Commit Graph

42 Commits

Author SHA1 Message Date
chattie
6cc91a3902 feat(F-125): completed feature 2026-08-21 17:58:15 +02:00
chattie
b9610bf546 feat(F-120): completed feature 2026-08-21 15:31:13 +02:00
chattie
13436652cd feat(F-117): completed feature 2026-08-21 14:26:52 +02:00
chattie
365059916d feat(F-116): completed feature 2026-08-21 14:23:17 +02:00
chattie
aa78ba6d8e feat(F-115): completed feature 2026-08-21 14:20:07 +02:00
chattie
77133c0ecf feat(F-112): completed feature 2026-08-21 13:31:28 +02:00
chattie
da919d705f feat(F-100): completed feature 2026-08-21 13:28:14 +02:00
chattie
21aeac307e feat(F-114): completed feature 2026-08-21 13:01:42 +02:00
chattie
c05c0b0582 feat(F-113): completed feature 2026-08-21 12:27:13 +02:00
chattie
027cacd871 feat(F-102): completed feature 2026-08-21 12:02:15 +02:00
chattie
b87f4f0c85 feat(F-111): completed feature 2026-08-21 10:10:35 +02:00
chattie
840c839f67 feat(F-108): completed feature 2026-08-21 09:57:11 +02:00
chattie
dca7c3214f feat(F-106): completed feature 2026-08-21 09:27:55 +02:00
chattie
5458789634 feat(F-105): completed feature 2026-08-21 08:06:31 +02:00
chattie
c07776822d feat(F-103): completed feature 2026-08-21 07:55:18 +02:00
chattie
5177a851aa feat(F-099): completed feature 2026-08-21 07:29:07 +02:00
chattie
3f1d08382f feat(F-098): completed feature 2026-08-20 22:39:06 +02:00
chattie
5561776627 feat(F-096): completed feature 2026-08-20 22:12:01 +02:00
chattie
c56037492d feat(F-093): completed feature 2026-08-20 21:57:43 +02:00
chattie
4d0970df5d feat(F-091): completed feature 2026-08-20 21:47:31 +02:00
chattie
84bf380987 feat(F-090): completed feature 2026-08-20 21:40:41 +02:00
chattie
63fdc775d9 feat(F-087): completed feature 2026-08-20 06:16:38 +02:00
chattie
822bc7546c feat(F-086): completed feature 2026-08-20 06:13:37 +02:00
chattie
7ece045e13 feat(F-085): completed feature 2026-08-20 06:10:48 +02:00
chattie
22ad15325f feat(F-083): completed feature 2026-08-20 06:08:32 +02:00
chattie
60206d88eb feat(F-079): completed feature 2026-08-20 05:57:24 +02:00
chattie
fffb52721a feat(F-078): completed feature 2026-08-20 05:55:46 +02:00
chattie
352033e3fc feat(F-072): completed feature 2026-08-19 19:22:08 +02:00
chattie
cf67f51d07 feat(F-071): completed feature 2026-08-19 19:04:41 +02:00
chattie
ddcf2e0c28 feat(F-069): completed feature 2026-08-19 18:09:23 +02:00
chattie
9f1858f6d7 feat(F-066): completed feature 2026-08-19 17:22:39 +02:00
chattie
4cdb5fb487 feat(F-058): completed feature 2026-08-19 15:17:51 +02:00
chattie
de41a42d88 feat(F-054): completed feature 2026-08-19 13:15:30 +02:00
chattie
835ab66eda feat(F-048): completed feature 2026-08-19 07:17:14 +02:00
chattie
8ee1938af9 feat(BD-09): completed feature 2026-08-18 06:23:37 +02:00
chattie
d595b4871f feat(ADM-018): completed feature 2026-08-17 22:23:10 +02:00
rikrdo
546971280f feat(F-006): users profile, addresses and RBAC
- users module: profile + address CRUD behind use cases (users_profiles,
  users_addresses)
- roles customer/admin on identity_users; role resolved from DB per request
- shared auth contract (Authenticate, requireRole, requireOwnerOrAdmin)
  injected from composition root; users never imports identity
- authorization runs before existence checks; address SQL scoped by user_id
- @fastify/cookie registered once at app root (cross-module)
- migrations 003_identity_roles + 004_users (reversible)
- no new npm dependencies; tests: unit 52, integration 22

Gates: reviewer/security/qa APPROVED; verify.sh green
2026-08-15 09:28:15 +02:00
rikrdo
75293f39bc feat(identity): F-005 register/login/logout with argon2 sessions and rate limiting
- Hexagonal identity module: domain ports, use cases, argon2id hasher, pg repos
- Migration 002_identity: identity_users + identity_sessions (token hash only)
- Opaque 512-bit session tokens; DB stores SHA-256 hash; 7-day TTL in SQL
- Cookie HttpOnly + Secure (COOKIE_SECURE, default true) + SameSite=Lax
- LoginRateLimiter: 10 failures -> 429 + Retry-After, 15-min cooldown
- Anti-enumeration: identical generic 401 + dummy-hash timing equalization
- buildApp gains optional pool/cookieSecure; foundation-only app preserved
- 47 unit + 14 integration tests; live smoke covers all acceptance criteria
2026-08-14 22:58:32 +02:00
rikrdo
4851692031 feat(F-004): typed fail-fast config and feature flag module
- loadConfig: pure over env object, accumulates all problems, names var names only
- DATABASE_URL now required at startup; PORT/HOST/LOG_LEVEL/NODE_ENV/REDIS_URL defaulted
- flags module behind FeatureFlagProvider; unknown flags OFF; runtime setEnabled (no redeploy)
- buildApp decorates app.flags; server.ts fail-fast before app boot
- tests caught and fixed flag-store case-normalization bug before gates
- zero new dependencies; all gates approved; verify.sh green
2026-08-14 22:29:18 +02:00
rikrdo
41f144d7bd feat(F-003): HTTP foundation with request context and error envelope
- request_id generated or sanitized-propagated on every request (x-request-id)
- structured JSON logging (pino), one correlated line per request, injectable logger
- error envelope v2 { error: { statusCode, code, message, details? }, requestId }
- 5xx messages always generic; stack traces stay in server logs only
- explicit parseJson (zod) input validation hook at the API layer
- README HTTP contract section; deps justified in spec/tech.md
- all gates approved; verify.sh green
2026-08-14 22:13:28 +02:00
rikrdo
425fedd13e feat(F-002): database foundation with migrations and dev compose
- node-pg-migrate + pg: baseline migration (extensions, app_meta) with working down
- src/infrastructure/db fail-fast pool and typed query helper
- docker-compose: postgres:16-alpine + redis:7-alpine with one-command up
- table naming convention <module>_<table> documented in README
- integration tests (6) against real PostgreSQL; strict identifier validation
  for test DDL after security-gate hardening round
- deps justified in spec/tech.md; all gates approved; verify.sh green
2026-08-14 22:00:16 +02:00
rikrdo
1d4eebca54 feat(F-001): scaffold modular monolith skeleton with boundary checker
- TypeScript + Fastify skeleton under project/ (src/modules, shared, infrastructure, app)
- scripts/check-module-boundaries.mjs enforcing module public-API rules (tested with fixtures)
- GET /health endpoint, error envelope without stack leakage
- specs/F-001-scaffold (SPEC/DESIGN/TASKS/TESTS), spec/tech.md dependency justification
- 30-ticket MercadoDeVida roadmap in backlog/features.json, spec/roadmap.md
- All gates approved: reviewer, security, qa; verify.sh green
2026-08-14 21:46:54 +02:00