Commit Graph

19 Commits

Author SHA1 Message Date
chattie
20f92b701e feat(F-136): completed feature 2026-08-21 21:10:29 +02:00
chattie
b9610bf546 feat(F-120): completed feature 2026-08-21 15:31:13 +02:00
chattie
77133c0ecf feat(F-112): completed feature 2026-08-21 13:31:28 +02:00
chattie
c05c0b0582 feat(F-113): completed feature 2026-08-21 12:27:13 +02:00
chattie
027cacd871 feat(F-102): completed feature 2026-08-21 12:02:15 +02:00
chattie
b87f4f0c85 feat(F-111): completed feature 2026-08-21 10:10:35 +02:00
chattie
dca7c3214f feat(F-106): completed feature 2026-08-21 09:27:55 +02:00
chattie
5458789634 feat(F-105): completed feature 2026-08-21 08:06:31 +02:00
chattie
c07776822d feat(F-103): completed feature 2026-08-21 07:55:18 +02:00
chattie
822bc7546c feat(F-086): completed feature 2026-08-20 06:13:37 +02:00
chattie
22ad15325f feat(F-083): completed feature 2026-08-20 06:08:32 +02:00
chattie
352033e3fc feat(F-072): completed feature 2026-08-19 19:22:08 +02:00
chattie
cf67f51d07 feat(F-071): completed feature 2026-08-19 19:04:41 +02:00
chattie
ddcf2e0c28 feat(F-069): completed feature 2026-08-19 18:09:23 +02:00
chattie
835ab66eda feat(F-048): completed feature 2026-08-19 07:17:14 +02:00
chattie
d595b4871f feat(ADM-018): completed feature 2026-08-17 22:23:10 +02:00
rikrdo
546971280f feat(F-006): users profile, addresses and RBAC
- users module: profile + address CRUD behind use cases (users_profiles,
  users_addresses)
- roles customer/admin on identity_users; role resolved from DB per request
- shared auth contract (Authenticate, requireRole, requireOwnerOrAdmin)
  injected from composition root; users never imports identity
- authorization runs before existence checks; address SQL scoped by user_id
- @fastify/cookie registered once at app root (cross-module)
- migrations 003_identity_roles + 004_users (reversible)
- no new npm dependencies; tests: unit 52, integration 22

Gates: reviewer/security/qa APPROVED; verify.sh green
2026-08-15 09:28:15 +02:00
rikrdo
75293f39bc feat(identity): F-005 register/login/logout with argon2 sessions and rate limiting
- Hexagonal identity module: domain ports, use cases, argon2id hasher, pg repos
- Migration 002_identity: identity_users + identity_sessions (token hash only)
- Opaque 512-bit session tokens; DB stores SHA-256 hash; 7-day TTL in SQL
- Cookie HttpOnly + Secure (COOKIE_SECURE, default true) + SameSite=Lax
- LoginRateLimiter: 10 failures -> 429 + Retry-After, 15-min cooldown
- Anti-enumeration: identical generic 401 + dummy-hash timing equalization
- buildApp gains optional pool/cookieSecure; foundation-only app preserved
- 47 unit + 14 integration tests; live smoke covers all acceptance criteria
2026-08-14 22:58:32 +02:00
rikrdo
425fedd13e feat(F-002): database foundation with migrations and dev compose
- node-pg-migrate + pg: baseline migration (extensions, app_meta) with working down
- src/infrastructure/db fail-fast pool and typed query helper
- docker-compose: postgres:16-alpine + redis:7-alpine with one-command up
- table naming convention <module>_<table> documented in README
- integration tests (6) against real PostgreSQL; strict identifier validation
  for test DDL after security-gate hardening round
- deps justified in spec/tech.md; all gates approved; verify.sh green
2026-08-14 22:00:16 +02:00