From d03ef2db50f0f245b94f432132167f41d2d09f2f Mon Sep 17 00:00:00 2001 From: sdarbinyan Date: Sun, 26 Jul 2026 12:35:26 +0400 Subject: [PATCH] docs: final project closeout - classify TODO, backend spec, status Classified every TODO.md item into one of DONE/BACKEND/PRODUCT DECISION/FUTURE VERSION/BUG, verified against source, not against prior docs: - BACKEND items (bootstrap content, builder draft/publish, 6 admin CRUD domains, media pipeline) confirmed already covered by BACKEND_INTEGRATION.md; appended a mapping appendix rather than duplicating raw bullets. Fixed 22 stale internal BACKEND_API.md cross-references left over from before that file was archived. - PRODUCT DECISION items (dark mode, brand-color WCAG contrast, stars.component token gap, footer Contacts content, advanced analytics, payment providers) moved to new docs/PRODUCT_BACKLOG.md. - FUTURE VERSION items (Angular 22, bundle splitting, cart-modal composition cleanup, hero-spacing investigation) moved to new docs/FUTURE_FEATURES.md. - BUG: rewrote docs/KNOWN-ISSUES.md down to the one real, verified, currently-reproducible frontend bug (Ed25519 admin-auth error codes session-expired/invalid-signature are unreachable - toAuthErrorShape() never reads a body error code, only maps HTTP status, and no status ever produces those two codes - confirmed by reading auth.service.ts + auth-error.model.ts). Condensed the "Fixed" history instead of carrying full verbose repro text forward. - DONE items removed outright (dead-code deletion, dashboard false positive, RC-02 fixes, stale "dynamic-renderer unwired"/"178 missing keys" claims already disproven by source). docs/TODO.md rewritten to the exact "no blockers" template - nothing left qualifies as a release blocker. New docs/PROJECT_STATUS.md: honest per-area status (frontend/backend/ docs/auth/builder/storefront/admin), known limitations, and explicit production/backend/demo readiness calls - including correcting an initial draft's unpushed-commit count (53, not 10, per git log origin/B2B..HEAD). New docs/NEXT_PHASE.md: work that can only start once a real backend exists (gateway swap-in, mock removal, dormant-auth activation, role enforcement, integration/E2E tests, perf profiling, monitoring, maintenance-mode UI). docs/PROJECT_INDEX.md (the stated entry point) updated to link the new doc set and stop pointing at the now-archived BACKEND_API.md/AUTH.md. docs/FRONTEND-ROADMAP.md's "Known open items" replaced with pointers to the new category-split docs instead of a duplicated mixed list. Not swept: a handful of low-traffic docs (architecture ADRs, FRONTEND.md, EDITOR.md, ARCHITECTURE.md, PROJECT-STRUCTURE.md, StaticPages.md, ADMIN.md) still reference the old BACKEND_API.md/ AUTH.md filenames - noted as a known gap in PROJECT_STATUS.md rather than touched blindly, since they're historical-context docs, not the navigation entry point. --- docs/BACKEND_INTEGRATION.md | 66 ++++-- docs/FRONTEND-ROADMAP.md | 23 +-- docs/FUTURE_FEATURES.md | 19 ++ docs/KNOWN-ISSUES.md | 395 ++++-------------------------------- docs/NEXT_PHASE.md | 39 ++++ docs/PRODUCT_BACKLOG.md | 39 ++++ docs/PROJECT_INDEX.md | 24 ++- docs/PROJECT_STATUS.md | 52 +++++ docs/TODO.md | 52 +---- 9 files changed, 253 insertions(+), 456 deletions(-) create mode 100644 docs/FUTURE_FEATURES.md create mode 100644 docs/NEXT_PHASE.md create mode 100644 docs/PRODUCT_BACKLOG.md create mode 100644 docs/PROJECT_STATUS.md diff --git a/docs/BACKEND_INTEGRATION.md b/docs/BACKEND_INTEGRATION.md index 222a5f9..b14f506 100644 --- a/docs/BACKEND_INTEGRATION.md +++ b/docs/BACKEND_INTEGRATION.md @@ -1,6 +1,6 @@ # Backend Integration — Canonical Specification -**This is the single source of truth for backend implementation.** It supersedes and merges `docs/BACKEND_API.md`, `docs/AUTH.md`, `docs/ADMIN.md`, and `docs/BACKEND_API_REMAINING_WORK.md` (all archived — see `docs/archive/` and the note at the end of this file). It incorporates `docs/AUTHENTICATION.md` (§4) and `docs/ERROR_CONTRACT.md` (§6) in full; those files remain in place as standalone references but this document is authoritative. `docs/MAINTENANCE_MODE.md` is a companion doc, referenced from §6. +**This is the single source of truth for backend implementation.** It supersedes and merges `docs/archive/BACKEND_API.md`, `docs/AUTH.md`, `docs/ADMIN.md`, and `docs/BACKEND_API_REMAINING_WORK.md` (all archived — see `docs/archive/` and the note at the end of this file). It incorporates `docs/AUTHENTICATION.md` (§4) and `docs/ERROR_CONTRACT.md` (§6) in full; those files remain in place as standalone references but this document is authoritative. `docs/MAINTENANCE_MODE.md` is a companion doc, referenced from §6. Everything here is derived from the actual current frontend source code (branch `B2B`), not from prior/stale documentation. Primary input: `docs/context/BACKEND-AUDIT.md` (exhaustive audit of every HTTP call, gateway, facade, and model in the frontend). @@ -34,7 +34,7 @@ Source of truth for this section: `src/app/core/config/tenant-resolver.service.ts`, `src/app/shared/models/config/*`, and the mock document `src/assets/mock/bootstrap/bootstrap.json`. Cross-referenced against -`docs/context/BACKEND-AUDIT.md` §6, §2 and the prior `docs/BACKEND_API.md`. +`docs/context/BACKEND-AUDIT.md` §6, §2 and the prior `docs/archive/BACKEND_API.md`. ### 1.1 Request contract @@ -999,7 +999,7 @@ Example response: Exhaustive per-domain, per-endpoint contract for every backend touch-point the Angular frontend expects. Derived from source on branch `B2B` and cross-checked against `docs/context/BACKEND-AUDIT.md` (the this-session audit — the ground -truth for what code actually does), the prior `docs/BACKEND_API.md`, and the two +truth for what code actually does), the prior `docs/archive/BACKEND_API.md`, and the two sibling specs written this session: - **Auth / headers / JWT** — see `docs/AUTHENTICATION.md`. This section never @@ -4180,7 +4180,7 @@ Frontend view model: `AdminOrder` + `AdminOrderCustomer`, `AdminOrderPayment`, Bridge: **a new `AdminOrdersApiGateway` must contain the mapping** JSON → `AdminOrder`, honoring the `AdminOrdersGateway` interface methods (`loadOrders`, `loadOrder`, `updateStatus`, `requestRefund`, `addNote`, `archiveOrder`, `restoreOrder`, `deleteOrder`). The `status` field -must respect the order state machine (see the Orders CRUD contract / BACKEND_API.md §8.1). +must respect the order state machine (see the Orders CRUD contract / archive/BACKEND_API.md §8.1). The same "no mapper exists, write one inside the new `*ApiGateway`" note applies to Products, Users, Transactions, Monitoring, and Moderation. @@ -4292,14 +4292,14 @@ L on the server. A literal, top-to-bottom checklist. Work the phases in order; within a phase, items are roughly independent. Section references point to the assembled backend-integration document (this doc's -§8, the CRUD-contracts sections, and `docs/BACKEND_API.md` where a full shape already lives). +§8, the CRUD-contracts sections, and `docs/archive/BACKEND_API.md` where a full shape already lives). ### Phase 1 — Foundation (nothing role-gated works until these land) -- [ ] Implement session issuance/check/logout: `POST /users/sessions`, `GET /users/sessions/:id`, `DELETE /users/sessions/:id` — per Auth contract (§5a; BACKEND_API.md `/users/sessions/*`, already client-LIVE). +- [ ] Implement session issuance/check/logout: `POST /users/sessions`, `GET /users/sessions/:id`, `DELETE /users/sessions/:id` — per Auth contract (§5a; archive/BACKEND_API.md `/users/sessions/*`, already client-LIVE). - [ ] Implement the Ed25519 admin-auth flow `GET /api/admin/auth/challenge`, `POST /verify`, `POST /refresh`, `POST /logout` — client wiring is LIVE and 404s today (§5b). Return `AuthChallenge` / `AuthTokenPair` shapes exactly. - [ ] Honor the admin auth headers on every gated path: `AdminWebSessionID` + `Authorization: Bearer` for URLs containing `/admin/`, `/backoffice/`, `/builder/`, `/media/` (§3 interceptor pipeline). -- [ ] Serve real `GET /bootstrap` **content** (branding, theme, navigation, seo — not just the transport) — per Bootstrap contract (§6; BACKEND_API.md §4). This is a P0 blocker. +- [ ] Serve real `GET /bootstrap` **content** (branding, theme, navigation, seo — not just the transport) — per Bootstrap contract (§6; archive/BACKEND_API.md §4). This is a P0 blocker. - [ ] Populate `bootstrap.apiEndpoints.{website,builder,backoffice}` records so tenant-scoped paths resolve at runtime (§6; audit §24 — no path literals exist in client code). - [ ] Confirm tenant resolution inputs (host/slug/code) match `TenantConfig` so `ApiConfigService.getBaseUrl()` resolves the right base (§2, §6). - [ ] Adopt a consistent error envelope; the client maps failures to a `backend-unavailable` screen for admin auth — keep error bodies non-leaky (§5b; security guidance). @@ -4309,34 +4309,34 @@ independent. Section references point to the assembled backend-integration docum - [ ] Stand up `GET /category` returning the `CategoryDto` shape `CategoryMapper` tolerates (§8.4 Example A; audit §8) — already LIVE client-side. - [ ] Stand up `GET /items/:id`, `GET /category/:id`, `GET /items/randomitems`, `GET /searchitems` within the `normalizeItem` tolerance envelope (§8.4 Example B; audit §4, §7). -- [ ] Serve admin categories CRUD via the existing `AdminCategoriesApiGateway` contract: `loadCategories`, `loadCategory`, `create/update/delete/restore`, `isSlugTaken` — per Categories CRUD contract (BACKEND_API.md §6.9). **Already wired client-side (DONE).