Files
mixmaker/backend
lemintare 6b189bfce4
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / compose (push) Has been cancelled
Add global role synchronization for Discord with configurable interval
This commit introduces a new feature for global role synchronization in Discord, allowing for periodic reconciliation of managed roles. A new environment variable, `DISCORD_GLOBAL_SYNC_INTERVAL`, has been added to configure the synchronization interval, defaulting to 5 minutes. The `RoleWorker` has been updated to schedule global sync jobs, ensuring that missing managed roles are restored and extra assignments are removed without affecting unrelated server roles. Database schema changes support the new synchronization logic, and tests have been added to validate the functionality of the global reconciliation process.
2026-07-19 12:04:33 +03:00
..

Mixmaker backend

Go/PostgreSQL API organized as domain, application, and inbound/outbound adapters.

Run

Required environment:

  • DATABASE_URL
  • DISCORD_CLIENT_ID
  • DISCORD_CLIENT_SECRET
  • DISCORD_REDIRECT_URL
  • ADMIN_DISCORD_IDS (comma-separated Discord IDs)

Optional environment:

  • HTTP_ADDR=:8080
  • FRONTEND_URL=/
  • SESSION_COOKIE_NAME=mixmaker_session
  • SESSION_TTL=168h
  • COOKIE_SECURE=true (set false only for local HTTP)
  • MIGRATIONS_DIR=migrations

Apply migrations and run:

go run ./cmd/api migrate
go run ./cmd/api

The same commands work with the container image:

docker run --rm ... mixmaker-api migrate
docker run --rm ... mixmaker-api

GET /healthz is a process health check and GET /readyz checks PostgreSQL. Authenticated realtime updates are available from GET /api/events/stream?topic=event:<event-id> as Server-Sent Events.

Security and behavior

Discord access tokens are used only during callback and are not stored. The API creates opaque server-side sessions and sends an HttpOnly, SameSite=Lax cookie. Initial administrators are promoted only when their Discord ID is present in ADMIN_DISCORD_IDS; existing administrators are never demoted by login.

Draft and series writes use persisted versions to reject stale repeated commands. RSVP overrides, captain assignments, balancing selections, tosses, draft actions, and results retain actor information in domain state or the append-only audit log.