FavoriteLink existed in schema.prisma but was never captured in a
migration -- same bug class as the DashboardLayout fix in
20260629130000_add_missing_tables. It silently worked in local dev
(table created via db push) but any environment relying on
`prisma migrate deploy` never got the table, causing every
GET /favorites request to 500 with PrismaClientKnownRequestError
P2021 ("table does not exist").
Found live testing the production deploy at alpha.tessera.ctl.de:
adding a Favoriten widget triggered the 500. Confirmed via server
logs (docker logs) and by inspecting _prisma_migrations / \dt on
that database.
CREATE TABLE/INDEX IF NOT EXISTS makes this safe to apply against
environments where the table already exists untracked (verified: ran
clean against local dev's DB, which already had the table from a
prior db push, with zero errors and zero data loss).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Persists per-tenant AD group/OU DNs to restrict which directory
entries get synced. Empty array (default) preserves current
behavior — import everyone under base DN.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Column already existed in production DB — migration failed with 42701.
Hotfixed via psql UPDATE on _prisma_migrations; migration SQL updated
to prevent recurrence on fresh deploys.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Column was added to schema but migration was missing, causing
PrismaClientKnownRequestError P2022 on prod API startup.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add avatarPath String? column to User model (migration: add_user_avatar)
- POST /users/me/avatar: 2MB limit, image/png/jpeg/webp allowlist, writes to user-files/avatars/{userId}.{ext}
- GET /users/me/avatar: streams avatar with Cache-Control: no-store
- AuthService.getMe(): returns isLocalUser + hasAvatar without leaking passwordHash/ldapDn
- AuthController GET /auth/me: now returns enriched profile via getMe()