yeuimu
fdfe435ecd
fix(admin): config dialog merge candidates search globally by name group
...
合并同名候选不再局限于当前分类节点:collectSiblings 改为按名称 3 段组键
(sameOriginGroup)遍历整棵右树收集同款链接(含已配置,勾选归族幂等),
跨分类的同款链接(如 BRTF004 分布在多个分类组)也能勾选归族
2026-08-28 20:04:29 +08:00
yeuimu
a14b8ecf4a
merge: feat/country-sort-and-sync-btn-dev into develop (local only, not pushed)
2026-08-28 20:01:04 +08:00
yeuimu
1e07c62fc8
feat(admin): country drag-sort + always-available member detail sync
...
- Country 加 sort_order(默认 0 保持 id 序);PATCH /countries/sort 批量保存
顺序(对齐 /tags/sort 模式);findAll 与公开 /public/countries 均按
sortOrder 排序
- CountriesView 表格改为可拖拽行列表:拖动松开即全量保存新顺序,失败回滚
- 商品编辑弹窗成员展开面板:同步详情按钮常驻(已同步显示 重新同步详情),
不再只在未同步态出现
- goods.service.spec 的 FamilyRecomputeService mock 补齐 syncFamilyTags 等
方法(全量并行时其他套件的扫名归族会把本套件夹具收进族,create/update
会调用到,mock 缺方法导致偶发 TypeError)
- api 164/164、admin typecheck+22/22+构建全绿
2026-08-28 20:00:56 +08:00
yeuimu
77f9c05346
merge: fix/tree-badge-family-aware-dev into develop (local only, not pushed)
2026-08-28 19:16:22 +08:00
yeuimu
fe6ab3825d
fix(admin): family-aware right-tree badges; flatten union size-chart cells
...
- 右树徽标/定位/配置按钮改按族语义:族内任一链接已配置 → 全族显示绿色
已配置(本链接未单独建商品时标题注明并入该款),配置入口在全族未配置时
才出现;拖拽已配置族链接配置时拦截提示(公开契约一族一款,重复商品官网
不可见);分组头计数与仅未配置筛选同步族感知(AUTM003/DG120 场景)
- 编辑弹窗族级尺码表把 measurements 数组摊平成列键(与成员级渲染一致),
修复列头在、格子全空的问题
2026-08-28 19:16:15 +08:00
yeuimu
8a6db1bdee
docs(agents): lessons — stop dev server before full jest; Chinese sort assertions
2026-08-28 18:51:22 +08:00
yeuimu
d0102ec4e8
merge: feature/public-family-id-dev home-goods test into develop (local only, not pushed)
2026-08-28 18:44:25 +08:00
yeuimu
63b436fe41
test(public): cover home-goods family dedupe
2026-08-28 18:44:24 +08:00
yeuimu
5a7a2841de
merge: feature/public-family-id-dev into develop (local only, not pushed)
2026-08-28 18:43:33 +08:00
yeuimu
8a052773cd
feat(public): family-first contract — goodId=familyId, strict 5-dim price matrix
...
公开契约族化(前端只需知道款号/族):
- GET /public/goods 一族一条(goodId=族ID,price=族起价,分页作用于分组后);
无族商品(自定义)不进任何公开端点(列表/首页/分类树/标签统计)
- GET /public/goods/:goodId 仅认族 ID;公共字段取代表 Good,变体=全体成员并集,
尺码表/包装规格=族物化并集;旧 SDS 链接 ID 寻址 404
- priceMatrix 严格五维:尺码×颜色×印花数量×工艺×物流;维度来源改为链接级
标签(人工接管按人工标签),弃用原始 craftLabel;CUSTOM 成员尊重显式标签
- 名称派生补裸「单面/双面」写法(直喷双面→双面印花+直喷,18 条存量链接修复)
- family_price_overrides 加 print_count 列(五键唯一),PUT/DELETE/校验五键化
- admin 编辑弹窗矩阵消费适配(SKU 列直读 printCount,成员格子三维匹配,
改价 payload 带 printCount)
- 存量 339 族已全量重算;api 162/162、admin 22/22、双端构建绿
2026-08-28 18:43:30 +08:00
yeuimu
e5ec022834
merge: fix/swagger-csp-dev into develop (local only, not pushed)
2026-08-28 17:50:39 +08:00
yeuimu
e018f16d0b
fix(api): drop helmet CSP upgrade-insecure-requests so Swagger UI loads over plain http
2026-08-28 17:50:39 +08:00
yeuimu
b055aedd3e
merge: fix/swagger-proxy-dev into develop (local only, not pushed)
2026-08-28 17:43:41 +08:00
yeuimu
1ef82c4c14
fix(admin): proxy /api/docs without prefix strip so Swagger UI works through vite dev server
2026-08-28 17:43:41 +08:00
yeuimu
f07e843130
fix(admin): move family union tabs to the bottom of edit dialog
2026-08-28 17:37:58 +08:00
yeuimu
6054cb556a
docs: family union tabs and searchable merge list
2026-08-28 17:27:53 +08:00
yeuimu
d4515631b1
merge: feat/family-detail-tabs-dev into develop (local only, not pushed)
2026-08-28 17:26:41 +08:00
yeuimu
c7e6c35fbf
feat(admin): family-level size/package/SKU union tabs in edit dialog; searchable merge-sibling list in config dialog
2026-08-28 17:26:41 +08:00
yeuimu
6d9305b878
merge: fix/config-dialog-siblings-dev into develop (local only, not pushed)
2026-08-28 17:11:36 +08:00
yeuimu
7c85f7fe9f
fix(admin): config dialog lists all same-category sibling links (incl. configured); drop merge tip text
2026-08-28 17:11:36 +08:00
yeuimu
f280b1daf5
docs: reflect simplified member price table
2026-08-28 17:03:12 +08:00
yeuimu
d67858c69b
