Workspaces Payload collection with the PAT as a write-only field: access.read () => false strips it from every access-controlled read path, and a field-level beforeChange hook encrypts on write with AES-256-GCM (scrypt key from VEECT_SECRET, random per-value salt + IV, v1 storage format) via node:crypto only. The real repository replaces the phase-1 stub with payload create/findByID; toDomain never maps the credential, and getDecryptedCredential(id) is the single server-side decrypt path for the runner handoff (story 07). Contract suite now covers create, write-only behaviour, and the decrypt path against both the mock and the Payload impl (stub runs the real collection hooks). Missing VEECT_SECRET fails production bind/boot with an actionable message; dev-seed boots without it. Env declared in turbo.json globalEnv + .env.example. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
32 lines
794 B
JSON
32 lines
794 B
JSON
{
|
|
"name": "@repo/core-cms",
|
|
"private": true,
|
|
"version": "0.0.0",
|
|
"type": "module",
|
|
"exports": {
|
|
".": "./src/index.ts",
|
|
"./generated-types": "./src/generated-types.ts"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc --noEmit",
|
|
"lint": "eslint .",
|
|
"typecheck": "tsc --noEmit",
|
|
"test": "vitest run --passWithNoTests"
|
|
},
|
|
"dependencies": {
|
|
"@payloadcms/db-postgres": "^3.14.0",
|
|
"@payloadcms/richtext-lexical": "^3.14.0",
|
|
"@repo/auth": "workspace:*",
|
|
"@repo/workspaces": "workspace:*",
|
|
"payload": "^3.14.0"
|
|
},
|
|
"devDependencies": {
|
|
"@repo/core-eslint": "workspace:*",
|
|
"@repo/core-testing": "workspace:*",
|
|
"@repo/core-typescript": "workspace:*",
|
|
"@types/node": "^22.0.0",
|
|
"@vitest/coverage-v8": "^3.2.4",
|
|
"vitest": "^3.0.0"
|
|
}
|
|
}
|