seahaven-ap/packages/api/docs/local-dev.md
Adam Moussa 864531b51e
feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64)
* feat(api): serve portal-shaped health and error envelope

Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.

* feat(api): switch live auth to host cookie BFF

Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.

* feat(web): add unused cookie SPA API client

Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.

* feat(api): add master-data OpenAPI and Hono stubs

* feat(api): add invoice, line, and document stubs

* feat(api): add approval policy, inbox, and activity stubs

* test(web): fix SPA client fetch mock types

* test(web): cast fetch mock call args for tsc

* fix(api): do not default DEV_AUTH_BYPASS outside local migrate

* fix(api): replace invoice lines in a single transaction

* fix(api): create invoices and lines in one transaction

* fix(api): inline GIT_SHA from the image build arg

* fix(api): stop PATCH from skipping the approval workflow

* fix(api): address review feedback

* fix(ci): format upsert-user test

* fix(api): document only the auth statuses the routes return

* fix(api): drop health 400 responses the routes never return
2026-09-25 22:43:44 +00:00

851 B

Local development

Data plane

docker compose up -d
npm run db:migrate
npm run db:seed
npm run dev:api

Defaults:

  • Postgres at postgresql://seahaven:seahaven@127.0.0.1:5432/seahaven_ap
  • API at http://127.0.0.1:8787
  • MinIO at http://127.0.0.1:9000 (documents bucket for AP-15)

Smoke

curl -s http://127.0.0.1:8787/api/health
curl -s http://127.0.0.1:8787/api/me

With DEV_AUTH_BYPASS=true and NODE_ENV=development (or test), /api/me does not require a Bearer token. Bypass is rejected for staging, preview, production, and any other NODE_ENV.

Docs

npm run lint:api
npm run docs:preview

docs:preview runs redocly build-docs (CLI v2) and opens the HTML at /tmp/seahaven-ap-api-docs.html. OpenAPI servers point at http://127.0.0.1:8787. Use this page for the local docs view.