Files
baya-monorepo/dev/shared-working-context/backend/STATUS.md
T
hamid 3a51305343 backend phase 2: identity — phone-OTP auth, sessions & roles (REST)
- six REST endpoints (auth/request_otp, verify_otp, refresh, logout, me,
  me/select_role) wrapping the existing JWE/TOTP/RBAC engine
- usr.UserSessions with refresh-token rotation + stolen-token (replay)
  detection → revoke-all + 401; logout rotates the security stamp
- users extended: gender, national_id (enc, NULL until KYC),
  shahkar_verified_at (auto-reset on phone change), phone_hash UNIQUE,
  is_active, deleted_at + soft-delete filter; phone/email/national_id
  encrypted at rest via IFieldEncryptor value converter
- user_roles grant/revoke audit trail + global revoked filter; 7 roles
  seeded; admin sub-roles never self-assignable (403)
- ISmsSender seam (mock logs the OTP code) replaces the TODO log lines
- OperationResult/BaseController learned enveloped 401/403
- auth knobs as platform_configs rows (resend/attempts/session TTL)
- migration IdentitySessionsAndUserExtensions applied to the dev DB
- 24 new tests incl. Baya.Test.Api (WebApplicationFactory over SQLite);
  47 total green, zero new build warnings; swagger snapshot + contract
  (identity-auth.md), handoff, report, mocks-registry updated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 02:34:11 +03:30

5.0 KiB

Backend status log (append-only)

One block per completed backend phase. Newest at the top. Backend lane writes here; frontend reads.

backend-phase-2 — Identity: phone-OTP auth, sessions & roles (REST) — 2026-07-02

  • Shipped: the six-endpoint REST auth surface (auth/request_otp, auth/verify_otp, auth/refresh, auth/logout, me, me/select_role) wrapping the existing JWE/TOTP/RBAC engine; new usr.UserSessions (refresh-token rotation + revoke-all on replayed token); usr.Users extended (Gender, NationalId enc NULL, ShahkarVerifiedAt auto-reset on phone change, PhoneHash UNIQUE, IsActive, DeletedAt + soft-delete filter); phone/email/national-id encrypted at rest (EF value converter over IFieldEncryptor); usr.UserRoles grant/revoke audit trail + revoked filter; 7 roles seeded; ISmsSender seam (mock logs the code); 3 auth config keys; OperationResult/BaseController learned 401/403.
  • Contracts: dev/contracts/domains/identity-auth.md + openapi snapshot refreshed (yes — 22 paths).
  • Mocked: ISmsSender🟡 (see reports/mocks-registry.md).
  • Gate: build clean (0 new code warnings) / tests green (47 pass: 10 new Baya.Test.Api integration + 14 new handler unit tests). Migration IdentitySessionsAndUserExtensions applied to the dev DB; full §7 flow verified live (OTP in log, tokens, 401/403/429, rotation, replay-revoke, logout stamp-kill).
  • Handoff: backend/handoff/after-backend-phase-2.md
  • Notes for frontend: exact paths are request_otp/verify_otp/select_role (snake_case transformer — not the otp/request sketch). Bodies camelCase. Fresh users: roles: [] → role router → me/select_rolerefresh tokens to pick up role claims. /me phone is masked. SMS is mocked — read the OTP from the server log.

backend-phase-1 — Config, reference & platform signals — 2026-07-02

  • Shipped: first marketplace migration baseline (InitialMarketplaceBaseline, new ops schema) with 6 tables (PlatformConfigs, AuditLogs, SystemEvents, IranianHolidays, Notifications, SupportAlerts) + seed (12 config keys, 7 holidays); platform-signal facades IPlatformConfig / IHolidayCalendar / IAnalyticsSink / IAuditLogger / INotificationService / ISupportAlertService (Persistence/Services/); AuditFieldInterceptor extended to write append-only audit_logs rows for IAuditable entities; real in-app INotificationDispatcher (b0 stub removed); notification-retention hosted service; 5 controllers (admin config/holidays/audit/support-alerts + current-user notifications).
  • Contracts: dev/contracts/domains/config-reference.md + openapi snapshot refreshed (yes — 16 paths).
  • Mocked: IHolidayCalendar, IAnalyticsSink, retention IJobScheduler🟡; INotificationDispatcher flipped to in-app-real 🟡 (SMS/push deferred). See reports/mocks-registry.md.
  • Gate: build clean (0 new code warnings) / tests green (22 pass: 4 identity + 18 foundation). Migration applied to the dev DB; API boots with all 16 paths in Swagger; retention job runs on startup.
  • Handoff: backend/handoff/after-backend-phase-1.md
  • Notes for frontend: f14 = notifications/* (envelope unchanged; unread-first lists; data_json is a typed deep-link payload). f15 = admin platform_config/*, holidays/*, audit/get_audit_trail, support_alerts/* (DynamicPermission). Pagination page/page_size (default 50, max 100).

backend-phase-0 — Foundation, cross-cutting seams & starter cleanup — 2026-06-28

  • Shipped: removed the Order demo (entity/feature/repo/config/gRPC) + 3 old migrations; fresh InitialBaseline migration; REST surface (PingController + System/Ping CQRS); ICurrentUser + AuditFieldInterceptor; five cross-cutting seams (IDateTimeProvider, IFieldEncryptor, ICacheService, IObjectStorage, INotificationDispatcher) with mocks; LoggingBehavior + rate limiter (per-IP global + otp/auth/sensitive).
  • Contracts: dev/contracts/openapi/swagger.v1.json published (envelope + ping schemas).
  • Mocked: the 5 seams above → 🟡 (see reports/mocks-registry.md).
  • Gate: build clean (0 new warnings) / tests green (10 pass). Live API verified vs 192.168.100.14 (migration applied + seeded; ping 200; rate-limit 429).
  • Handoff: backend/handoff/after-backend-phase-0.md
  • Notes for frontend: ApiResult envelope is fixed (camelCase body, snake_case URLs); GET /api/v1/ping/get_status is live to wire types against; 429 on over-limit.