Commit graph

43 commits

Author SHA1 Message Date
676ef9cfad Merge pull request 'fix/WNPT-735' (#9) from fix/WNPT-735 into develop
Reviewed-on: #9
2026-09-12 13:44:19 -04:00
Afra ‌
b548c59484 fix: single order checkout added 2026-09-05 16:24:45 +03:30
Afra ‌
c2b4c4a690 fix: minor modification on cart page's design 2026-09-05 14:00:55 +03:30
Afra ‌
6c5d02ddd0 feat: address pages added 2026-09-05 11:37:15 +03:30
Afra ‌
2048e99bf2 feat: C08 page implemented 2026-09-02 15:14:43 +03:30
2363fc0f88 Merge pull request 'feature/WNPT-752' (#7) from feature/WNPT-752 into develop
Reviewed-on: #7
2026-09-02 05:26:05 -04:00
1fe7c41bdc Merge branch 'develop' into feature/WNPT-752 2026-09-02 12:51:04 +03:30
bae58c8548 Merge pull request 'feature/WNPT-735' (#6) from feature/WNPT-735 into feature/WNPT-752
Reviewed-on: #6
2026-09-02 05:06:11 -04:00
61b82b0fb2 Merge pull request 'feature/WNPT-740' (#3) from feature/WNPT-740 into develop
Reviewed-on: #3
2026-09-02 04:02:09 -04:00
Afra ‌
ef75ed1a0c feat: checkout page implemented 2026-09-02 10:40:48 +03:30
Afra ‌
08e4a1a98a feat: checkout page implemented 2026-09-02 10:40:24 +03:30
Afra ‌
f94ee531a3 feat: checout page implemented 2026-09-02 01:55:25 +03:30
Afra ‌
adf31dc999 perf: cart page modified 2026-09-02 01:30:30 +03:30
Afra ‌
64e321dc3d perf: store and product pages' bottom bar modified 2026-09-02 00:38:22 +03:30
Afra ‌
418a63734f perf: product detail page modified 2026-09-02 00:29:50 +03:30
89d2a090e1 Merge pull request 'perf: logger + store page modification' (#4) from feature/WNPT-734 into develop
Reviewed-on: #4
2026-09-01 02:53:21 -04:00
Afra ‌
cc928871cc perf: logger + store page modification 2026-08-31 16:03:11 +03:30
b0ce5ce2f9 feat(profile): implement account fetching and context provider for user profile
feat(wallet): enhance wallet UI and transaction item display
fix(profile): update profile detail card to handle loading and error states
style: improve UI consistency across profile and wallet components
2026-08-30 13:28:27 +03:30
cbd0b4bebe feat(profile): complete profile and wallet UI with actions
- Add ProfileLayout with session authentication guard
- Create ProfilePage and WalletPage screen components
- Implement reusable profile UI elements:
  * ProfileMenu and ProfileMenuItem for navigation
  * ProfileExitAccount with logout handler
  * ProfilePersonDetailCard displaying user info
  * ProfilePageHeadLine for section titles
- Implement wallet section:
  * WalletBlancCard showing balance with charge/withdraw buttons
  * TransactionHistory listing recent transactions
  * TransactionItem with dynamic deposit/withdraw styling
- Use client components for interactive behaviours (logout, navigation)
- Apply consistent styling using Tailwind CSS and Lucide icons
2026-08-29 14:19:29 +03:30
9f76c2f16a Merge pull request 'feat: documentation added' (#2) from feature/WNPT-733 into main
Reviewed-on: #2
2026-08-29 05:45:01 -04:00
Afra ‌
d7a1067658 feat: documentation added 2026-08-29 11:35:57 +03:30
2cd5a9987d add priceUtils -- formatter price 2026-08-29 08:09:32 +03:30
2c6c8ad6e1 imp profile new design & wallet new design 2026-08-29 07:45:53 +03:30
17ee08bd5f Merge pull request 'feature/WNPT-733' (#1) from feature/WNPT-733 into main
Reviewed-on: #1
2026-08-26 04:17:34 -04:00
Afra ‌
0dc0cec4a6 perf: design enhancements implemented 2026-08-26 11:45:36 +03:30
Afra ‌
2490e9a21f feat: logger added 2026-08-25 12:21:03 +03:30
Afra ‌
84663e65a0 feat: shop detail page implemented 2026-08-23 09:24:22 +03:30
Afra ‌
716164ce96 fix: design issues fixed 2026-08-19 17:49:43 +03:30
Afra ‌
9a2d315046 perf: modified landing page's shop cards 2026-08-19 14:31:57 +03:30
Afra ‌
3a075c66ec feat: aggrigated all api calls 2026-08-19 13:01:19 +03:30
Afra ‌
524c504b70 fix: modified app naming 2026-08-19 11:18:47 +03:30
Afra ‌
bf1dc0b346 feat: dockerize (multi-stage build, standalone output)
Dockerfile: deps -> builder -> runner. NEXT_PUBLIC_* vars are passed as
build args (inlined into the client bundle at build time, per Next.js);
everything else is read at container runtime instead (docker-compose.yml's
env_file / docker run --env-file) and never baked into an image layer.
Runner stage is non-root, ships only server.js + .next/static + public/
via output: "standalone".

Verified by actually running the build twice locally (Docker itself isn't
available in this environment) -- once with the real .env.local, once with
only placeholder values and no .env.local at all, matching the real Docker
build condition. The second run caught a real, pre-existing bug that had
nothing to do with Docker specifically: /login and three other
client-component trees (location/error, location/permission,
CategoryChips and NeighborhoodSearch nested in Server Component pages) all
call useSearchParams() without a Suspense boundary. next dev tolerates
this; next build hard-fails on it ("missing-suspense-with-csr-bailout").
This would have broken any production build -- Vercel, bare metal,
whatever -- not just Docker; fixed all four by wrapping in <Suspense>.

Also added .env.example (committed, no real values -- .env.local itself
stays gitignored) and a docker-compose.yml, with the --env-file .env.local
requirement called out explicitly in README.md since Compose only
auto-reads a file literally named .env, not .env.local.
2026-08-19 11:00:09 +03:30
Afra ‌
4fad570e33 initial push 2026-08-19 10:29:38 +03:30
Afra ‌
573f43ea41 fix: self-healing session — stale/expired sessions no longer crash the app
Root cause of the home-page 500 ("اطلاعات برای اعتبارسنجی ارسال نشده است",
401 not_authenticated): getSession() only decrypted the session cookie, it
never checked whether the access token inside it had actually expired. The
JWE wrapper lives 30 days; the real Gooyal access token lives ~10 hours
(expires_in: 36000). So isAuthenticated stayed true long after the token
died, the home page called getCart() anyway, winofyFetch's refresh attempt
failed silently (dead refresh token) and returned no Authorization header
at all, and the resulting 401 was never caught -- crashing the whole page.

Fix: getValidSession() (session.ts) is now the single source of truth --
refreshes when possible, self-heals by clearing the cookie when refresh
fails, deduped per-request via React's cache(). winofyFetch and every
isAuthenticated check (home page, shop layout) now use it instead of the
raw cookie read.

That surfaced a second bug: Next.js forbids writing cookies during a plain
Server Component render (Server Actions/Route Handlers only), so
getValidSession()'s self-heal itself crashed when called from a page like
home. createSession()/deleteSession() now swallow that specific failure --
the refreshed/cleared session is still correct for the rest of the current
request, it just won't persist when called from a context that can't write
cookies (the next request re-derives the same correct answer).

Also added requireSession(path) and wired it into every auth-required page
(cart, checkout, addresses, orders, order-groups/[uuid], profile) --
proxy.ts's gate is deliberately optimistic (cookie presence only, per
Next.js's own guidance), so a present-but-dead session was reaching these
pages and crashing the same way; they now redirect to /login instead.

Verified against the exact failure: a session with a dead access+refresh
token now renders the home page as logged-out (200, not 500) and redirects
/cart to /login (307) instead of crashing. Also verified the happy path
(a genuinely fresh, valid session from a real OTP login) still works.
2026-08-19 10:26:02 +03:30
Afra ‌
bc6d66423c feat: allow deselecting the current neighborhood on the location search screen
Shows a clear/deselect row (only when a location is actually set) that
wipes the location cookie and returns to the unfiltered all-stores view.
Also highlights the currently selected neighborhood in the suggested/
results list with a checkmark, since it's now shown there too.
2026-08-19 10:12:09 +03:30
Afra ‌
e5b00c4d55 feat: consume MinIO presigned media URLs (feature/minio-integration)
icon/image/logo/cover_image are now MinIO object keys, not URLs -- every
serializer with one of these fields now returns a <field>_url sibling
that's an already-absolute, freshly presigned URL. Added those fields to
every affected type (StoreCategory, StoreListItem, ProductCategory,
ProductListItem) and switched every <img> call site to use the _url field
directly.

