Garmin Connect as the third connected-services provider (spec: garmin-import). The interesting parts: - Push-first ingestion: Garmin has no list endpoint. The webhook normalizes ping (callbackURL) and push (inline) notification batches into events; the slow work (authorized FIT download, FIT→GPX via the shared converter, activity creation) runs in a garmin-import-activity pg-boss job so the webhook answers fast. Callback URLs are validated against Garmin's API host before any fetch (SSRF guard). - History via backfill requests: /sync/import/garmin is a date-range requester with honest async progress (no pick list — the concept doesn't exist in a push model). Ranges chunk to Garmin's 90-day cap; overlaps are free via sync_imports dedupe. Requests persist in import_batches via two new nullable columns (range_start/range_end). - OAuth2 + PKCE on the existing oauth credential kind. Design correction from apply: the verifier rides a short-lived httpOnly cookie scoped to the callback path — the state param is visible in redirect URLs and must never carry it. Manifests opt in via pkce:true. - Deregistration notifications flip the connection to 'revoked' (row kept for audit, imports retained, re-connect prompt shown). - Framework evolutions, all additive: parseWebhook returns WebhookEvent[] (Garmin batches; Wahoo adapted), manifest gains configured()/importUrl/pkce, importActivity accepts summary stats for FIT-less imports, manager gains markRevoked. - Env-gated: no GARMIN_CLIENT_ID → provider hidden on /settings/connections. Privacy manifest entry (DE+EN). i18n en+de. Rollout (§6) stays gated on the Garmin Developer Program application (submitted 2026-06-07). Fixtures are doc-shaped; the staging soak swaps in recorded payloads if shapes differ. Gate: typecheck ✓ lint ✓ unit+integration ✓ e2e 70/72 + both known flakes green isolated ✓ openspec validate ✓ Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
41 lines
1.4 KiB
TypeScript
41 lines
1.4 KiB
TypeScript
// Server-only loader for /settings/connections. Pulled out of the route
|
|
// file so the component module doesn't pull `getDb` + Drizzle schema
|
|
// into its module graph (only the loader does, via `import("...")` at
|
|
// load time).
|
|
|
|
import { eq } from "drizzle-orm";
|
|
import { requireSessionUser } from "~/lib/auth/session.server";
|
|
import { getDb } from "~/lib/db";
|
|
import { connectedServices } from "@trails-cool/db/schema/journal";
|
|
import { getAllManifests } from "~/lib/connected-services";
|
|
|
|
export async function loadConnectionsSettings(request: Request) {
|
|
const user = await requireSessionUser(request);
|
|
|
|
const db = getDb();
|
|
const connections = await db
|
|
.select({
|
|
provider: connectedServices.provider,
|
|
providerUserId: connectedServices.providerUserId,
|
|
})
|
|
.from(connectedServices)
|
|
.where(eq(connectedServices.userId, user.id));
|
|
|
|
const providers = getAllManifests()
|
|
// Providers can hide themselves when the instance lacks their API
|
|
// credentials (Garmin: program keys are per-operator).
|
|
.filter((m) => m.configured?.() ?? true)
|
|
.map((m) => {
|
|
const conn = connections.find((c) => c.provider === m.id);
|
|
return {
|
|
id: m.id,
|
|
name: m.displayName,
|
|
connected: !!conn,
|
|
providerUserId: conn?.providerUserId,
|
|
connectUrl: m.connectUrl ?? null,
|
|
importUrl: m.importUrl ?? null,
|
|
};
|
|
});
|
|
|
|
return { providers };
|
|
}
|