phase-2: identity, from the landing hook to the profile screen
Flows A1 to A6 and E3 end to end. A visitor types a RUC on the landing page, sees their real filing dates, registers, verifies a six digit code, grants consent, completes a three step setup and lands on the first run screen, with the profile, consent and audit rows to show for it. API: public RUC lookup behind a token bucket (10/min/IP), the full /me surface (profile, dependents, consents, notification prefs, data export, account deletion), an append-only audit module that exports an insert and nothing else, and a PII module that is the only thing allowed near those tables. Deletion and consent revocation both freeze the account and drop every session, reusing better-auth's ban flag rather than adding a second notion of disabled. Nothing is destroyed yet: the purge is a job for phase 4. deadlineDigit is always derived server side, never accepted from the client. Web: landing with the RUC hook, registration, OTP verification, consent, the setup wizard, the profile screen with "Tus datos", and legal pages that ship as marked placeholders per COPY.md section 13. Money, Skeleton, Switch and EmptyState components added. The seed is now complete for identity: Maria at 4123456-1, filing digit 6 and day 19, with a dependant, consents and prefs; Carlos as an IVA-only company. Two real defects found by building the screens and fixed with tests: the OTP boxes dropped a digit because the handler fired effects inside a setState updater that React 19 invokes twice, and the switch knob rendered outside its track because translate-x-5.5 does not resolve. 232 vitest tests, 26 Playwright tests across mobile and desktop, coverage still 100% on the rules, typecheck and lint clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
80b10c958e
commit
0d7651b17c
+195
-7
@@ -1,4 +1,8 @@
|
||||
import { computeRucDv } from '@impuestos/rules';
|
||||
import { uuidv7 } from 'uuidv7';
|
||||
import type { Auth, Role } from '../auth/options';
|
||||
import { writeAudit } from '../modules/audit';
|
||||
import { CONSENT_TEXT_VERSION } from '../modules/pii';
|
||||
import type { DbHandle } from './index';
|
||||
|
||||
export interface SeedAccount {
|
||||
@@ -11,10 +15,6 @@ export interface SeedAccount {
|
||||
/**
|
||||
* Accounts per CONTRACTS.md section 4. Deterministic and idempotent: running the seed
|
||||
* twice leaves the same rows.
|
||||
*
|
||||
* Their profiles, documents and declarations are seeded by the phases that own those
|
||||
* tables. Until then `GET /me/profile` correctly answers 404 for each of them, which is
|
||||
* the documented state for a user who has not finished setup.
|
||||
*/
|
||||
export const SEED_ACCOUNTS: readonly SeedAccount[] = [
|
||||
{ email: 'superadmin@demo.local', password: 'demo-superadmin-1', name: 'Super Admin', role: 'superadmin' },
|
||||
@@ -23,6 +23,17 @@ export const SEED_ACCOUNTS: readonly SeedAccount[] = [
|
||||
{ email: 'carlos@demo.local', password: 'demo-carlos-1', name: 'Carlos Benitez', role: 'user' },
|
||||
];
|
||||
|
||||
/**
|
||||
* The showcase account: an individual whose RUC is her CI plus a check digit, registered
|
||||
* for both IVA and IRP. Base 4123456 ends in 6, so her filing day is the 19th, which is
|
||||
* the example FLOWS.md uses throughout.
|
||||
*/
|
||||
export const MARIA_RUC_BASE = '4123456';
|
||||
/** IVA only, to exercise the view with no IRP anywhere in it. */
|
||||
export const CARLOS_RUC_BASE = '80012345';
|
||||
|
||||
const SEEDED_AT = '2026-01-15T12:00:00.000Z';
|
||||
|
||||
export interface SeedResult {
|
||||
created: string[];
|
||||
existing: string[];
|
||||
@@ -30,9 +41,10 @@ export interface SeedResult {
|
||||
|
||||
export async function seed(handle: DbHandle, auth: Auth): Promise<SeedResult> {
|
||||
const result: SeedResult = { created: [], existing: [] };
|
||||
const db = handle.db;
|
||||
|
||||
for (const account of SEED_ACCOUNTS) {
|
||||
const found = await handle.db
|
||||
const found = await db
|
||||
.selectFrom('user')
|
||||
.select('id')
|
||||
.where('email', '=', account.email)
|
||||
@@ -49,14 +61,190 @@ export async function seed(handle: DbHandle, auth: Auth): Promise<SeedResult> {
|
||||
|
||||
// Roles and verification are set directly: the sign up endpoint always creates a
|
||||
// plain unverified `user`, and demo accounts need to be usable straight away.
