* improvement(auth): bump better-auth to 1.6.23 and add trusted-proxy client IP resolution
* chore(billing): record checkout-scope mirror re-verification against @better-auth/stripe 1.6.23
* chore(deploy): expose AUTH_TRUSTED_PROXIES in docker-compose.prod and Helm chart
* chore(typescript): upgrade to TypeScript 7 (native Go compiler)
Bumps typescript to ^7.0.2 across every workspace package. Full
bun run type-check/lint/build/test all pass; apps/sim's type-check
(the one needing an 8GB heap bump) drops from ~55s to ~7s wall time.
Migration fixes required by TS7's stricter defaults:
- baseUrl removed: drop it from 5 tsconfigs (paths already resolved
relative to tsconfig dir, so behavior is unchanged) and prefix the
one bare (non-relative) paths entry each in apps/sim and
apps/realtime with './'
- moduleResolution=node10 removed: switch packages/cli and
packages/ts-sdk to "bundler", matching the rest of the monorepo
- types now defaults to [] instead of auto-including every @types/*
package: add "types": ["node"] to the shared base tsconfig (this
is fundamentally a Node monorepo, so this restores prior behavior
in one place instead of duplicating it per-package), add explicit
@types/node deps to packages that now rely on it transitively via
@sim/db/@sim/logger, and add "declare module '*.css'" to the two
packages with plain (non-module) CSS side-effect imports that
TS7's stricter checker now flags
- packages/logger's isomorphic `typeof window` check no longer needs
DOM lib in every consumer: replaced with `'window' in globalThis`
- packages/testing and apps/realtime's fetch/DOM mocks need DOM lib
where they're compiled, since they model the browser Fetch API
- the `typescript` npm package no longer exports the classic
Compiler API from its main entry (moved to unstable/ast subpaths);
apps/sim's Function-block route used it at runtime to strip
import statements from user code, so that one call site now uses
Microsoft's official transition package, @typescript/typescript6
- Next.js 16.2.6's own TypeScript-detection heuristic hardcodes a
path TS7 no longer ships, and its auto-install fallback assumes
npm/pnpm; added @typescript/native-preview as a devDependency to
apps/sim and apps/docs so Next detects a valid native compiler
instead of trying (and failing) to auto-install one
Not merging yet: TS 7.0.2 published today and is still inside this
repo's bunfig.toml minimumReleaseAge (7-day) supply-chain gate, so
`bun install` will fail for everyone until 2026-07-15. Opening this
now to get it through review; hold the actual merge until then.
* fix(typescript): address Greptile review findings on TS7 upgrade
- packages/logger: 'window' in globalThis treats a shim that leaves
globalThis.window explicitly undefined as browser-only, silently
dropping production server logs. Restore the original
typeof !== 'undefined' semantics via an inline cast instead, so it
stays correct without requiring DOM lib in every consumer.
- packages/ts-sdk, packages/cli: both are tsc-built, published as
Node ESM (package.json "type": "module" with an "exports" map).
"moduleResolution": "bundler" is too permissive for that target -
it accepts import patterns (e.g. extensionless relative imports)
that Node's actual ESM resolver rejects at runtime. Switch both to
"module"/"moduleResolution": "nodenext", the correct pairing for a
published Node ESM package. Verified real tsc builds (not just
--noEmit) still succeed for both.
* chore(bunfig): temporarily disable minimumReleaseAge gate for TS7 install
TS 7.0.2 published today, still inside the 7-day gate. Lowering to 0
to unblock this merge; will restore to 604800 in an immediate follow-up
commit right after merging.
Patches a high-severity stored XSS in the oidc-provider and mcp plugins
via javascript:/data: redirect_uri schemes. Also bumps @better-auth/sso
and @better-auth/stripe to matching 1.6.13 peers. Patch-only release
(1.6.11 -> 1.6.12 -> 1.6.13), no breaking changes in either changelog.
* chore(auth): upgrade better-auth 1.3.12 → 1.6.11
* chore(auth): address Greptile review — broaden change-email type + migration newline
* fix(auth): correct oneTimeToken expiresIn unit (minutes, not seconds)
Better-auth's oneTimeToken expiresIn is in minutes (multiplied by 60_000ms
internally). Sim's existing 24*60*60 evaluated to ~60 days of token
lifetime instead of the intended 24 hours. Tokens are one-time-use and
typically consumed within seconds of generation (Socket.IO handshake),
so this tightens an unused security window without affecting UX.