** +- [ ] Serve admin categories CRUD via the existing `AdminCategoriesApiGateway` contract: `loadCategories`, `loadCategory`, `create/update/delete/restore`, `isSlugTaken` — per Categories CRUD contract (archive/BACKEND_API.md §6.9). **Already wired client-side (DONE).** - [ ] Serve `GET /api/backoffice/products` and `GET /api/backoffice/categories` (storefront cards) — `ApiBackofficeDataProvider` is LIVE (audit §9). - [ ] Stand up `GET /regions` → `Region[]` (feeds the `X-Region` header; client falls back to 6 hardcoded regions) (audit §12). ### Phase 3 — Write-heavy customer domains -- [ ] Keep `POST /cart` (`CartPaymentRequest` → `QrCreateResponse`) and the frozen QR/card payment polling working unchanged (§10; payments frozen per BACKEND_API.md §2.8). -- [ ] Implement `POST /orders` (`CreateOrderRequest` → `CreateOrderResponse`) — client call is LIVE, fire-and-forget after payment (§10; BACKEND_API.md §16.9, marked DONE client-side). +- [ ] Keep `POST /cart` (`CartPaymentRequest` → `QrCreateResponse`) and the frozen QR/card payment polling working unchanged (§10; payments frozen per archive/BACKEND_API.md §2.8). +- [ ] Implement `POST /orders` (`CreateOrderRequest` → `CreateOrderResponse`) — client call is LIVE, fire-and-forget after payment (§10; archive/BACKEND_API.md §16.9, marked DONE client-side). - [ ] Implement `POST /purchase-email` (email receipt) (audit §4). - [ ] Accept review/question writes `POST /items/:id/callback` and `POST /items/:id/questiion` (**preserve the `questiion` typo** — it matches the client literal) (§11; audit §4). ### Phase 4 — Admin domains (each needs the token seam added first — §8.5) -- [ ] Add `AdminOrdersGateway` token + `AdminOrdersApiGateway`, switch `AdminOrdersFacade` to the token; implement `GET/POST /backoffice/orders*` incl. `POST /backoffice/orders/:id/status` respecting the order state machine — per Orders CRUD contract (§8.4 Example C, §8.5; BACKEND_API.md §6.11/§8.1). -- [ ] Add `AdminProductsGateway` token + `AdminProductsApiGateway`, switch `AdminProductsFacade`; implement Products CRUD + variants — per Products CRUD contract (§8.5; BACKEND_API.md §6.10/§7.2). -- [ ] Add `AdminTransactionsGateway` token + api gateway, switch `AdminTransactionsFacade`; implement transactions list/detail + `retryFailed` + `setFraudFlag` (tied to orders) — per Transactions contract (§8.5; BACKEND_API.md §6.12). -- [ ] Add `AdminUsersGateway` token + api gateway, switch `AdminUsersFacade`; implement users/roles/invitations/sessions/audit — per Users contract (§8.5; BACKEND_API.md §6.13). Reconcile the duplicate `AdminRole` naming (audit §25 #3). -- [ ] Add `AdminModerationGateway` token + api gateway, switch `AdminModerationFacade`; implement review + report status transitions — per Moderation contract (§8.5; BACKEND_API.md §6.14/§8.4/§8.5). -- [ ] Add `AdminMonitoringGateway` token + api gateway, switch `AdminMonitoringFacade`; implement events/queues/webhooks reads — per Monitoring contract (§8.5; BACKEND_API.md §6.16). -- [ ] Wire `AdminDashboardMetricsApiGateway` to the existing `ADMIN_DASHBOARD_METRICS_GATEWAY` token; implement `loadMetrics` — per Dashboard contract (§8.5; BACKEND_API.md §6.15). +- [ ] Add `AdminOrdersGateway` token + `AdminOrdersApiGateway`, switch `AdminOrdersFacade` to the token; implement `GET/POST /backoffice/orders*` incl. `POST /backoffice/orders/:id/status` respecting the order state machine — per Orders CRUD contract (§8.4 Example C, §8.5; archive/BACKEND_API.md §6.11/§8.1). +- [ ] Add `AdminProductsGateway` token + `AdminProductsApiGateway`, switch `AdminProductsFacade`; implement Products CRUD + variants — per Products CRUD contract (§8.5; archive/BACKEND_API.md §6.10/§7.2). +- [ ] Add `AdminTransactionsGateway` token + api gateway, switch `AdminTransactionsFacade`; implement transactions list/detail + `retryFailed` + `setFraudFlag` (tied to orders) — per Transactions contract (§8.5; archive/BACKEND_API.md §6.12). +- [ ] Add `AdminUsersGateway` token + api gateway, switch `AdminUsersFacade`; implement users/roles/invitations/sessions/audit — per Users contract (§8.5; archive/BACKEND_API.md §6.13). Reconcile the duplicate `AdminRole` naming (audit §25 #3). +- [ ] Add `AdminModerationGateway` token + api gateway, switch `AdminModerationFacade`; implement review + report status transitions — per Moderation contract (§8.5; archive/BACKEND_API.md §6.14/§8.4/§8.5). +- [ ] Add `AdminMonitoringGateway` token + api gateway, switch `AdminMonitoringFacade`; implement events/queues/webhooks reads — per Monitoring contract (§8.5; archive/BACKEND_API.md §6.16). +- [ ] Wire `AdminDashboardMetricsApiGateway` to the existing `ADMIN_DASHBOARD_METRICS_GATEWAY` token; implement `loadMetrics` — per Dashboard contract (§8.5; archive/BACKEND_API.md §6.15). - [ ] Resolve Customers: derive from the real Orders token (`AdminCustomersFacade`) or add a first-class customers source (§8.3). -- [ ] Defer Analytics until orders/products/moderation are real and a tracking pipeline exists; then implement the analytics summary source (§8.3, §8.6 step 10; BACKEND_API.md §6.17). +- [ ] Defer Analytics until orders/products/moderation are real and a tracking pipeline exists; then implement the analytics summary source (§8.3, §8.6 step 10; archive/BACKEND_API.md §6.17). ### Phase 5 — Builder / CMS (net-new write paths — no client call exists today) -- [ ] Implement builder bootstrap draft/publish/validate: `GET/PUT /builder/bootstrap/draft`, `POST /builder/bootstrap/publish`, `POST /builder/bootstrap/validate` — and add the client-side write call in `ProjectEditorFacade`/`ProjectEditorIoService` (§8.3, §17; BACKEND_API.md §6.7). P0 for the builder. -- [ ] Implement content pages / CMS write path and wire `ContentManagementFacade` beyond in-memory bootstrap (§8.3, §16; BACKEND_API.md §6.8). -- [ ] Implement the media upload/delete/replace pipeline behind `ApiMediaRepository` bound to the `MediaRepository` token (§8.5; BACKEND_API.md §6.18/§10). +- [ ] Implement builder bootstrap draft/publish/validate: `GET/PUT /builder/bootstrap/draft`, `POST /builder/bootstrap/publish`, `POST /builder/bootstrap/validate` — and add the client-side write call in `ProjectEditorFacade`/`ProjectEditorIoService` (§8.3, §17; archive/BACKEND_API.md §6.7). P0 for the builder. +- [ ] Implement content pages / CMS write path and wire `ContentManagementFacade` beyond in-memory bootstrap (§8.3, §16; archive/BACKEND_API.md §6.8). +- [ ] Implement the media upload/delete/replace pipeline behind `ApiMediaRepository` bound to the `MediaRepository` token (§8.5; archive/BACKEND_API.md §6.18/§10). ### Phase 6 — Hardening @@ -4345,5 +4345,27 @@ independent. Section references point to the assembled backend-integration docum - [ ] Add audit logging for admin mutations (order status, role changes, moderation actions, publish) — the client already models `*AuditEntry` / timeline shapes (audit §23). - [ ] Implement maintenance-mode / graceful `backend-unavailable` responses the client can surface (§5b). - [ ] Implement `GET /items/batch?ids=` to unblock the user-experience id-only sync redesign (remaining-work #16; §8.3). -- [ ] Add search suggestions/catalog-filter source if pursuing #15 (§8.6 step 12; BACKEND_API.md §6.6). +- [ ] Add search suggestions/catalog-filter source if pursuing #15 (§8.6 step 12; archive/BACKEND_API.md §6.6). - [ ] Plan dynamic sitemap generation (server-side, no frontend action) (remaining-work #18). + +--- + +## Appendix: `docs/TODO.md` items merged into this document (2026-07-26) + +Final Project Closeout moved every backend-shaped item out of `docs/TODO.md` into this +document. None were duplicated as raw new bullets — each is already covered by an +existing section above: + +| TODO item | Covered by | +|---|---| +| `bootstrap.json` real content (branding/theme/nav/seo) | §1 Bootstrap | +| Builder bootstrap draft/publish/validate | §1 (Draft vs Published), §8, §9 Phase 5 | +| Backoffice Products CRUD | §3 Products, §8, §9 Phase 4 | +| Media upload/delete/replace pipeline | §7 Uploads, §9 Phase 5 | +| Backoffice Orders CRUD + status transitions | §3 Orders, §8, §9 Phase 4 | +| Backoffice Transactions | §3 Transactions, §9 Phase 4 | +| Backoffice Users/roles/invitations | §3 Users/Roles, §9 Phase 4 | +| Backoffice Moderation (reviews/reports) | §3 Reviews/Reports, §9 Phase 4 | +| Backend Ready sprint / no real API contract | This entire document | + +`docs/TODO.md` is now empty of blockers — see that file. diff --git a/docs/FRONTEND-ROADMAP.md b/docs/FRONTEND-ROADMAP.md index f41b152..67bae8c 100644 --- a/docs/FRONTEND-ROADMAP.md +++ b/docs/FRONTEND-ROADMAP.md @@ -28,21 +28,14 @@ Found and fixed **2 P0s**: (1) `language.guard.ts`'s legacy-URL redirect broke q ## Known open items (not yet scheduled) -Full detail in `docs/KNOWN-ISSUES.md`. Summary: -- Payment modal / bank-payment iframe on Cart still custom (own focus-trap, multi-step state — note: RC A11Y-01 added a real focus-trap to it, but it's still not `app-dialog` itself) — candidate for `app-dialog` migration. -- Cart's native `confirm()` on clear-cart — no existing confirm-dialog pattern to follow yet. -- Genuine brand-color contrast failures (`--border-color`, `--success/warning/error/info-color` as text) — flagged by RC A11Y-01, need theme-owner sign-off before changing. -- `stars.component` rating glyph color has no exact token match — needs a deliberate token-extension decision (the `pages/category`/`pages/search` half of this was resolved by deleting those files, see below). -- Homepage hero-to-categories dead-space gap — traces to mock bootstrap config, not a code defect; needs real-tenant-data reproduction. -- Footer "Contacts" link has no static-page content in mock data — needs a content decision (found during RC walkthrough). -- Builder's static-page body editor is hidden inside a collapsed "Advanced" section, mislabeled "Source HTML (advanced)" — works, but needs a navigation/labeling decision (found during RC walkthrough). -- ~178 missing `adminXxx.*` i18n keys across admin backoffice. -- Theme Mode (dark/system) selector has no runtime CSS effect — real feature project, not a wiring fix. -- ~~`dynamic-renderer/` pipeline exists but is unwired~~ — verified 2026-07-25 (RC-02 task 6): it IS wired, it's the live homepage rendering engine (`HomeComponent` → `WebsiteRuntimeFacade` → `PageRendererService`/`PageResolverService` → `DynamicPageLayoutComponent`). Prior "unwired" note was stale. -- `primeng`/`primeicons` still in `package.json` despite the only consumer being deleted (RC PERF-01) — `npm uninstall` blocked by an unrelated broken `barry-cache` devDependency (`ETARGET`); fix that first. -- 2 large lazy chunks (`project-editor` 320 kB, `catalog-container` 126 kB) — no mechanical split found, needs a dedicated task. -- **RESOLVED 2026-07-25 (RC-02 task 6)**: `pages/category`, `pages/search`, `pages/item-detail`, `pages/info/**`, `pages/legal/**` (40+ files) were entirely unrouted dead code — deleted. See `docs/KNOWN-ISSUES.md` item 13. -- Backend integration: still mostly PLANNED/mock — a "backend ready" sprint was attempted and explicitly deferred (2026-07-24) pending a real API contract (`docs/BACKEND_API.md` is the canonical spec — no live endpoint confirmation beyond what's already CURRENT). +As of the 2026-07-26 Final Project Closeout, open items are split by category instead of one mixed list: +- Real, reproducible frontend bugs: `docs/KNOWN-ISSUES.md` (one open item). +- Items needing a client/business decision (dark mode, brand-color contrast, Contacts page content, advanced analytics, payment providers): `docs/PRODUCT_BACKLOG.md`. +- Nice-to-have, non-blocking future work (Angular 22, bundle splitting, cart-modal composition cleanup, hero-spacing investigation): `docs/FUTURE_FEATURES.md`. +- Backend integration: fully specified, not yet implemented — the single canonical spec is `docs/BACKEND_INTEGRATION.md`. +- Release blockers: `docs/TODO.md` — currently none. + +Overall status: `docs/PROJECT_STATUS.md`. ## Not audited / out of scope diff --git a/docs/FUTURE_FEATURES.md b/docs/FUTURE_FEATURES.md new file mode 100644 index 0000000..c95218f --- /dev/null +++ b/docs/FUTURE_FEATURES.md @@ -0,0 +1,19 @@ +# Future Features + +Nice-to-have, non-blocking work — no client decision needed, just not worth doing now. Verified against current repo state 2026-07-26. + +## Cart payment modal → `app-dialog` migration + +`.bank-payment-modal` on the cart page is a custom overlay component with its own focus-trap (added during the WCAG audit) rather than the shared `app-dialog` primitive. Functionally and accessibly complete as-is — migrating it to the shared primitive is a composition cleanup, deliberately deferred across every polish pass so far because it touches multi-step payment state. + +## Angular 22 upgrade + +Researched, not executed. Estimated ~2–3.5 days, needs the `barry-cache` dependency