Skip to content

Migration API for importing spaces into a self-hosted install - #73

Merged
alexcibotari merged 1 commit into
developfrom
feat/firebase-migration-api
Oct 10, 2026
Merged

alexcibotari merged 1 commit into
developfrom
feat/firebase-migration-api

Conversation

@alexcibotari

Copy link
Copy Markdown
Contributor

Summary

Adds what a self-hosted Localess install needs to import spaces from this Firebase environment (Admin → Spaces → Import from Firebase on the self-hosted side).

  • Migration API (functions/src/migration.ts, function migrationapi, Hosting rewrite /api/migration/**): read-only, bearer migration token.
    • GET /api/migration/spaces, /spaces/{id}, /spaces/{id}/tokens|webhooks|schemas
    • /spaces/{id}/translations|assets|contents?cursor= paged by 500 ({ items, cursor }, cursor = last id, null at the end)
    • Answers 404 everywhere while no token is configured, 401 for a missing or wrong one.
    • Asset files are read through the existing public /api/v1/spaces/{id}/assets/{assetId}/original.
  • Migration token (functions/src/migration-token.ts): admin-only callables migrationtoken-generate (returns the token once) and migrationtoken-revoke. Only the sha256 is stored, in configs/migration; the check uses timingSafeEqual.
  • firestore.rules: configs/migration is readable by admins only and not writable by clients, so nobody can set a token of their choosing.
  • Admin → Settings → Migration tab to generate (shown once), regenerate and revoke the token.
  • README: "Moving to a self-hosted install".

The self-hosted side lives on refactor/monorepo-structure (design: docs/roadmap/firebase-space-import.md there).

Testing

  • functions: npm test → 40 files / 641 tests (new: token hashing/check, API auth/shape/paging, callables admin-only and hash-only storage); npm run build, npm run lint (0 errors)
  • web: ng test → 175 files / 1595 tests (new: Migration tab incl. error states); ng build, ng lint
  • The Firestore rules change has no automated test (no rules emulator harness on develop).

🤖 Generated with Claude Code

…install

- functions: read-only /api/migration/** (spaces, space, tokens, webhooks, schemas; translations, assets, contents paged
  by 500), bearer migration token, 404 while no token is configured
- functions: admin-only migrationtoken-generate / -revoke callables; only the token's sha256 is stored (configs/migration)
- firestore.rules: configs/migration is read by admins only and written only by the callables
- admin UI: Settings → Migration tab to generate (shown once), regenerate and revoke the token
- hosting: /api/migration/** rewrite; README: moving to a self-hosted install
@alexcibotari
alexcibotari merged commit b357ff7 into develop Oct 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant