Wire prisma-field-encryption AES-256-GCM extension on the shared Prisma client and annotate the four sensitive columns on Profile with @encrypted: - weightStartKg / weightCurrentKg / weightGoalKg (Decimal → String) - targetDate (DateTime @db.Date → String, ISO YYYY-MM-DD) Other Profile fields stay in clear text per ADR 0002 (age, gender, heightCm, activityLevel) — they're needed for plan generation and aggregate analytics, and are not strongly identifying on their own. apps/api profile.routes.ts: - serialize() now reads the columns as strings and parses them back to numbers for BMR/TDEE; targetDate is already an ISO string from the DB - the upsert stringifies numeric inputs and slices the date to YYYY-MM-DD Env wiring: - packages/db, apps/api, apps/web .env.example all document PRISMA_FIELD_ENCRYPTION_KEY (k1.aesgcm256.<base64url>) — must match across every process that hits the DB - key generation snippet documented inline Migration is intentionally NOT in this commit: needs to be created against a live Postgres instance and applied. The fields change Decimal/Date → text so prisma migrate dev will require a USING cast — see the follow-up commit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
36 lines
870 B
JSON
36 lines
870 B
JSON
{
|
|
"name": "@ketopath/db",
|
|
"version": "0.0.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"main": "./src/index.ts",
|
|
"types": "./src/index.ts",
|
|
"exports": {
|
|
".": "./src/index.ts"
|
|
},
|
|
"scripts": {
|
|
"typecheck": "tsc --noEmit",
|
|
"lint": "eslint src --max-warnings=0",
|
|
"db:generate": "prisma generate",
|
|
"db:migrate": "prisma migrate dev",
|
|
"db:migrate:deploy": "prisma migrate deploy",
|
|
"db:studio": "prisma studio",
|
|
"db:format": "prisma format",
|
|
"db:seed": "tsx prisma/seed.ts"
|
|
},
|
|
"dependencies": {
|
|
"@prisma/client": "^5.18.0",
|
|
"prisma-field-encryption": "^1.6.0"
|
|
},
|
|
"devDependencies": {
|
|
"@ketopath/eslint-config": "workspace:*",
|
|
"@ketopath/tsconfig": "workspace:*",
|
|
"prisma": "^5.18.0",
|
|
"tsx": "^4.16.2"
|
|
},
|
|
"prisma": {
|
|
"schema": "prisma/schema.prisma",
|
|
"seed": "tsx prisma/seed.ts"
|
|
}
|
|
}
|