Skip to content

Chore/port foundation modules - #2

Merged
bobbybol merged 23 commits into
oss-migrationfrom
chore/port-foundation-modules
Jul 18, 2026
Merged

bobbybol merged 23 commits into
oss-migrationfrom
chore/port-foundation-modules

Conversation

@bobbybol

@bobbybol bobbybol commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • New Features
    • Added authenticated GET /auth/me with JWT and X-API-KEY authentication plus Supabase-backed principal claims.
    • Introduced privileged admin workflows (members, agents, customers) with new validation DTOs and user/admin module wiring.
    • Added local API smoke-test setup using httpYac and updated env templates (including per-host .env.example).
  • Bug Fixes
    • Health checks now return DB-backed status.
    • Default grid timezone changed to UTC.
  • Documentation
    • Refreshed config/env templates and deployment/dev seed/testing docs; updated architecture ADRs.
  • Tests
    • Added/updated Jest unit, integration, and E2E configurations with conditional local Supabase runs.

@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@bobbybol

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 92c7311d-6bc7-4e45-8206-621deb7875b0

📥 Commits

Reviewing files that changed from the base of the PR and between 0ef2a31 and 2a50bb8.

📒 Files selected for processing (1)
  • docs/architecture/005-inter-host-communication.md

📝 Walkthrough

Walkthrough

The change completes a Foundation migration across API and worker hosts, adding Supabase authentication, user administration, local seed/test workflows, shared infrastructure, and updated configuration. Legacy foundation modules are removed or narrowed, while architecture and migration records document the completed decisions.

Changes

Foundation migration

Layer / File(s) Summary
Host configuration and infrastructure wiring
.env.example, apps/api/..., apps/worker/..., libs/core/..., tsconfig*.json, eslint.config.mjs
Hosts now use explicit infrastructure and Foundation module arrays, shared Supabase services, updated configuration schemas, environment templates, logging placeholders, package exports, and decorator-enabled root compiler settings.
Authentication and authenticated principal
apps/api/src/modules/auth/*, apps/api/src/modules/health/*
Bearer JWT and X-API-KEY authentication, AuthenticatedUser, CurrentUser, AuthenticationGuard, /auth/me, and a Supabase-backed health probe are added.
User administration workflows
apps/api/src/modules/user-admin/*
Validated member, agent, and customer administration flows perform Supabase Auth, domain-table, wallet, audit, soft-delete, and account-ban operations.
Seed, smoke tests, and test execution
apps/api/http/*, apps/api/test/*, supabase/seed.sql, apps/api/jest*
Local seed fixtures, HTTPYac requests, shared Jest configuration, integration/E2E targets, and environment-gated authentication tests are added.
Legacy foundation removal
legacy/apps/tiamat/..., legacy/libs/core/...
Legacy foundation modules and entities are removed from wiring, and the legacy grid controller no longer exposes GET /grids/:id.
Architecture and migration records
docs/architecture/*, docs/deployment/*, docs/plans/*
ADR-005 and ADR-014 are recorded, Foundation migration tasks are marked complete, and deployment, schema, and seed documentation is updated.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant AuthenticationGuard
  participant SupabaseStrategy
  participant ApiKeyStrategy
  participant AuthController
  Client->>AuthenticationGuard: request /auth/me
  AuthenticationGuard->>SupabaseStrategy: validate bearer JWT
  AuthenticationGuard->>ApiKeyStrategy: validate X-API-KEY
  SupabaseStrategy->>AuthController: provide AuthenticatedUser
  ApiKeyStrategy->>AuthController: provide AuthenticatedUser
  AuthController-->>Client: return authenticated identity
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches the PR’s main theme of porting foundation modules and related wiring changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/port-foundation-modules

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 14

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
docs/plans/002-oss-migration/002d-platform-core-import.md (1)

299-309: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Use db reset in the seed completion criterion.

The “Done when” text says pnpm supabase start + seed, while the implemented/configured flow runs seed.sql on pnpm exec supabase db reset. Update the criterion to name the actual command explicitly.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/plans/002-oss-migration/002d-platform-core-import.md` around lines 299 -
309, Update the “Done when” criterion in the 002d migration plan to explicitly
require running `pnpm exec supabase db reset`, while preserving the requirement
for a coherent Foundation dataset and usable test user.
🧹 Nitpick comments (4)
apps/api/src/main.ts (1)

15-20: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Add whitelist: true to the global ValidationPipe.

Without whitelist: true, unknown properties in request bodies are not stripped, creating a potential mass-assignment risk when DTOs map to database writes. Adding whitelist: true (and optionally forbidNonWhitelisted: true) ensures only explicitly declared DTO fields are accepted.

🛡️ Suggested fix
   new ValidationPipe({
     transform: true,
+    whitelist: true,
+    forbidNonWhitelisted: true,
     transformOptions: { enableImplicitConversion: false },
   }),
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/api/src/main.ts` around lines 15 - 20, Update the global ValidationPipe
configuration in main.ts to enable whitelist: true, ensuring unknown request
properties are stripped while preserving the existing transformation settings.
libs/core/src/modules/supabase/supabase.errors.ts (1)

24-31: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low value

Consider tightening the Cloudflare HTML error detection.