fix and a Node version bump first. Explicitly out of scope for the Backend Finalization Sprint. Plan: `docs/ANGULAR22_PLAN.md`. + +## Bundle splitting + +Two lazy chunks are large: `project-editor` (320 kB), `catalog-container` (126 kB). No mechanical split found yet — needs a dedicated profiling task. + +## Homepage hero-to-categories spacing investigation + +A dead-space gap between the hero and categories section on the storefront home page traces to bootstrap mock config (widget/section padding values in the dev fixture), not a confirmed code defect. Needs reproduction with real tenant data before it's worth investigating further — not a bug until it's confirmed to happen outside the mock fixture. diff --git a/docs/KNOWN-ISSUES.md b/docs/KNOWN-ISSUES.md index c20c740..5ceab63 100644 --- a/docs/KNOWN-ISSUES.md +++ b/docs/KNOWN-ISSUES.md @@ -1,368 +1,41 @@ -# Known Issues (fix after sprint wrap-up) +# Known Issues -Running list of bugs spotted during manual verification, deferred until the -current sprint's feature work is done. Add to this list as more are found; -don't fix inline unless asked. +Real, reproducible, currently-open frontend bugs only. Everything that needed a product/business decision moved to `docs/PRODUCT_BACKLOG.md`; everything nice-to-have moved to `docs/FUTURE_FEATURES.md`; everything backend-shaped moved to `docs/BACKEND_INTEGRATION.md`. Re-verified against source 2026-07-26. ## Open -1. **Homepage hero-to-categories dead space gap on the storefront home - page.** Traces to bootstrap mock config (widget/section padding values - in the dev bootstrap fixture), not a code defect in - `dynamic-page-layout.component.ts` or the widget components - not fixed - this session, needs config-side investigation if it reproduces with - real tenant data rather than mock config. +1. **Ed25519 admin-auth error codes `session-expired` and `invalid-signature` are unreachable — dead UI.** + `AuthError.code` is documented as routing to a dedicated recovery screen per code + (`core/auth/models/auth-error.model.ts:1-4`), but `toAuthErrorShape()` in + `core/auth/services/auth.service.ts:110-118` derives the code for any real + `HttpErrorResponse` *exclusively* from `authErrorCodeFromStatus(error.status)` + (line 112) — it never reads the caller-supplied `fallbackCode` parameter for + real HTTP errors, and never reads any body-level error code from the response. + `authErrorCodeFromStatus()` (`auth-error.model.ts:21-32`) only ever returns + `'unauthorized'`, `'forbidden'`, or `'backend-unavailable'` — there is no status + or body condition anywhere in the codebase that produces `'session-expired'` or + `'invalid-signature'`. Both screens exist and are wired, but are permanently + unreachable from any real backend response today. + - **Fix requires both sides**: a backend that returns a distinguishable + `error.code` in the response body (see `docs/ERROR_CONTRACT.md`), and a small + frontend change to `toAuthErrorShape()` to prefer that body code over the + blanket status-based fallback. + - Found: 2026-07-26, Backend Finalization Sprint documentation pass (traced while + writing `docs/AUTHENTICATION.md`/`docs/ERROR_CONTRACT.md`). -2. **~179 untranslated raw i18n keys across the entire admin backoffice CRUD - UI (products/categories/orders/transactions/users/monitoring/analytics).** - `translations.ts`/`en.ts`/`ru.ts`/`hy.ts` have no `adminProducts.*`, - `adminCategories.*`, `adminOrders.*`, `adminTransactions.*`, - `adminUsers.*`, `adminMonitoring.*`, or `adminAnalytics.*` sections at all - (confirmed: zero matches for any of these prefixes in any of the 4 i18n - files). `TranslateService.t()` falls through to returning the raw dotted - key string when a key isn't found (see `translate.service.ts`), so every - templated string in these features (buttons, table headers, filters, - badges, empty/placeholder text) renders literally as e.g. - `adminProducts.create` instead of real copy - same root cause as the - already-fixed dashboard Quick Actions bug below, just at the scale of - almost the entire admin backoffice built across Sprints 20-27. - - Counted by grepping all `'adminXxx.yyy'` translate-pipe usages under - `src/app/features/admin/**`: `adminProducts` 72, `adminCategories` 23, - `adminOrders` 24, `adminUsers` 21, `adminMonitoring` 13, - `adminAnalytics` 12, `adminTransactions` 13 (≈178 distinct keys, ×3 - locales ≈ 534 strings to author). - - Likely why it was never caught: every affected Sprint (20-27) explicitly - noted live-browser click-through was blocked on the guarded admin route - and verification was tsc/build/arch:check only - none of those catch - missing i18n keys (pipe arguments are plain strings, not type-checked). - - Found: 2026-07-15, during Sprint 28 manual audit (reading templates + - grepping i18n files, not live browser). - - **Deferred to Sprint 29** ("translation validation" is explicit Sprint 29 - scope per `SPRINT-PLAN.md` (removed, see git history)) rather than fixed inline during Sprint - 28 polish - authoring ~534 correct strings across 3 languages is a large, - separate, mechanical pass of its own and shouldn't be rushed inside a - polish sprint. Sprint 28 only adds the handful of new keys it introduces - itself (empty-state copy for the skeleton/empty-state consistency fix), - it does not touch the ~178 pre-existing gap. +## Fixed (this cycle) -3. **Theme Mode selector has no runtime effect.** `theme-section`'s light/dark/ - system dropdown saves correctly and `theme-engine.service.ts` sets a - `data-theme-mode` attribute on ``, but no CSS anywhere in the app - reads that attribute — picking Dark or System changes nothing visually - today. Theme palette colors are unaffected (they're real CSS custom - properties, genuinely live). Fixing this means implementing actual - dark-mode CSS (a dark palette + `[data-theme-mode]`/`prefers-color-scheme` - strategy + a `matchMedia` listener for "system", since that can change - without a reload) — a real feature project, not a wiring fix. - - Found: 2026-07-17, project-editor bug-hunt audit (`docs/EDITOR.md`). +Condensed — full detail in commit history and `docs/RELEASE_REPORT.md`. -4. **`dynamic-renderer/` pipeline exists but is never wired up.** - `src/app/dynamic-renderer/{page-renderer,section-renderer,section-engine, - page-resolver,widget-host}` has services and models but zero components - or templates (every directory has only a `.gitkeep`). The storefront - homepage renders through a separate, older path that doesn't consume it. - Two editor fields feed this dead pipeline with no visible effect: - `layout.type` (Theme section, "Site Layout") and the homepage section's - own `type` field (`homepage-section.component.ts`'s - `updateSection(id, 'type', ...)` has no UI calling it, because of this). - Needs a decision: finish wiring it in (if it's WIP for a planned - replacement) or delete it as abandoned scaffolding. - - Found: 2026-07-17, project-editor bug-hunt audit. - -5. **`HeaderConfig.showProfile` toggle has no corresponding UI.** The header - editor's "Profile" toggle updates a real config field, but - `header.component.html` never references `showProfile` — there's no - profile/account menu in the storefront header to show or hide. Needs an - auth-system check first (does one exist yet?) before building the menu. - - Found: 2026-07-17, project-editor bug-hunt audit. - -6. **Payment modal / bank-payment iframe on Cart still custom, not `app-dialog`.** - Correction (2026-07-24, RC A11Y-01): the "already has focus-trap" assumption - below was wrong — it had none. RC A11Y-01 ported `app-dialog`'s confirmed- - correct focus-trap/Escape/return-focus pattern directly onto it - (`ACCESSIBILITY_REPORT.md` (removed, see git history)), so the accessibility gap is closed. It's - still a separate custom component, not the shared `app-dialog` itself — - migrating it to the actual primitive remains a composition change, - deliberately left out of every polish pass so far. - - Found: 2026-07-23, RC-Premium-01 (`STORE_FRONT_UX_REVIEW.md` (removed, see git history)). - -7. **Cart's `clearCart()` uses native `confirm()`, no styled confirm dialog.** - No existing storefront pattern for a confirm-remove dialog to follow yet — - introducing the first one is an architecture decision, not polish. - - Found: 2026-07-23, RC-Premium-01. - -8. ~~`stars.component` rating glyph color and a few legacy hex literals in - `pages/category`/`pages/search` have no exact design-token match.`~~ - **Resolved 2026-07-25 (RC-02 task 6):** `pages/category`/`pages/search` - deleted as unrouted dead code (see item 13). `stars.component` literals - remain, tracked separately if still relevant. - - Found: 2026-07-23, RC-Premium-01. - -9. **Genuine brand-color contrast failures (WCAG AA).