Phase 1 foundation: backend, web profile, and mobile app
Greenfield implementation of CardClaws Phase 1 across three surfaces. Backend (Rust/Axum workspace, 67 tests): - cardclaws-types/config/db/auth/api/wallet crates - Auth: register, login + lockout, magic link, refresh rotation, Apple verify - Cards: CRUD, tier-limited publish, duplicate, public handle lookup - Assets: R2 presigned uploads; vCard export - Apple Wallet .pkpass pipeline (PKCS#7 signer behind apple-signing feature) - Analytics ingest + summary with daily-salted IP hashing - Migrations 0001 (incl. cardclaws_sessions) + 0002 analytics Web profile (Astro SSR): cardclaws.com/[handle] hero + flip, contact actions, client-built vCard, visit attribution. Verified end-to-end. Mobile (Expo SDK 51): auth, card list/create, builder v1 (bg/text/logo, palette, undo/redo), Skia/Reanimated viewer (flip + ambient). 22 logic tests. CI: policy/backend/profile/mobile jobs; LOC + no-placeholder lint. Review fixes baked in: `back` (not `cardclaws`) key; strip image is a bundled manifest file (not a URL); sessions table added; NFC reframed; test doubles allowed for external services. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
//! Wallet pass generation (PRD §10). Phase 1 implements the Apple `.pkpass`
|
||||
//! pipeline; Google Wallet (JWT) lands in Phase 2.
|
||||
//!
|
||||
//! KEY CORRECTION vs. the PRD draft (plan review A1): the strip image is a
|
||||
//! **bundled file** inside the `.pkpass` zip and is included in the manifest
|
||||
//! SHA-1 hashes — it is NOT an `stripImage` URL. The pipeline here renders the
|
||||
//! strip, writes it into the bundle, hashes every file in the manifest, signs
|
||||
//! the manifest (PKCS#7 detached), and zips everything.
|
||||
|
||||
pub mod apple;
|
||||
pub mod error;
|
||||
pub mod strip_renderer;
|
||||
|
||||
pub use error::WalletError;
|
||||
Reference in New Issue
Block a user