* Scripts: close every msg_info block with msg_ok
Past-tense msg_info calls that should have been msg_ok, notices that opened a block before a prompt, and blocks without a closing msg_ok. These already left a stale spinner; with core's block stack they would resume it after every later msg_ok.
* Generate passwords with random_password
openssl rand -base64 | tr -dc | head -c returned fewer characters than asked for, and the unfiltered | cut variants put / and + into passwords that end up in DSNs and sed expressions. Secrets an app decodes as base64 are unchanged. Requires community-scripts/core#61.
* Keep data directories through CLEAN_INSTALL instead of copying them
create_backup copied uploads, storage and similar directories twice per update and needed their size again in free space. CLEAN_INSTALL_KEEP moves them aside instead. Only directories the upstream release does not ship, in scripts that restored right after the fetch. Requires community-scripts/core#61.
* Drop the 300s uv timeout overrides
setup_uv exports UV_HTTP_TIMEOUT=600 now; the scripts' 300 only lowered it. Requires community-scripts/core#61.
Upstream's nginx.conf gained a resolver ${NGINX_RESOLVER} line that its Docker
entrypoint fills from /etc/resolv.conf; the script substitutes a fixed list of
placeholders, so the literal variable reached nginx and the config test failed.
Take the nameservers from resolv.conf the same way.
* sparkyfitness: run the Better Auth migration during the update
1.7.1 ships a Better Auth version whose schema has columns 1.6.5 never
created, and nothing in the update adds them. The backend starts, then
refuses every sign-in:
Database schema mismatch
Missing columns session.impersonated_by two_factor.verified ...
Run `npx auth migrate` to add the missing tables and columns.
Run exactly that after the backend dependencies are in place, with the
config Better Auth looks for, SparkyFitnessServer/auth.ts, and the
database credentials from /etc/sparkyfitness/.env. Users who hit this
were left running the server by hand to get the columns created.
A failure warns instead of aborting: the rest of the update has already
succeeded at that point, and the message names the remaining step.
* sparkyfitness: start the server through the entrypoint that migrates
The Better Auth CLI added in the previous commit is the wrong tool. It
generates sso_provider.user_id as text and cannot reference this
schema's uuid user.id:
foreign key constraint "sso_provider_user_id_fkey" cannot be
implemented [...] incompatible types: text and uuid
The real cause is one line up in the unit. It ran
tsx SparkyFitnessServer.js
which imports the application module directly and never applies the
schema migrations. Upstream starts through index.ts - nodemon.json has
exec: tsx index.ts - and that file runs applyMigrations() and
applyRlsPolicies() before importing anything, with a comment naming this
exact failure:
Better Auth validates the database schema eagerly, the moment
betterAuth() is constructed at auth.ts module scope [...] When
migrations ran later (from inside SparkyFitnessServer.ts) that check
read the pre-migration schema on the first boot after an upgrade, so
every /api/auth request failed until the container was restarted.
Point both the install and the update at index.ts and drop the CLI call.
index.ts exits non-zero when a migration fails, so systemd surfaces that
instead of serving a broken login.