fix: change UUID_HANDLING default to true

Update default from false to true to enable AID client compatibility
out of the box:

- lib/server/env.js: readENVTruthy('UUID_HANDLING', true)
- README.md: Document UUID_HANDLING in Features section
- docs/example-template.env: Update comments, show true as default

Rationale:
- Loop, Trio, AAPS, xDrip+ use UUID sync patterns by default
- Before MongoDB 5.x, UUID _id didn't crash (just didn't CRUD properly)
- ObjectID users completely unaffected (quirk only triggers on UUID)
- Can set UUID_HANDLING=false for strict mode if needed

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Ben West
2026-03-17 14:17:48 -07:00
co-authored by Copilot
parent 942263c4d3
commit 3bb100836b
3 changed files with 11 additions and 7 deletions
+1
View File
@@ -252,6 +252,7 @@ To learn more about the Nightscout API, visit https://YOUR-SITE.com/api-docs/ or
Setting it to `denied` will require a token from every visit, using `status-only` will enable api-secret based login. Setting it to `denied` will require a token from every visit, using `status-only` will enable api-secret based login.
* `IMPORT_CONFIG` - Used to import settings and extended settings from a url such as a gist. Structure of file should be something like: `{"settings": {"theme": "colors"}, "extendedSettings": {"upbat": {"enableAlerts": true}}}` * `IMPORT_CONFIG` - Used to import settings and extended settings from a url such as a gist. Structure of file should be something like: `{"settings": {"theme": "colors"}, "extendedSettings": {"upbat": {"enableAlerts": true}}}`
* `TREATMENTS_AUTH` (`on`) - possible values `on` or `off`. Deprecated, if set to `off` the `careportal` role will be added to `AUTH_DEFAULT_ROLES` * `TREATMENTS_AUTH` (`on`) - possible values `on` or `off`. Deprecated, if set to `off` the `careportal` role will be added to `AUTH_DEFAULT_ROLES`
* `UUID_HANDLING` (`true`) - Controls how UUID `_id` values are handled for treatments and entries. When `true` (default), UUID values in `_id` are extracted to an `identifier` field and the server generates a proper ObjectId. This enables sync with Loop, Trio, AAPS, and xDrip+ which use UUID patterns. Set to `false` for strict mode where UUID `_id` values are rejected.
#### Data Rights #### Data Rights
+7 -4
View File
@@ -15,9 +15,12 @@ NODE_ENV=development
AUTH_FAIL_DELAY=50 AUTH_FAIL_DELAY=50
# UUID handling for AID clients (Loop, Trio, AAPS, xDrip+) # UUID handling for AID clients (Loop, Trio, AAPS, xDrip+)
# When true: UUID _id values are normalized to 'identifier' field # When true (default): UUID _id values are normalized to 'identifier' field
# - POST/PUT: UUID in _id extracted to identifier, server generates ObjectId # - POST/PUT: UUID in _id extracted to identifier, server generates ObjectId
# - GET/DELETE: UUID _id searches by identifier field # - GET/DELETE: UUID _id searches by identifier field
# When false (default): UUID _id values return empty results on read # When false: Strict mode - UUID _id values rejected on write, ignored on read
# Enable this if using Loop, Trio, or other apps with UUID sync patterns # Default is true to support Loop, Trio, AAPS, xDrip+ UUID sync patterns
UUID_HANDLING=false # UUID_HANDLING=true
#
# Set to false for strict ObjectId-only mode:
# UUID_HANDLING=false
+3 -3
View File
@@ -77,9 +77,9 @@ function setSSL () {
env.secureCspReportOnly = readENVTruthy("SECURE_CSP_REPORT_ONLY", false); env.secureCspReportOnly = readENVTruthy("SECURE_CSP_REPORT_ONLY", false);
// UUID handling for AID clients (Loop, Trio, AAPS, xDrip+) // UUID handling for AID clients (Loop, Trio, AAPS, xDrip+)
// When true: UUID _id values are normalized to 'identifier' field // When true (default): UUID _id values are normalized to 'identifier' field
// When false: UUID _id values are rejected on write, ignored on read // When false: UUID _id values are rejected on write, ignored on read (strict mode)
env.uuidHandling = readENVTruthy("UUID_HANDLING", false); env.uuidHandling = readENVTruthy("UUID_HANDLING", true);
} }
// A little ugly, but we don't want to read the secret into a var // A little ugly, but we don't want to read the secret into a var