The isCloudflareHtmlError check matches any error message containing the substring "html" (case-insensitive). This could false-positive on legitimate PostgREST error messages that mention HTML (e.g., "invalid html entity"). A more specific check for actual HTML content like <!doctype or <html would reduce false positives while still catching Cloudflare error pages.

♻️ Suggested refinement
 function isCloudflareHtmlError(error: unknown): boolean {
   const msg = hasMessage(error) ? error.message : undefined;
   if (typeof msg !== 'string') {
     return false;
   }
   const checkableMsg = msg.trim().toLowerCase();
-  return checkableMsg.includes('html') || checkableMsg.includes('internal server error');
+  return checkableMsg.includes('<html') || checkableMsg.includes('<!doctype') || checkableMsg.includes('internal server error');
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@libs/core/src/modules/supabase/supabase.errors.ts` around lines 24 - 31,
Refine isCloudflareHtmlError so it no longer treats any message containing
“html” as a Cloudflare page; detect actual HTML markers such as “<!doctype” or
“<html” after normalization, while preserving the existing “internal server
error” detection.
libs/core/src/types/supabase-types-adjusted.ts (1)

16-19: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Consider using a tuple type for GeoJSON Point coordinates.

coordinates: number[] allows arrays of any length. The GeoJSON Point spec requires exactly 2 (or 3) coordinate values. A tuple type [number, number] would be more precise and catch invalid coordinate arrays at compile time.

♻️ Suggested type refinement
         location_geom: {
           type: 'Point';
-          coordinates: number[];
+          coordinates: [number, number];
         } | null;

And similarly for poles:

           location_geom: {
             type: 'Point';
-            coordinates: number[];
+            coordinates: [number, number];
           };

Also applies to: 24-27

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@libs/core/src/types/supabase-types-adjusted.ts` around lines 16 - 19, Refine
the GeoJSON Point coordinate types in the location_geom and poles definitions
from number[] to a tuple enforcing two or three numeric coordinates, such as a
union of [number, number] and [number, number, number].
apps/api/test/unit/helpers/local-supabase-env.spec.ts (1)

10-15: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Test only covers both-missing case, not individual missing vars.

The test name says "when SUPABASE_URL or SUPABASE_SECRET_KEY is missing" but only deletes both. The helper uses if (!url || !secretKey), so each branch should be tested independently to verify the || logic.

🧪 Suggested additional test cases
   it('returns null when SUPABASE_URL or SUPABASE_SECRET_KEY is missing', () => {
     delete process.env.SUPABASE_URL;
     delete process.env.SUPABASE_SECRET_KEY;

     expect(getLocalSupabaseEnv()).toBeNull();
   });

+  it('returns null when only SUPABASE_URL is missing', () => {
+    process.env.SUPABASE_URL = '';
+    process.env.SUPABASE_SECRET_KEY = 'test-secret';
+
+    expect(getLocalSupabaseEnv()).toBeNull();
+  });
+
+  it('returns null when only SUPABASE_SECRET_KEY is missing', () => {
+    process.env.SUPABASE_URL = 'http://127.0.0.1:54321';
+    process.env.SUPABASE_SECRET_KEY = '';
+
+    expect(getLocalSupabaseEnv()).toBeNull();
+  });
+
   it('returns trimmed url and secret when both are set', () => {
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/api/test/unit/helpers/local-supabase-env.spec.ts` around lines 10 - 15,
Expand the test for getLocalSupabaseEnv to cover each missing-variable case
independently: retain the both-missing scenario, then add cases where only
SUPABASE_URL is deleted and only SUPABASE_SECRET_KEY is deleted, asserting null
each time. Ensure the other environment variable is set so each test validates
one side of the helper’s OR condition.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@apps/api/.env.example`:
- Around line 19-20: Update the JWT environment-variable comments in the example
configuration to match SupabaseStrategy: document SUPABASE_JWT_SECRET as
applicable only when SUPABASE_JWKS_URL is unset, and state that both variables
may be present with JWKS taking precedence; do not describe fallback on JWKS
endpoint unavailability.

In `@apps/api/src/main.ts`:
- Line 14: Update the CORS configuration at app.enableCors() to use an explicit
allowlist of origins sourced from the application’s existing config or
environment settings, rather than the permissive default. Preserve the API’s
current CORS behavior for approved origins and reject unconfigured origins.

In `@apps/api/src/modules/auth/api-key.strategy.ts`:
- Around line 53-55: The API-key authentication path must not fall through to
the privileged service_role client. Update the strategy and affected handler
flow around the API-key authentication logic to reject user-scoped database
operations unless a tenant-scoped client or explicit authorization boundary is
available; preserve service_role access only for explicitly authorized
non-user-scoped operations.
- Around line 56-64: Update the principal construction in the authentication
strategy to validate account.email, account.full_name, and account.supabase_id
before returning the AuthenticatedUser object. Reject authentication when any
required claim is missing instead of coercing it to an empty string, while
preserving the existing successful return path for complete account records.

