Sea Haven AP — internal AP automation (ap.seahaven.com)
Find a file
Adam Moussa 864531b51e
feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64)
* feat(api): serve portal-shaped health and error envelope

Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.

* feat(api): switch live auth to host cookie BFF

Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.

* feat(web): add unused cookie SPA API client

Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.

* feat(api): add master-data OpenAPI and Hono stubs

* feat(api): add invoice, line, and document stubs

* feat(api): add approval policy, inbox, and activity stubs

* test(web): fix SPA client fetch mock types

* test(web): cast fetch mock call args for tsc

* fix(api): do not default DEV_AUTH_BYPASS outside local migrate

* fix(api): replace invoice lines in a single transaction

* fix(api): create invoices and lines in one transaction

* fix(api): inline GIT_SHA from the image build arg

* fix(api): stop PATCH from skipping the approval workflow

* fix(api): address review feedback

* fix(ci): format upsert-user test

* fix(api): document only the auth statuses the routes return

* fix(api): drop health 400 responses the routes never return
2026-09-25 22:43:44 +00:00
.github chore(deps): update sea-haven-industries/.github action to v1.0.11 (#60) 2026-09-14 17:46:09 +00:00
e2e feat(web): add minimal Filter slide-over for invoice processing (AP-46) (#19) 2026-09-25 22:35:10 +00:00
packages feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
public/fixtures feat(frontend): add invoice detail 3-pane shell (AP-6) (#9) 2026-08-10 22:22:22 +00:00
scripts feat(settings): add settings and approvals POC shells (AP-7) (#8) 2026-08-10 22:00:51 +00:00
src feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
.dockerignore feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
.env.example feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
.gitignore feat(shared): add payment ladder and CSV domain package (AP-13) (#11) 2026-08-10 19:28:02 -04:00
.npmrc feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
.prettierignore feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
.prettierrc feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
.redocly.lint-ignore.yaml feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
docker-compose.yml chore(deps): update postgres docker tag to v18 (#51) 2026-08-25 18:19:19 +00:00
Dockerfile feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
eslint.config.js feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
index.html feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
package-lock.json feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
package.json chore(deps): update dependency vitest to v5 (#63) 2026-09-25 22:39:24 +00:00
playwright.config.ts feat(web): fix shell chrome, logo home, and live nav badges (#14) 2026-08-14 12:28:35 -04:00
README.md feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
redocly.yaml feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
tsconfig.json feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
tsconfig.node.json feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
vite.config.ts feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
vitest.config.ts feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00

Sea Haven AP

Internal accounts payable automation for Sea Haven Industries. Local API is http://127.0.0.1:8787. CloudFront on seahaven-dev is the first hosted origin.

Workspace layout

npm workspaces:

  • @seahaven-ap/web — Vite/React SPA (repo root)
  • @seahaven-ap/shared — payment ladder, invoice helpers, pay-date parsers, CSV constants (packages/shared)
  • @seahaven-ap/api — Hono API, Drizzle schema, auth/RBAC (packages/api)

Local development

Frontend (mocks)

npm ci
cp .env.example .env   # optional; defaults already use mocks
npm run dev

App serves at http://localhost:3000. VITE_USE_MOCKS=true is the default data path until AP-15 wires live API calls.

API + data plane (AP-14)

docker compose up -d
cp .env.example .env
npm run db:migrate
npm run db:seed
npm run dev:api

API listens on http://127.0.0.1:8787. Vite proxies /api to that port.

Smoke:

curl -s http://127.0.0.1:8787/api/health
curl -s http://127.0.0.1:8787/api/me

DEV_AUTH_BYPASS=true is local-only and only allowed when NODE_ENV is development or test (rejected for production, staging, preview, and any other value). Cookie session names are ap_* locally and __Host-ap_* outside local.

API roles (source of truth): admin, ap_processor, approver, viewer. Frontend mocks still use ap_operator until AP-15 remaps them.

OpenAPI / Redocly

Linting uses the same redocly.yaml ruleset as procurement-ingest.

npm run lint:api
npm run docs:preview   # builds HTML via redocly build-docs and opens it

Verify

npm run verify
npm run test:e2e