with a pointer to the move.
  • Waitlist sort: lower(email) instead of COLLATE NOCASE (Postgres has no such collation; identical order on both).
  • addColumnIfMissing also accepts Postgres's "already exists" (the client rewrites to ADD COLUMN IF NOT EXISTS anyway).
  • next.config.mjs: pg and both drivers stay external.

Checks: bun test tests/ 253/253, next build clean.

Data: dev2-site db-create moshcoding.com, schema from libsql-pg convert-schema, libsql-pg copy --verify, then provision (+ env_remove for the Turso settings) and deploy.

🤖 Generated with Claude Code

Production reads DATABASE_URL=postgres://... through @profullstack/libsql-pg,
which keeps the @libsql/client surface every query here was written against,
rewrites the SQLite idioms per statement and runs the CREATE TABLEs in
initSchema through its schema converter. Local runs and the tests keep a
libSQL file (@libsql/client is now a devDependency, loaded lazily for file:
URLs; TURSO_DATABASE_URL still names one). libsql:// is refused with a
message pointing at the move.

Dialect fixes: the waitlist sort orders by lower(email) instead of
COLLATE NOCASE (no such collation in Postgres; same order on both), and
addColumnIfMissing also accepts Postgres's "already exists" message.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​profullstack/​libsql-pg@​0.1.37610010091100

View full report

Comment thread .env.example Fixed
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

20 finding(s)

HIGH/CRITICAL: 3 | MEDIUM: 13 | LOW: 4

Severity Rule Location
HIGH sh-remote-script-execution public/install.sh:302
HIGH sh-remote-script-execution public/install.sh:305
HIGH sh-remote-script-execution public/install.sh:432
MEDIUM js-open-redirect app/dashboard/[[...tab]]/page.tsx:67
MEDIUM js-open-redirect app/signup/page.tsx:38
MEDIUM js-open-redirect components/PitSearch.tsx:118
MEDIUM js-unescaped-html-sink components/Tenant.tsx:21
MEDIUM js-unescaped-html-sink components/Tenant.tsx:22
MEDIUM js-unescaped-html-sink components/Tenant.tsx:62
MEDIUM js-unescaped-html-sink components/Tenant.tsx:136
MEDIUM sql-template-interpolation lib/db.ts:1117
MEDIUM sql-template-interpolation lib/db.ts:1147
MEDIUM redos-nested-quantifier lib/markdown.ts:109
MEDIUM sh-remote-script-execution public/install.sh:123
MEDIUM sh-remote-script-execution public/install.sh:127
MEDIUM sh-remote-script-execution public/install.sh:146
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:18
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:25
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:30
LOW secret-generic-credential tests/project-webhook-management.test.mjs:53

Snippets are redacted; ThreatCrush never prints matched credential material.

Postgres returns created_at/expires_at as ISO strings; appending "Z" to one made
an Invalid Date, whose getTime() compares as never expired.
@ralyodio
ralyodio merged commit 0e06660 into master Sep 25, 2026
5 checks passed
@ralyodio
ralyodio deleted the port/libsql-pg branch September 25, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants