Commit graph

9 commits

Author SHA1 Message Date
Afra ‌
bc6d66423c feat: allow deselecting the current neighborhood on the location search screen
Shows a clear/deselect row (only when a location is actually set) that
wipes the location cookie and returns to the unfiltered all-stores view.
Also highlights the currently selected neighborhood in the suggested/
results list with a checkmark, since it's now shown there too.
2026-08-19 10:12:09 +03:30
Afra ‌
e5b00c4d55 feat: consume MinIO presigned media URLs (feature/minio-integration)
icon/image/logo/cover_image are now MinIO object keys, not URLs -- every
serializer with one of these fields now returns a <field>_url sibling
that's an already-absolute, freshly presigned URL. Added those fields to
every affected type (StoreCategory, StoreListItem, ProductCategory,
ProductListItem) and switched every <img> call site to use the _url field
directly.

Deleted resolveMediaUrl/resolveClientMediaUrl and the
NEXT_PUBLIC_WINOFY_MEDIA_ORIGIN env var -- they existed only to turn
relative paths under the Winofy origin into absolute URLs, which no longer
applies now that media lives on a different host (MinIO) and comes back
pre-resolved.

Also fixes cart-item-row.tsx's product thumbnail, which had been commented
out (broken under the old relative-path assumption).

Restored image_url as a required non-optional field per the doc rather
than treating it as possibly-missing, since every serializer covered by
this migration always includes it (null when no image, not omitted).
2026-08-18 13:32:30 +03:30
Afra ‌
6f207753be fix: swap header order so neighborhood selector sits on the right and login/cart button on the top-left 2026-08-17 17:38:41 +03:30
Afra ‌
3609c97e34 feat: guest-home/C04 shell, location onboarding (L01/L04/L06), profile placeholder
Implements winofyfrontenddoc (1).md §3-4: unified guest-home/authenticated-home
screen (header with login chip vs cart badge, pill search bar, dismissible
location-reminder banner, category chips, store cards, interleaved seller
promo card, sticky bottom nav), plus the full post-OTP location-onboarding
sub-flow (geolocation permission -> error/retry -> manual neighborhood
search, unified idle/results/empty states per the doc's own recommendation).

Location state persists in a plain (non-httpOnly) cookie readable both
client- and server-side, since it drives SSR store queries (neighborhood
or lat/lng) as well as client interactions.

Moved cart/checkout/store/product/orders/addresses under a new (shop) route
group so the new home-shell header doesn't double up with the existing
simple nav header on inner pages.

Real bug caught via live staging data: Neighborhood.city is a nested
{uuid, name, slug} object, not a bare uuid string as typed -- broke both
the address form's city filter and the new neighborhood search. Fixed and
verified against real API responses, not just assumed from the guide.
2026-08-17 17:24:27 +03:30
Afra ‌
f18778c5f3 fix: use real logotype-winsoo.svg asset in auth header banner instead of a hand-drawn placeholder icon 2026-08-17 14:23:43 +03:30
Afra ‌
c290575be7 feat: real design system tokens + C01/C02/C03 login-OTP flow per winofyfrontenddoc.md
Replaces placeholder colors/type-scale with the documented Figma design
system (§1), and rebuilds login as three screens matching the doc exactly:
role selection, phone entry, and 6-box OTP verification with countdown
resend. Fixes a real bug along the way: normalizeIranianPhone stripped
Persian-digit keyboard input entirely instead of converting it (\D matches
non-ASCII digits too) -- added toLatinDigits/toPersianDigits and verified
the round-trip in isolation.
2026-08-17 14:10:27 +03:30
Afra ‌
d000df2e41 feat: customer shopping flow (store/product pages, cart, addresses, checkout, order tracking); auth calls Gooyal directly from browser 2026-08-17 10:19:59 +03:30
Afra ‌
6a44887111 feat: auth flow (Gooyal OTP/OAuth2) + customer home page against live staging API
- Session stored as an encrypted (JWE) httpOnly cookie; access/refresh tokens
  never reach the client, client_secret never leaves the server.
- winofyFetch: server-side API client matching FRONTEND_GUIDE.md's plain-success
  / wrapped-error (§4.1-4.2) convention, with auto token refresh.
- Login page (phone -> OTP) wired to Gooyal accounts staging; request_otp
  verified working end-to-end. Token exchange returns invalid_client with the
  client_id/secret currently on hand — needs a fix from whoever issued them.
- proxy.ts (Next 16's renamed middleware) gates seller/cart/checkout/orders
  routes, verified redirecting unauthenticated requests to /login.
- Customer home page renders real store/category data fetched live from
  winofy-staging.winsoo.ir.
2026-08-15 14:56:52 +03:30
Afra ‌
4e1b6f8bad Initial commit from Create Next App 2026-08-15 14:44:07 +03:30