winofy-front/src/lib/auth
Afra ‌ 6a44887111 feat: auth flow (Gooyal OTP/OAuth2) + customer home page against live staging API
- Session stored as an encrypted (JWE) httpOnly cookie; access/refresh tokens
  never reach the client, client_secret never leaves the server.
- winofyFetch: server-side API client matching FRONTEND_GUIDE.md's plain-success
  / wrapped-error (§4.1-4.2) convention, with auto token refresh.
- Login page (phone -> OTP) wired to Gooyal accounts staging; request_otp
  verified working end-to-end. Token exchange returns invalid_client with the
  client_id/secret currently on hand — needs a fix from whoever issued them.
- proxy.ts (Next 16's renamed middleware) gates seller/cart/checkout/orders
  routes, verified redirecting unauthenticated requests to /login.
- Customer home page renders real store/category data fetched live from
  winofy-staging.winsoo.ir.
2026-08-15 14:56:52 +03:30
..
gooyal.ts feat: auth flow (Gooyal OTP/OAuth2) + customer home page against live staging API 2026-08-15 14:56:52 +03:30
session.ts feat: auth flow (Gooyal OTP/OAuth2) + customer home page against live staging API 2026-08-15 14:56:52 +03:30