@@ -8,6 +8,151 @@ permissions:
88 contents : read
99
1010jobs :
11+ oauth-postgres :
12+ name : PostgreSQL integration (${{ matrix.provision }})
13+ runs-on : ${{ (vars.CI_PROVIDER == '' || vars.CI_PROVIDER == 'blacksmith') && 'blacksmith-8vcpu-ubuntu-2404' || 'ubuntu-latest' }}
14+ timeout-minutes : 15
15+ strategy :
16+ fail-fast : false
17+ matrix :
18+ provision : [push, migrate]
19+ services :
20+ postgres :
21+ image : pgvector/pgvector:pg17
22+ env :
23+ POSTGRES_USER : postgres
24+ POSTGRES_PASSWORD : postgres
25+ POSTGRES_DB : sim_auth_scim
26+ ports :
27+ - 5432:5432
28+ options : >-
29+ --health-cmd "pg_isready -U postgres -d sim_auth_scim"
30+ --health-interval 5s
31+ --health-timeout 5s
32+ --health-retries 10
33+ env :
34+ DATABASE_URL : postgresql://postgres:postgres@127.0.0.1:5432/sim_auth_scim
35+ OAUTH_TOKEN_FAMILY_TEST_DATABASE_URL : postgresql://postgres:postgres@127.0.0.1:5432/sim_auth_scim
36+ BETTER_AUTH_SECRET : oauth-postgres-ci-secret-at-least-32-characters
37+ NEXT_PUBLIC_APP_URL : https://test.sim.ai
38+ ENCRYPTION_KEY : ' 0000000000000000000000000000000000000000000000000000000000000000'
39+
40+ steps :
41+ - name : Checkout code
42+ uses : actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
43+
44+ - name : Setup Bun
45+ uses : oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
46+ with :
47+ bun-version : 1.4.1
48+
49+ - name : Setup Node
50+ uses : actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
51+ with :
52+ node-version : 24
53+
54+ - name : Mount Bun cache
55+ uses : ./.github/actions/cache-mount
56+ with :
57+ provider : ${{ vars.CI_PROVIDER }}
58+ key : ${{ github.repository }}-bun-cache-${{ github.event_name }}${{ github.event.pull_request.head.repo.fork && '-fork' || '' }}
59+ path : ~/.bun/install/cache
60+
61+ - name : Install dependencies
62+ run : bun install --frozen-lockfile --ignore-scripts
63+
64+ - name : Provision a fresh database through the supported command
65+ working-directory : packages/db
66+ run : |
67+ bun -e 'import postgres from "postgres"; const sql = postgres(process.env.DATABASE_URL); for (const extension of ["vector", "btree_gin", "pg_trgm"]) await sql`CREATE EXTENSION IF NOT EXISTS ${sql(extension)}`; await sql.end()'
68+ bun run db:${{ matrix.provision }}
69+
70+ - name : Verify migration replay is a no-op
71+ if : matrix.provision == 'migrate'
72+ working-directory : packages/db
73+ run : bun run db:migrate
74+
75+ - name : Verify OAuth lifecycle and SCIM membership guards in PostgreSQL
76+ working-directory : apps/sim
77+ run : >-
78+ bunx vitest run
79+ lib/auth/oauth-token-family.postgres.test.ts
80+ lib/auth/oauth-provider-lifecycle.postgres.test.ts
81+ app/api/auth/oauth2/token/route.postgres.test.ts
82+ lib/auth/sim-auth-adapter.test.ts
83+ ee/scim/lib/managed-membership.postgres.test.ts
84+ lib/auth/sso/application/admit-sso-user.postgres.test.ts
85+
