* feat(api): serve portal-shaped health and error envelope
Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.
* feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
* feat(web): add unused cookie SPA API client
Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.
* feat(api): add master-data OpenAPI and Hono stubs
* feat(api): add invoice, line, and document stubs
* feat(api): add approval policy, inbox, and activity stubs
* test(web): fix SPA client fetch mock types
* test(web): cast fetch mock call args for tsc
* fix(api): do not default DEV_AUTH_BYPASS outside local migrate
* fix(api): replace invoice lines in a single transaction
* fix(api): create invoices and lines in one transaction
* fix(api): inline GIT_SHA from the image build arg
* fix(api): stop PATCH from skipping the approval workflow
* fix(api): address review feedback
* fix(ci): format upsert-user test
* fix(api): document only the auth statuses the routes return
* fix(api): drop health 400 responses the routes never return
|
||
|---|---|---|
| .github | ||
| e2e | ||
| packages | ||
| public/fixtures | ||
| scripts | ||
| src | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| .npmrc | ||
| .prettierignore | ||
| .prettierrc | ||
| .redocly.lint-ignore.yaml | ||
| docker-compose.yml | ||
| Dockerfile | ||
| eslint.config.js | ||
| index.html | ||
| package-lock.json | ||
| package.json | ||
| playwright.config.ts | ||
| README.md | ||
| redocly.yaml | ||
| tsconfig.json | ||
| tsconfig.node.json | ||
| vite.config.ts | ||
| vitest.config.ts | ||
Sea Haven AP
Internal accounts payable automation for Sea Haven Industries. Local API is http://127.0.0.1:8787. CloudFront on seahaven-dev is the first hosted origin.
Workspace layout
npm workspaces:
@seahaven-ap/web— Vite/React SPA (repo root)@seahaven-ap/shared— payment ladder, invoice helpers, pay-date parsers, CSV constants (packages/shared)@seahaven-ap/api— Hono API, Drizzle schema, auth/RBAC (packages/api)
Local development
Frontend (mocks)
npm ci
cp .env.example .env # optional; defaults already use mocks
npm run dev
App serves at http://localhost:3000. VITE_USE_MOCKS=true is the default data path until AP-15 wires live API calls.
API + data plane (AP-14)
docker compose up -d
cp .env.example .env
npm run db:migrate
npm run db:seed
npm run dev:api
API listens on http://127.0.0.1:8787. Vite proxies /api to that port.
Smoke:
curl -s http://127.0.0.1:8787/api/health
curl -s http://127.0.0.1:8787/api/me
DEV_AUTH_BYPASS=true is local-only and only allowed when NODE_ENV is development or test (rejected for production, staging, preview, and any other value). Cookie session names are ap_* locally and __Host-ap_* outside local.
API roles (source of truth): admin, ap_processor, approver, viewer. Frontend mocks still use ap_operator until AP-15 remaps them.
OpenAPI / Redocly
Linting uses the same redocly.yaml ruleset as procurement-ingest.
npm run lint:api
npm run docs:preview # builds HTML via redocly build-docs and opens it
Verify
npm run verify
npm run test:e2e