39 Commits
Author SHA1 Message Date
sbstp f480407927 update htmx to latest in 2.x branch
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
ci/woodpecker/tag/release Pipeline was successful
2026-08-07 22:53:42 -04:00
sbstp 9267786371 cargo fmt
ci/woodpecker/push/fmt Pipeline is pending
ci/woodpecker/push/test Pipeline is pending
ci/woodpecker/push/e2e Pipeline was canceled
2026-08-07 22:49:50 -04:00
sbstp e24f4ff7e2 archived list count 2026-08-07 22:49:31 -04:00
sbstp 56cd6e32e9 hx boost + bug fix 2026-08-07 22:46:53 -04:00
sbstp 689bd95ff0 list archive
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-07 22:16:29 -04:00
sbstp 240d993d57 improve ux 2026-08-07 21:42:38 -04:00
sbstp c2f6b07742 version 0.4.0 [skip ci]
ci/woodpecker/tag/release Pipeline was successful
2026-08-04 00:06:03 -04:00
sbstp 863d43ef8c record meals that were added to list, allow delete with ingredients
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-04 00:01:23 -04:00
sbstp dcd1203d31 fix width of passkey button
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-03 22:36:40 -04:00
sbstp 5638fc4979 fmt & version 0.3.0 [skip ci]
ci/woodpecker/tag/release Pipeline was successful
2026-08-03 21:35:40 -04:00
sbstp 3695fc68d6 meal categories
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-03 21:29:33 -04:00
sbstp cf6853d71e show/hide password button 2026-08-03 21:02:03 -04:00
sbstp fdbf40adac style updates 2026-08-03 14:58:10 -04:00
sbstp a6482ddb0e reset/update password
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-03 11:33:24 -04:00
sbstp 3160a898be version 0.2.0 [skip ci]
ci/woodpecker/tag/release Pipeline was successful
2026-08-03 00:24:54 -04:00
sbstp 209363774c passwordless login + proper migrations
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-03 00:23:10 -04:00
sbstp 1291c5a33a embed assets and version 0.1.2
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
ci/woodpecker/tag/release Pipeline was successful
2026-08-02 21:28:54 -04:00
sbstp d6c31375ae version 0.1.1 [skip ci]
ci/woodpecker/tag/release Pipeline was successful
2026-08-02 20:42:12 -04:00
sbstp a014ffc602 fix release ci [skip ci] 2026-08-02 20:41:38 -04:00
sbstp c80cc02798 add woodpecker release job [skip ci]
ci/woodpecker/tag/release Pipeline was canceled
2026-08-02 20:36:16 -04:00
sbstp fdd3e8c5da add passkey support
ci/woodpecker/push/e2e Pipeline failed
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-02 16:46:52 -04:00
sbstp 04c9724c76 reduce e2e test flakiness
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-02 00:18:22 -04:00
sbstp a2134b93f1 cargo fmt
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-01 23:52:40 -04:00
sbstp 51dcff1202 fix logging issues
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-01 23:42:26 -04:00
sbstp a7544f837e make list text clickable to toggle 2026-08-01 23:24:13 -04:00
sbstp 279cdb869d cargo fmt
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-01 23:05:37 -04:00
sbstp fbb49bc560 fix flaky e2e test 2026-08-01 23:05:20 -04:00
sbstp 7309971c74 websocket sync e2e test 2026-08-01 23:01:42 -04:00
sbstp 4adcfb1377 add meal e2e test
ci/woodpecker/push/e2e Pipeline failed
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-01 22:47:41 -04:00
sbstp 77a9d49eb4 add e2e tests for lists and meals 2026-08-01 22:40:43 -04:00
sbstp 2e0d76a9c2 fix fmt 2026-08-01 22:14:33 -04:00
sbstp b8a75ee2b1 fix e2e tests
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-01 22:05:22 -04:00
sbstp 0324a97748 add woodpecker pipelines
ci/woodpecker/push/fmt Pipeline is pending
