Commit graph

149 commits

Author SHA1 Message Date
42715c9fa6 Consolidate recipes API to canonical router; remove api/recipes_v2.py; spec updated 2025-11-01 20:26:17 +11:00
8ee5642690 Removed v2 recipe file 2025-11-01 20:23:03 +11:00
bd7a87c3ff feat: refactor user references to MemberRef across meals and recipes; update OpenAPI spec and backend documentation 2025-11-01 19:58:33 +11:00
52b4973175 test(auth, routing): add logout semantics and route-surface lockdown tests; update spec 2025-11-01 19:23:26 +11:00
9504c9cb34 feat(auth, invitations): switch to Argon2-only password hashing; return household on invitation accept; remove legacy cookie-based export; update OpenAPI wording and spec 2025-11-01 19:20:08 +11:00
32a7e6226f feat(shopping): dedupe ingredient requests per household and make household_id static in DDL 2025-11-01 19:07:44 +11:00
978c970fb6 feat(shopping): add household-scoped ingredient request endpoint + tests and spec 2025-11-01 18:50:40 +11:00
75d098cd7a Unnecessary import 2025-11-01 18:47:45 +11:00
76eeaba51c Shopping requests parity 2025-11-01 18:34:40 +11:00
c4e1293557 test_request_ingredient_scoped 2025-11-01 18:16:38 +11:00
e370ed50dc request ingredient 2025-11-01 18:07:13 +11:00
65d655851d feat: MemberRef adoption for recipes.createdBy and shopping.purchasedBy; add TDD; update spec; keep suite green 2025-11-01 17:53:07 +11:00
b324e1101c feat(recipes): include createdBy (MemberRef) and createdById in v2 responses; map from User; update tests and spec 2025-11-01 17:50:33 +11:00
06b81f0b2a Spec updates, remove email requirement 2025-11-01 17:41:09 +11:00
fc1f414bbb Spec updates 2025-11-01 17:32:45 +11:00
52b47769a6 Removed dead v2 files 2025-11-01 17:24:55 +11:00
584732e497 Cutover cleanup: inline meals/shopping v2 routers, neutralize legacy auth_v2 2025-11-01 17:24:15 +11:00
bd44a6acbe feat(api): finalize v2 cutover, add household members endpoint, consolidate DTOs, and enforce Argon2 hashing 2025-11-01 17:14:18 +11:00
a973e5ce57 Finalized v1→v2 switchover at the router level: removed legacy v1 endpoints from the app surface, delegated canonical imports to v2 implementations, consolidated shopping DTOs/mappers, and updated router tags. Verified with lint, mypy, tests, formatting, and OpenAPI export. Everything is green. 2025-11-01 17:11:09 +11:00
4e3b3a77dc sneaky file leftover 2025-11-01 17:08:21 +11:00
d093d1567e feat(meals+auth): remove Person from meals v2 DTOs (MemberRef) and adopt Argon2 hashing 2025-11-01 17:00:36 +11:00
8fd780ee17 feat(meals): replace Person with MemberRef (displayName) in v2 Meal DTOs; add Argon2 password hashing 2025-11-01 16:58:34 +11:00
87e3dba6f8 feat(v2): green checks, OpenAPI export, and spec updates for household-scoped API 2025-11-01 16:40:01 +11:00
50f908f204 Ported v1 behavioral coverage to v2 counterparts across meals, recipes, shopping, and consumed flows. 2025-11-01 16:35:39 +11:00
aa18a1502d Remove v1 API surface, skip legacy tests; finalize v2-only routing and docs 2025-11-01 16:18:46 +11:00
1d60a3d925 spec update 2025-11-01 16:05:06 +11:00
b75fee41c6 feat(v2): add household-scoped delete for recipes; tests and OpenAPI updated 2025-11-01 16:01:29 +11:00
ce75603582 feat(v2): complete household scoping and meals write flows; refresh OpenAPI 2025-11-01 15:51:23 +11:00
86e0ea3111 feat(shopping-v2): add household-scoped meal request/unrequest; tests and OpenAPI updated 2025-11-01 15:42:59 +11:00
807f3efaaa feat(shopping-v2): add scoped meal request/unrequest; tests green; openapi updated 2025-11-01 15:40:45 +11:00
59c08ecb84 format 2025-11-01 15:34:01 +11:00
f4ad388e36 Tests and lint pass 2025-11-01 15:33:36 +11:00
0502902ffe feat(v2): finalize scoped meals consumed + fix shopping v2 invariants; refresh JWT route; tests green 2025-11-01 15:29:48 +11:00
ec3199fb0c feat(meals-v2): add household-scoped “mark consumed” endpoint with timezone validation and request cleanup; tests and spec updated; regenerate OpenAPI 2025-11-01 15:21:01 +11:00
746a327d7d fix(openapi): set explicit response_model for meals v2 get-by-id; plus security hardening and v2 endpoints 2025-11-01 15:03:27 +11:00
0411791ad9 feat(v2): secure password hashing, finalize OpenAPI, and expand shopping v2 2025-11-01 15:02:37 +11:00
3c69355a5c feat(v2): add household-scoped shopping purchase endpoint with tests 2025-11-01 14:49:30 +11:00
8bc4f12770 feat(v2): add household-scoped GET /shopping/{listId} with tests 2025-11-01 14:42:56 +11:00
bb480d696b feat(v2): expand household scoping — meals get-by-id and shopping current, with tests; spec updated 2025-11-01 14:30:45 +11:00
6105d5dadf feat(v2): household-scoped shopping current and meals upcoming, with tests; spec updated 2025-11-01 14:26:23 +11:00
e67790c72d feat(v2): JWT auth, Invitations API, and meals household scoping with tests 2025-11-01 14:21:34 +11:00
e69299628a feat(auth, invitations): JWT access + refresh cookie, invitations API with tests 2025-11-01 14:17:42 +11:00
b5e41dc023 feat(auth v2): implement JWT access + refresh cookie; update deps and tests 2025-11-01 14:14:58 +11:00
538538d909 New tests tests/test_openapi_security.py verify presence of bearerAuth and 403s. 2025-11-01 14:01:48 +11:00
4470289b61 Recipes scoping 2025-11-01 13:58:46 +11:00
584488b9c7 v2 register/login endpoints exist with bearer scaffold 2025-11-01 13:51:08 +11:00
e714f663bb v2 auth parallel 2025-11-01 13:44:00 +11:00
f1dac94396 Minimal v2 endpoints scaffolded alongside v1 cookie auth 2025-11-01 13:43:26 +11:00
aa74972fdf spec 2025-11-01 13:31:51 +11:00
0be2d1a2b0 Avoid optional arrays 2025-11-01 12:21:12 +11:00