mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 09:13:17 +00:00
* feat(api): serve portal-shaped health and error envelope
Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.
* feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
* feat(web): add unused cookie SPA API client
Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.
* feat(api): add master-data OpenAPI and Hono stubs
* feat(api): add invoice, line, and document stubs
* feat(api): add approval policy, inbox, and activity stubs
* test(web): fix SPA client fetch mock types
* test(web): cast fetch mock call args for tsc
* fix(api): do not default DEV_AUTH_BYPASS outside local migrate
* fix(api): replace invoice lines in a single transaction
* fix(api): create invoices and lines in one transaction
* fix(api): inline GIT_SHA from the image build arg
* fix(api): stop PATCH from skipping the approval workflow
* fix(api): address review feedback
* fix(ci): format upsert-user test
* fix(api): document only the auth statuses the routes return
* fix(api): drop health 400 responses the routes never return
32 lines
836 B
YAML
32 lines
836 B
YAML
get:
|
|
tags:
|
|
- Session
|
|
summary: Complete hosted UI sign-in
|
|
description: Exchanges the authorization code, sets HttpOnly session cookies, and redirects to returnTo.
|
|
operationId: get-api-auth-callback
|
|
security: []
|
|
parameters:
|
|
- name: code
|
|
in: query
|
|
required: false
|
|
description: Authorization code from Cognito.
|
|
schema:
|
|
type: string
|
|
example: abcdef
|
|
- name: state
|
|
in: query
|
|
required: false
|
|
description: PKCE state echoed from login.
|
|
schema:
|
|
type: string
|
|
example: state-token
|
|
- name: error
|
|
in: query
|
|
required: false
|
|
description: Cognito error code when sign-in failed.
|
|
schema:
|
|
type: string
|
|
example: access_denied
|
|
responses:
|
|
"302":
|
|
description: Redirect to the SPA or the login error page.
|