010-identity-auth
Replaces the no-op fastify.authenticate stub and the never-implemented
identity/auth login with real bcrypt password verification, JWT session
issuance/verification (reusing the existing JWT_SECRET), and a Redis-backed
revocation denylist for logout. Adds requireRole('ADMIN') to admin-only
configuration writes across 002-009 that previously relied on a decorator
that never actually checked anything. Adds self-identity (GET /auth/me,
re-validated against live account state) and admin-provisioned accounts
(POST /admin/users).
Making the auth check genuinely reject invalid/missing tokens exposed that
~18 pre-existing integration test files called already-gated routes with no
Authorization header (safe against the old no-op stub, broken against a real
one) — fixed via a shared tests/helpers/auth.ts (loginAs/authHeader) and a
file-by-file pass, plus two related SLA-run cleanup races exposed once admin
setup calls in those files' own beforeAll blocks started actually succeeding.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
SupportHub API
Development (Docker)
- Start all services:
docker compose --env-file .env.development -f docker-compose.development.yml up -d --build - Start only database & cache (for local app development):
docker compose --env-file .env.development -f docker-compose.development.yml up -d postgres redis
Test (Docker)
docker compose --env-file .env.test -f docker-compose.test.yml up --build
Production (Docker)
docker compose --env-file .env.prod -f docker-compose.prod.yml up --build -d
Stop / Down
- Stop production:
docker compose -f docker-compose.prod.yml down - Stop development:
docker compose -f docker-compose.development.yml down - Stop development & wipe volumes:
docker compose --env-file .env.development -f docker-compose.development.yml down -v
List Containers & Logs
- List containers:
docker compose --env-file .env.development -f docker-compose.development.yml ps - Follow logs:
docker compose --env-file .env.development -f docker-compose.development.yml logs -f
Local Development (Host)
- Start database & cache in Docker:
docker compose --env-file .env.development -f docker-compose.development.yml up -d postgres redis - Start API server in watch mode:
npm run dev
Database Migrations & Prisma
-
Generate Prisma Client:
npm run prisma:generate -
Run / Apply Dev Migrations:
npx dotenv-cli -e .env.development -- npm run prisma:migrate -
Deploy Migrations (Production/CI):
npx dotenv-cli -e .env.development -- npm run prisma:deploy -
Push Schema directly (Sync schema without migration files):
npx dotenv-cli -e .env.development -- npx prisma db push
Database Seeding
- Seed Database (Roles, Products, Categories, Hierarchy & Demo data):
npx dotenv-cli -e .env.development -- npm run prisma:seed
Languages
TypeScript
93.2%
PowerShell
6.5%
JavaScript
0.2%