ci/woodpecker/push/test Pipeline is pending
ci/woodpecker/push/e2e Pipeline was canceled
2026-08-01 21:50:19 -04:00
sbstp 61ea97265c add playwright tests 2026-08-01 21:24:48 -04:00
sbstp 250a18cfbb remove dead code 2026-08-01 20:35:14 -04:00
sbstpandsbstp 9b32fd23a7 Add support for meals (#1)
Reviewed-on: #1
Co-authored-by: Simon Bernier St-Pierre <git.sbstp.ca@gmail.com>
2026-08-01 20:27:38 -04:00
sbstp 6a2cef2003 cleanup errors 2026-08-01 18:32:14 -04:00
sbstp 188ce23e67 hexagonal refactor 2026-08-01 18:27:22 -04:00
sbstp 6979cabe8b clean shutdown 2026-08-01 16:29:31 -04:00
42 changed files with 9432 additions and 1940 deletions
+4
View File
@@ -3,3 +3,7 @@
/sustenance.db*
/.env
/seed.json
/e2e/node_modules/
/e2e/test-results/
/e2e/playwright-report/
/test-results/
+17
View File
@@ -0,0 +1,17 @@
when:
event: [push, pull_request]
steps:
e2e-build:
image: rust:1
commands:
- cargo build
e2e-test:
image: node:24
directory: e2e
commands:
- apt-get update
- apt-get install -y --no-install-recommends ca-certificates fonts-liberation libasound2 libatk-bridge2.0-0 libatk1.0-0 libcups2 libdbus-1-3 libdrm2 libgbm1 libglib2.0-0 libgtk-3-0 libnspr4 libnss3 libpango-1.0-0 libx11-6 libxcb1 libxcomposite1 libxdamage1 libxext6 libxfixes3 libxkbcommon0 libxrandr2 xdg-utils
- npm install && npx playwright install chromium
- npx playwright test
+9
View File
@@ -0,0 +1,9 @@
when:
event: [push, pull_request]
steps:
fmt:
image: rust:1
commands:
- rustup component add rustfmt
- cargo fmt --all -- --check
+17
View File
@@ -0,0 +1,17 @@
when:
- event: tag
steps:
build:
image: rust:1
commands:
- cargo build --release
publish:
image: alpine:3.23
commands:
- apk add --no-cache nodejs
- node ci/release.js target/release/sustenance
environment:
GITEA_RELEASE_TOKEN:
from_secret: gitea_release_token
+8
View File
@@ -0,0 +1,8 @@
when:
event: [push, pull_request]
steps:
test:
image: rust:1
commands:
- cargo test --all
Generated
+1323 -47
View File
File diff suppressed because it is too large Load Diff
+15 -3
View File
@@ -1,21 +1,33 @@
[package]
name = "sustenance"
version = "0.1.0"
version = "0.4.0"
edition = "2024"
[dependencies]
argon2 = "0.5"
async-trait = "0.1"
axum = { version = "0.8", features = ["ws"] }
base64 = "0.22"
futures-util = "0.3"
hex = "0.4"
maud = "0.27"
pulldown-cmark = "0.13"
rand = "0.8"
rusqlite = { version = "0.32", features = ["bundled"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
sha2 = "0.10"
sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio", "sqlite", "macros", "migrate", "tls-rustls"] }
thiserror = "2"
tokio = { version = "1", features = ["full"] }
tower-http = { version = "0.6", features = ["fs", "trace"] }
tower = "0.5"
tower-http = { version = "0.6", features = ["fs", "trace", "set-header"] }
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
url = "2"
webauthn-rs = "0.3"
[profile.release]
opt-level = "z"
strip = true
lto = true
codegen-units = 1
+33 -3
View File
@@ -8,7 +8,13 @@ A small shared grocery list built with Rust, Axum, Maud, htmx, WebSockets, and S
cargo run
```
Open <http://127.0.0.1:3000>. The application creates `sustenance.db` in the working directory on first start.
Open <http://localhost:3000>. The application creates `sustenance.db` in the
working directory on first start.
**Note:** use `localhost` (not `127.0.0.1`) when testing passkeys locally —
browsers reject IP addresses as WebAuthn RP IDs. The app defaults to
`localhost` for loopback hosts, so passkeys work out of the box when you access
the site via `http://localhost:3000`.
