Phase 1 foundation: backend, web profile, and mobile app
CI / policy (push) Successful in 0s
CI / mobile (push) Successful in 47s
CI / profile (push) Successful in 49s
CI / backend (push) Failing after 49s

Greenfield implementation of CardClaws Phase 1 across three surfaces.

Backend (Rust/Axum workspace, 67 tests):
- cardclaws-types/config/db/auth/api/wallet crates
- Auth: register, login + lockout, magic link, refresh rotation, Apple verify
- Cards: CRUD, tier-limited publish, duplicate, public handle lookup
- Assets: R2 presigned uploads; vCard export
- Apple Wallet .pkpass pipeline (PKCS#7 signer behind apple-signing feature)
- Analytics ingest + summary with daily-salted IP hashing
- Migrations 0001 (incl. cardclaws_sessions) + 0002 analytics

Web profile (Astro SSR): cardclaws.com/[handle] hero + flip, contact actions,
client-built vCard, visit attribution. Verified end-to-end.

Mobile (Expo SDK 51): auth, card list/create, builder v1 (bg/text/logo,
palette, undo/redo), Skia/Reanimated viewer (flip + ambient). 22 logic tests.

CI: policy/backend/profile/mobile jobs; LOC + no-placeholder lint.

Review fixes baked in: `back` (not `cardclaws`) key; strip image is a bundled
manifest file (not a URL); sessions table added; NFC reframed; test doubles
allowed for external services.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-04 10:17:26 -05:00
co-authored by Claude Opus 4.8
commit c30d3afeec
128 changed files with 36279 additions and 0 deletions
@@ -0,0 +1,46 @@
//! Route table (PRD §13). Only the auth surface and health are mounted in B1;
//! card/wallet/profile/analytics routes attach in later phases.
use axum::routing::{get, post};
use axum::Router;
use crate::handlers::{analytics, assets, auth, cards, health, wallet};
use crate::middleware::cors;
use crate::state::AppState;
pub fn build_router(state: AppState) -> Router {
let auth_routes = Router::new()
.route("/register", post(auth::register))
.route("/login", post(auth::login))
.route("/magic-link/request", post(auth::magic_link_request))
.route("/magic-link/verify", post(auth::magic_link_verify))
.route("/oauth/apple", post(auth::oauth_apple))
.route("/refresh", post(auth::refresh))
.route("/logout", post(auth::logout));
let v1 = Router::new()
.nest("/auth", auth_routes)
.route("/cards", get(cards::list_cards).post(cards::create_card))
.route(
"/cards/:id",
get(cards::get_card)
.put(cards::replace_card)
.patch(cards::patch_card)
.delete(cards::delete_card),
)
.route("/cards/:id/publish", post(cards::publish_card))
.route("/cards/:id/duplicate", post(cards::duplicate_card))
.route("/cards/:id/export/vcf", get(cards::export_vcf))
.route("/cards/:id/wallet/apple", post(wallet::apple_pass))
.route("/cards/handle/:handle", get(cards::get_card_by_handle))
.route("/cards/:id/analytics", get(analytics::summary))
.route("/analytics/event", post(analytics::ingest_event))
.route("/assets/upload", post(assets::presign_upload))
.route("/assets/*key", axum::routing::delete(assets::delete_asset));
Router::new()
.route("/health", get(health::health))
.nest("/v1", v1)
.layer(cors::layer())
.with_state(state)
}