phase-6: the staff console, and a log that says who did what

Flow H, three screens behind a role check: find an account, work the
ingestion error queue, read and export the audit log. Superadmins can
change a role, never their own.

The error queue merges ingest errors and dead jobs into one table with a
cursor that pages both sources; only a job can be retried and only an
ingest row resolved, with a note that migration 003 gives it somewhere
to live.

writeAudit no longer defaults a missing subject to the actor, which had
been recording a user search as staff looking themselves up. Omitting
the subject still means acting on yourself; null now means the action
has no subject, which is what a search, a retry and an export are.

Reading the log is not audited. Exporting it is: a copy leaving the
building is a different act from looking.

e2e/global-setup.ts asks for every screen once before the suite starts,
so a dev server's first-request compile is paid before the first test
rather than by it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-04 21:55:59 +00:00
co-authored by Claude Opus 5
parent 6620650e9e
commit 4c39926483
39 changed files with 2767 additions and 11 deletions
+18 -2
View File
@@ -7,9 +7,10 @@ and ready to file yourself.
Working name. See `docs/` for the specifications, `DECISIONS.md` for choices made along the
way and the gaps that still need answers.
> **Status: phase 5 of 8.** The whole taxpayer path works: scan a comprobante, confirm it,
> **Status: phase 6 of 8.** The whole taxpayer path works: scan a comprobante, confirm it,
> watch the position move, and take the resulting Formulario 120 or 515 from review to
> approved to a PDF you file yourself in Marangatu. The admin area, the PWA and the
> approved to a PDF you file yourself in Marangatu. Staff have a console: look an account
> up, work the ingestion error queue, read and export the audit log. The PWA polish and the
> scale-out work are still ahead.
---
@@ -28,6 +29,11 @@ pnpm dev
The web app is on http://localhost:3005, the API on http://localhost:4000. `db:seed`
prints the development sign in details for the four demo accounts.
Two of those accounts reach the staff console at `/es/usuarios`, `/es/errores` and
`/es/auditoria`: `staff@demo.local` can search accounts, work the error queue and read the
audit log, and `superadmin@demo.local` can also change roles. Everyone else gets a plain
"team only" page and a 403 from the API.
The web port lives in `apps/web/.env` and `apps/api/.env` has to name the same one in
`APP_PUBLIC_URL` and `BETTER_AUTH_URL`. Auth checks the request Origin, so a mismatch
fails sign in with a 403 that looks nothing like a port problem. `localhost` and
@@ -183,3 +189,13 @@ Then start the stack and run it:
```bash
E2E_BASE_URL=http://localhost:3005 pnpm test:e2e
```
A dev server compiles each route the first time it is asked for, which is slow enough to
push a sign in past the five seconds Playwright waits on a navigation. `e2e/global-setup.ts`
asks for every screen once before the suite starts, so the cost is paid before the first
test rather than by it. Against a heavily loaded dev server, one worker is still steadier
than two:
```bash
E2E_BASE_URL=http://localhost:3005 npx playwright test --workers=1
```