merge: fix/session-restore-and-price-table-dev into develop (local only, not pushed)
2026-08-28 17:02:26 +08:00
yeuimu
c2d50c9fa3
fix(admin): restore session via /auth/me in router guard (refresh no longer logs out); simplify member price table (no title/source/action columns)
2026-08-28 17:02:25 +08:00
yeuimu
9863346c6d
merge: fix/goods-view-feedback-dev into develop (local only, not pushed)
2026-08-28 16:55:08 +08:00
yeuimu
f28f51155f
feat(goods): per-member detail tabs in edit dialog; revert right-tree to raw names; split configured/family badges; add GET /origin-goods/:id
2026-08-28 16:55:07 +08:00
yeuimu
753b554413
merge: feature/goods-dialog-split-dev into develop (local only, not pushed)
2026-08-28 16:40:48 +08:00
yeuimu
10197c47a8
refactor(admin): split GoodsView into dialog components; fix(GoodsView): raw member names, no primary badges, member price grid; feat(tag): 光板 maps to 不打印
2026-08-28 16:40:48 +08:00
yeuimu
34d84a7a7c
merge: feature/link-tags-and-sku-dims-dev into develop (local only, not pushed)
2026-08-28 16:00:52 +08:00
yeuimu
6f22a6fd1f
feat(admin): expandable family members with per-link tag config + SKU pricing dims columns
2026-08-28 16:00:46 +08:00
yeuimu
08201f18a4
feat(product-family): link-level tags (origin_good_tags) with manual override + member detail enrichment
2026-08-28 16:00:46 +08:00
yeuimu
37b52c5ebb
merge: feature/family-link-tags-ui-dev into develop (local only, not pushed)
2026-08-28 15:33:17 +08:00
yeuimu
1128167aef
feat(admin): family-aware goods view - auto tags readonly, clean link names, config badges, locate highlight
2026-08-28 15:33:11 +08:00
yeuimu
ee336968a0
feat(product-family): derive tags per link name (印花数量/工艺/物流 rules)
2026-08-28 15:33:11 +08:00
yeuimu
f5a3b8c840
merge: bring in public media/variant dedup from origin/develop (local only)
2026-08-28 15:15:17 +08:00
yeuimu
6395d9e6ab
feat(product-family): family-derived tags replace manual logistics/craft tagging
2026-08-28 14:57:26 +08:00
yeuimu
eedfbb344e
feat(product-family): auto-derive logistics/craft tags from family members
2026-08-28 14:57:25 +08:00
yeuimu
a13931c84c
revert(admin): keep original admin layout with family replacing primary/secondary sources
2026-08-28 14:35:34 +08:00
yeuimu
353e51e871
revert(admin): restore original layout, replace primary/secondary source UI with family members
2026-08-28 14:35:34 +08:00
yeuimu
7b17fff86f
fix(admin): fail loudly when dev port 5173 is occupied
2026-08-28 14:21:37 +08:00
yeuimu
f919577ddd
feat(product-family): goods view family integration, family-based public variant union
2026-08-28 14:14:59 +08:00
yeuimu
4eadb67c36
feat(product-family): replace legacy good merge with family mechanism in config view and public detail
2026-08-28 14:14:58 +08:00
yeuimu
14c53504f0
feat(product-family): public detail family block and good family derivation
2026-08-28 13:40:19 +08:00
yeuimu
6418aa7302
feat(api): public good detail family block behind gray-release flag
2026-08-28 13:40:19 +08:00
yeuimu
b4b9fbbe60
feat(api): good family_id column with backfill
2026-08-28 13:34:42 +08:00
yeuimu
ba3c6d2d4f
feat(admin): product family management tab, price override matrix and family grouping
2026-08-28 13:30:38 +08:00
yeuimu
d70a03f6fa
docs: admin product family references
2026-08-28 13:30:37 +08:00
yeuimu
fd7ca5d53f
feat(admin): goods view family badges and sibling matching
2026-08-28 13:29:54 +08:00
yeuimu
07f3134f79
feat(admin): product family management tab
2026-08-28 13:28:37 +08:00
yeuimu
dcd2b235b9
feat(admin): family match util
2026-08-28 13:25:31 +08:00
yeuimu
c492469d70
feat(admin): product families api client and types
2026-08-28 13:25:10 +08:00
yeuimu
8fad8de73e
docs(agents): add lessons for db drift resolution and shared-db test isolation
2026-08-28 12:53:10 +08:00
yeuimu
e49eebcedd
fix(product-family): tolerant auto-group member attach
2026-08-28 12:52:22 +08:00
yeuimu
ab450c350e
