Files
ketopath/packages/db/prisma/schema.prisma
T
lucianoandClaude Opus 4.7 9555022143 feat(db): encrypt Profile health fields at rest (ADR 0002)
Wire prisma-field-encryption AES-256-GCM extension on the shared Prisma
client and annotate the four sensitive columns on Profile with @encrypted:
- weightStartKg / weightCurrentKg / weightGoalKg (Decimal → String)
- targetDate (DateTime @db.Date → String, ISO YYYY-MM-DD)

Other Profile fields stay in clear text per ADR 0002 (age, gender,
heightCm, activityLevel) — they're needed for plan generation and
aggregate analytics, and are not strongly identifying on their own.

apps/api profile.routes.ts:
- serialize() now reads the columns as strings and parses them back to
  numbers for BMR/TDEE; targetDate is already an ISO string from the DB
- the upsert stringifies numeric inputs and slices the date to YYYY-MM-DD

Env wiring:
- packages/db, apps/api, apps/web .env.example all document
  PRISMA_FIELD_ENCRYPTION_KEY (k1.aesgcm256.<base64url>) — must match
  across every process that hits the DB
- key generation snippet documented inline

Migration is intentionally NOT in this commit: needs to be created against
a live Postgres instance and applied. The fields change Decimal/Date → text
so prisma migrate dev will require a USING cast — see the follow-up commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 15:03:24 +02:00

164 lines
4.7 KiB
Plaintext

// KetoPath — schema Prisma
// Schema iniziale: solo le 3 entità di base (User, Profile, Preferences).
// Le altre entità del PRD §8 (MealPlan, Recipe, WeightEntry, ecc.) verranno
// aggiunte in step successivi, allineate alle feature corrispondenti.
generator client {
provider = "prisma-client-js"
}
datasource db {
provider = "postgresql"
url = env("DATABASE_URL")
}
enum Role {
USER
COACH
}
enum Gender {
MALE
FEMALE
OTHER
}
enum ActivityLevel {
SEDENTARY
LIGHT
MODERATE
INTENSE
}
enum Phase {
INTENSIVE
TRANSITION
MAINTENANCE
}
enum CookingTime {
LOW
MEDIUM
HIGH
}
enum FastingProtocol {
FOURTEEN_TEN
SIXTEEN_EIGHT
EIGHTEEN_SIX
TWENTY_FOUR
ESE_24
FIVE_TWO
}
model User {
id String @id @default(cuid())
email String @unique
emailVerified Boolean @default(false) @map("email_verified")
name String?
image String?
role Role @default(USER)
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
profile Profile?
preferences Preferences?
sessions Session[]
accounts Account[]
@@map("users")
}
// Better Auth — sessione utente firmata.
model Session {
id String @id @default(cuid())
userId String @map("user_id")
token String @unique
expiresAt DateTime @map("expires_at")
ipAddress String? @map("ip_address")
userAgent String? @map("user_agent")
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
@@map("sessions")
}
// Better Auth — credenziali (email+password) o account OAuth.
// Per email+password il provider è 'credential' e la password (hash scrypt)
// è salvata nel campo `password`.
model Account {
id String @id @default(cuid())
userId String @map("user_id")
accountId String @map("account_id")
providerId String @map("provider_id")
accessToken String? @map("access_token")
refreshToken String? @map("refresh_token")
idToken String? @map("id_token")
accessTokenExpiresAt DateTime? @map("access_token_expires_at")
refreshTokenExpiresAt DateTime? @map("refresh_token_expires_at")
scope String?
password String?
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
@@unique([providerId, accountId])
@@map("accounts")
}
// Better Auth — token monouso (email verification, password reset, magic link).
model Verification {
id String @id @default(cuid())
identifier String
value String
expiresAt DateTime @map("expires_at")
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
@@unique([identifier, value])
@@map("verifications")
}
model Profile {
id String @id @default(cuid())
userId String @unique @map("user_id")
age Int
gender Gender
heightCm Int @map("height_cm")
/// @encrypted
weightStartKg String @map("weight_start_kg")
/// @encrypted
weightCurrentKg String @map("weight_current_kg")
/// @encrypted
weightGoalKg String @map("weight_goal_kg")
activityLevel ActivityLevel @map("activity_level")
/// @encrypted
targetDate String? @map("target_date")
currentPhase Phase @default(INTENSIVE) @map("current_phase")
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
@@map("profiles")
}
model Preferences {
id String @id @default(cuid())
userId String @unique @map("user_id")
exclusions String[] @default([])
cuisinePreferences String[] @default([]) @map("cuisine_preferences")
cookingTime CookingTime @default(MEDIUM) @map("cooking_time")
fastingProtocol FastingProtocol? @map("fasting_protocol")
notificationSettings Json @default("{}") @map("notification_settings")
createdAt DateTime @default(now()) @map("created_at")
updatedAt DateTime @updatedAt @map("updated_at")
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
@@map("preferences")
}