Skip to content

refactor(user-tokens): migrate from server - #2279

Open
shikanime wants to merge 1 commit into
mainfrom
shikanime/push-uotmotuknkvy
Open

shikanime wants to merge 1 commit into
mainfrom
shikanime/push-uotmotuknkvy

Conversation

@shikanime

@shikanime shikanime commented Jun 30, 2026 •

Copy link
Copy Markdown
Member

Issues liées

Refs #1889


Quel est le comportement actuel ?

Le module user-tokens (tokens d'accès utilisateur, génération, révocation, exposition) est servi par l'ancienne application Fastify apps/server, dans apps/server/src/resources/user/tokens/.

Quel est le nouveau comportement ?

Migration du module user-tokens vers apps/server-nestjs :

  • UserTokensController, UserTokensService, UserTokensModule.
  • user-tokens-queries.utils.ts : sélections Prisma typées.
  • user-tokens.utils.ts : génération de token (longueur, expiration 24h) et helpers de révocation.
  • Enregistrement du module dans main.module.ts.
  • Parité des contrats et codes HTTP contre apps/server/src/resources/user/tokens/.

Cette PR introduit-elle un breaking change ?

Non.

Autres informations

Rebasé sur main post-#2371 ; crypto.utils.ts et packages/shared/src/schemas/index.ts sont alignés sur la version fusionnée de #2371 (#2442 fermée sans fusion).

Statut bascule : ce module est porté et enregistré, non routé — aucune règle Nginx V1 ne pointe vers NestJS, le fallback legacy reste actif. La migration applicative ne constitue pas une bascule de trafic. La PR de bascule Nginx sera référencée ici dès son ouverture ; le registre #1889 sera mis à jour à la fusion.

Comment thread apps/server-nestjs/src/modules/admin-token/admin-token.service.ts Fixed
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.ts Fixed
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch from a9a75b7 to 64a5234 Compare June 30, 2026 10:02
Comment thread apps/server-nestjs/src/modules/admin-token/admin-token.service.ts Fixed
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.ts Fixed
Comment thread apps/server-nestjs/test/admin-token.e2e-spec.ts Fixed
Comment thread apps/server-nestjs/test/user-tokens.e2e-spec.ts Fixed
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch 10 times, most recently from b37e308 to 0331d48 Compare July 1, 2026 09:54
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch from 0331d48 to c53cb23 Compare July 1, 2026 10:19
Comment thread apps/server-nestjs/src/modules/gitlab/gitlab-client.service.ts Fixed
Comment thread apps/server-nestjs/src/modules/gitlab/gitlab.service.ts Fixed
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch 2 times, most recently from 09f3402 to b667443 Compare July 1, 2026 11:29
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch 2 times, most recently from 1b31261 to f16a730 Compare July 1, 2026 12:00
@shikanime shikanime changed the title refactor(server-nestjs): migrate project hook refactor(user-tokens): migrate from server Jul 1, 2026
@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch 4 times, most recently from cecad1b to 10b4770 Compare July 1, 2026 13:35
@github-actions github-actions Bot added the built label Jul 1, 2026
@github-actions

github-actions Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

🤖 Hey !

The security scan report for the current pull request is available here.

@shikanime
shikanime force-pushed the shikanime/push-uotmotuknkvy branch 2 times, most recently from 0eb3e93 to 43d21dc Compare July 1, 2026 13:56
@shikanime

This comment has been minimized.

@shikanime

This comment has been minimized.

Comment thread apps/server-nestjs/src/modules/admin-token/admin-token.service.ts
Comment thread apps/server-nestjs/src/modules/admin-token/admin-token.service.ts
Comment thread apps/server-nestjs/src/modules/project/project-testing.utils.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.module.ts
Comment thread apps/server-nestjs/test/admin-token.e2e-spec.ts
Comment thread apps/server-nestjs/test/user-tokens.e2e-spec.ts Outdated
Comment thread apps/server-nestjs/test/user-tokens.e2e-spec.ts Outdated
Comment thread apps/server-nestjs/vitest.config.ts Outdated
Comment thread packages/shared/src/schemas/index.ts
@shikanime

This comment has been minimized.

@shikanime

This comment has been minimized.

Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens-queries.utils.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.module.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.spec.ts Outdated
Comment thread apps/server-nestjs/test/user-tokens.e2e-spec.ts Outdated
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

A preview of the application is available at : https://console-pr-2279.dso.cpin-hp.numerique-interieur.fr

Please be patient, deployment may take a few minutes.

Comment thread apps/server-nestjs/src/utils/crypto.utils.ts Dismissed
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.controller.spec.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.spec.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.spec.ts Outdated
Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.service.spec.ts Outdated

@StephaneTrebel StephaneTrebel left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

La migration applicative suit le découpage code/cutover observé dans le dépôt. La divergence entre le contrat partagé et la validation NestJS doit toutefois être corrigée avant approbation.

Comment thread apps/server-nestjs/src/main.module.ts
Comment thread packages/shared/src/schemas/token.ts

@shikanime shikanime left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict : Commentaire

Migration user-tokens aboutie après six semaines d'itérations : hachage paritaire documenté, expiration validée par ExpirationDateSchema désormais réellement branchée sur le contrat de création, et le verifyTokenHash mort signalé en revue a disparu. Les demandes du relecteur sur le schéma de contrat et la bascule nginx sont résolues.

@StephaneTrebel StephaneTrebel left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 important — la branche n’est pas rebasée sur main : son merge-base est 5729b71, alors que main pointe sur b17a159 (elle est donc en retard d’un commit). Merci de rebaser, puis de relancer les contrôles ; après vérification, la migration user-tokens préserve l’authentification humaine, le bornage propriétaire de la suppression, le contrat partagé et l’absence d’exposition du hash.

@StephaneTrebel StephaneTrebel left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 important — le commit courant fa4c349 est intitulé « placeholder », ce qui ne respecte pas la convention Conventional Commits du dépôt. Merci de le renommer avec un intitulé conventionnel décrivant la migration (par exemple : refactor(user-tokens): migrate from server), puis de relancer la CI.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I241a395b8533631173b04f556b97bf666a6a6964

Signed-off-by: Shikanime Deva <22115108+shikanime@users.noreply.github.com>

@shikanime shikanime left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Revue du head 75cd904d — migration user-tokens propre. Le module NestJS (controller/service/module + specs colocalisées) reproduit la parité legacy : hash SHA-256 sans sel centralisé dans hashToken, suppression silencieuse 204 alignée sur deleteToken legacy (findUnique puis delete), imports de module minimaux (AuthModule, DatabaseModule, UserPermissionModule). Aucun cast as, aucune interaction Vault nouvelle, specs adaptées et non supprimées (le spec dso-token réutilise hashToken au lieu de re-bricoler createHash). Le remplacement de daysAgoFromNow local par daysAgo partagé est un bon réflexe anti-duplication. Verdict : aucun point bloquant ni important ; un seul nit de rédaction du corps de la PR.

Résumé des sévérités : 0 bloquant, 0 important, 1 nit.

Comment thread apps/server-nestjs/src/modules/user-tokens/user-tokens.module.ts
@cloud-pi-native-sonarqube

Copy link
Copy Markdown

@StephaneTrebel StephaneTrebel left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✨ La migration sépare bien les DTO du stockage, limite les opérations au propriétaire du token et préserve le hash compatible avec le serveur legacy. Le statut non routé est clairement documenté et la CI est verte.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

built refactor Refactor code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants