Mirrored from GitHub github.com/roostorg/coop

[Kysely] Migrate OrgAPI parent helpers off sequelize (#390) master

* [Kysely] Migration of OrgAPI Helpers * fix lint * [Kysely] Migrate HashBank and Backtest GraphQL mappers off sequelize (#392) * [Kysely] Migrate test fixtures and bin script off sequelize (#414) * [Kysely] Migrate test fixtures and bin script off sequelize * Address PR #414 review comments - clickhouseSql: use `typeof value === 'X'` directly so TypeScript narrows `value` inside each branch, and drop the now-unneeded `as boolean` cast. - apiKeyMiddleware: fix stale comment that said "return a 400" - the code (correctly) returns 401 Unauthorized for invalid API keys. * Address PR #414 follow-up review comments Update two stale block comments where eslint's autofix removed the type assertion they were originally explaining: - sql.ts (`takeLast`): explain that the casts on the initial `outer` binding and the return value are what keep the concrete builder type in the face of `orderBy` chaining widening it. - SignalsService.ts (`runSignal`): explain that the looked-up signal's input type is the union of all signals' inputs, and the return-type cast (not a `never` cast on the input) is what reconciles the call. * [Kysely] Demolish server/models/, flip Rule codegen mappers, drop sequelize from server/ (#420) * [Kysely] Demolish server/models/, flip Rule codegen mappers, drop sequelize from server/ * update configs for pg config * Address PR #390 Copilot review: 401 should be Unauthenticated The api-key middleware was returning a 401 with `ErrorType.Unauthorized` and `name: 'UnauthorizedError'`, which is the authorization (403/forbidden) bucket. Per `server/api.ts`, only `ErrorType.Unauthenticated` maps to GraphQL `code: 'UNAUTHENTICATED'`, so the middleware's response was semantically wrong (and would surface as a FORBIDDEN code to clients that look at the GraphQL extension). - Add `'UnauthenticatedError'` to the `CoopErrorName` union. - Add `makeUnauthenticatedError` factory next to `makeUnauthorizedError`, so the 401-vs-403 split is symmetric and discoverable. - Refactor `apiKeyMiddleware` to use the new factory (also drops the raw `new CoopError({...})` construction). Note: `routes/action/submitAction.ts` and `routes/gdpr/delete.ts` still call `makeUnauthorizedError('Invalid API Key', ...)` for the same api-key-validation failure. Those are outside this PR's diff and worth fixing in a follow-up. * Sync server/graphql/generated.ts with graphql-codegen output PR #420 (the demolition PR) hand-patched this file with an aliased import (`GraphQLRuleParent as Rule`) instead of running the real codegen, so the file diverged from what `npm run generate` actually produces. The CI `check_generated_graphql` job runs `npm run generate` then asserts `git status --porcelain` is clean, which was failing on this PR. The diff is purely cosmetic — every reference is the same Kysely parent type, just spelled `GraphQLRuleParent` (the canonical codegen output) instead of `Rule` (the alias). Behavior, mappers, and all resolver signatures are unchanged.


+1562 -2772
108 changed files