## Configuration
@@ -20,7 +26,9 @@ Open <http://127.0.0.1:3000>. The application creates `sustenance.db` in the wor
| `COOKIE_SECURE` | `false` | Add the `Secure` attribute to session cookies |
| `REGISTRATION_MODE` | `invite_only` | Use `open` for local development; otherwise registration requires a valid list invitation after the first account |
| `SEED_CONFIG` | `seed.json` | Optional JSON file with a default user to create when the database is first initialized |
| `RUST_LOG` | `sustenance=debug,tower_http=info` | Log filter |
| `RP_ID` | derived from `PUBLIC_BASE_URL` | WebAuthn relying party ID (the host users access the site from) |
| `RP_NAME` | `Sustenance` | WebAuthn relying party name shown to users |
| `RUST_LOG` | `sustenance=info,tower_http=info` | Log filter; HTTP requests are logged at info level |
### Seeding a default user
@@ -41,12 +49,14 @@ The file is optional — if it is missing or invalid, seeding is silently skippe
## Current features
- Email/password accounts with Argon2 password hashes
- Optional WebAuthn passkeys for passwordless sign-in (managed from the account page)
- Cookie-backed sessions and CSRF tokens for list mutations
- Shared lists with one-time, seven-day invitation links
- Invite-only registration by default after the first account
- Add, edit, check, and delete grocery items
- List-scoped categories with common defaults and custom category creation
- Global categories with common defaults seeded at startup and custom category creation
- Items grouped by category and assigned from the add/edit forms
- Meals with ingredients, markdown descriptions, and one-click "add meal to list"
- Server-authoritative last-write-wins updates
- Per-list WebSocket updates with server-rendered htmx fragments
- In-memory presence for members currently viewing a list
@@ -61,3 +71,23 @@ cargo fmt --all -- --check
cargo check
cargo test
```
### End-to-end tests (Playwright)
The e2e tests live in `e2e/` and use Playwright with a real browser. Each test
starts its own server against a fresh, throwaway database on a unique port, so
tests are fully isolated from each other and from your real `sustenance.db`.
The tests launch `target/debug/sustenance`, so build the server first:
```sh
# one-time setup
cargo build
cd e2e
npm install
npx playwright install chromium
# run the tests (each test launches its own server against a fresh DB)
cd e2e
npx playwright test
```
+91
View File
@@ -0,0 +1,91 @@
import * as fs from 'node:fs/promises';
import { basename } from 'node:path';
function getEnv(name) {
const val = process.env[name];
if (!val) {
throw new Error(`Environment variable ${name} is empty`);
}
return val;
}
async function fetchJSON(url, options) {
const resp = await fetch(url, options);
if (!resp.ok) {
throw new Error(`Unexpected HTTP status: ${resp.status}`, {
cause: {
status: resp.status,
body: await resp.text(),
},
});
}
return await resp.json();
}
async function postJSON(url, token, payload) {
return fetchJSON(url, {
method: "POST",
headers: {
"Authorization": `token ${token}`,
"Content-Type": "application/json",
},
body: JSON.stringify(payload),
});
}
async function postFile(url, token, files) {
const formData = new FormData();
for (const [name, path] of Object.entries(files)) {
const fileBuffer = await fs.readFile(path);
const fileObject = new File([fileBuffer], basename(path), { type: 'application/octet-stream' });
formData.append(name, fileObject)
}
return await fetchJSON(url, {
method: "POST",
headers: {
"Authorization": `token ${token}`,
},
body: formData,
});
}
async function canRead(path) {
try {
await fs.access(path, fs.constants.R_OK);
return true;
} catch {
return false;
}
}
async function main() {
const path = process.argv[2];
if (!path || !canRead(path)) {
throw Error(`Path ${path} is undefined or inaccessible, use node release.js <path>`);
}
const token = getEnv("GITEA_RELEASE_TOKEN");
const tag = getEnv("CI_COMMIT_TAG");
const repo = getEnv("CI_REPO");
console.log("Creating release...");
const releaseData = await postJSON(`https://git.sbstp.ca/api/v1/repos/${repo}/releases`, token, {
name: `Release ${tag}`,
tag_name: tag,
target_commitish: tag,
draft: false,
prerelease: false,
});
console.log(`Created release ID ${releaseData.id}`);
console.log("Uploading asset...");
const assetData = await postFile(`https://git.sbstp.ca/api/v1/repos/${repo}/releases/${releaseData.id}/assets?name=${basename(path)}`, token, {
attachment: path,
});
console.log("Asset uploaded:", assetData);
}
try {
await main();
} catch (err) {
console.error(err);
}
+126
View File
@@ -0,0 +1,126 @@
import { test as base, expect, Page } from "@playwright/test";
import { spawn, ChildProcess } from "child_process";
import * as fs from "fs";
import * as os from "os";
import * as path from "path";
/**
* Starts a fresh Sustenance server against a unique, throwaway database on a
* unique port for each test, and tears it down afterwards. This gives every
* test a clean DB with no shared state between tests.
