Initial commit: Kalendartool (Next.js, Prisma, Docker)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Kühn
2026-10-08 14:38:04 +02:00
commit bc49c3074e
94 changed files with 12812 additions and 0 deletions

View File

@@ -0,0 +1,26 @@
-- Least-Privilege-DB-User fuer die App (wird nur bei INITIALISIERUNG
-- eines leeren pgdata-Volumes automatisch ausgefuehrt).
--
-- Bei BESTEHENDem Volume den User einmalig manuell anlegen:
-- docker compose exec db psql -U calendar -d calendar -f - <<'SQL'
-- ... (Inhalt dieses Scripts)
-- SQL
--
-- Der App-User darf nur in seiner Datenbank arbeiten und besitzt
-- keine Superuser-Rechte (im Gegensatz zum Owner "calendar").
DO $$
BEGIN
IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'calendar_app') THEN
CREATE ROLE calendar_app LOGIN PASSWORD 'calendar_app';
END IF;
END
$$;
GRANT CONNECT ON DATABASE calendar TO calendar_app;
GRANT USAGE ON SCHEMA public TO calendar_app;
GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA public TO calendar_app;
ALTER DEFAULT PRIVILEGES IN SCHEMA public
GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO calendar_app;
GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public TO calendar_app;
GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public TO calendar_app;