mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 06:53:18 +00:00
* feat(api): serve portal-shaped health and error envelope
Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.
* feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
* feat(web): add unused cookie SPA API client
Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.
* feat(api): add master-data OpenAPI and Hono stubs
* feat(api): add invoice, line, and document stubs
* feat(api): add approval policy, inbox, and activity stubs
* test(web): fix SPA client fetch mock types
* test(web): cast fetch mock call args for tsc
* fix(api): do not default DEV_AUTH_BYPASS outside local migrate
* fix(api): replace invoice lines in a single transaction
* fix(api): create invoices and lines in one transaction
* fix(api): inline GIT_SHA from the image build arg
* fix(api): stop PATCH from skipping the approval workflow
* fix(api): address review feedback
* fix(ci): format upsert-user test
* fix(api): document only the auth statuses the routes return
* fix(api): drop health 400 responses the routes never return
37 lines
1.1 KiB
Text
37 lines
1.1 KiB
Text
# Default data path until the API is wired (AP later tickets).
|
|
VITE_USE_MOCKS=true
|
|
|
|
# AP-22 visual parity uses Stampli wordmark when false/unset.
|
|
# AP-38 Sea Haven branding cutover: set true.
|
|
VITE_SEA_HAVEN_BRAND=false
|
|
|
|
# --- @seahaven-ap/api (AP-14) ---
|
|
API_PORT=8787
|
|
DATABASE_DRIVER=postgres
|
|
DATABASE_URL=postgresql://seahaven:seahaven@127.0.0.1:5432/seahaven_ap
|
|
|
|
# Local-only auth bypass. Allowed only when NODE_ENV is development or test.
|
|
DEV_AUTH_BYPASS=true
|
|
DEV_AUTH_SUB=seed-sub-admin
|
|
DEV_AUTH_EMAIL=admin@seahavenind.com
|
|
DEV_AUTH_NAME=Dev Admin
|
|
DEV_AUTH_ROLE=admin
|
|
|
|
# Cognito (required when DEV_AUTH_BYPASS=false)
|
|
# COGNITO_ISSUER=https://cognito-idp.us-east-1.amazonaws.com/<pool-id>
|
|
# COGNITO_AUDIENCE=<app-client-id>
|
|
# COGNITO_DOMAIN=<hosted-ui-domain>
|
|
# APP_ORIGIN=http://127.0.0.1:3000
|
|
# ORIGIN_VERIFY_SECRET=
|
|
|
|
# Aurora Data API driver (DATABASE_DRIVER=data-api)
|
|
# AWS_REGION=us-east-1
|
|
# RDS_CLUSTER_ARN=
|
|
# RDS_SECRET_ARN=
|
|
# RDS_DATABASE=seahaven_ap
|
|
|
|
# MinIO (docker compose) — used by AP-15 document uploads
|
|
MINIO_ENDPOINT=http://127.0.0.1:9000
|
|
MINIO_ACCESS_KEY=seahaven
|
|
MINIO_SECRET_KEY=seahavensecret
|
|
MINIO_BUCKET=seahaven-ap-documents
|