*/
export const test = base.extend<{ server: { baseURL: string }; page: Page }>({
server: [
async ({}, use) => {
const server = await startServer();
await use({ baseURL: server.baseURL });
await killTree(server.child);
// Clean up the DB files (including -wal / -shm).
for (const suffix of ["", "-wal", "-shm"]) {
fs.rmSync(server.dbPath + suffix, { force: true });
}
},
{ scope: "test", auto: true },
],
// Provide a page whose baseURL points at this test's server.
page: async ({ browser, server }, use) => {
const context = await browser.newContext({ baseURL: server.baseURL });
const page = await context.newPage();
await use(page);
await context.close();
},
});
/** Starts a server, retrying on a fresh port if the first attempt fails to bind. */
async function startServer() {
for (let attempt = 0; attempt < 5; attempt++) {
const dbPath = path.join(
os.tmpdir(),
`sustenance-e2e-${process.pid}-${Date.now()}-${Math.random()
.toString(36)
.slice(2)}.db`,
);
const port = 20000 + Math.floor(Math.random() * 30000);
const baseURL = `http://localhost:${port}`;
const child = spawn(
path.resolve(__dirname, "..", "target", "debug", "sustenance"),
[],
{
env: {
...process.env,
DATABASE_PATH: dbPath,
REGISTRATION_MODE: "open",
BIND_ADDRESS: `127.0.0.1:${port}`,
PUBLIC_BASE_URL: baseURL,
// WebAuthn requires a valid domain for the RP ID; localhost is allowed.
RP_ID: "localhost",
// Point SEED_CONFIG at a nonexistent file so no default user is created.
SEED_CONFIG: path.join(os.tmpdir(), "sustenance-e2e-no-seed.json"),
},
stdio: ["ignore", "ignore", "pipe"],
// Run in its own process group so we can kill the whole tree.
detached: true,
},
);
let stderr = "";
child.stderr?.on("data", (chunk) => {
stderr += chunk.toString();
});
try {
await waitForServer(baseURL, child);
return { baseURL, child, dbPath };
} catch (error) {
// The server may have failed to bind (port collision). Clean up and retry.
await killTree(child);
for (const suffix of ["", "-wal", "-shm"]) {
fs.rmSync(dbPath + suffix, { force: true });
}
if (attempt === 4) {
throw new Error(
`server failed to start after retries; last stderr:\n${stderr}\n${error}`,
);
}
}
}
throw new Error("unreachable");
}
async function waitForServer(baseURL: string, child: ChildProcess) {
const deadline = Date.now() + 60_000;
while (Date.now() < deadline) {
if (child.exitCode !== null) {
throw new Error(`server exited early with code ${child.exitCode}`);
}
try {
const res = await fetch(baseURL + "/login");
if (res.ok) return;
} catch {
// not up yet
}
await new Promise((r) => setTimeout(r, 200));
}
throw new Error("timed out waiting for server to start");
}
async function killTree(child: ChildProcess) {
try {
process.kill(-child.pid!, "SIGTERM");
} catch {
child.kill("SIGTERM");
}
// Give it a moment to shut down gracefully, then force-kill if needed.
