amber-backend/pb_migrations
Claude 6be486b275 Fix auto-update file gating: mark releases.file protected (#16)
The E2E caught a real leak: a non-nsfw (even anonymous) account could download
an adult artifact. In PocketBase, file protection is a per-FIELD flag, not
derived from the collection view rule — the original migration left releases.file
unprotected, so its URL was public despite the gated read rules.

- Add protected:true to the file field (correct for fresh installs).
- 1786500001_releases_protect_file.js: alter the field on the already-deployed
  instance (applied migrations don't re-run, so the fix needs its own migration).
- Doc: correct the gating explanation (protection is the field flag; the file
  token grant then re-checks the view rule).

With this, a protected file needs a file token whose grant re-checks the view
rule, so a clean account is denied the adult artifact.
2026-07-20 11:48:07 +02:00
..
1752600000_init_accounts_schema.js feat: PocketBase backend + account/profile schema (epic #6, issue #9) 2026-07-15 20:22:45 +02:00
1784250000_sync_fields.js feat(schema): fields the client needs to sync watch state / watchlist / prefs 2026-07-17 16:20:38 +02:00
1785200000_addon_config.js feat(schema): encrypted addon-config collection (issue #20) 2026-07-18 02:14:40 +02:00
1786000000_device_auth.js feat(device-auth): codeless device sign-in backend (#12) 2026-07-19 14:36:15 +02:00
1786500000_releases.js Fix auto-update file gating: mark releases.file protected (#16) 2026-07-20 11:48:07 +02:00
1786500001_releases_protect_file.js Fix auto-update file gating: mark releases.file protected (#16) 2026-07-20 11:48:07 +02:00