86+ - name : Verify SCIM and administration over real HTTP
87+ working-directory : apps/sim
88+ env :
89+ NEXT_PUBLIC_APP_URL : http://127.0.0.1:3017
90+ BETTER_AUTH_URL : http://127.0.0.1:3017
91+ NEXT_PUBLIC_FORCE_HOSTED : ' true'
92+ BILLING_ENABLED : ' true'
93+ NEXT_PUBLIC_BILLING_ENABLED : ' true'
94+ ENTERPRISE_ENABLED : ' true'
95+ NEXT_PUBLIC_ENTERPRISE_ENABLED : ' true'
96+ SCIM_ENABLED : ' true'
97+ NEXT_PUBLIC_SCIM_ENABLED : ' true'
98+ SSO_ENABLED : ' true'
99+ NEXT_PUBLIC_SSO_ENABLED : ' true'
100+ ORGANIZATIONS_ENABLED : ' true'
101+ NEXT_PUBLIC_ORGANIZATIONS_ENABLED : ' true'
102+ INTERNAL_API_SECRET : scim-http-ci-local-secret-at-least-32-characters
103+ DB_TX_TRIPWIRE : throw
104+ DISABLE_TELEMETRY : ' true'
105+ NEXT_TELEMETRY_DISABLED : ' 1'
106+ NEXT_PUBLIC_CHAT_DISABLED : ' true'
107+ run : |
108+ server_log="$RUNNER_TEMP/scim-next.log"
109+ node ../../node_modules/next/dist/bin/next dev --hostname 127.0.0.1 --port 3017 > "$server_log" 2>&1 &
110+ server_pid=$!
111+ finish() {
112+ kill "$server_pid" 2>/dev/null || true
113+ wait "$server_pid" 2>/dev/null || true
114+ awk '/^ (GET|POST|PUT|PATCH|DELETE|HEAD) \/api\// { print }' "$server_log" > "$RUNNER_TEMP/scim-http-status.log"
115+ }
116+ trap finish EXIT
117+ deadline=$((SECONDS + 120))
118+ until curl --fail --silent --max-time 3 http://127.0.0.1:3017/api/health > /dev/null; do
119+ if ! kill -0 "$server_pid" 2>/dev/null; then
120+ echo 'Local SCIM app exited during startup.'
121+ exit 1
122+ fi
123+ if [ "$SECONDS" -ge "$deadline" ]; then
124+ echo 'Local SCIM app did not become ready within 120 seconds.'
125+ exit 1
126+ fi
127+ sleep 2
128+ done
129+ SCIM_E2E_BASE_URL="$NEXT_PUBLIC_APP_URL" \
130+ SCIM_E2E_DATABASE_URL="$DATABASE_URL" \
131+ SCIM_E2E_AUTH_SECRET="$BETTER_AUTH_SECRET" \
132+ SCIM_E2E_REPORT_PATH="$RUNNER_TEMP/scim-e2e-report.json" \
133+ bun run test:scim:e2e
134+
135+ - name : Upload SCIM failure report and HTTP status log
136+ if : failure()
137+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
138+ with :
139+ name : scim-failure-${{ matrix.provision }}
140+ path : |
141+ ${{ runner.temp }}/scim-e2e-report.json
142+ ${{ runner.temp }}/scim-http-status.log
143+ if-no-files-found : ignore
144+ retention-days : 7
145+
146+ - name : Verify durable provenance bindings and concurrent memory writes
147+ working-directory : apps/sim
148+ env :
149+ TABLE_PROVENANCE_TEST_DATABASE_URL : postgresql://postgres:postgres@127.0.0.1:5432/sim_auth_scim
150+ MEMORY_PROVENANCE_TEST_DATABASE_URL : postgresql://postgres:postgres@127.0.0.1:5432/sim_auth_scim
151+ run : >-
152+ bunx vitest run
153+ lib/table/rows/secret-provenance.postgres.test.ts
154+ lib/memory/message-provenance.postgres.test.ts
155+
11156 test-build :
12157 name : Lint and Test
13158 runs-on : ${{ (vars.CI_PROVIDER == '' || vars.CI_PROVIDER == 'blacksmith') && 'blacksmith-8vcpu-ubuntu-2404' || 'ubuntu-latest' }}
0 commit comments