const exited = new Promise((resolve) => child.once("exit", resolve));
const timeout = new Promise((resolve) => setTimeout(resolve, 5000));
await Promise.race([exited, timeout]);
try {
process.kill(-child.pid!, "SIGKILL");
} catch {
/* already gone */
}
}
export { expect };
+68
View File
@@ -0,0 +1,68 @@
import { Page, expect } from "@playwright/test";
/** Registers a fresh account and lands on the lists page. */
export async function registerAndLogin(page: Page, email: string) {
await page.goto("/register");
await page.fill("#display-name", "Test User");
await page.fill("#email", email);
await page.fill("#password", "a-strong-password");
await page.click('button[type="submit"]');
await expect(page).toHaveURL(/\/lists/);
}
/** Creates a meal with the given name and markdown description. */
export async function createMeal(
page: Page,
name: string,
description: string,
category?: string,
) {
await page.goto("/meals/new");
await page.fill("#meal-name", name);
if (category) {
await page.selectOption("#meal-category", { label: category });
}
await page.fill("#meal-description", description);
await page.click('button:has-text("Save meal")');
await expect(page).toHaveURL(/\/meals\/\d+/);
}
/** Creates a list and lands on its page. */
export async function createList(page: Page, name: string) {
await page.goto("/lists");
await page.fill("#list-name", name);
await page.click('button:has-text("Create list")');
await expect(page).toHaveURL(/\/lists\/\d+/);
}
/** Adds an item to the current list page. */
export async function addItem(page: Page, name: string, quantity = "") {
await page.fill("#item-name", name);
if (quantity) {
await page.fill("#item-quantity", quantity);
}
await page.click("#add-item-button");
await expect(page.locator(".item-row").filter({ hasText: name })).toBeVisible();
}
/** Adds an ingredient to the current meal page. */
export async function addIngredient(page: Page, name: string, quantity = "") {
await page.fill("#ingredient-name", name);
if (quantity) {
await page.fill("#ingredient-quantity", quantity);
}
await page.click("#add-ingredient-button");
await expect(page.locator(".ingredient-list").filter({ hasText: name })).toBeVisible();
}
/** Creates a meal and adds the given ingredients to it. */
export async function createMealWithIngredients(
page: Page,
name: string,
ingredients: Array<{ name: string; quantity?: string }>,
) {
await createMeal(page, name, "");
for (const ingredient of ingredients) {
await addIngredient(page, ingredient.name, ingredient.quantity ?? "");
}
}
+90
View File
@@ -0,0 +1,90 @@
{
"name": "sustenance-e2e",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "sustenance-e2e",
"version": "1.0.0",
"devDependencies": {
"@playwright/test": "^1.45.0",
"@types/node": "^26.1.2"
}
},
"node_modules/@playwright/test": {
"version": "1.62.1",
"resolved": "https://registry.npmjs.org/@playwright/test/-/test-1.62.1.tgz",
"integrity": "sha512-DTcUc8qii+cpHvtOwggMtBRMjKZHXYWdw8syRYu2vtzuq4Wxphqq4NfCs5Zt44L6mA8rfDfj+PHnxFc/FeK6mQ==",
"dev": true,
"dependencies": {
"playwright": "1.62.1"
},
"bin": {
"playwright": "cli.js"
},
"engines": {
"node": ">=20"
}
},
"node_modules/@types/node": {
"version": "26.1.2",
"resolved": "https://registry.npmjs.org/@types/node/-/node-26.1.2.tgz",
"integrity": "sha512-Vu4a5UFA9rIIFJ7rB/Vaafh9lrCQszopTCx6KjFboXTGQbPNasehVR5TEiithSDGyd1DEiUByggTZsg8jukeIg==",
"dev": true,
"dependencies": {
"undici-types": "~8.3.0"
}
},
"node_modules/fsevents": {
"version": "2.3.2",
"resolved": "https://registry.npmjs.org/fsevents/-/fsevents-2.3.2.tgz",
"integrity": "sha512-xiqMQR4xAeHTuB9uWm+fFRcIOgKBMiOBP+eXiyT7jsgVCq1bkVygt00oASowB7EdtpOHaaPgKt812P9ab+DDKA==",
"dev": true,
"hasInstallScript": true,
"optional": true,
"os": [
"darwin"
],
"engines": {