In `@apps/api/src/modules/auth/supabase.strategy.ts`:
- Around line 96-99: Update the organization_id validation in the authentication
strategy to require a finite positive value, matching the existing account_id
check. Reject zero and negative organization IDs with the same
UnauthorizedException path while preserving valid organization claims.

In `@apps/api/src/modules/user-admin/user-admin.service.ts`:
- Around line 65-76: Update inviteMember and every related user-admin service
method to perform authorization before obtaining or using the service-role
client: require an authorized administrative role, validate that the target
organization belongs to author.organization_id, and permit cross-tenant targets
only for the explicit platform role. Do not rely on author.validate() alone;
apply these checks to all organization, grid, and entity IDs accepted by the
admin operations.
- Around line 111-120: Update every audit insert flow in the user-admin service,
including the shown call and the referenced locations, so rejected audit writes
are handled rather than detached with void. Prefer awaiting the Supabase insert
and response handling within the surrounding async operation; if the audit
remains best-effort, explicitly catch and log failures while preserving the
primary operation’s behavior.
- Around line 211-213: Update the user-creation methods containing the
fire-and-forget updateUserById calls to await the app_metadata persistence
before returning. Handle and propagate any rejected update, and validate the
update result so account, organization, and grid claims are persisted before the
new user can receive tokens; apply the same change to both create flows.
- Around line 78-109: Update the user-creation workflows surrounding the Auth
calls and database writes, including the analogous member, agent, customer,
restore, and delete flows, to be resumable and idempotent. Track completed
mutations and compensate them when later steps fail, including removing or
disabling orphaned Auth users and reverting stale metadata or database rows;
ensure retries safely reuse or reconcile existing records instead of duplicating
them.

In
`@docs/architecture/004-open-source-architecture-and-capability-modularization.md`:
- Around line 157-160: Move the ADR-005 entry out of the “Out of Scope /
Deferred to Follow-up ADRs” section, or rename that section to “Follow-up ADRs”
so the accepted status is consistent with the document’s roadmap.

In `@docs/architecture/005-inter-host-communication.md`:
- Line 225: Remove the unmatched closing parenthesis after the final bullet in
the Related section, leaving the section properly terminated without altering
its content.

In `@docs/architecture/014-api-key-and-machine-credentials.md`:
- Around line 99-110: Before adding or exposing additional machine routes,
update the API-key authentication flow around ApiKeyStrategy and
AuthenticatedUser.supabase to enforce an explicit route allowlist and scopes,
then attach a principal-specific RLS-bound Supabase client from the JWT claims.
Ensure machine handlers use that client instead of service_role for data access,
retaining the admin client only for genuinely privileged Auth Admin operations.

In `@legacy/apps/tiamat/src/modules/app.module.ts`:
- Line 4: Update the app module imports and module configuration to restore
GlobalHttpModule and GlobalSupabaseModule for GridsModule, ensuring the
HttpService and SupabaseService dependencies used by GridsService are available
during Nest bootstrap; do not remove or migrate the existing service injections.

In `@libs/core/src/modules/supabase/supabase.module.ts`:
- Around line 45-54: Rename the HANDLE_RESPONSE_UNTYPED handler to a camelCase
name consistent with handleResponse and handleSingle, and update every reference
to it throughout the module without changing its behavior.

---

Outside diff comments:
In `@docs/plans/002-oss-migration/002d-platform-core-import.md`:
- Around line 299-309: Update the “Done when” criterion in the 002d migration
plan to explicitly require running `pnpm exec supabase db reset`, while
preserving the requirement for a coherent Foundation dataset and usable test
user.

---

Nitpick comments:
In `@apps/api/src/main.ts`:
- Around line 15-20: Update the global ValidationPipe configuration in main.ts
to enable whitelist: true, ensuring unknown request properties are stripped
while preserving the existing transformation settings.

In `@apps/api/test/unit/helpers/local-supabase-env.spec.ts`:
- Around line 10-15: Expand the test for getLocalSupabaseEnv to cover each
missing-variable case independently: retain the both-missing scenario, then add
cases where only SUPABASE_URL is deleted and only SUPABASE_SECRET_KEY is
deleted, asserting null each time. Ensure the other environment variable is set
so each test validates one side of the helper’s OR condition.

In `@libs/core/src/modules/supabase/supabase.errors.ts`:
- Around line 24-31: Refine isCloudflareHtmlError so it no longer treats any
message containing “html” as a Cloudflare page; detect actual HTML markers such
as “<!doctype” or “<html” after normalization, while preserving the existing
“internal server error” detection.