fix(api): tolerant member attach in auto-group under concurrent cleanup
2026-08-28 12:52:22 +08:00
yeuimu
f7c4252a91
feat(product-family): merge SPU family layer phase-1 backend
2026-08-28 12:50:49 +08:00
yeuimu
502b7eba6e
docs: update references for product families; fix controller import and test isolation
2026-08-28 12:50:42 +08:00
yeuimu
c8531bfe08
feat(api): category-based family grouping, tree family info and custom goods family attribution
2026-08-28 12:43:58 +08:00
yeuimu
d63f1a6f35
feat(api): product families backfill script
2026-08-28 12:36:39 +08:00
yeuimu
d20a933e34
feat(api): sync hooks for parsing, auto-attach and family recompute
2026-08-28 12:33:33 +08:00
yeuimu
f68898dea4
feat(api): product families module with CRUD, auto-group, members, custom members and price overrides
2026-08-28 12:30:57 +08:00
yeuimu
de0f5509b1
feat(api): add family recompute service with union and price matrix
2026-08-28 12:27:29 +08:00
yeuimu
c07b28def7
feat(api): add product_families schema and migration
2026-08-28 12:24:24 +08:00
yeuimu
60946b5f64
feat(api): add origin good name parser
2026-08-28 12:23:35 +08:00
yeuimu
37b45a4679
docs(plans): add product family merge phase-1 implementation plan
2026-08-28 12:22:23 +08:00
yeuimu
573549eb15
docs(specs): reuse public endpoints and include admin frontend scope
2026-08-28 12:04:35 +08:00
yeuimu
14d77fbab2
docs(specs): allow manual price overrides and custom family members
2026-08-28 12:01:13 +08:00
yeuimu
1186d615e2
docs(specs): add product family merge design
2026-08-28 11:45:18 +08:00
yeuimu
270e516f94
fix(public): media images are objects ({id,url,sortOrder}) - handle both shapes in mergeMedia
2026-08-28 11:22:53 +08:00
yeuimu
d826c5bdd4
feat(public): merge secondary media gallery images with URL dedup
2026-08-28 11:19:27 +08:00
yeuimu
457792b729
feat(public): dedupe merged variants and merge specs/options from secondary origins
2026-08-28 11:05:34 +08:00
yeuimu
8233dda07a
fix(admin): initial goods load also uses pageSize 1000
2026-08-28 09:49:40 +08:00
yeuimu
cbdb507be9
fix(api): allow pageSize up to 1000 so admin goods tree can load full list
2026-08-28 09:36:15 +08:00
yeuimu
b3bd10de06
fix(admin): load all goods in left tree (pageSize 1000) so low-priority new goods are searchable
2026-08-28 09:31:02 +08:00
yeuimu
e7582bbd6e
fix(deploy): add .dockerignore so host node_modules does not break image build
2026-08-27 19:13:57 +08:00
yeuimu
4c50189538
merge: multi-origin-good-merge-zll into develop
2026-08-27 18:51:28 +08:00
yeuimu
4bebb9e4b2
docs: document merged origin goods feature
2026-08-27 18:49:17 +08:00
yeuimu
ac29a0c7bf
feat(admin): show merged count badge on good nodes
2026-08-27 18:45:51 +08:00
yeuimu
ac3a39f40d
feat(admin): manage merged origin goods in good edit modal
2026-08-27 18:43:30 +08:00
yeuimu
491e74b905
feat(admin): add origin name grouping utils with vitest coverage
2026-08-27 18:40:22 +08:00
yeuimu
0aa6cbf1d9
feat(admin): suggest and merge sibling origin goods in config modal
2026-08-27 18:40:13 +08:00
yeuimu
697b82a64b
fix(admin): resolve pre-existing template type errors blocking build
2026-08-27 18:40:08 +08:00
yeuimu
f06dfffbda
feat(public): resolve goods by secondary sds id and merge variants
2026-08-27 18:20:25 +08:00
yeuimu
d9ecd04747
feat(origin-goods): include merged secondary references in tree stats
2026-08-27 18:18:29 +08:00
yeuimu
9c279ae393
feat(goods): support merged secondary origin goods in create/update/detail
2026-08-27 18:15:56 +08:00
yeuimu
848eed0b6f
feat(db): add good_origin_goods junction table for merged origin goods
2026-08-27 18:09:00 +08:00
yeuimu
043d2463a6
docs(plan): add multi origin good merge design and implementation plan
2026-08-27 17:08:06 +08:00
yeuimu
005ab5b585
chore: restore files unintentionally deleted in 6c61a4e
2026-08-26 17:54:35 +08:00
yeuimu
6c61a4e871
feat(deploy): production deployment setup and fixes
...
