Light up the two faces of the configurable service catalog over a new cached
services/catalog domain (consumes the b5 contract; unlocks f6 search).
- services/catalog: types/keys/constants/apis(client+mock+seam)/hooks/index +
names.ts. Categories & option groups are session-cached reference data
(Infinity staleTime, like geography); variant mutations invalidate
myVariantsLists() and setQueryData the edited row. Mock-primary
(USE_CATALOG_MOCK), one-line swap; mock reproduces the 400 missing-required
and (nurse,category,option-set) 409 duplicate rules.
- Customer Home (A5): greeting+avatar, search bar (navigates toward f6),
data-driven category grid (loading/empty/error), patient nudge from the
cached f2 query. Deferred /search placeholder stub.
- Nurse Services & prices (B7) at /nurse/services: offerings list (active vs
deactivated, edit, soft-deactivate w/ confirm, reactivate, no delete) and a
3-step variant builder (category -> required/optional options -> price+unit+
duration). Required-group gate; Toman->IRR digit-string at the field
boundary (no float); live unit-aware estimated total (never from price
alone); editable auto display_name; inline 409 duplicate warning; locked
category edit form.
- Shared, tested components: CategoryTile, PriceDisplay, VariantCard. Money
util: tomanToRial + multiplyIrr (integer-safe) + tests.
- i18n: catalog/services/search namespaces + home additions + nav.services
(both locales, in sync). Icons, routes (SEARCH, NURSE_SERVICES), nurse nav.
Gate: npm run check green; npm run test:ci green (147 tests, +18 across 4
suites); npm run build green with NEXT_PUBLIC_API_URL set.
Docs: client/CLAUDE.md (Project Structure, caching note, namespaces), STATUS,
for-backend REQ-010 (pagination param casing), phase report, mocks registry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The trust engine. New `verif` schema (5 tables) + a data-driven verification
pipeline: steps are rows (6 seeded step-types), not a code enum.
- nurse_verifications.status is the single source of verification truth;
nurse_profiles.is_verified is flipped ONLY inside the finalize transaction
(VerificationAggregator: tracked verification + tracked profile -> one commit)
and reversed on suspension/expiry — no in-between state.
- is_automated snapshotted onto each step at submit; steps seeded from active
required step-types; automated runs (identity-KYC, Shahkar, IBAN ownership)
find their step by code.
- users.national_id populated only on identity-KYC pass; Shahkar + IBAN owner
compare against it (money-mule guard); shared-SIM -> shared_sim support alert.
- Documents are metadata-only behind signed URLs; credential_number encrypted
and never serialized; public trust badge exposes credential TYPES, not numbers;
holder-name cross-checked against the verified identity before recording.
- Admin-triggered credential-expiry scan reverts lapsed steps, re-gates
bookability, raises a verification_expired alert + verification_expiry_prompt
notification (scheduled cron deferred; config key
verification_expiry_scan_cadence_hours).
Three new mock vendor seams (IShahkarVerifier / IIdentityKycProvider /
ICredentialVerifier) behind DI; reuses b3 IBankAccountOwnershipVerifier and
b0 IObjectStorage/IFieldEncryptor. 15 endpoints across 4 controllers.
Two migrations (tables + step-type seed). 154 tests pass, zero new warnings.
Contract dev/contracts/domains/verification.md + swagger snapshot refreshed;
handoff/report/mocks-registry updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Two-tier service model the marketplace is priced and searched on. Admin
catalog skeleton (categories + EAV option groups/values, addable as data
not migrations; NULL category = cross-category) and the nurse pricing layer
(nurse_service_variants — the atomic bookable unit: category + one value per
required dimension at the nurse's own IRR price and price unit).
- New `catalog` schema via one additive migration; Price BIGINT (no floats),
on the wire as a string of digits; total = price + unit + session_count.
- Duplicate-listing guard: deterministic option_set_hash + filtered
UNIQUE(nurse_id, service_category_id, option_set_hash) WHERE deleted_at IS
NULL + friendly 409 pre-check. One value per dimension; required groups
(incl. cross-category) enforced; deactivate, never delete.
- Public catalog browse cached behind a CatalogCache generation token,
invalidated on any admin write. IVariantSnapshotSerializer shipped for b8.
- Contract (catalog.md) + handoff + report published; swagger refreshed.
122 tests green; zero new build warnings.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adds the province -> city -> district reference hierarchy (geo schema,
seeded with 31 provinces + capital cities + Tehran's 22 districts),
nurse service areas (district_id NULL = whole city, filtered-index-pair
uniqueness -> 409), and encrypted, geocoded customer addresses with a
single-primary invariant. Introduces the IGeocoder seam (mocked) and
409 Conflict on the result envelope. Public cascading lookups are cached
behind a generation-token scheme with invalidate-on-admin-write.
One EF migration (GeographyAddressesServiceAreas, applied). Contract +
swagger snapshot + handoff/report/registry updated. 103 tests pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Replace the username/password stub with Balinyaar's real credential (phone-OTP)
and add the role router every authenticated screen sits behind.
- services/auth rewritten for OTP over the b2 contract: types/keys/constants,
clientApi+mockApi behind a config'd seam, hooks (useRequestOtp/useVerifyOtp/
useMe/useRefresh/useLogout/useSelectRole/useSessionRoleSync). Stub removed.
- A1/A2 customer login + B1/B2 nurse switch as one OTP flow at /login
(PhoneStep/OtpStep: auto-verify, resend countdown, wrong/expired/lockout states).
- Role router: pure resolveRoleDestination + RoleRouter -> family / nurse /
admin / select-role, with a splash while /me loads (no wrong-shell flash).