In `@libs/core/src/types/supabase-types-adjusted.ts`:
- Around line 16-19: Refine the GeoJSON Point coordinate types in the
location_geom and poles definitions from number[] to a tuple enforcing two or
three numeric coordinates, such as a union of [number, number] and [number,
number, number].
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0f5ffa9a-c37c-4d87-8f2e-263555fb284f

📥 Commits

Reviewing files that changed from the base of the PR and between 8ada9ee and 9ba7681.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (120)
  • .env.example
  • .gitignore
  • .nxignore
  • .vscode/extensions.json
  • .vscode/settings.json
  • AGENTS.md
  • README.md
  • apps/api/.env.example
  • apps/api/http/.httpyac.js
  • apps/api/http/README.md
  • apps/api/http/login.http
  • apps/api/http/me.http
  • apps/api/http/user-admin.http
  • apps/api/jest.config.cts
  • apps/api/jest.e2e.config.cts
  • apps/api/jest.integration.config.cts
  • apps/api/jest.shared.cjs
  • apps/api/package.json
  • apps/api/src/main.ts
  • apps/api/src/modules/app.module.ts
  • apps/api/src/modules/auth/api-key.strategy.ts
  • apps/api/src/modules/auth/auth.controller.ts
  • apps/api/src/modules/auth/auth.module.ts
  • apps/api/src/modules/auth/authenticated-user.ts
  • apps/api/src/modules/auth/authentication.guard.ts
  • apps/api/src/modules/auth/supabase.strategy.ts
  • apps/api/src/modules/health/health.service.ts
  • apps/api/src/modules/user-admin/dto/create-agent.dto.ts
  • apps/api/src/modules/user-admin/dto/invite-member.dto.ts
  • apps/api/src/modules/user-admin/dto/update-agent.dto.ts
  • apps/api/src/modules/user-admin/dto/update-customer.dto.ts
  • apps/api/src/modules/user-admin/dto/update-member.dto.ts
  • apps/api/src/modules/user-admin/user-admin.controller.ts
  • apps/api/src/modules/user-admin/user-admin.module.ts
  • apps/api/src/modules/user-admin/user-admin.service.ts
  • apps/api/test/e2e/auth.e2e.spec.ts
  • apps/api/test/helpers/local-supabase-env.ts
  • apps/api/test/integration/auth/api-key.strategy.integration.spec.ts
  • apps/api/test/unit/helpers/local-supabase-env.spec.ts
  • apps/api/tsconfig.app.json
  • apps/api/tsconfig.spec.json
  • apps/worker/.env.example
  • apps/worker/src/main.ts
  • apps/worker/src/modules/app.module.ts
  • apps/worker/tsconfig.app.json
  • apps/worker/tsconfig.spec.json
  • config.default.json
  • config.example.json
  • docs/architecture/004-open-source-architecture-and-capability-modularization.md
  • docs/architecture/005-inter-host-communication.md
  • docs/architecture/007-configuration-and-wiring-mechanism.md
  • docs/architecture/012-company-cutover-strategy.md
  • docs/architecture/014-api-key-and-machine-credentials.md
  • docs/deployment/supabase.md
  • docs/plans/002-oss-migration.md
  • docs/plans/002-oss-migration/002b-schema-deviation-register.md
  • docs/plans/002-oss-migration/002d-platform-core-import.md
  • docs/plans/002-oss-migration/internationalization-and-debrand-register.md
  • eslint.config.mjs
  • legacy/apps/tiamat/src/modules/accounts/accounts.module.ts
  • legacy/apps/tiamat/src/modules/api-keys/api-keys.module.ts
  • legacy/apps/tiamat/src/modules/app.module.ts
  • legacy/apps/tiamat/src/modules/auth/api-key.strategy.ts
  • legacy/apps/tiamat/src/modules/auth/auth.controller.ts
  • legacy/apps/tiamat/src/modules/auth/auth.module.ts
  • legacy/apps/tiamat/src/modules/auth/auth.service.ts
  • legacy/apps/tiamat/src/modules/auth/authentication.guard.ts
  • legacy/apps/tiamat/src/modules/auth/nxt-supabase-user.ts
  • legacy/apps/tiamat/src/modules/auth/supabase.strategy.ts
  • legacy/apps/tiamat/src/modules/grids/grids.controller.ts
  • legacy/apps/tiamat/src/modules/grids/grids.module.ts
  • legacy/apps/tiamat/src/modules/grids/grids.service.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.controller.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.module.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.service.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/create-agent.dto.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/update-agent.dto.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.module.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.service.ts
  • legacy/libs/core/src/index.ts
  • legacy/libs/core/src/modules/accounts/accounts.service.ts
  • legacy/libs/core/src/modules/accounts/entities/account.entity.ts
  • legacy/libs/core/src/modules/api-keys/api-keys.service.ts
  • legacy/libs/core/src/modules/api-keys/entities/api-key.entity.ts
  • legacy/libs/core/src/modules/grids/grids.service.ts
  • legacy/libs/core/src/modules/logger-module.ts
  • legacy/libs/core/src/modules/members/entities/member.entity.ts
  • legacy/libs/core/src/modules/organizations/entities/organization.entity.ts
  • legacy/libs/core/src/modules/supabase.module.ts
  • libs/core/README.md
  • libs/core/jest.config.cts
  • libs/core/package.json
  • libs/core/src/config/index.ts
  • libs/core/src/config/loader.ts
  • libs/core/src/config/require-env.ts
  • libs/core/src/config/schema.ts
  • libs/core/src/constants.ts
  • libs/core/src/index.ts
  • libs/core/src/modules/customers/dto/create-customer.dto.ts
  • libs/core/src/modules/demo/demo-modules.spec.ts
  • libs/core/src/modules/demo/demo-modules.ts
  • libs/core/src/modules/demo/demo.module.ts
  • libs/core/src/modules/demo/demo.schema.ts
  • libs/core/src/modules/demo/demo.service.ts
  • libs/core/src/modules/global-http-module.ts
  • libs/core/src/modules/logger/logger.module.ts
  • libs/core/src/modules/logger/logger.options.ts
  • libs/core/src/modules/platform/package-info.ts
  • libs/core/src/modules/supabase/supabase.errors.ts
  • libs/core/src/modules/supabase/supabase.module.ts
  • libs/core/src/types/supabase-types-adjusted.ts
  • libs/core/test/unit/config/__fixtures__/from-default.config.json
  • libs/core/test/unit/config/__fixtures__/from-path.config.json
  • libs/core/test/unit/config/__fixtures__/invalid-schema-version.config.json
  • libs/core/test/unit/config/index.spec.ts
  • libs/core/test/unit/config/loader.spec.ts
  • libs/core/tsconfig.spec.json
  • supabase/migrations/20260710120000_init.sql
  • supabase/seed.sql
  • tsconfig.base.json
💤 Files with no reviewable changes (37)
  • legacy/apps/tiamat/src/modules/user-admin/dto/create-agent.dto.ts
  • legacy/apps/tiamat/src/modules/accounts/accounts.module.ts
  • config.default.json
  • legacy/apps/tiamat/src/modules/organizations/organizations.controller.ts
  • legacy/libs/core/src/modules/accounts/accounts.service.ts
  • libs/core/src/modules/demo/demo-modules.spec.ts
  • legacy/apps/tiamat/src/modules/auth/auth.controller.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.module.ts
  • libs/core/src/modules/platform/package-info.ts
  • legacy/apps/tiamat/src/modules/api-keys/api-keys.module.ts
  • libs/core/src/modules/demo/demo.module.ts
  • libs/core/test/unit/config/fixtures/invalid-schema-version.config.json
  • legacy/apps/tiamat/src/modules/auth/auth.service.ts
  • legacy/apps/tiamat/src/modules/auth/supabase.strategy.ts
  • legacy/libs/core/src/modules/members/entities/member.entity.ts
  • legacy/apps/tiamat/src/modules/auth/api-key.strategy.ts
  • apps/worker/tsconfig.app.json
  • legacy/libs/core/src/index.ts
  • legacy/libs/core/src/modules/api-keys/entities/api-key.entity.ts
  • legacy/libs/core/src/modules/logger-module.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.service.ts
  • legacy/libs/core/src/modules/api-keys/api-keys.service.ts
  • legacy/apps/tiamat/src/modules/auth/authentication.guard.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.service.ts
  • legacy/apps/tiamat/src/modules/auth/auth.module.ts
  • libs/core/src/modules/demo/demo.service.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/update-agent.dto.ts
  • libs/core/src/modules/demo/demo.schema.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.module.ts
  • libs/core/test/unit/config/fixtures/from-default.config.json
  • apps/api/tsconfig.app.json
  • libs/core/src/modules/demo/demo-modules.ts
  • libs/core/test/unit/config/fixtures/from-path.config.json
  • legacy/apps/tiamat/src/modules/auth/nxt-supabase-user.ts
  • legacy/libs/core/src/modules/supabase.module.ts
  • legacy/libs/core/src/modules/accounts/entities/account.entity.ts
  • legacy/libs/core/src/modules/organizations/entities/organization.entity.ts