"node": "^8.16.0 || ^10.6.0 || >=11.0.0"
}
},
"node_modules/playwright": {
"version": "1.62.1",
"resolved": "https://registry.npmjs.org/playwright/-/playwright-1.62.1.tgz",
"integrity": "sha512-0M+L3LAD8/nm554LOla9Ayx0j0tmFZ0FBcoQ7F1VuVHpM/XpiC8RcDzBQB8W5+hA8L22THxELzeF+2WcUzvcLg==",
"dev": true,
"dependencies": {
"playwright-core": "1.62.1"
},
"bin": {
"playwright": "cli.js"
},
"engines": {
"node": ">=20"
},
"optionalDependencies": {
"fsevents": "2.3.2"
}
},
"node_modules/playwright-core": {
"version": "1.62.1",
"resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.62.1.tgz",
"integrity": "sha512-wPYSwEBJY9GHraISXqyqtx0na0LpO3XEX7jNDhntbex7tzUS7kLnZsOlFruFJB4Hi/rhDMjXGqHewDZ68nYZVw==",
"dev": true,
"bin": {
"playwright-core": "cli.js"
},
"engines": {
"node": ">=20"
}
},
"node_modules/undici-types": {
"version": "8.3.0",
"resolved": "https://registry.npmjs.org/undici-types/-/undici-types-8.3.0.tgz",
"integrity": "sha512-j375ScV60dom+YkPFIfTLcOiPxkN/buHz5GobjLhixFuANaNs3C9l4GmrWqejgXWJ7BbJcFYpTEUkS1Ge8bpZQ==",
"dev": true
}
}
}
+13
View File
@@ -0,0 +1,13 @@
{
"name": "sustenance-e2e",
"version": "1.0.0",
"private": true,
"scripts": {
"test": "playwright test",
"test:headed": "playwright test --headed"
},
"devDependencies": {
"@playwright/test": "^1.45.0",
"@types/node": "^26.1.2"
}
}
+10
View File
@@ -0,0 +1,10 @@
import { defineConfig } from "@playwright/test";
export default defineConfig({
testDir: "./tests",
timeout: 30_000,
retries: 2,
use: {
trace: "on-first-retry",
},
});
+98
View File
@@ -0,0 +1,98 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, createMealWithIngredients } from "../helpers";
test("a user can add a meal's ingredients to a list via the picker", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMealWithIngredients(page, "Spaghetti Bolognese", [
{ name: "Penne", quantity: "500g" },
{ name: "Tomato", quantity: "2" },
]);
await createList(page, "Weekly shop");
// Open the add-meal picker.
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
await expect(picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" })).toBeVisible();
// Select the meal.
await picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" }).click();
// The picker closes and the meal's ingredients appear as items.
await expect(picker).toHaveCount(0);
await expect(page.locator(".item-row").filter({ hasText: "Penne" })).toBeVisible();
await expect(page.locator(".item-row").filter({ hasText: "Tomato" })).toBeVisible();
await expect(page.locator(".item-row").filter({ hasText: "Penne" }).locator(".item-qty")).toHaveText("(500g)");
});
test("the add-meal picker closes via the close button", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMealWithIngredients(page, "Spaghetti Bolognese", [{ name: "Penne" }]);
await createList(page, "Weekly shop");
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
await picker.locator(".meal-picker-close").click();
await expect(picker).toHaveCount(0);
});
test("the add-meal picker closes when clicking outside", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMealWithIngredients(page, "Spaghetti Bolognese", [{ name: "Penne" }]);
await createList(page, "Weekly shop");
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
// Click the backdrop itself (outside the modal card), at the viewport corner.
await page.mouse.click(10, 10);
await expect(picker).toHaveCount(0);
});
test("a meal added to a list is shown in the meals panel", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMealWithIngredients(page, "Spaghetti Bolognese", [
{ name: "Penne", quantity: "500g" },
{ name: "Tomato", quantity: "2" },
]);
await createList(page, "Weekly shop");
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" }).click();
// The meal appears in the "Meals on this list" panel.