|
||||
await handle.db
|
||||
await db
|
||||
.updateTable('user')
|
||||
.set({ role: account.role, emailVerified: 1, updatedAt: new Date().toISOString() })
|
||||
.set({ role: account.role, emailVerified: 1, updatedAt: SEEDED_AT })
|
||||
.where('email', '=', account.email)
|
||||
.execute();
|
||||
|
||||
result.created.push(account.email);
|
||||
}
|
||||
|
||||
await seedProfiles(handle);
|
||||
await seedAuditTrail(handle);
|
||||
return result;
|
||||
}
|
||||
|
||||
async function seedProfiles(handle: DbHandle): Promise<void> {
|
||||
const db = handle.db;
|
||||
|
||||
const maria = await userIdFor(handle, 'maria@demo.local');
|
||||
const carlos = await userIdFor(handle, 'carlos@demo.local');
|
||||
|
||||
await upsertProfileRow(handle, {
|
||||
userId: maria,
|
||||
fullName: 'Maria Gonzalez',
|
||||
docType: 'ruc',
|
||||
ruc: MARIA_RUC_BASE,
|
||||
rucDv: String(computeRucDv(MARIA_RUC_BASE)),
|
||||
ci: MARIA_RUC_BASE,
|
||||
taxpayerKind: 'individual',
|
||||
obligations: [
|
||||
{ code: 'iva_120', active: true, since: '2024-01-01' },
|
||||
{ code: 'irp_515', active: true, since: '2024-01-01' },
|
||||
],
|
||||
irpGrossEstimate: 180_000_000,
|
||||
});
|
||||
|
||||
await upsertProfileRow(handle, {
|
||||
userId: carlos,
|
||||
fullName: 'Benitez y Asociados SRL',
|
||||
docType: 'ruc',
|
||||
ruc: CARLOS_RUC_BASE,
|
||||
rucDv: String(computeRucDv(CARLOS_RUC_BASE)),
|
||||
ci: null,
|
||||
taxpayerKind: 'company',
|
||||
obligations: [{ code: 'iva_120', active: true, since: '2023-06-01' }],
|
||||
irpGrossEstimate: null,
|
||||
});
|
||||
|
||||
const hasDependent = await db
|
||||
.selectFrom('dependents')
|
||||
.select('id')
|
||||
.where('user_id', '=', maria)
|
||||
.executeTakeFirst();
|
||||
|
||||
if (!hasDependent) {
|
||||
await db
|
||||
.insertInto('dependents')
|
||||
.values({
|
||||
id: uuidv7(),
|
||||
user_id: maria,
|
||||
display_name: 'Lucas Gonzalez',
|
||||
relationship: 'hijo',
|
||||
doc_number: null,
|
||||
active: 1,
|
||||
created_at: SEEDED_AT,
|
||||
updated_at: SEEDED_AT,
|
||||
})
|
||||
.execute();
|
||||
}
|
||||
|
||||
for (const userId of [maria, carlos]) {
|
||||
for (const kind of ['data_processing', 'notifications'] as const) {
|
||||
const existing = await db
|
||||
.selectFrom('consents')
|
||||
.select('id')
|
||||
.where('user_id', '=', userId)
|
||||
.where('kind', '=', kind)
|
||||
.executeTakeFirst();
|
||||
if (existing) continue;
|
||||
|
||||
await db
|
||||
.insertInto('consents')
|
||||
.values({
|
||||
id: uuidv7(),
|
||||
user_id: userId,
|
||||
kind,
|
||||
granted_at: SEEDED_AT,
|
||||
revoked_at: null,
|
||||
text_version: CONSENT_TEXT_VERSION,
|
||||
})
|
||||
.execute();
|
||||
}
|
||||
|
||||
const prefs = await db
|
||||
.selectFrom('notification_prefs')
|
||||
.select('user_id')
|
||||
.where('user_id', '=', userId)
|
||||