Comment thread apps/api/.env.example Outdated
Comment thread apps/api/src/main.ts
Comment thread apps/api/src/modules/auth/api-key.strategy.ts
Comment thread apps/api/src/modules/auth/api-key.strategy.ts
Comment thread apps/api/src/modules/auth/supabase.strategy.ts
Comment thread docs/architecture/005-inter-host-communication.md Outdated
Comment thread docs/architecture/014-api-key-and-machine-credentials.md
Comment thread legacy/apps/tiamat/src/modules/app.module.ts
Comment thread libs/core/src/modules/supabase/supabase.module.ts
@bobbybol

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 18, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@bobbybol

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 18, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 8

♻️ Duplicate comments (1)
legacy/apps/tiamat/src/modules/app.module.ts (1)

4-4: 🩺 Stability & Availability | 🔴 Critical

Restore the providers required by the retained GridsModule.

GridsModule is still registered on Line [67], but its GridsService constructor still injects HttpService and SupabaseService in legacy/apps/tiamat/src/modules/grids/grids.service.ts (constructor block, Lines 30-39). Removing GlobalHttpModule and GlobalSupabaseModule leaves Nest unable to resolve those tokens during bootstrap. Restore both modules or remove/migrate GridsModule and its remaining consumers together.

Proposed fix
-import { CoreTypeOrmModule, CorePgModule } from '`@core`';
+import {
+  CoreTypeOrmModule,
+  CorePgModule,
+  GlobalHttpModule,
+  GlobalSupabaseModule,
+} from '`@core`';

   CorePgModule,
+  GlobalHttpModule,
+  GlobalSupabaseModule,

Also applies to: 53-53

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@legacy/apps/tiamat/src/modules/app.module.ts` at line 4, Restore
GlobalHttpModule and GlobalSupabaseModule in the module imports/providers
required by the retained GridsModule, so GridsService can resolve HttpService
and SupabaseService during bootstrap. Alternatively, remove or migrate
GridsModule and all remaining consumers together, but do not leave the existing
GridsModule registration without its dependencies.
🧹 Nitpick comments (2)
libs/core/src/modules/logger/logger.options.ts (1)

70-77: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

Validate LOG_LEVEL before passing it to Pino.