const panel = page.locator("#list-meals-panel");
await expect(panel).toBeVisible();
await expect(panel.locator(".list-meal-row").filter({ hasText: "Spaghetti Bolognese" })).toBeVisible();
});
test("removing a meal from a list removes its ingredients", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMealWithIngredients(page, "Spaghetti Bolognese", [
{ name: "Penne", quantity: "500g" },
{ name: "Tomato", quantity: "2" },
]);
await createList(page, "Weekly shop");
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" }).click();
await expect(page.locator(".item-row").filter({ hasText: "Penne" })).toBeVisible();
await expect(page.locator(".item-row").filter({ hasText: "Tomato" })).toBeVisible();
// Remove the meal from the list.
const panel = page.locator("#list-meals-panel");
const row = panel.locator(".list-meal-row").filter({ hasText: "Spaghetti Bolognese" });
await row.locator(".list-meal-remove-button").click();
// The meal's ingredients are removed from the list.
await expect(page.locator(".item-row").filter({ hasText: "Penne" })).toHaveCount(0);
await expect(page.locator(".item-row").filter({ hasText: "Tomato" })).toHaveCount(0);
await expect(row).toHaveCount(0);
});
+83
View File
@@ -0,0 +1,83 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, addItem } from "../helpers";
test("a user can archive a list and it moves to the archive page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
// Archive from the list page.
await page.click('button:has-text("Archive")');
// Lands back on the lists page; the list is no longer shown.
await expect(page).toHaveURL(/\/lists/);
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toHaveCount(0);
// The archived list is reachable from the archive page.
await page.goto("/archive");
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toBeVisible();
});
test("the lists frame links to the archive page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await page.goto("/lists");
await page.click('a.archive-link');
await expect(page).toHaveURL(/\/archive/);
});
test("an archived list is read-only", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
await page.click('button:has-text("Archive")');
// Open the archived list directly.
await page.goto("/archive");
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await expect(page).toHaveURL(/\/lists\/\d+/);
// The item is still visible.
await expect(page.locator(".item-row").filter({ hasText: "Apple" })).toBeVisible();
// No mutation UI is present.
await expect(page.locator("#add-item-form")).toHaveCount(0);
await expect(page.locator(".item-actions-button")).toHaveCount(0);
await expect(page.locator(".check-form")).toHaveCount(0);
await expect(page.locator('button:has-text("+ Add meal")')).toHaveCount(0);
});
test("a user can restore an archived list and edit it again", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
await page.click('button:has-text("Archive")');
// Open the archived list and restore it.
await page.goto("/archive");
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await page.click('button:has-text("Restore")');
// Back on the lists page, the list is active again.
await expect(page).toHaveURL(/\/lists/);
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toBeVisible();
// The list is editable again.
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await expect(page.locator("#add-item-form")).toBeVisible();
await addItem(page, "Banana");
await expect(page.locator(".item-row").filter({ hasText: "Banana" })).toBeVisible();
});
test("the archive page shows the list name and created date", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await page.click('button:has-text("Archive")');
await page.goto("/archive");
const card = page.locator(".list-card").filter({ hasText: "Weekly shop" });
await expect(card).toBeVisible();
// The card shows a created date (e.g. "Created 7 Aug 2026").
await expect(card.locator("small")).toContainText("Created");
});
+45
View File
@@ -0,0 +1,45 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin } from "../helpers";
test("a user can register and log in", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await expect(page.locator("h1")).toContainText("Grocery lists");
});
test("a user can log out", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.click('button:has-text("Sign out")');
await expect(page).toHaveURL(/\/login/);
await expect(page.locator("h1")).toContainText("Welcome back");
});
test("a user can change their password", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/account");
await page.fill("#new-password", "a-new-strong-password");
await page.fill("#confirm-password", "a-new-strong-password");
await page.click('button:has-text("Update password")');
await expect(page.locator(".alert-success")).toContainText("updated");
// The old password no longer works; the new one does.
