refinement phase 0

This commit is contained in:
hamid
2026-07-12 01:09:11 +03:30
parent 850cdf3414
commit 7acecda5c4
18 changed files with 672 additions and 30 deletions
@@ -6,6 +6,8 @@
<IsPackable>true</IsPackable>
<GenerateDocumentationFile>true</GenerateDocumentationFile>
<NoWarn>$(NoWarn);1591</NoWarn>
<!-- Enables `dotnet user-secrets` for the local-dev connection string (never a committed secret). -->
<UserSecretsId>baya-web-api</UserSecretsId>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.EntityFrameworkCore.Design">
@@ -0,0 +1,43 @@
using System.ComponentModel.DataAnnotations;
using Asp.Versioning;
using Baya.Infrastructure.CrossCutting.Seams;
using Baya.WebFramework.Attributes;
using Baya.WebFramework.BaseController;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.DependencyInjection;
using Microsoft.Extensions.Hosting;
using AppModels = Baya.Application.Models.Common;
namespace Baya.Web.Api.Controllers.V1;
[ApiVersion("1")]
[ApiController]
[Route("api/v{version:apiVersion}/[controller]")]
[Display(Description = "Development-only helpers (return 404 outside the Development environment)")]
public sealed class DevController(IHostEnvironment environment) : BaseController
{
/// <summary>
/// Development-only: returns the most recent OTP for <paramref name="phone"/> so a browser or an
/// automated end-to-end flow can complete phone-OTP login without an SMS gateway (the code is otherwise
/// only written to the server log by <c>LoggingSmsSender</c>). Returns 404 in every non-Development
/// environment — the capture is not even wired there — so it can never leak a code in staging/production.
/// It does not touch the OTP rate-limit or the per-phone resend window. Superseded by the real SMS gateway
/// in refinement Phase 8.
/// </summary>
[HttpGet("[action]/{phone}")]
[ProducesOkApiResponseType<DevLastOtpResult>]
public IActionResult LastOtp(string phone)
{
if (!environment.IsDevelopment())
return NotFound();
var code = HttpContext.RequestServices.GetService<DevOtpStore>()?.GetLatest(phone);
return code is null
? OperationResult(AppModels.OperationResult<DevLastOtpResult>.NotFoundResult("No OTP has been issued for this phone yet."))
: OperationResult(AppModels.OperationResult<DevLastOtpResult>.SuccessResult(new DevLastOtpResult(phone, code)));
}
}
/// <summary>The most recent OTP captured for a phone (Development only).</summary>
public record DevLastOtpResult(string Phone, string Code);
+10
View File
@@ -72,8 +72,14 @@ builder.Services.AddApplicationServices()
.AddPersistenceServices(configuration)
.AddCrossCuttingSeams(configuration)
.AddWebFrameworkServices()
.AddCorsPolicies(configuration)
.AddRateLimitingPolicies();
// Development-only: capture each OTP in-memory so GET /api/v1/dev/last_otp/{phone} can complete a login
// without an SMS gateway. Nothing here is wired in any other environment.
if (builder.Environment.IsDevelopment())
builder.Services.AddDevelopmentOtpCapture();
builder.Services.RegisterValidatorsAsServices();
builder.Services.AddExceptionHandler<ExceptionHandler>();
@@ -114,6 +120,10 @@ app.UseSwaggerAndUi();
app.UseRouting();
// After UseRouting and before the rate limiter / authentication so a pre-flight OPTIONS is answered
// (and not rejected as 429/401) before the browser sends the real cross-origin request.
app.UseCors(CorsServiceExtension.PolicyName);
app.UseRateLimiter();
app.UseAuthentication();
@@ -1,7 +1,7 @@
{
"ConnectionStrings": {
"SqlServer": "Server=87.107.152.16,1433;Database=Baya;User Id=sa;Password=N8@s5Taw1zWeh@#Hm;TrustServerCertificate=True;Encrypt=False;",
"logDb":"Server=87.107.152.16,1433;Database=Baya_Logs;User Id=sa;Password=N8@s5Taw1zWeh@#Hm;TrustServerCertificate=True;Encrypt=False;"
"SqlServer": "Server=localhost,1433;Database=Baya;User Id=sa;Password=SET_VIA_USER_SECRETS_OR_ENV;TrustServerCertificate=True;Encrypt=False;",
"logDb": "Server=localhost,1433;Database=Baya_Logs;User Id=sa;Password=SET_VIA_USER_SECRETS_OR_ENV;TrustServerCertificate=True;Encrypt=False;"
},
"IdentitySettings": {
"SecretKey": "ShouldBe-LongerThan-16Char-SecretKey",
@@ -25,6 +25,9 @@
"ResolvedConfidence": 0.9
}
},
"Cors": {
"AllowedOrigins": [ "http://localhost:3000" ]
},
"AllowedHosts": "*",
"Kestrel": {
"EndpointDefaults": {
+5 -2
View File
@@ -1,7 +1,7 @@
{
"ConnectionStrings": {
"SqlServer": "Server=87.107.152.16,1433;Database=Baya;User Id=sa;Password=N8@s5Taw1zWeh@#Hm;TrustServerCertificate=True;Encrypt=False;",
"logDb":"Server=87.107.152.16,1433;Database=Baya_Logs;User Id=sa;Password=N8@s5Taw1zWeh@#Hm;TrustServerCertificate=True;Encrypt=False;"
"SqlServer": "Server=localhost,1433;Database=Baya;User Id=sa;Password=SET_VIA_USER_SECRETS_OR_ENV;TrustServerCertificate=True;Encrypt=False;",
"logDb": "Server=localhost,1433;Database=Baya_Logs;User Id=sa;Password=SET_VIA_USER_SECRETS_OR_ENV;TrustServerCertificate=True;Encrypt=False;"
},
"IdentitySettings": {
"SecretKey": "ShouldBe-LongerThan-16Char-SecretKey",
@@ -25,6 +25,9 @@
"ResolvedConfidence": 0.9
}
},
"Cors": {
"AllowedOrigins": []
},
"AllowedHosts": "*",
"Kestrel": {
"EndpointDefaults": {