seahaven-ap/README.md
Adam Moussa 9d3646876e
feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12)
* feat(api): stand up Hono Drizzle foundation with auth and Redocly

* fix(api): bump drizzle-orm and hono node-server past audit highs

* fix(api): harden auth upsert and Cognito token verification
2026-08-11 00:10:49 +00:00

1.5 KiB

Sea Haven AP

Internal accounts payable automation for Sea Haven Industries (ap.seahaven.com).

Workspace layout

npm workspaces:

  • @seahaven-ap/web — Vite/React SPA (repo root)
  • @seahaven-ap/shared — payment ladder, invoice helpers, pay-date parsers, CSV constants (packages/shared)
  • @seahaven-ap/api — Hono API, Drizzle schema, auth/RBAC (packages/api)

Local development

Frontend (mocks)

npm ci
cp .env.example .env   # optional; defaults already use mocks
npm run dev

App serves at http://localhost:3000. VITE_USE_MOCKS=true is the default data path until AP-15 wires live API calls.

API + data plane (AP-14)

docker compose up -d
cp .env.example .env
npm run db:migrate
npm run db:seed
npm run dev:api

API listens on http://127.0.0.1:8787. Vite proxies /api to that port.

Smoke:

curl -s http://127.0.0.1:8787/health
curl -s http://127.0.0.1:8787/api/me

DEV_AUTH_BYPASS=true is local-only and only allowed when NODE_ENV is development or test (rejected for production, staging, preview, and any other value).

API roles (source of truth): admin, ap_processor, approver, viewer. Frontend mocks still use ap_operator until AP-15 remaps them.

OpenAPI / Redocly

Linting uses the same redocly.yaml ruleset as procurement-ingest.

npm run lint:api
npm run docs:preview   # builds HTML via redocly build-docs and opens it

Verify

npm run verify
npm run test:e2e