.executeTakeFirst();
|
||||
if (!prefs) {
|
||||
await db
|
||||
.insertInto('notification_prefs')
|
||||
.values({
|
||||
user_id: userId,
|
||||
push_enabled: 0,
|
||||
email_enabled: 1,
|
||||
telegram_chat_id: null,
|
||||
digest_hour: 9,
|
||||
})
|
||||
.execute();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/** CONTRACTS.md section 4: the audit table starts with the role assignments. */
|
||||
async function seedAuditTrail(handle: DbHandle): Promise<void> {
|
||||
const existing = await handle.db
|
||||
.selectFrom('audit_log')
|
||||
.select('id')
|
||||
.where('action', '=', 'admin.role_change')
|
||||
.executeTakeFirst();
|
||||
if (existing) return;
|
||||
|
||||
const superadmin = await userIdFor(handle, 'superadmin@demo.local');
|
||||
|
||||
for (const email of ['staff@demo.local'] as const) {
|
||||
await writeAudit(handle.db, {
|
||||
actorUserId: superadmin,
|
||||
actorRole: 'superadmin',
|
||||
subjectUserId: await userIdFor(handle, email),
|
||||
action: 'admin.role_change',
|
||||
resource: 'user',
|
||||
detail: { role: 'staff', seeded: true },
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
interface ProfileSeed {
|
||||
userId: string;
|
||||
fullName: string;
|
||||
docType: 'ruc' | 'ci';
|
||||
ruc: string | null;
|
||||
rucDv: string | null;
|
||||
ci: string | null;
|
||||
taxpayerKind: 'individual' | 'company';
|
||||
obligations: { code: 'iva_120' | 'irp_515'; active: boolean; since: string }[];
|
||||
irpGrossEstimate: number | null;
|
||||
}
|
||||
|
||||
async function upsertProfileRow(handle: DbHandle, seed: ProfileSeed): Promise<void> {
|
||||
const existing = await handle.db
|
||||
.selectFrom('profiles')
|
||||
.select('user_id')
|
||||
.where('user_id', '=', seed.userId)
|
||||
.executeTakeFirst();
|
||||
if (existing) return;
|
||||
|
||||
const base = seed.ruc ?? seed.ci;
|
||||
if (!base) throw new Error(`seed profile for ${seed.fullName} needs a RUC or a CI`);
|
||||
|
||||
await handle.db
|
||||
.insertInto('profiles')
|
||||
.values({
|
||||
user_id: seed.userId,
|
||||
full_name: seed.fullName,
|
||||
doc_type: seed.docType,
|
||||
ruc: seed.ruc,
|
||||
ruc_dv: seed.rucDv,
|
||||
ci: seed.ci,
|
||||
taxpayer_kind: seed.taxpayerKind,
|
||||
deadline_digit: Number(base[base.length - 1]),
|
||||
obligations: JSON.stringify(seed.obligations),
|
||||
irp_gross_estimate: seed.irpGrossEstimate,
|
||||
auto_confirm_days: 7,
|
||||
locale: 'es',
|
||||
created_at: SEEDED_AT,
|
||||
updated_at: SEEDED_AT,
|
||||
})
|
||||
.execute();
|
||||
}
|
||||
|
||||
async function userIdFor(handle: DbHandle, email: string): Promise<string> {
|
||||
const row = await handle.db
|
||||
.selectFrom('user')
|
||||
.select('id')
|
||||
.where('email', '=', email)
|
||||
.executeTakeFirstOrThrow();
|
||||
return row.id;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user