phase-0: foundation, both apps boot end to end
Monorepo (pnpm workspaces) with two deployable apps and three pure packages. apps/api (Hono on Node): Zod validated env that fails fast and names the problem, Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable migrations covering the whole SPEC section 5 schema, Better Auth with the four roles and seeded demo accounts, localized error envelope, /healthz and /readyz, graceful SIGTERM drain. Dialect specific SQL is confined to the two factories. apps/web (Next.js App Router): locale routed shell in es and en with a language switcher, sign in screen, and a runtime /api proxy so the browser only ever sees one origin and cookies stay first party. packages/i18n ships both catalogs complete; es is generated from COPY.md and a test re-derives it from the document on every run so it cannot drift. packages/contracts holds the Zod schemas and the typed client the web app uses. Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck and lint clean, migrate and seed from a clean database, sign in through the proxy with CSRF rejection of foreign origins. Not verified here: docker compose. This user has no access to the docker socket. RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and no tax rule, check digit or deadline was invented. See DECISIONS.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,62 @@
|
||||
import type { Auth, Role } from '../auth/options';
|
||||
import type { DbHandle } from './index';
|
||||
|
||||
export interface SeedAccount {
|
||||
email: string;
|
||||
password: string;
|
||||
name: string;
|
||||
role: Role;
|
||||
}
|
||||
|
||||
/**
|
||||
* Accounts per CONTRACTS.md section 4. Deterministic and idempotent: running the seed
|
||||
* twice leaves the same rows.
|
||||
*
|
||||
* Their profiles, documents and declarations are seeded by the phases that own those
|
||||
* tables. Until then `GET /me/profile` correctly answers 404 for each of them, which is
|
||||
* the documented state for a user who has not finished setup.
|
||||
*/
|
||||
export const SEED_ACCOUNTS: readonly SeedAccount[] = [
|
||||
{ email: 'superadmin@demo.local', password: 'demo-superadmin-1', name: 'Super Admin', role: 'superadmin' },
|
||||
{ email: 'staff@demo.local', password: 'demo-staff-1', name: 'Staff Demo', role: 'staff' },
|
||||
{ email: 'maria@demo.local', password: 'demo-maria-1', name: 'Maria Gonzalez', role: 'user' },
|
||||
{ email: 'carlos@demo.local', password: 'demo-carlos-1', name: 'Carlos Benitez', role: 'user' },
|
||||
];
|
||||
|
||||
export interface SeedResult {
|
||||
created: string[];
|
||||
existing: string[];
|
||||
}
|
||||
|
||||
export async function seed(handle: DbHandle, auth: Auth): Promise<SeedResult> {
|
||||
const result: SeedResult = { created: [], existing: [] };
|
||||
|
||||
for (const account of SEED_ACCOUNTS) {
|
||||
const found = await handle.db
|
||||
.selectFrom('user')
|
||||
.select('id')
|
||||
.where('email', '=', account.email)
|
||||
.executeTakeFirst();
|
||||
|
||||
if (found) {
|
||||
result.existing.push(account.email);
|
||||
continue;
|
||||
}
|
||||
|
||||
await auth.api.signUpEmail({
|
||||
body: { email: account.email, password: account.password, name: account.name },
|
||||
});
|
||||
|
||||
// Roles and verification are set directly: the sign up endpoint always creates a
|
||||
// plain unverified `user`, and demo accounts need to be usable straight away.
|
||||
await handle.db
|
||||
.updateTable('user')
|
||||
.set({ role: account.role, emailVerified: 1, updatedAt: new Date().toISOString() })
|
||||
.where('email', '=', account.email)
|
||||
.execute();
|
||||
|
||||
result.created.push(account.email);
|
||||
}
|
||||
|
||||
return result;
|
||||
}
|
||||
Reference in New Issue
Block a user