Deleted resolveMediaUrl/resolveClientMediaUrl and the
NEXT_PUBLIC_WINOFY_MEDIA_ORIGIN env var -- they existed only to turn
relative paths under the Winofy origin into absolute URLs, which no longer
applies now that media lives on a different host (MinIO) and comes back
pre-resolved.

Also fixes cart-item-row.tsx's product thumbnail, which had been commented
out (broken under the old relative-path assumption).

Restored image_url as a required non-optional field per the doc rather
than treating it as possibly-missing, since every serializer covered by
this migration always includes it (null when no image, not omitted).
2026-08-18 13:32:30 +03:30
Afra ‌
6f207753be fix: swap header order so neighborhood selector sits on the right and login/cart button on the top-left 2026-08-17 17:38:41 +03:30
Afra ‌
3609c97e34 feat: guest-home/C04 shell, location onboarding (L01/L04/L06), profile placeholder
Implements winofyfrontenddoc (1).md §3-4: unified guest-home/authenticated-home
screen (header with login chip vs cart badge, pill search bar, dismissible
location-reminder banner, category chips, store cards, interleaved seller
promo card, sticky bottom nav), plus the full post-OTP location-onboarding
sub-flow (geolocation permission -> error/retry -> manual neighborhood
search, unified idle/results/empty states per the doc's own recommendation).

Location state persists in a plain (non-httpOnly) cookie readable both
client- and server-side, since it drives SSR store queries (neighborhood
or lat/lng) as well as client interactions.

Moved cart/checkout/store/product/orders/addresses under a new (shop) route
group so the new home-shell header doesn't double up with the existing
simple nav header on inner pages.

Real bug caught via live staging data: Neighborhood.city is a nested
{uuid, name, slug} object, not a bare uuid string as typed -- broke both
the address form's city filter and the new neighborhood search. Fixed and
verified against real API responses, not just assumed from the guide.
2026-08-17 17:24:27 +03:30
Afra ‌
f18778c5f3 fix: use real logotype-winsoo.svg asset in auth header banner instead of a hand-drawn placeholder icon 2026-08-17 14:23:43 +03:30
Afra ‌
c290575be7 feat: real design system tokens + C01/C02/C03 login-OTP flow per winofyfrontenddoc.md
Replaces placeholder colors/type-scale with the documented Figma design
system (§1), and rebuilds login as three screens matching the doc exactly:
role selection, phone entry, and 6-box OTP verification with countdown
resend. Fixes a real bug along the way: normalizeIranianPhone stripped
Persian-digit keyboard input entirely instead of converting it (\D matches
non-ASCII digits too) -- added toLatinDigits/toPersianDigits and verified
the round-trip in isolation.
2026-08-17 14:10:27 +03:30
Afra ‌
d000df2e41 feat: customer shopping flow (store/product pages, cart, addresses, checkout, order tracking); auth calls Gooyal directly from browser 2026-08-17 10:19:59 +03:30
Afra ‌
6a44887111 feat: auth flow (Gooyal OTP/OAuth2) + customer home page against live staging API
- Session stored as an encrypted (JWE) httpOnly cookie; access/refresh tokens
  never reach the client, client_secret never leaves the server.
- winofyFetch: server-side API client matching FRONTEND_GUIDE.md's plain-success
  / wrapped-error (§4.1-4.2) convention, with auto token refresh.
- Login page (phone -> OTP) wired to Gooyal accounts staging; request_otp
  verified working end-to-end. Token exchange returns invalid_client with the
  client_id/secret currently on hand — needs a fix from whoever issued them.
- proxy.ts (Next 16's renamed middleware) gates seller/cart/checkout/orders
  routes, verified redirecting unauthenticated requests to /login.
- Customer home page renders real store/category data fetched live from
  winofy-staging.winsoo.ir.
2026-08-15 14:56:52 +03:30
Afra ‌
4e1b6f8bad Initial commit from Create Next App 2026-08-15 14:44:07 +03:30