phase-0: foundation, both apps boot end to end
Monorepo (pnpm workspaces) with two deployable apps and three pure packages. apps/api (Hono on Node): Zod validated env that fails fast and names the problem, Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable migrations covering the whole SPEC section 5 schema, Better Auth with the four roles and seeded demo accounts, localized error envelope, /healthz and /readyz, graceful SIGTERM drain. Dialect specific SQL is confined to the two factories. apps/web (Next.js App Router): locale routed shell in es and en with a language switcher, sign in screen, and a runtime /api proxy so the browser only ever sees one origin and cookies stay first party. packages/i18n ships both catalogs complete; es is generated from COPY.md and a test re-derives it from the document on every run so it cannot drift. packages/contracts holds the Zod schemas and the typed client the web app uses. Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck and lint clean, migrate and seed from a clean database, sign in through the proxy with CSRF rejection of foreign origins. Not verified here: docker compose. This user has no access to the docker socket. RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and no tax rule, check digit or deadline was invented. See DECISIONS.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,117 @@
|
||||
import js from '@eslint/js';
|
||||
import react from 'eslint-plugin-react';
|
||||
import reactHooks from 'eslint-plugin-react-hooks';
|
||||
import globals from 'globals';
|
||||
import tseslint from 'typescript-eslint';
|
||||
|
||||
export default tseslint.config(
|
||||
{
|
||||
ignores: ['**/dist/**', '**/.next/**', '**/node_modules/**', '**/coverage/**', '**/*.d.ts'],
|
||||
},
|
||||
|
||||
js.configs.recommended,
|
||||
...tseslint.configs.recommended,
|
||||
|
||||
{
|
||||
rules: {
|
||||
// `any` is allowed only with a written reason, per the build constraints.
|
||||
'@typescript-eslint/no-explicit-any': 'error',
|
||||
'@typescript-eslint/no-unused-vars': [
|
||||
'error',
|
||||
{ argsIgnorePattern: '^_', varsIgnorePattern: '^_' },
|
||||
],
|
||||
'@typescript-eslint/consistent-type-imports': ['error', { fixStyle: 'inline-type-imports' }],
|
||||
eqeqeq: ['error', 'always'],
|
||||
'no-console': 'off',
|
||||
},
|
||||
},
|
||||
|
||||
// Module boundaries, SPEC.md section 4.
|
||||
{
|
||||
files: ['packages/**/*.ts'],
|
||||
rules: {
|
||||
'no-restricted-imports': [
|
||||
'error',
|
||||
{
|
||||
patterns: [
|
||||
{
|
||||
group: ['**/apps/**', '@impuestos/api', '@impuestos/web'],
|
||||
message:
|
||||
'packages/* are pure and must not import from apps. Move the shared piece into a package.',
|
||||
},
|
||||
],
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
|
||||
{
|
||||
files: ['apps/api/src/**/*.ts'],
|
||||
languageOptions: { globals: globals.node },
|
||||
rules: {
|
||||
'no-restricted-imports': [
|
||||
'error',
|
||||
{
|
||||
patterns: [
|
||||
{
|
||||
// Only modules/pii may reach the pii tables. Everything else goes through
|
||||
// the functions that module exports, so PII access stays auditable.
|
||||
group: ['**/modules/pii/*', '!**/modules/pii/index'],
|
||||
message:
|
||||
'Import from modules/pii (its index) instead of reaching into the pii module.',
|
||||
},
|
||||
],
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
{
|
||||
files: ['apps/api/src/modules/pii/**/*.ts', 'apps/api/src/db/**/*.ts'],
|
||||
rules: { 'no-restricted-imports': 'off' },
|
||||
},
|
||||
|
||||
// The web app has no database access at all: it holds no DB dependency and may not
|
||||
// import one even transitively through a shared package.
|
||||
{
|
||||
files: ['apps/web/**/*.{ts,tsx}'],
|
||||
languageOptions: {
|
||||
globals: { ...globals.browser, ...globals.node },
|
||||
parserOptions: { ecmaFeatures: { jsx: true } },
|
||||
},
|
||||
plugins: { react, 'react-hooks': reactHooks },
|
||||
settings: { react: { version: 'detect' } },
|
||||
rules: {
|
||||
...reactHooks.configs.recommended.rules,
|
||||
'no-restricted-imports': [
|
||||
'error',
|
||||
{
|
||||
paths: [
|
||||
{ name: 'kysely', message: 'The web app never touches the database.' },
|
||||
{ name: 'better-sqlite3', message: 'The web app never touches the database.' },
|
||||
{ name: 'pg', message: 'The web app never touches the database.' },
|
||||
{
|
||||
name: 'better-auth',
|
||||
message: 'Auth server code lives in apps/api. Use better-auth/react here.',
|
||||
},
|
||||
],
|
||||
},
|
||||
],
|
||||
// Constraint 12: user facing copy comes from the catalogs, never inline.
|
||||
// Punctuation and separators are allowed so layout markup stays readable.
|
||||
'react/jsx-no-literals': [
|
||||
'error',
|
||||
{
|
||||
noStrings: true,
|
||||
allowedStrings: ['·', '/', '|', ':', ',', '.', '-', '+', '(', ')', '%', '✓'],
|
||||
ignoreProps: true,
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
|
||||
// Tests assert on real copy, so literals are the point there.
|
||||
{
|
||||
files: ['**/*.test.ts', '**/*.test.tsx', 'e2e/**/*.ts'],
|
||||
rules: { 'react/jsx-no-literals': 'off' },
|
||||
},
|
||||
);
|
||||
Reference in New Issue
Block a user