Stood up Verdaccio (Docker, on the dev server) as a private npm registry since no public registry/NPM_TOKEN exists yet. Published @marketplaces/auth and @marketplaces/payment there, removed the local packages/ staging copy from this repo, and switched marketplaces to install @marketplaces/auth 0.1.0 as a real npm dependency through the registry. - .npmrc scopes @marketplaces to the Verdaccio registry (no token committed; each installer/CI supplies its own via npm login or an env-injected token) - Verified: fresh npm install, ng build, arch:check:boundaries, and full test suite (103/103) all pass against the registry-installed package - Registry is reachable only via SSH tunnel today (firewall allows 80/443/ SSH only); public/CI access is a follow-up decision, documented in docs/PACKAGE-EXTRACTION.md Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
4.5 KiB
@marketplaces/auth & @marketplaces/payment — build, version, publish, consume
See ADR-0001 for why. This doc is the how.
Current state
Live end to end. marketplaces has no local copy of either package — it installs @marketplaces/auth@0.1.0 from a private Verdaccio registry on the dev server. packages/ no longer exists in this repo.
1. Source repo
sources.vitanova.network/sdarbinyan/vitanovaPackages — single monorepo (npm workspaces), packages/auth + packages/payment, main branch. This is where the package source lives and where CI publishes from.
2. Registry
Verdaccio, running in Docker on the dev server (213.21.246.138, container verdaccio, config/storage at /srv/marketplaces/verdaccio/). Not publicly reachable — the server firewall only allows 80/443/SSH, and opening 4873 or loosening the registry's $authenticated access policy are both security-relevant changes that need an explicit decision, not something done silently. Reach it today via SSH tunnel:
ssh -L 4873:127.0.0.1:4873 seto@213.21.246.138
Follow-up decision needed before CI can publish/consume without a human at the keyboard: either (a) reverse-proxy /verdaccio/ or a subdomain through the existing nginx on 443 with TLS, or (b) open 4873 directly (not recommended — plain HTTP with credentials). Neither is done yet.
@marketplaces/* packages require an authenticated user to install (access: $authenticated in Verdaccio config) — deliberately not $all, since loosening that is itself a security-relevant config change. A registry user marketplaces-ci exists; get a token via npm login --registry=http://127.0.0.1:4873/ (through the tunnel) and set it locally as a user-level ~/.npmrc _authToken line, or export NPM_TOKEN and append it to .npmrc at CI runtime — never commit a token into this repo's .npmrc.
marketplaces/.npmrc maps the scope: @marketplaces:registry=http://127.0.0.1:4873/ — update this once the registry has a real public/internal address.
3. Versioning
Changesets — built for "many packages, one repo, independent versions." A PR that changes packages/auth adds a changeset file (npx changeset from the vitanovaPackages repo root, picks package + bump type + writes a short description) alongside the code change.
4. Publishing (CI)
vitanovaPackages/.github/workflows/release.yml: on push to main, installs, builds, tests, then changesets/action — opens/updates a version-bump PR if unreleased changesets exist, publishes once that PR merges. Needs NPM_TOKEN (Verdaccio token) and GITHUB_TOKEN as repo secrets; also needs CI to reach the registry, which circles back to §2's open follow-up. Until that's resolved, publish manually the same way this session did it: build (tsc), npm publish --registry http://127.0.0.1:4873/ through the tunnel.
5. Consuming from marketplaces (and other projects)
npm install @marketplaces/auth
import { AuthService, AdminAuthService, adminAuthGuard, ... } from '@marketplaces/auth';
Pinned to an exact version ("0.1.0", no ^/~) per ADR-0001's consequence about registry-outage blast radius — bump deliberately, not automatically.
renovate.json at repo root opens a grouped PR whenever either package publishes a new version — review and merge it manually (automerge: false).
6. Migration cutover
Auth: done. @marketplaces/auth@0.1.0 holds the real implementation — two independent modules, telegram/ (live Telegram QR/session auth, customer + admin) and ed25519/ (future challenge/response admin auth, backend not shipped). Environment coupling was replaced with AUTH_API_URL/TELEGRAM_BOT_USERNAME injection tokens, provided from app.config.ts; environment.production became Angular's isDevMode(). AdminPermissionsService and requireAdminPermission stayed in marketplaces (core/admin-auth/) since they read this app's mock Users domain, not a portable auth concern. All ~30 call sites import @marketplaces/auth. npm run build, npm run arch:check:boundaries, and npm test (103/103) all pass against the registry-installed package.
Payment: not started. core/finance/core/pricing still live in marketplaces, same process as above once prioritized. @marketplaces/payment@0.1.0 is published (scaffold only) but not yet a marketplaces dependency.