Skip to content

Migrate HackKit to MikroORM and Core-owned Better Auth - #3

Draft
joshuasilva414 wants to merge 5 commits into
devfrom
codex/mikroorm-core-auth
Draft

joshuasilva414 wants to merge 5 commits into
devfrom
codex/mikroorm-core-auth

Conversation

@joshuasilva414

@joshuasilva414 joshuasilva414 commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Completes the migration started in the cloud checkpoint. Based on dev commit 1c1b0adbfef1bf46bf539fdd913a378e0533c3f7; the checkpoint is 19b01115d417e629525ff72585ab688fd1160891.

  • Use native MikroORM entities and EntityManager queries throughout Core and server plugins. Remove the generic database adapters, custom schema/type machinery, schema compiler, Drizzle package, and generated Drizzle schemas.
  • Move Better Auth construction and persistence into Core. Create auth identity and HackKit profile atomically, keep email authoritative in auth, and preserve profile edits across sessions.
  • Share connections while creating a fresh EntityManager and actor scope per request/action/job. Generated plugin actions resolve the current request when invoked. Server action actor IDs come exclusively from the authenticated session, with role-permission and team-ownership tests. Browser consumers use a separate Core client entrypoint and plain DTOs.
  • Make registration, membership, invite, RSVP, and related domain writes transactional. Serialize capacity checks with portable database locks. Atomically claim notifications and run external Discord delivery after committing domain changes.
  • Collect Core, auth, plugin, and application entities in one registry for runtime and migrations. Add explicit native migration generation, application, and seeding, with reviewed initial migration chains for PostgreSQL, MySQL, and SQLite/libSQL.
  • Update Next integration, Node/TypeScript versions, CI, setup documentation, and superseded ADRs.

Validation

All local checks used disposable databases. No deployed database was accessed.

  • 66 package tests passed: Core 35, CLI 6, Config 2, Next 14, Teams 6, Discord 2, Email notifications 1.
  • App migration/auth test passed; database workflow isolation passed.
  • All five real driver cases passed against committed migrations: SQLite, local libSQL, PostgreSQL 14.15, MySQL 8.4.11, and HTTP libSQL (sqld 0.24.32). Includes schema agreement, signup/session/profile behavior, JSON/date/boolean/null values, rollback, concurrent registration capacity, teams, uniqueness, and FK cleanup.
  • Package/app typechecks and the complete web dependency build passed.
  • Next production build passed. The production HTTP test passed with two users, isolated sessions, onboarding rendering, 401/403 permission responses, and anonymous redirects.
  • Frozen-lockfile installation, changed-file Prettier checks, and git diff --check passed.
  • Local execution used Node 24.2.0. The complete Web CI job passed on Node 22.17.0 at commit 6bae1c8, including all five database cases, all 66 package tests, typechecking, production build, and HTTP checks.

Review and release notes

  • Fresh databases only. This does not convert existing deployed data or user accounts. Migration application and seeding are explicit release steps, never startup behavior.
  • The repository-wide Prettier check has 102 unchanged files with existing formatting issues. Changed files pass. The existing whole-repository formatting gate can therefore remain red.
  • Next still emits dynamic-import warnings from MikroORM and the community adapter's CLI dependencies. Runtime entity discovery is explicit; the production HTTP checks pass.
  • Better Auth's upstream package still declares its unused Drizzle adapter dependency. HackKit does not import it; drizzle-orm is absent from the resolved dependency graph.
  • Hosted Turso authentication/TLS, real OAuth providers, and external email/Discord delivery were not exercised. The matrix uses a real local HTTP libSQL server.
  • Notification claims prevent competing workers from duplicating normal delivery; an interrupted worker can leave a processing intent requiring operational recovery.

See docs/adr/0013-mikroorm-and-core-auth.md and apps/web/README.md for architecture and commands.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants