Phase 1 foundation: backend, web profile, and mobile app
CI / policy (push) Successful in 0s
CI / mobile (push) Successful in 47s
CI / profile (push) Successful in 49s
CI / backend (push) Failing after 49s

Greenfield implementation of CardClaws Phase 1 across three surfaces.

Backend (Rust/Axum workspace, 67 tests):
- cardclaws-types/config/db/auth/api/wallet crates
- Auth: register, login + lockout, magic link, refresh rotation, Apple verify
- Cards: CRUD, tier-limited publish, duplicate, public handle lookup
- Assets: R2 presigned uploads; vCard export
- Apple Wallet .pkpass pipeline (PKCS#7 signer behind apple-signing feature)
- Analytics ingest + summary with daily-salted IP hashing
- Migrations 0001 (incl. cardclaws_sessions) + 0002 analytics

Web profile (Astro SSR): cardclaws.com/[handle] hero + flip, contact actions,
client-built vCard, visit attribution. Verified end-to-end.

Mobile (Expo SDK 51): auth, card list/create, builder v1 (bg/text/logo,
palette, undo/redo), Skia/Reanimated viewer (flip + ambient). 22 logic tests.

CI: policy/backend/profile/mobile jobs; LOC + no-placeholder lint.

Review fixes baked in: `back` (not `cardclaws`) key; strip image is a bundled
manifest file (not a URL); sessions table added; NFC reframed; test doubles
allowed for external services.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-04 10:17:26 -05:00
co-authored by Claude Opus 4.8
commit c30d3afeec
128 changed files with 36279 additions and 0 deletions
@@ -0,0 +1,71 @@
//! Asset upload/delete handlers (PRD §13.7). Uploads are presigned so bytes go
//! directly to R2. Keys are namespaced per user and deletes are restricted to
//! the caller's own prefix.
use axum::extract::{Path, State};
use axum::Json;
use cardclaws_types::AppError;
use serde::{Deserialize, Serialize};
use serde_json::{json, Value};
use uuid::Uuid;
use crate::error::ApiResult;
use crate::middleware::auth::AuthUser;
use crate::state::AppState;
#[derive(Deserialize)]
pub struct UploadRequest {
/// File extension without the dot, e.g. "png", "jpg", "mp4".
pub ext: String,
}
#[derive(Serialize)]
pub struct UploadResponse {
/// The object key to store in the card definition / profile.
pub key: String,
/// Presigned PUT URL (valid 5 minutes) the client uploads bytes to.
pub upload_url: String,
}
/// Allowed upload extensions (server-side gate; full MIME re-validation happens
/// on first serve — see assets.rs note).
const ALLOWED_EXT: &[&str] = &[
"png", "jpg", "jpeg", "webp", "gif", "mp4", "mov", "ttf", "otf",
];
pub async fn presign_upload(
State(state): State<AppState>,
user: AuthUser,
Json(req): Json<UploadRequest>,
) -> ApiResult<Json<UploadResponse>> {
let ext = req.ext.to_ascii_lowercase();
if !ALLOWED_EXT.contains(&ext.as_str()) {
return Err(AppError::Validation(format!("unsupported file type: {ext}")).into());
}
let key = format!("assets/{}/{}.{}", user.user_id, Uuid::new_v4(), ext);
let upload_url = state
.assets
.presign_put(&key)
.map_err(|e| AppError::Internal(e.0))?;
Ok(Json(UploadResponse { key, upload_url }))
}
pub async fn delete_asset(
State(state): State<AppState>,
user: AuthUser,
Path(key): Path<String>,
) -> ApiResult<Json<Value>> {
// Only allow deleting objects under the caller's own prefix.
let prefix = format!("assets/{}/", user.user_id);
if !key.starts_with(&prefix) {
return Err(AppError::Forbidden.into());
}
state
.assets
.delete(&key)
.await
.map_err(|e| AppError::Internal(e.0))?;
Ok(Json(json!({ "status": "deleted" })))
}