** `--border-color` - fails 3:1 UI-component contrast in every theme (1.24-1.42:1 measured); - `--success/--warning/--error/--info-color` fail 4.5:1 when used as plain - text-on-white in a handful of places. Real palette colors, not a token - bug — fixing means visibly changing the brand, needs theme-owner sign-off. - - Found: 2026-07-24, RC A11Y-01 (`ACCESSIBILITY_REPORT.md` (removed, see git history)). - -10. **Footer "Contacts" link has no static-page content in mock data.** - Unlike the "About" link (which was a route-name mismatch, fixed), no - content exists for Contacts at all — needs a content decision, not a - code fix. - - Found: 2026-07-24, Release Candidate walkthrough (`RELEASE_REPORT.md` (removed, see git history)). - -11. **Builder's static-page body editor is hidden and mislabeled.** The - actual WYSIWYG content editor isn't on the "Content" tab (title/image - only) — it's inside a collapsed `
` under "Advanced", labeled - "Source HTML (advanced)" though it's the only way to edit page content. - Works correctly once found; relocating/relabeling is a navigation - decision, not a bug fix. - - Found: 2026-07-24, Release Candidate walkthrough. - -12. **`primeng`/`primeicons` still in `package.json` after their only - consumer was deleted.** `npm uninstall` fails (`ETARGET`) on a - pre-existing, unrelated broken `barry-cache` devDependency resolution — - fix that first, then drop the now-fully-unused dependency (likely closes - most of the remaining bundle-budget overage in one move). - - Found: 2026-07-24, RC PERF-01 (`PERFORMANCE_REPORT.md` (removed, see git history)). - -13. **RESOLVED 2026-07-25 (RC-02 task 6) — `pages/category/*`, `pages/search/*`, - `pages/item-detail/*`, `pages/info/**`, `pages/legal/**` (40+ files) were - entirely unrouted dead code, not live pages.** Decision: delete (not - wire up) — each had a live replacement already serving its traffic. - Verified directly against `src/app/app.routes.ts`: - `category/:id` and `category/:id/items` `redirectTo: 'catalog/:id'` - (served by `CatalogContainerComponent`); `search` also routes to - `CatalogContainerComponent`; `product/:id` routes to - `ProductDetailsContainerComponent`, not `pages/item-detail`; - `cmsContentRoutes` (meant to route `pages/info/**`/`pages/legal/**`) is a - literal empty array (`app.routes.ts:292`) behind a - `// TODO(CMS): Resolve informational/legal pages from backend content - configuration here` comment — About/Contacts/FAQ/Delivery/Guarantee/ - Company-Details/Payment-Terms/Return-Policy/Public-Offer/Privacy-Policy - are all actually served by the catch-all `:staticPath` route resolving - `bootstrap.staticPages` (`pages/static-page/static-page.component.ts`), - confirmed independently by `docs/FRONTEND.md`'s own routing section - ("Static/CMS pages resolve dynamically... no hardcoded page list"). - **This means several "fixes" earlier in this document and in - since-deleted audit reports (see git history) were applied to dead code - with zero production effect** - — see the correction note on Fixed item 7 below. This was missed by - three separate passes this cycle (RC-Premium-01, RC STORE-01, and the - dead-code cleanup sprint, which manually re-verified against - `app.routes.ts` and still concluded these files were live — an error in - that verification, not a tooling blind spot this time) before being - caught during the documentation-consolidation pass. Needs a decision: - wire `cmsContentRoutes` back up (restoring 10 hardcoded per-locale pages - that duplicate what the CMS static-page renderer already does), or - delete all 40+ files as genuinely dead now that the duplication is - confirmed intentional-by-omission rather than accidental. - - Found: 2026-07-25, Documentation Cleanup pass. - -14. **No `canDeactivate` guard on `admin/products/:id/edit`.** Categories - protect against navigating away with unsaved changes - (`adminCategoryDirtyGuard`, `app.routes.ts:121,131`); products do not, - despite `AdminProductsFacade` having its own dirty-tracking draft logic. - Inconsistent, low-effort fix (mirror the categories guard) but not - applied here — this pass is documentation-only. - - Found: 2026-07-19 (`PROJECT-STATE.md` (removed, see git history)), re-verified - 2026-07-25 against current `app.routes.ts` — still true. - -## Fixed - -1. **Full-project UX/UI + motion pass across storefront, admin dashboard, - admin CRUD, and project-editor.** - User asked (2026-07-16) for a full UX/UI audit across admin, dashboard, - and storefront, sequenced: storefront -> admin dashboard -> admin CRUD -> - project-editor. All 4 phases completed: - - Fixed: `project-editor-save-bar` buttons were plain unstyled `