# @platform-modules/db

## 0.4.0

### Minor Changes

- 1fd8651: Make the D1 atomicity capability truthful and stop advertising an interactive transaction the driver does not have.

  `@platform-modules/db` — `createD1Client` no longer exposes a `transaction` member or `TransactionIdentity`, and is no longer assignable to `TransactionalDatabase`. Cloudflare D1 has no interactive transaction callback API, so the previous shape was a false claim that failed at runtime with `Failed query: begin`; D1 gets a typed atomic batch seam over exactly one real `binding.batch(...)` call instead. Genuinely transactional adapters (Postgres) keep the callback-minted transaction, exact identity semantics and rollback.

  The transaction handle splits in two: `Transaction<S>` is now the dialect-neutral mutation handle (`execute()` only), while the Postgres query-builder surface (`select`/`insert`/`update`/`delete`) lives on `PostgresTransaction<S>`. Callers that use query builders inside a transaction must type against `PostgresTransaction<S>`.

  `withTransactionIdentity` becomes public API. It was marked internal, yet every package's real-Postgres harness needs it to produce a value satisfying `TransactionalDatabase`, and three packages had resorted to importing it through a relative path into `db/src` — which breaks the moment these packages are consumed as published `dist`. Consumers that build their own driver client now have a supported way to brand it.

  Every downstream consumer is migrated: transaction parameters re-annotated, PG test harnesses branded through the public helper or rebuilt on the first-party adapters, and `PgliteTransactionalDatabase` now declares the `$client` the driver actually attaches.

  Two latent defects surfaced and are fixed, both the same shape — code reading one result shape through a cast that hid the mismatch from the compiler:

  - `@platform-modules/content` — `taxonomy.ts` read `result.rows` behind an `as { rows?: unknown[] }` cast, so `isInSubtree` always returned false and the depth-cap query never matched. `moveTerm` would accept a parent inside its own subtree (creating a cycle) and allow a subtree past the depth cap, raising no error.
  - `@platform-modules/affiliate` — `maturity-sweep.ts` cast every `execute()` result to `{ rows }`. Its opening probe short-circuits the sweep when empty, so on a handle returning the other shape the sweep silently promoted nothing and moved no money.

  Both now normalize both shapes rather than casting to one: `execute()` yields a plain row array inside a platform-wrapped transaction and the driver's `{ rows }` envelope on an unwrapped handle, and consuming code must tolerate either.

  Breaking at the seam, released as minor: these packages are pre-1.0.0 and stay 0.x until the deliberate public release.

### Patch Changes

- Updated dependencies [fd62ea1]
  - @platform-modules/util@0.4.0

## 0.3.0

### Minor Changes

- df32439: D1 client satisfies the `execute()` contract. `SQLiteQuerier` now declares `execute(query)`, and `createD1Client` maps it to drizzle's `.all()` so raw statements return their `RETURNING` rows instead of D1's row-less `{ success, meta }` envelope.

## 0.2.2

### Patch Changes

- Updated dependencies [a708afa]
  - @platform-modules/util@0.3.0

## 0.2.1

### Patch Changes

- Updated dependencies [7d474ec]
  - @platform-modules/util@0.2.0

## 0.2.0

### Minor Changes

- f895518: Add per-module health probes (Wave-2 CMS capability extensions): `@platform-modules/db/health` and `@platform-modules/cache/health`, each a `healthCheck` factory returning a `HealthCheck` (from `@platform-modules/util/health`). `db` runs a `SELECT 1` round-trip + latency over any `Querier`; `cache` runs a set→get→del probe-key over any `CacheBackend` with a short TTL so a failed cleanup self-expires. Both NEVER throw (availability floor → `status:'down'`) and scrub a failure `detail` to a generic string (info-disclosure floor — the raw driver/backend error, which may carry a DSN/credentials, is never surfaced). `/health` is a subpath so the type-only `db` root stays import-light. mail/jobs/uploads deliberately ship no probe (no module-ownable no-op seam) — the host composes those inline against the same public `HealthCheck` interface.

### Patch Changes

- Updated dependencies [c80eaad]
- Updated dependencies [324de71]
  - @platform-modules/util@0.1.0

## 0.1.0

### Minor Changes

- 8f09581: Adapters return driver-concrete types so `execute<T>` row typing flows; core agnostic vocabulary unchanged.

## 0.0.1

### Patch Changes

- d72b1ba: Initial publish — first versioned release.
