Files
marketplaces/docs/PACKAGE-EXTRACTION.md
sdarbinyan 2e4bb4ae00
Some checks failed
Architecture Governance / architecture (push) Has been cancelled
feat: publish @marketplaces/auth to private registry, drop local package copy
Stood up Verdaccio (Docker, on the dev server) as a private npm registry
since no public registry/NPM_TOKEN exists yet. Published @marketplaces/auth
and @marketplaces/payment there, removed the local packages/ staging copy
from this repo, and switched marketplaces to install @marketplaces/auth
0.1.0 as a real npm dependency through the registry.

- .npmrc scopes @marketplaces to the Verdaccio registry (no token committed;
  each installer/CI supplies its own via npm login or an env-injected token)
- Verified: fresh npm install, ng build, arch:check:boundaries, and full
  test suite (103/103) all pass against the registry-installed package
- Registry is reachable only via SSH tunnel today (firewall allows 80/443/
  SSH only); public/CI access is a follow-up decision, documented in
  docs/PACKAGE-EXTRACTION.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-18 01:32:20 +04:00

4.5 KiB

@marketplaces/auth & @marketplaces/payment — build, version, publish, consume

See ADR-0001 for why. This doc is the how.

Current state

Live end to end. marketplaces has no local copy of either package — it installs @marketplaces/auth@0.1.0 from a private Verdaccio registry on the dev server. packages/ no longer exists in this repo.

1. Source repo

sources.vitanova.network/sdarbinyan/vitanovaPackages — single monorepo (npm workspaces), packages/auth + packages/payment, main branch. This is where the package source lives and where CI publishes from.

2. Registry

Verdaccio, running in Docker on the dev server (213.21.246.138, container verdaccio, config/storage at /srv/marketplaces/verdaccio/). Not publicly reachable — the server firewall only allows 80/443/SSH, and opening 4873 or loosening the registry's $authenticated access policy are both security-relevant changes that need an explicit decision, not something done silently. Reach it today via SSH tunnel:

ssh -L 4873:127.0.0.1:4873 seto@213.21.246.138

Follow-up decision needed before CI can publish/consume without a human at the keyboard: either (a) reverse-proxy /verdaccio/ or a subdomain through the existing nginx on 443 with TLS, or (b) open 4873 directly (not recommended — plain HTTP with credentials). Neither is done yet.

@marketplaces/* packages require an authenticated user to install (access: $authenticated in Verdaccio config) — deliberately not $all, since loosening that is itself a security-relevant config change. A registry user marketplaces-ci exists; get a token via npm login --registry=http://127.0.0.1:4873/ (through the tunnel) and set it locally as a user-level ~/.npmrc _authToken line, or export NPM_TOKEN and append it to .npmrc at CI runtime — never commit a token into this repo's .npmrc.

marketplaces/.npmrc maps the scope: @marketplaces:registry=http://127.0.0.1:4873/ — update this once the registry has a real public/internal address.

3. Versioning

Changesets — built for "many packages, one repo, independent versions." A PR that changes packages/auth adds a changeset file (npx changeset from the vitanovaPackages repo root, picks package + bump type + writes a short description) alongside the code change.

4. Publishing (CI)

vitanovaPackages/.github/workflows/release.yml: on push to main, installs, builds, tests, then changesets/action — opens/updates a version-bump PR if unreleased changesets exist, publishes once that PR merges. Needs NPM_TOKEN (Verdaccio token) and GITHUB_TOKEN as repo secrets; also needs CI to reach the registry, which circles back to §2's open follow-up. Until that's resolved, publish manually the same way this session did it: build (tsc), npm publish --registry http://127.0.0.1:4873/ through the tunnel.

5. Consuming from marketplaces (and other projects)

npm install @marketplaces/auth
import { AuthService, AdminAuthService, adminAuthGuard, ... } from '@marketplaces/auth';

Pinned to an exact version ("0.1.0", no ^/~) per ADR-0001's consequence about registry-outage blast radius — bump deliberately, not automatically.

renovate.json at repo root opens a grouped PR whenever either package publishes a new version — review and merge it manually (automerge: false).

6. Migration cutover

Auth: done. @marketplaces/auth@0.1.0 holds the real implementation — two independent modules, telegram/ (live Telegram QR/session auth, customer + admin) and ed25519/ (future challenge/response admin auth, backend not shipped). Environment coupling was replaced with AUTH_API_URL/TELEGRAM_BOT_USERNAME injection tokens, provided from app.config.ts; environment.production became Angular's isDevMode(). AdminPermissionsService and requireAdminPermission stayed in marketplaces (core/admin-auth/) since they read this app's mock Users domain, not a portable auth concern. All ~30 call sites import @marketplaces/auth. npm run build, npm run arch:check:boundaries, and npm test (103/103) all pass against the registry-installed package.

Payment: not started. core/finance/core/pricing still live in marketplaces, same process as above once prioritized. @marketplaces/payment@0.1.0 is published (scaffold only) but not yet a marketplaces dependency.