- SelectRole first-use screen at /select-role.
- Widened AuthState (roles via SessionUser), hydrated from /me by useSessionRoleSync.
- Fetch-layer silent token refresh (single-flight + one retry) + shared
persistAuthTokens/clearAuthTokens; useRefresh as the on-demand path.
- auth i18n namespace in both locales; tests for routing branches, countdown,
OtpStep state machine, RoleRouter branches; fixed jest @/ -> src alias.
- Docs: client/CLAUDE.md, frontend STATUS/report, for-backend REQ-002..004.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Turn the starter into the Balinyaar foundation for the three actor
experiences and lock in the patterns later phases copy.
- Cleanup: remove toastDemo namespace, placeholder home page, and the two
dead icons; fix BottomBar to use usePathname (locale-aware active tab).
- Three actor shells under (private-routes), no layout above [locale]:
customer (customer) group with the 5-tab bottom nav; nurse (/nurse) and
admin (/admin) on the shared sidebar engine. Role model via constants/roles
+ useActorRole (defaults to customer until roles land in f1-b2).
- services/{domain} reference (patients) with a mock behind a config seam,
hierarchical query keys, deliberate staleTime, and mutation invalidation;
shared ApiEnvelope/Paginated wire types + unwrap() in lib/api/types.
- Money (integer-safe IRR/Toman) + Shamsi-date utils; toEnglishDigits helper.
- Shared composites, each tested: OtpInput, PhoneNumberField, StepperHeader,
StatusChip, PlaceholderScreen.
- i18n: seed nav/common/shell/patients in both locales; document namespace
conventions. Update client/CLAUDE.md Project Structure + fix ColorSchemeScript
doc drift. Add phase report, STATUS, and REQ-001 (envelope/casing/pagination).
Gate: npm run check + test:ci green (72 tests); build green with NEXT_PUBLIC_API_URL.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Lay the cross-cutting platform backbone every later phase reads from. Adds
the first marketplace EF migration baseline (new `ops` schema) and the
mechanisms b2..b15 reuse: typed runtime config, an append-only audit trail,
an analytics event log, the holiday/bank-closure calendar, in-app
notifications, and the internal support-alert worklist.
Schema & migration
- New `ops` schema + migration InitialMarketplaceBaseline with 6 tables:
PlatformConfigs (IAuditable), AuditLogs (append-only), SystemEvents,
IranianHolidays, Notifications, SupportAlerts — with indexes/uniques and
FKs to usr.Users. Seeded 12 config keys + 7 sample holidays via HasData.
Domain / Application
- IAuditable marker + [AuditRedacted] attribute; entities + string-code
constant holders (config data_type, holiday type, alert type/severity/status).
- Facade contracts: IPlatformConfig, IHolidayCalendar, IAnalyticsSink,
IAuditLogger, INotificationService, ISupportAlertService; DTOs +
PagedResult<T>; evolved the INotificationDispatcher.Notification record to
carry Type + DataJson; Pagination helper.
- 14 CQRS commands/queries (+ validators) wiring the endpoints to the facades.
Infrastructure
- DB-backed facade implementations in Persistence/Services/; real in-app
INotificationDispatcher (removes the b0 log stub); notification-retention
hosted service (purge is_read=1 AND age>90d).
- Extended AuditFieldInterceptor to also append an old/new-diff audit_logs row
for every IAuditable change in the same transaction (PII redacted).
- Registered all facades + hosted service in AddPersistenceServices; removed
the dispatcher registration from AddCrossCuttingSeams.
API
- 5 controllers: admin PlatformConfig/Holidays/Audit/SupportAlerts
([Authorize(DynamicPermission)]) + current-user Notifications ([Authorize]),
all tenant-scoped and paginated. 16 Swagger paths total.
Money-correctness & safety rules honoured
- Config read at compute time (cached, parsed by data_type), never hardcoded;
every config change is audited in the same transaction; audit_logs is
append-only (no update/delete path); support alerts are admin-only;
notifications are tenant-scoped; analytics is fire-and-forget.
Tests & docs
- 18 new foundation tests over in-memory SQLite (config typing + audit,
holidays, notifications + tenancy + retention, support alerts, analytics);
build clean (0 new code warnings), 22 tests green; migration applied to the
dev DB and swagger.v1.json refreshed.
- Updated server Project map + CONVENTIONS, product data-model doc 12 (seeded
config defaults), config-reference contract, mock registry, backend handoff/
STATUS/report.
Follow-ups: add FK constraints for SupportAlerts.BookingId (b9) and ReviewId
(b14) when those tables land.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Remove the Order demo (entity/feature/repo/config/gRPC/proto) and the three
pre-marketplace migrations; regenerate a fresh InitialBaseline migration.
Stand up the REST surface (PingController + System/Ping CQRS) proving the
Mediator -> behaviors -> OperationResult -> ApiResult envelope end to end.
Close wiring gaps: register LoggingBehavior (outermost) and add the built-in
rate limiter (per-IP global + otp/auth/sensitive policies), placed before
authentication.
Add current-user + audit plumbing: ICurrentUser (HttpContext + null impls),
rename BaseEntity audit fields to CreatedAt/ModifiedAt (DateTimeOffset) +
CreatedById/ModifiedById, stamped by a new AuditFieldInterceptor.
Introduce five cross-cutting seams (IDateTimeProvider, IFieldEncryptor,
ICacheService, IObjectStorage, INotificationDispatcher) with in-memory/local
mocks registered via AddCrossCuttingSeams.
Add Baya.Test.Foundation (encryptor, audit interceptor, ping handler) and
update docs, contracts (swagger.v1.json), handoff, report, and mocks registry.