3a51305343
- six REST endpoints (auth/request_otp, verify_otp, refresh, logout, me, me/select_role) wrapping the existing JWE/TOTP/RBAC engine - usr.UserSessions with refresh-token rotation + stolen-token (replay) detection → revoke-all + 401; logout rotates the security stamp - users extended: gender, national_id (enc, NULL until KYC), shahkar_verified_at (auto-reset on phone change), phone_hash UNIQUE, is_active, deleted_at + soft-delete filter; phone/email/national_id encrypted at rest via IFieldEncryptor value converter - user_roles grant/revoke audit trail + global revoked filter; 7 roles seeded; admin sub-roles never self-assignable (403) - ISmsSender seam (mock logs the OTP code) replaces the TODO log lines - OperationResult/BaseController learned enveloped 401/403 - auth knobs as platform_configs rows (resend/attempts/session TTL) - migration IdentitySessionsAndUserExtensions applied to the dev DB - 24 new tests incl. Baya.Test.Api (WebApplicationFactory over SQLite); 47 total green, zero new build warnings; swagger snapshot + contract (identity-auth.md), handoff, report, mocks-registry updated Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
dev/ — the Balinyaar build workspace
This folder is the plan for building Balinyaar, not application code. It takes the repo from its
current starter + auth baseline to the MVP described in product/, as a chain of
agent-runnable prompt files split into two parallel tracks.
| Folder | What it is |
|---|---|
phases/ |
The prompt chain — backend/ (b0–b15) and frontend/ (f0–f15), plus the shared rules/template in phases/_shared/. Start at phases/README.md. |
contracts/ |
The shared API/flow contract between the two independent projects. Backend writes, frontend reads. |
shared-working-context/ |
The parallel-agent handoff + per-phase reports + the mock registry. Each lane writes only its own files. |
How to use it
- Read
phases/README.md— the roadmap and dependency graph. - To run a phase, point a fresh agent at one phase file (e.g. "Execute
dev/phases/backend/backend-phase-2.md"). The phase file tells it what to read, what to build, and how to close out. - Run the two tracks in parallel with two agents if you like: a frontend phase named
frontend-phase-N-bM.mdonly needs backend phase bM merged first; everything else about the two tracks is decoupled throughcontracts/andshared-working-context/(which are designed so the two agents never touch the same files).
Non-negotiables (every phase enforces them)
- Follow the project rules in the relevant
CLAUDE.md/CONVENTIONS.mdand the shared operating rules. - Mock external services behind DI seams and record them in
shared-working-context/reports/mocks-registry.md. - Finish each phase with: updated docs, a written contract (backend), a handoff note, a phase report, and saved memory.