phase-0: foundation, both apps boot end to end

Monorepo (pnpm workspaces) with two deployable apps and three pure packages.

apps/api (Hono on Node): Zod validated env that fails fast and names the problem,
Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable
migrations covering the whole SPEC section 5 schema, Better Auth with the four
roles and seeded demo accounts, localized error envelope, /healthz and /readyz,
graceful SIGTERM drain. Dialect specific SQL is confined to the two factories.

apps/web (Next.js App Router): locale routed shell in es and en with a language
switcher, sign in screen, and a runtime /api proxy so the browser only ever sees
one origin and cookies stay first party.

packages/i18n ships both catalogs complete; es is generated from COPY.md and a
test re-derives it from the document on every run so it cannot drift.
packages/contracts holds the Zod schemas and the typed client the web app uses.

Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck
and lint clean, migrate and seed from a clean database, sign in through the proxy
with CSRF rejection of foreign origins.

Not verified here: docker compose. This user has no access to the docker socket.

RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and
no tax rule, check digit or deadline was invented. See DECISIONS.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-03 21:46:35 +00:00
co-authored by Claude Opus 5
commit ae2ea20b7e
106 changed files with 11541 additions and 0 deletions
@@ -0,0 +1,52 @@
import { isApiError } from '@impuestos/contracts';
import { setRequestLocale } from 'next-intl/server';
import { getT } from '@/i18n/t';
import { redirect } from '@/i18n/navigation';
import { Card } from '@/components/ui/card';
import { LanguageSwitcher } from '@/components/language-switcher';
import { serverApi } from '@/lib/api-server';
/**
* Phase 0 shell. It exists to prove the whole chain end to end: browser to the Next
* rewrite, to the API, through the typed client, with the session cookie intact.
* The real dashboard (FLOWS.md Flow C) replaces this in phase 4.
*/
export default async function InicioPage({ params }: { params: Promise<{ locale: string }> }) {
const { locale } = await params;
setRequestLocale(locale);
const t = await getT(locale);
const api = await serverApi();
const profile = await api.getProfile().catch((error: unknown) => {
if (!isApiError(error)) throw error;
// 404 is the documented state for a user who has not finished setup yet.
if (error.code === 'not_found') return null;
if (error.code === 'unauthorized') redirect({ href: '/login', locale });
throw error;
});
return (
<div className="mx-auto flex min-h-dvh max-w-2xl flex-col">
<header className="flex items-center justify-between px-5 py-4">
<h1 className="text-base font-semibold tracking-tight">{t('home.title')}</h1>
<LanguageSwitcher />
</header>
<main className="px-5 pb-16">
<Card className="space-y-2">
{profile ? (
<>
<p className="text-sm text-[var(--text-muted)]">{t('setup.fullName')}</p>
<p className="text-2xl font-semibold tracking-tight">{profile.fullName}</p>
</>
) : (
<>
<h2 className="text-xl font-semibold tracking-tight">{t('setup.step1.title')}</h2>
<p className="text-sm text-[var(--text-muted)]">{t('setup.income.help')}</p>
</>
)}
</Card>
</main>
</div>
);
}