T1/Phase 1: scaffold Vite SPA + Hono API + Bun worker

- apps/web: Vite + React 19 + TanStack Router/Query + shadcn/ui
   - apps/api: Hono + Bun on :3001 with /api/health, /api/auth/*, /mcp stubs
   - apps/worker: Bun worker stub, DB connection, graceful SIGTERM
   - apps/web-legacy/: old Next.js code moved aside (preserved for T2-T8 reference)
   - Dockerfiles: api (Bun), worker (Bun), spa (multi-stage Caddy)
   - Caddyfile: serves dist + reverse-proxies /api/* + /mcp to api
   - docker-compose.yml: 4-service target (api, spa, db, worker)
   - packages/db/src/client.ts: shared Drizzle client for api + worker
   - db/client.ts: root-level alias for convenience

   Parent: t_e1cbd87d -> t_24c9c3fd (T0)
This commit is contained in:
Hermes
2026-08-01 01:15:31 +00:00
parent 9203aee758
commit fca56ab77e
312 changed files with 3489 additions and 196 deletions
@@ -0,0 +1,11 @@
// AGENT INSTRUCTION: After every write (INSERT/UPDATE/DELETE), you MUST:
// 1. Insert activity feed entry
// 2. Call pg.notify('project_e_events', JSON.stringify({ type, action, id, workspace_id }))
// See AGENTS.md for full rules.
import NextAuth from 'next-auth';
import { authOptions } from '@/lib/auth-config';
const handler = NextAuth(authOptions);
export { handler as GET, handler as POST };
+26
View File
@@ -0,0 +1,26 @@
// AGENT INSTRUCTION: After every write (INSERT/UPDATE/DELETE), you MUST:
// 1. Insert activity feed entry
// 2. Call pg.notify('project_e_events', JSON.stringify({ type, action, id, workspace_id }))
// See AGENTS.md for full rules.
import { NextRequest, NextResponse } from 'next/server';
import { getAuthUser } from '@/lib/auth';
export async function GET(request: NextRequest) {
try {
const user = await getAuthUser(request);
if (!user) {
return NextResponse.json(
{ error: { code: 'UNAUTHORIZED', message: 'Not authenticated' } },
{ status: 401 }
);
}
return NextResponse.json({ user });
} catch {
return NextResponse.json(
{ error: { code: 'AUTH_ERROR', message: 'Invalid or expired token' } },
{ status: 401 }
);
}
}
@@ -0,0 +1,55 @@
// AGENT INSTRUCTION: After every write (INSERT/UPDATE/DELETE), you MUST:
// 1. Insert activity feed entry
// 2. Call pg.notify('project_e_events', JSON.stringify({ type, action, id, workspace_id }))
// See AGENTS.md for full rules.
import { NextRequest, NextResponse } from 'next/server';
import { db, users } from '@project-e/db';
import { eq } from 'drizzle-orm';
// POST /api/auth/passkey/login — Verify passkey login
export async function POST(request: NextRequest) {
try {
const body = await request.json();
const { credentialId, signature, authenticatorData, clientDataJSON } = body;
if (!credentialId || !signature) {
return NextResponse.json(
{ error: { code: 'VALIDATION_ERROR', message: 'credentialId and signature are required' } },
{ status: 400 }
);
}
// Find user by credential ID
const [user] = await db
.select()
.from(users)
.where(eq(users.passkeyCredentialId, credentialId))
.limit(1);
if (!user) {
return NextResponse.json(
{ error: { code: 'UNAUTHORIZED', message: 'Passkey not found' } },
{ status: 401 }
);
}
// In production, verify the WebAuthn assertion here using SimpleWebAuthn
// For now, we accept the passkey and return the user info
// The actual verification will be implemented with @simplewebauthn/server
return NextResponse.json({
user: {
id: user.id,
email: user.email,
name: user.name,
},
});
} catch (error) {
console.error('[passkey/login] error:', error);
return NextResponse.json(
{ error: { code: 'INTERNAL_ERROR', message: 'Failed to verify passkey' } },
{ status: 500 }
);
}
}
@@ -0,0 +1,49 @@
// AGENT INSTRUCTION: After every write (INSERT/UPDATE/DELETE), you MUST:
// 1. Insert activity feed entry
// 2. Call pg.notify('project_e_events', JSON.stringify({ type, action, id, workspace_id }))
// See AGENTS.md for full rules.
import { NextRequest, NextResponse } from 'next/server';
import { getAuthUser } from '@/lib/auth';
import { db, users } from '@project-e/db';
import { eq } from 'drizzle-orm';
// POST /api/auth/passkey/register — Start passkey registration
export async function POST(request: NextRequest) {
try {
const user = await getAuthUser(request);
if (!user) {
return NextResponse.json(
{ error: { code: 'UNAUTHORIZED', message: 'Not authenticated' } },
{ status: 401 }
);
}
const body = await request.json();
const { credentialId, publicKey, counter } = body;
if (!credentialId || !publicKey) {
return NextResponse.json(
{ error: { code: 'VALIDATION_ERROR', message: 'credentialId and publicKey are required' } },
{ status: 400 }
);
}
await db
.update(users)
.set({
passkeyCredentialId: credentialId,
passkeyPublicKey: publicKey,
passkeyCounter: counter ?? 0,
})
.where(eq(users.id, user.id));
return NextResponse.json({ success: true });
} catch (error) {
console.error('[passkey/register] error:', error);
return NextResponse.json(
{ error: { code: 'INTERNAL_ERROR', message: 'Failed to register passkey' } },
{ status: 500 }
);
}
}