yeuimu
8233dda07a
fix(admin): initial goods load also uses pageSize 1000
2026-08-28 09:49:40 +08:00
yeuimu
b3bd10de06
fix(admin): load all goods in left tree (pageSize 1000) so low-priority new goods are searchable
2026-08-28 09:31:02 +08:00
yeuimu
ac29a0c7bf
feat(admin): show merged count badge on good nodes
2026-08-27 18:45:51 +08:00
yeuimu
ac3a39f40d
feat(admin): manage merged origin goods in good edit modal
2026-08-27 18:43:30 +08:00
yeuimu
491e74b905
feat(admin): add origin name grouping utils with vitest coverage
2026-08-27 18:40:22 +08:00
yeuimu
0aa6cbf1d9
feat(admin): suggest and merge sibling origin goods in config modal
2026-08-27 18:40:13 +08:00
yeuimu
697b82a64b
fix(admin): resolve pre-existing template type errors blocking build
2026-08-27 18:40:08 +08:00
yeuimu
6c61a4e871
feat(deploy): production deployment setup and fixes
...
- Debian-based api image (bookworm-slim), docker/debian mirrors, prisma
binaryTargets for openssl 3.0
- nginx: admin SPA under /admin, TLS via acme.sh (ZeroSSL) + auto-renewal
cron, http->https redirect
- prisma: add origin_goods.delisted migration, sync missing schema
(good_image/tag_font_color/good_tags), fix users.createdAt Timestamptz
- api: CORS wildcard reflection, helmet CORP cross-origin, price
backfill in persistProductDetail, categoryIcon ancestor fallback,
mediaByColor per-color gallery in public goods detail
- admin: /admin base path (vite + router)
- import-data.mjs: udt_name casting, serial sequence advance fix
2026-08-26 14:23:09 +08:00
yeuimu
be0b90e68f
feat(security): HttpOnly cookie sessions, token revocation, and RBAC
...
- Add User.role (enum Role/ADMIN) and User.tokenVersion with migration
- Login now issues short-lived access token (30m default) + 7d refresh
token, both embedding tokenVersion and a typ discriminator
- Tokens delivered via HttpOnly SameSite cookies (ir_at, ir_rt scoped
to /auth); refresh token never leaves the cookie
- New endpoints: POST /auth/refresh (rotation), GET /auth/me,
POST /auth/logout (bumps tokenVersion, revoking all tokens)
- JWT strategy accepts bearer or cookie, rejects refresh tokens, and
verifies tokenVersion + user existence on every request
- Global RolesGuard: authenticated routes require ADMIN unless widened
via @Roles(...)
- Admin SPA: session fully cookie-based, no token in localStorage;
router guard restores session via /auth/me; axios auto-refreshes once
on 401; stale localStorage keys cleaned up
2026-08-22 12:04:56 +08:00
yeuimu
9ed569f5bc
fix(admin): simplify product forms
2026-08-21 14:54:08 +08:00
yeuimu
b04623ebdd
feat(goods): add editable custom products
2026-08-21 14:45:42 +08:00
yeuimu
a4151607c5
fix(sync): hydrate all origin product details
2026-08-21 14:05:15 +08:00
yeuimu
a43353aa98
fix(dev): support admin access over LAN
2026-08-21 10:53:47 +08:00
yeuimu
6e5f7edbb7
chore: update admin generated types and env ignore
2026-08-21 10:39:23 +08:00
yeuimu
d375df810d
feat(admin): manage and sync product details
2026-08-21 10:18:57 +08:00
yeuimu
fcbf8bb494
chore: stop tracking env files (.env, .env.development)
...
Credentials and per-environment config should not be committed.
Files stay on disk locally; .gitignore now covers .env.development.
2026-08-20 18:44:44 +08:00
yeuimu
79fabd85f7
feat(product-center): implement Figma-designed UI, upload module, and website tests
...
- Redesign website homepage & product-center per Figma (fonts, logos, hero/footer/customer cases)
- Add API upload module (multer) with static serving for uploads/public assets
- Add OriginGood.delisted flag and SDS request retry logic
- Add admin ImageUpload component and goods import/upload flows
- Add vitest suite for website components and composables (32 tests)
- Add skills, docs, plans and PRODUCT.md
2026-08-20 14:32:03 +08:00
yeuimu
7e04877bb6
chore: migrate to pnpm workspaces monorepo with Turborepo
...
- Restructure directories: apps/api, apps/admin, apps/website
- Add root pnpm-workspace.yaml, turbo.json, .prettierrc, .gitignore
- Rename packages to @inkreach/api, @inkreach/admin, @inkreach/website
- Add shared packages: packages/tsconfig, packages/shared-types
- Add pnpm.onlyBuiltDependencies for native builds
- Update docs: README.md, structs.md
- All three projects build successfully
2026-07-11 16:54:05 +08:00