chore(deps): update astro to 7.2.1 and drop the unused session runtime #217
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!217
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/astro-7.2"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Updates Astro to 7.2.1 and adopts the one change in 7.2 that applies to this repo.
Versions
astro@astrojs/node@lucide/astroPinned exactly, matching the rest of
package.json.pnpm up --latestwould have written caretranges instead, so the pins were edited in place and installed.
Supersedes #209 and #210. Both target older releases than these: #209 wants astro 7.2.0 with
@astrojs/node11.1.0, and #210 wants@lucide/astro1.29.0. Close them in favour of this.Left out on purpose.
typescript6 to 7 andpako2 to 3 are majors and deserve their own changewith their own review.
cssnano,pg,eslintand thetypescript-eslintpackages have patchupdates that Renovate handles on its own schedule.
What 7.2 offers, and what applies here
Four changes shipped. One is relevant.
session: false, adopted. The portal has never used Astro's session API. Sessions here are asigned cookie of our own (
src/lib/auth/session.ts): HMAC-SHA256, verified in constant time, withthe payload shape checked after the MAC. No driver was configured for Astro's own store either, so
the runtime sat in the bundle serving nothing. Before 7.2 it shipped regardless.
Measured on the built output rather than assumed. Rebased onto
mainafter #216 landed,dist/servergoes from 2344 kB to 2304 kB, and the one file that referenced the session runtime is gone. The
saving is 40 kB either way; only the baseline moved when #216 merged.
Astro.sessionis now undefined, which is the honest signal. Reaching for it is a mistake in thiscodebase and should fail at the call site rather than hand back a store nothing else reads. It also
means slightly less code in the bundle that has any say in who is logged in.
Incremental static builds, skipped. Experimental, and routes opt in by returning a
cacheKeyfrom
getStaticPaths. There is nogetStaticPathsanywhere in this repo andoutputis"server",so there is nothing for it to attach to.
astro preview --background, skipped.pnpm previewrunsnode ./dist/server/entry.mjsdirectly, not
astro preview.Relative
logger.entrypoint, skipped. Needs a custom logger. There is none.Notes for review
The unmet eslint peer warning is not new.
eslint-plugin-jsx-a11ywants eslint 9 or lower and therepo runs 10.8.0. Verified identical before and after the upgrade, so nothing here touches it.
Version bumped 1.4.1 to 1.4.2. Patch, because a dependency upgrade and the removal of unused runtime
preserve meaning and add no content or components.
Verified
Re-run after the rebase onto
mainwith #216 in, so these cover astro 7.2.1 sitting alongside thenew
src/lib/env.ts, which readsimport.meta.env.pnpm test: 361 passed, unchanged from mainpnpm check: 0 errors, 0 warningspnpm eslint,pnpm stylelint,pnpm format:check,pnpm mdlint,pnpm lang-check: all cleanpnpm build: standalone server builds, sitemap and robots.txt generatedpnpm install --frozen-lockfile: lockfile coherent with #216's zod entry, supply-chain policies pass9fe087c2b191b771a174