Commit graph

35 commits

Author SHA1 Message Date
d41c09d1a3 Remove cookie auth helpers, clean Person-based recipe function; add indices and test seeding helper; spec updated 2025-11-01 21:28:50 +11:00
0ba9634131 Remove legacy cookie auth and Person-based recipe helper; add composite indices; spec updated 2025-11-01 21:25:18 +11:00
93b9869735 Remove legacy cookie auth and Person-based recipe helper; spec updated 2025-11-01 21:21:53 +11:00
42715c9fa6 Consolidate recipes API to canonical router; remove api/recipes_v2.py; spec updated 2025-11-01 20:26:17 +11:00
bd7a87c3ff feat: refactor user references to MemberRef across meals and recipes; update OpenAPI spec and backend documentation 2025-11-01 19:58:33 +11:00
52b4973175 test(auth, routing): add logout semantics and route-surface lockdown tests; update spec 2025-11-01 19:23:26 +11:00
9504c9cb34 feat(auth, invitations): switch to Argon2-only password hashing; return household on invitation accept; remove legacy cookie-based export; update OpenAPI wording and spec 2025-11-01 19:20:08 +11:00
32a7e6226f feat(shopping): dedupe ingredient requests per household and make household_id static in DDL 2025-11-01 19:07:44 +11:00
76eeaba51c Shopping requests parity 2025-11-01 18:34:40 +11:00
e370ed50dc request ingredient 2025-11-01 18:07:13 +11:00
65d655851d feat: MemberRef adoption for recipes.createdBy and shopping.purchasedBy; add TDD; update spec; keep suite green 2025-11-01 17:53:07 +11:00
b324e1101c feat(recipes): include createdBy (MemberRef) and createdById in v2 responses; map from User; update tests and spec 2025-11-01 17:50:33 +11:00
06b81f0b2a Spec updates, remove email requirement 2025-11-01 17:41:09 +11:00
fc1f414bbb Spec updates 2025-11-01 17:32:45 +11:00
584732e497 Cutover cleanup: inline meals/shopping v2 routers, neutralize legacy auth_v2 2025-11-01 17:24:15 +11:00
d093d1567e feat(meals+auth): remove Person from meals v2 DTOs (MemberRef) and adopt Argon2 hashing 2025-11-01 17:00:36 +11:00
87e3dba6f8 feat(v2): green checks, OpenAPI export, and spec updates for household-scoped API 2025-11-01 16:40:01 +11:00
aa18a1502d Remove v1 API surface, skip legacy tests; finalize v2-only routing and docs 2025-11-01 16:18:46 +11:00
1d60a3d925 spec update 2025-11-01 16:05:06 +11:00
ce75603582 feat(v2): complete household scoping and meals write flows; refresh OpenAPI 2025-11-01 15:51:23 +11:00
86e0ea3111 feat(shopping-v2): add household-scoped meal request/unrequest; tests and OpenAPI updated 2025-11-01 15:42:59 +11:00
0502902ffe feat(v2): finalize scoped meals consumed + fix shopping v2 invariants; refresh JWT route; tests green 2025-11-01 15:29:48 +11:00
ec3199fb0c feat(meals-v2): add household-scoped “mark consumed” endpoint with timezone validation and request cleanup; tests and spec updated; regenerate OpenAPI 2025-11-01 15:21:01 +11:00
0411791ad9 feat(v2): secure password hashing, finalize OpenAPI, and expand shopping v2 2025-11-01 15:02:37 +11:00
3c69355a5c feat(v2): add household-scoped shopping purchase endpoint with tests 2025-11-01 14:49:30 +11:00
8bc4f12770 feat(v2): add household-scoped GET /shopping/{listId} with tests 2025-11-01 14:42:56 +11:00
bb480d696b feat(v2): expand household scoping — meals get-by-id and shopping current, with tests; spec updated 2025-11-01 14:30:45 +11:00
6105d5dadf feat(v2): household-scoped shopping current and meals upcoming, with tests; spec updated 2025-11-01 14:26:23 +11:00
e67790c72d feat(v2): JWT auth, Invitations API, and meals household scoping with tests 2025-11-01 14:21:34 +11:00
e69299628a feat(auth, invitations): JWT access + refresh cookie, invitations API with tests 2025-11-01 14:17:42 +11:00
b5e41dc023 feat(auth v2): implement JWT access + refresh cookie; update deps and tests 2025-11-01 14:14:58 +11:00
538538d909 New tests tests/test_openapi_security.py verify presence of bearerAuth and 403s. 2025-11-01 14:01:48 +11:00
4470289b61 Recipes scoping 2025-11-01 13:58:46 +11:00
f1dac94396 Minimal v2 endpoints scaffolded alongside v1 cookie auth 2025-11-01 13:43:26 +11:00
aa74972fdf spec 2025-11-01 13:31:51 +11:00