Any non-empty string is currently accepted, so a typo such as LOG_LEVEL=debgu can fail logger initialization when this deferred configuration is restored. Normalize against the configured logger levels or fall back to info.

Suggested guard
-  const level = process.env.LOG_LEVEL?.trim() || DEFAULT_LOG_LEVEL;
+  const configuredLevel = process.env.LOG_LEVEL?.trim().toLowerCase();
+  const allowedLevels = new Set([ 'trace', 'debug', 'info', 'warn', 'error', 'fatal', 'silent' ]);
+  const level =
+    configuredLevel && allowedLevels.has(configuredLevel)
+      ? configuredLevel
+      : DEFAULT_LOG_LEVEL;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@libs/core/src/modules/logger/logger.options.ts` around lines 70 - 77, Update
buildPinoHttpOptions to validate the trimmed LOG_LEVEL against the configured
Pino logger levels before assigning level; preserve valid configured values and
fall back to the info/default level for empty or unrecognized values, so invalid
environment input cannot reach Pino.
apps/api/jest.e2e.config.cts (1)

3-8: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Do not silently pass dedicated test targets with zero collected tests.

passWithNoTests: true can hide broken globs or accidental test exclusion. If environment gating is intentional for local runs, keep that behavior in a separate optional target and make CI’s integration/e2e targets fail when no tests are collected.

  • apps/api/jest.e2e.config.cts#L3-L8: make the CI-facing e2e configuration strict, or document the optional-only target.
  • apps/api/jest.integration.config.cts#L3-L8: apply the same policy to integration tests.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/api/jest.e2e.config.cts` around lines 3 - 8, Make the CI-facing Jest
configurations strict by removing passWithNoTests: true from
apps/api/jest.e2e.config.cts and apps/api/jest.integration.config.cts; if local
environment-gated runs require allowing zero tests, move that behavior to
separately named optional targets and document the distinction.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/architecture/005-inter-host-communication.md`:
- Around line 16-19: Update the roadmap-status paragraph in ADR-005’s context
section to reflect that ADR-005 was accepted on July 17, 2026. Reword the
reference to Production Monitoring import (002e) to identify it as the first
capability import applying the accepted policy, rather than stating that the ADR
remains open until 002e.

In `@docs/plans/002-oss-migration/002d-platform-core-import.md`:
- Around line 294-297: Update the status entries for Task 5 and Task 6 in the
migration plan to record their actual sign-off status and date, removing the
stale “awaiting sign-off” wording. If either task is not signed off, revise the
plan header, Task 11, and exit bar so the overall completion state remains
pending.
- Line 114: Update the Foundation scope row in the migration plan to remove the
“new pino logging” claim and describe the shipped logging implementation as Nest
Logger plus the no-op GlobalLoggerModule, while retaining the Supabase client
and HTTP entries.

In `@legacy/apps/tiamat/src/modules/app.module.ts`:
- Around line 13-14: Update the Task 11 comment in app.module.ts to remove the
inaccurate “controller gone” claim and accurately state that GridsModule and its
GridsController remain, with only the GET /grids/:id route removed.

In `@libs/core/src/modules/supabase/supabase.errors.ts`:
- Around line 55-56: Remove the raw console.info(error) call from the Supabase
error handling in supabase.errors.ts. Replace it with the configured logger and
a sanitized summary only, avoiding complete upstream error objects or sensitive
details.
- Around line 63-67: Update the error handling around resolveErrorMessage so its
detailed result is used only for server-side logger.error diagnostics. Pass a
stable, generic public message to HttpException while preserving the resolved
status code and existing logging context.
- Around line 24-30: The isCloudflareHtmlError predicate must require a 5xx
response status before classifying an error as a Cloudflare failure. Update it
to read the supplied response status and actual response body, returning false
for non-5xx statuses such as 401, and only match the existing Cloudflare
indicators within that body before the caller overrides the status.
- Around line 35-45: Update resolveErrorMessage so its final serialization path
always returns a string: safely attempt JSON.stringify(error), handle
serialization failures or an undefined result, and fall back to String(error).
Preserve the existing handling for string, Error, and message-bearing values.

---

Duplicate comments:
In `@legacy/apps/tiamat/src/modules/app.module.ts`:
- Line 4: Restore GlobalHttpModule and GlobalSupabaseModule in the module
imports/providers required by the retained GridsModule, so GridsService can
resolve HttpService and SupabaseService during bootstrap. Alternatively, remove
or migrate GridsModule and all remaining consumers together, but do not leave
the existing GridsModule registration without its dependencies.

---

Nitpick comments:
In `@apps/api/jest.e2e.config.cts`:
- Around line 3-8: Make the CI-facing Jest configurations strict by removing
passWithNoTests: true from apps/api/jest.e2e.config.cts and
apps/api/jest.integration.config.cts; if local environment-gated runs require
allowing zero tests, move that behavior to separately named optional targets and
document the distinction.