- Debian-based api image (bookworm-slim), docker/debian mirrors, prisma
binaryTargets for openssl 3.0
- nginx: admin SPA under /admin, TLS via acme.sh (ZeroSSL) + auto-renewal
cron, http->https redirect
- prisma: add origin_goods.delisted migration, sync missing schema
(good_image/tag_font_color/good_tags), fix users.createdAt Timestamptz
- api: CORS wildcard reflection, helmet CORP cross-origin, price
backfill in persistProductDetail, categoryIcon ancestor fallback,
mediaByColor per-color gallery in public goods detail
- admin: /admin base path (vite + router)
- import-data.mjs: udt_name casting, serial sequence advance fix
2026-08-26 14:23:09 +08:00
yeuimu
be0b90e68f
feat(security): HttpOnly cookie sessions, token revocation, and RBAC
...
- Add User.role (enum Role/ADMIN) and User.tokenVersion with migration
- Login now issues short-lived access token (30m default) + 7d refresh
token, both embedding tokenVersion and a typ discriminator
- Tokens delivered via HttpOnly SameSite cookies (ir_at, ir_rt scoped
to /auth); refresh token never leaves the cookie
- New endpoints: POST /auth/refresh (rotation), GET /auth/me,
POST /auth/logout (bumps tokenVersion, revoking all tokens)
- JWT strategy accepts bearer or cookie, rejects refresh tokens, and
verifies tokenVersion + user existence on every request
- Global RolesGuard: authenticated routes require ADMIN unless widened
via @Roles(...)
- Admin SPA: session fully cookie-based, no token in localStorage;
router guard restores session via /auth/me; axios auto-refreshes once
on 401; stale localStorage keys cleaned up
2026-08-22 12:04:56 +08:00
yeuimu
755b40aded
merge: security hardening fixes
2026-08-22 11:55:14 +08:00
yeuimu
9c1106586a
fix(security): harden auth, upload, and API configuration
...
- Lock public registration to first-user bootstrap (403 afterwards)
- Require JwtAuthGuard on upload + whitelist png/jpg/webp/gif (SVG/XSS blocked)
- Add global throttling (login/register 5/min, upload 10/min)
- Add helmet security headers; serve uploads with nosniff
- Replace permissive CORS (origin:true+credentials) with CORS_ORIGINS whitelist
- Disable Swagger outside development; sanitize 500 error responses
- Enforce 32+ char JWT_SECRET; make token expiry configurable (TOKEN_EXPIRES_IN)
- Re-check user in DB on every JWT validation (revocation on user delete)
- Dummy bcrypt compare to prevent login user-enumeration via timing
- Map malformed BigInt inputs to 400 instead of 500
- Widen .gitignore to .env* and add apps/api/.env.example
- Disable Nuxt devtools and sourcemaps
2026-08-22 11:55:13 +08:00
yeuimu
9ed569f5bc
fix(admin): simplify product forms
2026-08-21 14:54:08 +08:00
yeuimu
b04623ebdd
feat(goods): add editable custom products
2026-08-21 14:45:42 +08:00
yeuimu
a4151607c5
fix(sync): hydrate all origin product details
2026-08-21 14:05:15 +08:00
yeuimu
4cc99f3f23
fix(docs): describe tags as grouped array
2026-08-21 11:44:25 +08:00
yeuimu
8b38d6fef7
refactor(api): group public tag filters
2026-08-21 11:34:57 +08:00
yeuimu
4963a5c463
docs: update local API startup command
2026-08-21 11:01:02 +08:00
yeuimu
a43353aa98
fix(dev): support admin access over LAN
2026-08-21 10:53:47 +08:00
yeuimu
6e5f7edbb7
chore: update admin generated types and env ignore
2026-08-21 10:39:23 +08:00
yeuimu
437d9ca93b
refactor(api): pair public tag filters with groups
2026-08-21 10:24:35 +08:00
yeuimu
d375df810d
feat(admin): manage and sync product details
2026-08-21 10:18:57 +08:00