* improvement(repo): restructuring to make realtime image narrower scoped
* improvements
* chore(repo): rebase fixes and quality improvements for realtime split
Addresses merge-time issues and gaps from the realtime app split:
- Retarget stale vi.mock paths to @sim/workflow-persistence/subblocks
- Restore README branding, fix AGENTS.md script reference
- Restore TSDoc on workflow-persistence subblocks helpers
- Use toError() from @sim/utils/errors in save.ts
- Add vitest config + local mocks so @sim/audit tests run standalone
- Move socket.io-client to devDependencies in apps/realtime
- Add missing package COPY steps to docker/app.Dockerfile
- Add check:boundaries/check:realtime-prune scripts and wire into CI
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* refactor(security): consolidate crypto primitives into @sim/security
Move general-purpose crypto primitives out of apps/sim into the
@sim/security package so both apps/sim and apps/realtime can share them.
@sim/security exports (all pure, dependency-free):
./compare safeCompare (constant-time HMAC-wrapped equality)
./encryption encrypt/decrypt (AES-256-GCM, iv:cipher:tag format)
./hash sha256Hex
./tokens generateSecureToken (base64url)
Migrate apps/sim call sites to use these + @sim/utils helpers:
crypto.randomUUID() -> generateId() from @sim/utils/id
createHash('sha256').digest -> sha256Hex
timingSafeEqual on hashed hex -> safeCompare
new Promise(setTimeout) -> sleep from @sim/utils/helpers
No behavior change: encryption format, digest output, and token
length are preserved exactly.
* refactor(copilot): use toError in remaining otel/finalize sites
Replace the last two `error instanceof Error ? error : new Error(String(error))`
patterns with toError from @sim/utils/errors. Completes the sweep of clean
candidates — no behavior change.
* refactor(security): consolidate HMAC-SHA256 primitives into @sim/security
Adds hmacSha256Hex and hmacSha256Base64 to @sim/security/hmac and migrates
15 webhook providers plus 5 other hot paths (deployment token signing,
outbound webhook requests, workspace notification delivery, notification
test route, Shopify OAuth callback) off bare `createHmac` calls. Secret
parameter accepts `string | Buffer` to cover base64-decoded Svix-style
secrets (Resend) and MS Teams' HMAC scheme. AWS SigV4 signing in S3 and
Textract tools intentionally retains direct `createHmac` usage — its
multi-step key derivation chain doesn't fit a generic helper.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* chore(packages): post-audit test + packaging polish
- Add safeCompare unit tests (identity, length mismatch, hex-nibble diff).
- Add Buffer-secret cases to hmac tests to lock in Svix/MS-Teams contract.
- Declare `reactflow` as a peerDependency on @sim/workflow-types — only used for type imports.
- Add a barrel export to @sim/workflow-persistence for consumers that prefer package-level imports; subpath exports retained.
- Document the data-field invariant in load.ts for loop/parallel subflow patching.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* chore(realtime): address PR review feedback
- Remove redundant SOCKET_PORT=3002 env from Dockerfile runner stage
(env.PORT already defaults to 3002 via zod schema).
- Reorder PORT fallback so an explicitly-set SOCKET_PORT wins over
the schema default for PORT; keeps SOCKET_PORT functional as an
override instead of dead code.
- Add dedicated type-check CI step for @sim/realtime so TS errors
surface pre-deploy (the Dockerfile runs source TS via Bun and has
no implicit build-time type check).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* chore(realtime): remove unused SOCKET_PORT env var
SOCKET_PORT has lived in the socket server since the June 2025 refactor
but was never actually set in any deploy config — docker-compose.prod,
helm values/templates, .env.example, and docs all use PORT or the 3002
default exclusively. No self-hoster was ever pointed at SOCKET_PORT, so
removing it is safe.
Simplifies realtime port resolution to `env.PORT` (zod-validated with a
3002 default) and drops the orphaned sim-side schema entry.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Waleed Latif <walif6@gmail.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>