In `@libs/core/src/modules/logger/logger.options.ts`:
- Around line 70-77: Update buildPinoHttpOptions to validate the trimmed
LOG_LEVEL against the configured Pino logger levels before assigning level;
preserve valid configured values and fall back to the info/default level for
empty or unrecognized values, so invalid environment input cannot reach Pino.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 76439faa-9f89-4126-bfac-090836603e5a

📥 Commits

Reviewing files that changed from the base of the PR and between 8ada9ee and 0ef2a31.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (122)
  • .coderabbit.yaml
  • .env.example
  • .gitignore
  • .nxignore
  • .vscode/extensions.json
  • .vscode/settings.json
  • AGENTS.md
  • README.md
  • apps/api/.env.example
  • apps/api/http/.httpyac.js
  • apps/api/http/README.md
  • apps/api/http/login.http
  • apps/api/http/me.http
  • apps/api/http/user-admin.http
  • apps/api/jest.config.cts
  • apps/api/jest.e2e.config.cts
  • apps/api/jest.integration.config.cts
  • apps/api/jest.shared.cjs
  • apps/api/package.json
  • apps/api/src/main.ts
  • apps/api/src/modules/app.module.ts
  • apps/api/src/modules/auth/api-key.strategy.ts
  • apps/api/src/modules/auth/auth.controller.ts
  • apps/api/src/modules/auth/auth.module.ts
  • apps/api/src/modules/auth/authenticated-user.ts
  • apps/api/src/modules/auth/authentication.guard.ts
  • apps/api/src/modules/auth/supabase.strategy.ts
  • apps/api/src/modules/health/health.service.ts
  • apps/api/src/modules/user-admin/dto/create-agent.dto.ts
  • apps/api/src/modules/user-admin/dto/invite-member.dto.ts
  • apps/api/src/modules/user-admin/dto/update-agent.dto.ts
  • apps/api/src/modules/user-admin/dto/update-customer.dto.ts
  • apps/api/src/modules/user-admin/dto/update-member.dto.ts
  • apps/api/src/modules/user-admin/user-admin.controller.ts
  • apps/api/src/modules/user-admin/user-admin.module.ts
  • apps/api/src/modules/user-admin/user-admin.service.ts
  • apps/api/test/e2e/auth.e2e.spec.ts
  • apps/api/test/helpers/local-supabase-env.ts
  • apps/api/test/integration/auth/api-key.strategy.integration.spec.ts
  • apps/api/test/unit/helpers/local-supabase-env.spec.ts
  • apps/api/tsconfig.app.json
  • apps/api/tsconfig.spec.json
  • apps/worker/.env.example
  • apps/worker/src/main.ts
  • apps/worker/src/modules/app.module.ts
  • apps/worker/tsconfig.app.json
  • apps/worker/tsconfig.spec.json
  • config.default.json
  • config.example.json
  • docs/architecture/004-open-source-architecture-and-capability-modularization.md
  • docs/architecture/005-inter-host-communication.md
  • docs/architecture/007-configuration-and-wiring-mechanism.md
  • docs/architecture/012-company-cutover-strategy.md
  • docs/architecture/014-api-key-and-machine-credentials.md
  • docs/deployment/supabase.md
  • docs/plans/002-oss-migration.md
  • docs/plans/002-oss-migration/002b-schema-deviation-register.md
  • docs/plans/002-oss-migration/002d-platform-core-import.md
  • docs/plans/002-oss-migration/internationalization-and-debrand-register.md
  • eslint.config.mjs
  • legacy/apps/tiamat/src/modules/accounts/accounts.module.ts
  • legacy/apps/tiamat/src/modules/api-keys/api-keys.module.ts
  • legacy/apps/tiamat/src/modules/app.module.ts
  • legacy/apps/tiamat/src/modules/auth/api-key.strategy.ts
  • legacy/apps/tiamat/src/modules/auth/auth.controller.ts
  • legacy/apps/tiamat/src/modules/auth/auth.module.ts
  • legacy/apps/tiamat/src/modules/auth/auth.service.ts
  • legacy/apps/tiamat/src/modules/auth/authentication.guard.ts
  • legacy/apps/tiamat/src/modules/auth/nxt-supabase-user.ts
  • legacy/apps/tiamat/src/modules/auth/supabase.strategy.ts
  • legacy/apps/tiamat/src/modules/grids/grids.controller.ts
  • legacy/apps/tiamat/src/modules/grids/grids.module.ts
  • legacy/apps/tiamat/src/modules/grids/grids.service.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.controller.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.module.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.service.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/create-agent.dto.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/update-agent.dto.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.module.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.service.ts
  • legacy/libs/core/src/index.ts
  • legacy/libs/core/src/modules/accounts/accounts.service.ts
  • legacy/libs/core/src/modules/accounts/entities/account.entity.ts
  • legacy/libs/core/src/modules/api-keys/api-keys.service.ts
  • legacy/libs/core/src/modules/api-keys/entities/api-key.entity.ts
  • legacy/libs/core/src/modules/grids/grids.service.ts
