Commit Graph
66 Commits
Author SHA1 Message Date
yeuimu 1ef82c4c14 fix(admin): proxy /api/docs without prefix strip so Swagger UI works through vite dev server 2026-08-28 17:43:41 +08:00
yeuimu f07e843130 fix(admin): move family union tabs to the bottom of edit dialog 2026-08-28 17:37:58 +08:00
yeuimu c7e6c35fbf feat(admin): family-level size/package/SKU union tabs in edit dialog; searchable merge-sibling list in config dialog 2026-08-28 17:26:41 +08:00
yeuimu 7c85f7fe9f fix(admin): config dialog lists all same-category sibling links (incl. configured); drop merge tip text 2026-08-28 17:11:36 +08:00
yeuimu c2d50c9fa3 fix(admin): restore session via /auth/me in router guard (refresh no longer logs out); simplify member price table (no title/source/action columns) 2026-08-28 17:02:25 +08:00
yeuimu f28f51155f feat(goods): per-member detail tabs in edit dialog; revert right-tree to raw names; split configured/family badges; add GET /origin-goods/:id 2026-08-28 16:55:07 +08:00
yeuimu 10197c47a8 refactor(admin): split GoodsView into dialog components; fix(GoodsView): raw member names, no primary badges, member price grid; feat(tag): 光板 maps to 不打印 2026-08-28 16:40:48 +08:00
yeuimu 6f22a6fd1f feat(admin): expandable family members with per-link tag config + SKU pricing dims columns 2026-08-28 16:00:46 +08:00
yeuimu 08201f18a4 feat(product-family): link-level tags (origin_good_tags) with manual override + member detail enrichment 2026-08-28 16:00:46 +08:00
yeuimu 1128167aef feat(admin): family-aware goods view - auto tags readonly, clean link names, config badges, locate highlight 2026-08-28 15:33:11 +08:00
yeuimu ee336968a0 feat(product-family): derive tags per link name (印花数量/工艺/物流 rules) 2026-08-28 15:33:11 +08:00
yeuimu f5a3b8c840 merge: bring in public media/variant dedup from origin/develop (local only) 2026-08-28 15:15:17 +08:00
yeuimu eedfbb344e feat(product-family): auto-derive logistics/craft tags from family members 2026-08-28 14:57:25 +08:00
yeuimu 353e51e871 revert(admin): restore original layout, replace primary/secondary source UI with family members 2026-08-28 14:35:34 +08:00
yeuimu 7b17fff86f fix(admin): fail loudly when dev port 5173 is occupied 2026-08-28 14:21:37 +08:00
yeuimu 4eadb67c36 feat(product-family): replace legacy good merge with family mechanism in config view and public detail 2026-08-28 14:14:58 +08:00
yeuimu 6418aa7302 feat(api): public good detail family block behind gray-release flag 2026-08-28 13:40:19 +08:00
yeuimu b4b9fbbe60 feat(api): good family_id column with backfill 2026-08-28 13:34:42 +08:00
yeuimu fd7ca5d53f feat(admin): goods view family badges and sibling matching 2026-08-28 13:29:54 +08:00
yeuimu 07f3134f79 feat(admin): product family management tab 2026-08-28 13:28:37 +08:00
yeuimu dcd2b235b9 feat(admin): family match util 2026-08-28 13:25:31 +08:00
yeuimu c492469d70 feat(admin): product families api client and types 2026-08-28 13:25:10 +08:00
yeuimu ab450c350e fix(api): tolerant member attach in auto-group under concurrent cleanup 2026-08-28 12:52:22 +08:00
yeuimu 502b7eba6e docs: update references for product families; fix controller import and test isolation 2026-08-28 12:50:42 +08:00
yeuimu c8531bfe08 feat(api): category-based family grouping, tree family info and custom goods family attribution 2026-08-28 12:43:58 +08:00
yeuimu d63f1a6f35 feat(api): product families backfill script 2026-08-28 12:36:39 +08:00
yeuimu d20a933e34 feat(api): sync hooks for parsing, auto-attach and family recompute 2026-08-28 12:33:33 +08:00
yeuimu f68898dea4 feat(api): product families module with CRUD, auto-group, members, custom members and price overrides 2026-08-28 12:30:57 +08:00
yeuimu de0f5509b1 feat(api): add family recompute service with union and price matrix 2026-08-28 12:27:29 +08:00
yeuimu c07b28def7 feat(api): add product_families schema and migration 2026-08-28 12:24:24 +08:00
yeuimu 60946b5f64 feat(api): add origin good name parser 2026-08-28 12:23:35 +08:00
yeuimu 270e516f94 fix(public): media images are objects ({id,url,sortOrder}) - handle both shapes in mergeMedia 2026-08-28 11:22:53 +08:00
yeuimu d826c5bdd4 feat(public): merge secondary media gallery images with URL dedup 2026-08-28 11:19:27 +08:00
