Add SQLite groundwork: Lib\Db, migrations, and a project-owned data dir

Lib\Db (novaconium/lib/Db.php) is a thin, no-ORM PDO wrapper — lazy-connect
like Lib\Csrf, Db::query() as the only query-running helper (prepared
statements only, no interpolation shortcut, per Lib\Input's existing
security stance). Plain .sql migrations under App/migrations/, applied in
filename order and tracked in an auto-created schema_migrations table, run
automatically on first connection or via novaconium/bin/migrate.php.

Data lives in a new top-level data/ directory rather than novaconium/ or
public/ — outside public/ so it's never web-accessible, and outside
novaconium/ since that directory gets wholesale-replaced by the "Updating
the framework" workflow, which would otherwise destroy it on every update.

New config keys: db_driver (only 'sqlite' implemented), db_path,
db_migrations_dir. Documented at /admin/docs/database and in AGENTS.md.
Closes the "SQLite groundwork" backlog item in novaconium/ISSUES.md.
This commit is contained in:
code
2026-07-14 03:33:38 +00:00
parent 672f997d8b
commit a3b996719a
13 changed files with 314 additions and 47 deletions
+11
View File
@@ -38,4 +38,15 @@ return [
// 'admin_password_hash' => '$2y$10$...',
'admin_username' => 'admin',
'admin_password_hash' => '',
// Lib\Db (see /admin/docs/database). Only 'sqlite' is implemented today
// — MySQL support is tracked as a separate Backlog item in
// novaconium/ISSUES.md. db_path deliberately lives outside both
// public/ (must never be web-accessible) and novaconium/ (gets wholly
// replaced on a framework update — see /admin/docs/getting-started's
// "Updating the framework" section) — a top-level data/ directory,
// project-owned like App/, is the only safe place for it.
'db_driver' => 'sqlite',
'db_path' => __DIR__ . '/../data/novaconium.sqlite',
'db_migrations_dir' => __DIR__ . '/../App/migrations',
];