Audited every *.md in docs/ and root. Merged five overlapping backend docs (BACKEND_INTEGRATION.md + AUTHENTICATION.md + ERROR_CONTRACT.md + MAINTENANCE_MODE.md + the already-archived BACKEND_API.md/ BACKEND_API_REMAINING_WORK.md) into one canonical docs/BACKEND.md (4775 lines, 10 numbered sections) - deleted the four standalone files outright now that their content is fully inlined. Archived (not deleted - real historical value): ADMIN.md (Sprint 19-28 build log, sprint-report-shaped, not a living reference) and FRONTEND-ROADMAP.md (despite its name, a shipped-history changelog with detail no other doc has - not a forward roadmap, so keeping it in root alongside NEXT_PHASE.md was exactly the "10 roadmaps" confusion being cleaned up). Deleted outright (zero value): SPRINTS.md - a leftover copy-pasted sprint-kickoff prompt saved as a file, not documentation. Rewrote docs/PROJECT_STATUS.md with completion-percentage estimates per area (frontend/backend/UI/admin/storefront) and an explicit first-customer-readiness call. Rewrote docs/NEXT_PHASE.md to the strict 5-phase structure (backend integration -> production testing -> performance -> monitoring -> v2 ideas), pointing to PRODUCT_BACKLOG .md/FUTURE_FEATURES.md for phase 5 detail instead of duplicating it. Rewrote root README.md - was stale (referenced deleted pages/info, pages/legal folders from a prior RC pass), now covers architecture, frontend/backend status, how to run, mock<->API switch mechanism (useMockData in environment.ts), current folder structure, and a documentation map. Updated docs/PROJECT_INDEX.md (the stated entry point) to link only the surviving doc set - every remaining document is reachable from it. Fixed every broken/stale cross-reference to the deleted/renamed backend docs across ARCHITECTURE.md, EDITOR.md, FRONTEND.md, PROJECT-STRUCTURE.md, StaticPages.md, KNOWN-ISSUES.md (10 individual link fixes, verified by repo-wide grep before and after). Left CHANGELOG.md's two historical entries untouched - changelogs are append-only history, not live navigation, editing past entries would misrepresent what was true at the time. Not touched (explicitly out of scope): docs/architecture/foundation/** (enforced ADRs/governance, permanent not sprint-shaped), docs/context/** (Barry Cache infrastructure, "do not edit by hand" per CLAUDE.md), .claude/worktrees/** (separate git worktrees containing an unrelated project's docs, not this repo's documentation). docs/ root: 22 files -> 16. Plus 5 in docs/archive/ (was 3).
42 lines
3.5 KiB
Markdown
42 lines
3.5 KiB
Markdown
# Known Issues
|
|
|
|
Real, reproducible, currently-open frontend bugs only. Everything that needed a product/business decision moved to `docs/PRODUCT_BACKLOG.md`; everything nice-to-have moved to `docs/FUTURE_FEATURES.md`; everything backend-shaped moved to `docs/BACKEND.md`. Re-verified against source 2026-07-26.
|
|
|
|
## Open
|
|
|
|
1. **Ed25519 admin-auth error codes `session-expired` and `invalid-signature` are unreachable — dead UI.**
|
|
`AuthError.code` is documented as routing to a dedicated recovery screen per code
|
|
(`core/auth/models/auth-error.model.ts:1-4`), but `toAuthErrorShape()` in
|
|
`core/auth/services/auth.service.ts:110-118` derives the code for any real
|
|
`HttpErrorResponse` *exclusively* from `authErrorCodeFromStatus(error.status)`
|
|
(line 112) — it never reads the caller-supplied `fallbackCode` parameter for
|
|
real HTTP errors, and never reads any body-level error code from the response.
|
|
`authErrorCodeFromStatus()` (`auth-error.model.ts:21-32`) only ever returns
|
|
`'unauthorized'`, `'forbidden'`, or `'backend-unavailable'` — there is no status
|
|
or body condition anywhere in the codebase that produces `'session-expired'` or
|
|
`'invalid-signature'`. Both screens exist and are wired, but are permanently
|
|
unreachable from any real backend response today.
|
|
- **Fix requires both sides**: a backend that returns a distinguishable
|
|
`error.code` in the response body (see `docs/BACKEND.md` §6 Error Model), and a small
|
|
frontend change to `toAuthErrorShape()` to prefer that body code over the
|
|
blanket status-based fallback.
|
|
- Found: 2026-07-26, Backend Finalization Sprint documentation pass (traced while
|
|
writing `docs/BACKEND.md` §4 Authentication / §6 Error Model).
|
|
|
|
## Fixed (this cycle)
|
|
|
|
Condensed — full detail in commit history and `docs/RELEASE_REPORT.md`.
|
|
|
|
- App-wide query-param routing broken (P0) — `language.guard.ts` legacy redirect percent-encoded query strings into the path.
|
|
- Backoffice Categories CRUD broken end-to-end (P0) — wrong provider-mode fallback always picked the real HTTP gateway with no backend present.
|
|
- Cart/builder native `confirm()`/`alert()` (16 call sites) replaced with shared `app-confirm-dialog` / toast service.
|
|
- `getMainImage()` no-photo fallback and footer payment-icon assets referenced files that didn't exist — both fixed, `onerror` fallback added everywhere.
|
|
- Backoffice Monitoring showed raw HTTP/queue/webhook strings by default — now friendly wording with technical detail collapsed behind a `<details>`.
|
|
- Category/subcategory empty states used apology wording ("Oops!") for a normal zero-results state.
|
|
- `pages/category`, `pages/search`, `pages/item-detail`, `pages/info/**`, `pages/legal/**` (40+ files) were unrouted dead code — deleted.
|
|
- `dynamic-renderer/` was believed unwired — verified it's the live homepage rendering pipeline, no action needed.
|
|
- `admin/products/:id/edit` missing `canDeactivate` guard — added, mirrors categories.
|
|
- `primeng`/`primeicons` unused dependency — removed.
|
|
- Builder static-page body editor hidden inside a mislabeled collapsed section — un-hidden, relabeled.
|
|
- Several project-editor/admin-categories correctness bugs (footer icon id collisions, features toggle only driving one flag, languages silent duplicate no-op, static-pages slug collision, branding `socialImageUrl` never read, media-picker facade filter leakage between dialogs, categories draft-recovery/drag-reorder bugs, hardcoded locale-tab order) — see git history for the full per-bug list.
|