  • legacy/libs/core/src/modules/logger-module.ts
  • legacy/libs/core/src/modules/members/entities/member.entity.ts
  • legacy/libs/core/src/modules/organizations/entities/organization.entity.ts
  • legacy/libs/core/src/modules/supabase.module.ts
  • libs/core/README.md
  • libs/core/jest.config.cts
  • libs/core/package.json
  • libs/core/src/config/index.ts
  • libs/core/src/config/loader.ts
  • libs/core/src/config/require-env.ts
  • libs/core/src/config/schema.ts
  • libs/core/src/constants.ts
  • libs/core/src/index.ts
  • libs/core/src/modules/customers/dto/create-customer.dto.ts
  • libs/core/src/modules/demo/demo-modules.spec.ts
  • libs/core/src/modules/demo/demo-modules.ts
  • libs/core/src/modules/demo/demo.module.ts
  • libs/core/src/modules/demo/demo.schema.ts
  • libs/core/src/modules/demo/demo.service.ts
  • libs/core/src/modules/global-http-module.ts
  • libs/core/src/modules/logger/logger.module.ts
  • libs/core/src/modules/logger/logger.options.ts
  • libs/core/src/modules/platform/package-info.ts
  • libs/core/src/modules/supabase/supabase.errors.ts
  • libs/core/src/modules/supabase/supabase.module.ts
  • libs/core/src/types/supabase-types-adjusted.ts
  • libs/core/src/types/supabase-types.ts
  • libs/core/test/unit/config/__fixtures__/from-default.config.json
  • libs/core/test/unit/config/__fixtures__/from-path.config.json
  • libs/core/test/unit/config/__fixtures__/invalid-schema-version.config.json
  • libs/core/test/unit/config/index.spec.ts
  • libs/core/test/unit/config/loader.spec.ts
  • libs/core/tsconfig.spec.json
  • supabase/migrations/20260710120000_init.sql
  • supabase/seed.sql
  • tsconfig.base.json
💤 Files with no reviewable changes (37)
  • libs/core/src/modules/demo/demo.module.ts
  • libs/core/src/modules/demo/demo-modules.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.module.ts
  • apps/api/tsconfig.app.json
  • legacy/libs/core/src/modules/logger-module.ts
  • libs/core/src/modules/platform/package-info.ts
  • legacy/apps/tiamat/src/modules/auth/api-key.strategy.ts
  • legacy/apps/tiamat/src/modules/api-keys/api-keys.module.ts
  • libs/core/test/unit/config/fixtures/from-default.config.json
  • legacy/apps/tiamat/src/modules/user-admin/dto/create-agent.dto.ts
  • legacy/apps/tiamat/src/modules/auth/authentication.guard.ts
  • libs/core/test/unit/config/fixtures/from-path.config.json
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.module.ts
  • legacy/apps/tiamat/src/modules/user-admin/dto/update-agent.dto.ts
  • legacy/libs/core/src/modules/api-keys/entities/api-key.entity.ts
  • libs/core/src/modules/demo/demo.service.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.controller.ts
  • libs/core/src/modules/demo/demo-modules.spec.ts
  • config.default.json
  • legacy/libs/core/src/modules/organizations/entities/organization.entity.ts
  • legacy/apps/tiamat/src/modules/auth/auth.controller.ts
  • legacy/apps/tiamat/src/modules/organizations/organizations.service.ts
  • legacy/apps/tiamat/src/modules/accounts/accounts.module.ts
  • libs/core/src/modules/demo/demo.schema.ts
  • legacy/apps/tiamat/src/modules/auth/supabase.strategy.ts
  • legacy/libs/core/src/modules/members/entities/member.entity.ts
  • legacy/apps/tiamat/src/modules/auth/auth.service.ts
  • libs/core/test/unit/config/fixtures/invalid-schema-version.config.json
  • legacy/apps/tiamat/src/modules/auth/nxt-supabase-user.ts
  • legacy/libs/core/src/index.ts
  • legacy/apps/tiamat/src/modules/auth/auth.module.ts
  • legacy/libs/core/src/modules/accounts/entities/account.entity.ts
  • legacy/libs/core/src/modules/api-keys/api-keys.service.ts
  • legacy/libs/core/src/modules/supabase.module.ts
  • apps/worker/tsconfig.app.json
  • legacy/libs/core/src/modules/accounts/accounts.service.ts
  • legacy/apps/tiamat/src/modules/user-admin/user-admin.service.ts

Comment thread docs/architecture/005-inter-host-communication.md Outdated
Comment thread docs/plans/002-oss-migration/002d-platform-core-import.md
Comment thread docs/plans/002-oss-migration/002d-platform-core-import.md
Comment thread legacy/apps/tiamat/src/modules/app.module.ts
Comment thread libs/core/src/modules/supabase/supabase.errors.ts
Comment thread libs/core/src/modules/supabase/supabase.errors.ts
Comment thread libs/core/src/modules/supabase/supabase.errors.ts
Comment thread libs/core/src/modules/supabase/supabase.errors.ts
@bobbybol
bobbybol merged commit 282bf43 into oss-migration Jul 18, 2026
1 of 2 checks passed
@bobbybol
bobbybol deleted the chore/port-foundation-modules branch July 18, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant