P0: Next.js shell — tokens, motion, SlidePanel, LeftRail, auth plumbing

- Tailwind v4 @theme block encoding all spec §2 tokens; full §3 keyframe
  inventory with prefers-reduced-motion handling; Geist vendored (air-gap)
- SlidePanel width-animation primitive (component-tested: exit-transition
  unmount, fixed-width inner content, a11y region semantics)
- session-key.ts mirroring the Rust codec + URL-param encoding; nuqs
  panel-params with spec ?sessions=1 flag shape and routines->scheduled alias
- Zod-typed API client; httpOnly cookie session bridge (/auth/session);
  login page; (workspace) layout with LeftRail roster/nav/user; Team and
  Credits pages on real endpoints (+ GET /api/team/members in tc-api)
- Vitest + Testing Library harness (26 tests); ESLint max-lines 1250 +
  no-warning-comments mirroring the CI gates

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-09 22:43:50 -05:00
co-authored by Claude Fable 5
parent c4349bf292
commit 172a3c8fed
50 changed files with 9415 additions and 1 deletions
+46
View File
@@ -0,0 +1,46 @@
// Session bridge: exchanges credentials with the Rust backend and stores the
// bearer token in an httpOnly cookie so client JavaScript can never read it.
import { NextResponse, type NextRequest } from "next/server";
import { apiOrigin, TOKEN_COOKIE } from "@/lib/api/http";
const SESSION_MAX_AGE_SECONDS = 7 * 24 * 60 * 60;
export async function POST(request: NextRequest) {
const body = await request.json();
const upstream = await fetch(`${apiOrigin()}/api/auth/login`, {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify(body),
});
if (!upstream.ok) {
return NextResponse.json({ error: "invalid credentials" }, { status: 401 });
}
const { token } = (await upstream.json()) as { token: string };
const response = new NextResponse(null, { status: 204 });
response.cookies.set({
name: TOKEN_COOKIE,
value: token,
httpOnly: true,
sameSite: "lax",
secure: process.env.NODE_ENV === "production",
path: "/",
maxAge: SESSION_MAX_AGE_SECONDS,
});
return response;
}
export async function DELETE(request: NextRequest) {
const token = request.cookies.get(TOKEN_COOKIE)?.value;
if (token) {
await fetch(`${apiOrigin()}/api/auth/logout`, {
method: "POST",
headers: { Authorization: `Bearer ${token}` },
});
}
const response = new NextResponse(null, { status: 204 });
response.cookies.delete(TOKEN_COOKIE);
return response;
}