yeuimu 457792b729 feat(public): dedupe merged variants and merge specs/options from secondary origins 2026-08-28 11:05:34 +08:00
yeuimu 8233dda07a fix(admin): initial goods load also uses pageSize 1000 2026-08-28 09:49:40 +08:00
yeuimu cbdb507be9 fix(api): allow pageSize up to 1000 so admin goods tree can load full list 2026-08-28 09:36:15 +08:00
yeuimu b3bd10de06 fix(admin): load all goods in left tree (pageSize 1000) so low-priority new goods are searchable 2026-08-28 09:31:02 +08:00
yeuimu ac29a0c7bf feat(admin): show merged count badge on good nodes 2026-08-27 18:45:51 +08:00
yeuimu ac3a39f40d feat(admin): manage merged origin goods in good edit modal 2026-08-27 18:43:30 +08:00
yeuimu 491e74b905 feat(admin): add origin name grouping utils with vitest coverage 2026-08-27 18:40:22 +08:00
yeuimu 0aa6cbf1d9 feat(admin): suggest and merge sibling origin goods in config modal 2026-08-27 18:40:13 +08:00
yeuimu 697b82a64b fix(admin): resolve pre-existing template type errors blocking build 2026-08-27 18:40:08 +08:00
yeuimu f06dfffbda feat(public): resolve goods by secondary sds id and merge variants 2026-08-27 18:20:25 +08:00
yeuimu d9ecd04747 feat(origin-goods): include merged secondary references in tree stats 2026-08-27 18:18:29 +08:00
yeuimu 9c279ae393 feat(goods): support merged secondary origin goods in create/update/detail 2026-08-27 18:15:56 +08:00
yeuimu 848eed0b6f feat(db): add good_origin_goods junction table for merged origin goods 2026-08-27 18:09:00 +08:00
yeuimu 6c61a4e871 feat(deploy): production deployment setup and fixes
- Debian-based api image (bookworm-slim), docker/debian mirrors, prisma
  binaryTargets for openssl 3.0
- nginx: admin SPA under /admin, TLS via acme.sh (ZeroSSL) + auto-renewal
  cron, http->https redirect
- prisma: add origin_goods.delisted migration, sync missing schema
  (good_image/tag_font_color/good_tags), fix users.createdAt Timestamptz
- api: CORS wildcard reflection, helmet CORP cross-origin, price
  backfill in persistProductDetail, categoryIcon ancestor fallback,
  mediaByColor per-color gallery in public goods detail
- admin: /admin base path (vite + router)
- import-data.mjs: udt_name casting, serial sequence advance fix
2026-08-26 14:23:09 +08:00
yeuimu be0b90e68f feat(security): HttpOnly cookie sessions, token revocation, and RBAC
- Add User.role (enum Role/ADMIN) and User.tokenVersion with migration
- Login now issues short-lived access token (30m default) + 7d refresh
  token, both embedding tokenVersion and a typ discriminator
- Tokens delivered via HttpOnly SameSite cookies (ir_at, ir_rt scoped
  to /auth); refresh token never leaves the cookie
- New endpoints: POST /auth/refresh (rotation), GET /auth/me,
  POST /auth/logout (bumps tokenVersion, revoking all tokens)
- JWT strategy accepts bearer or cookie, rejects refresh tokens, and
  verifies tokenVersion + user existence on every request
- Global RolesGuard: authenticated routes require ADMIN unless widened
  via @Roles(...)
- Admin SPA: session fully cookie-based, no token in localStorage;
  router guard restores session via /auth/me; axios auto-refreshes once
  on 401; stale localStorage keys cleaned up
2026-08-22 12:04:56 +08:00
yeuimu 9c1106586a fix(security): harden auth, upload, and API configuration
- Lock public registration to first-user bootstrap (403 afterwards)
- Require JwtAuthGuard on upload + whitelist png/jpg/webp/gif (SVG/XSS blocked)
- Add global throttling (login/register 5/min, upload 10/min)
- Add helmet security headers; serve uploads with nosniff
- Replace permissive CORS (origin:true+credentials) with CORS_ORIGINS whitelist
- Disable Swagger outside development; sanitize 500 error responses
- Enforce 32+ char JWT_SECRET; make token expiry configurable (TOKEN_EXPIRES_IN)
- Re-check user in DB on every JWT validation (revocation on user delete)
- Dummy bcrypt compare to prevent login user-enumeration via timing
- Map malformed BigInt inputs to 400 instead of 500
- Widen .gitignore to .env* and add apps/api/.env.example
- Disable Nuxt devtools and sourcemaps
2026-08-22 11:55:13 +08:00
yeuimu 9ed569f5bc fix(admin): simplify product forms 2026-08-21 14:54:08 +08:00