await page.click('button:has-text("Sign out")');
await page.fill("#email", "alice@example.com");
await page.fill("#password", "a-strong-password");
await page.click('button[type="submit"]');
await expect(page.locator(".alert-error")).toContainText("incorrect");
await page.fill("#email", "alice@example.com");
await page.fill("#password", "a-new-strong-password");
await page.click('button[type="submit"]');
await expect(page).toHaveURL(/\/lists/);
});
test("changing password rejects a mismatched confirmation", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/account");
await page.fill("#new-password", "a-new-strong-password");
await page.fill("#confirm-password", "a-different-password");
await page.click('button:has-text("Update password")');
await expect(page.locator(".alert-error")).toContainText("do not match");
});
+93
View File
@@ -0,0 +1,93 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, addItem } from "../helpers";
test("a user can create a list", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await expect(page.locator("h1")).toContainText("Weekly shop");
await expect(page.locator(".empty-items")).toBeVisible();
});
test("a user can add an item with a quantity", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple", "2");
// Quantity renders in parens to the left of the name.
const row = page.locator(".item-row").filter({ hasText: "Apple" });
await expect(row.locator(".item-qty")).toHaveText("(2)");
await expect(row.locator("strong")).toHaveText("Apple");
});
test("a user can check off an item", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
const row = page.locator(".item-row").filter({ hasText: "Apple" });
await row.locator(".check-button").click();
await expect(row).toHaveClass(/is-checked/);
});
test("clicking an item's text toggles the checkbox", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
const row = page.locator(".item-row").filter({ hasText: "Apple" });
await row.locator(".item-copy").click();
await expect(row).toHaveClass(/is-checked/);
});
test("a user can edit an item via the actions modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple", "2");
const row = page.locator(".item-row").filter({ hasText: "Apple" });
await row.locator(".item-actions-button").click();
const dialog = row.locator("dialog.item-modal");
await expect(dialog).toBeVisible();
await dialog.locator('[id^="item-edit-name"]').fill("Banana");
await dialog.locator('[id^="item-edit-quantity"]').fill("6");
await dialog.locator('[id^="item-edit-save"]').click();
const updated = page.locator(".item-row").filter({ hasText: "Banana" });
await expect(updated).toBeVisible();
await expect(updated.locator(".item-qty")).toHaveText("(6)");
});
test("a user can delete an item via the actions modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
const row = page.locator(".item-row").filter({ hasText: "Apple" });
await row.locator(".item-actions-button").click();
const dialog = row.locator("dialog.item-modal");
await expect(dialog).toBeVisible();
await dialog.locator('[id^="item-edit-delete"]').click();
await expect(page.locator(".item-row").filter({ hasText: "Apple" })).toHaveCount(0);
await expect(page.locator(".empty-items")).toBeVisible();
});
test("a user can add a category", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
// Categories are managed from the main lists page.
await page.goto("/lists");
await page.fill("#category-name", "Bakery");
await page.click("#add-category-button");
await expect(page.locator(".category-chip").filter({ hasText: "Bakery" })).toBeVisible();
});
+111
View File
@@ -0,0 +1,111 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createMeal } from "../helpers";
test("meals are grouped under their category on the meals page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await createMeal(page, "Chicken Curry", "", "Chicken");
await createMeal(page, "Plain Rice", "");
await page.goto("/meals");
// Each category appears as a heading with its meals beneath it.
const beef = page.locator(".category-group").filter({ hasText: "Beef" });
await expect(beef.locator(".category-heading")).toContainText("Beef");
await expect(beef.locator(".list-card").filter({ hasText: "Beef Stew" })).toBeVisible();
const chicken = page.locator(".category-group").filter({ hasText: "Chicken" });
await expect(chicken.locator(".list-card").filter({ hasText: "Chicken Curry" })).toBeVisible();
// Uncategorized meals land in their own group.
const uncategorized = page.locator(".category-group").filter({ hasText: "Uncategorized" });
await expect(uncategorized.locator(".list-card").filter({ hasText: "Plain Rice" })).toBeVisible();
});
test("a user can create a meal category", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/meals");
await page.fill('form[action="/meals/categories"] input[name="name"]', "Breakfast");
await page.click('form[action="/meals/categories"] button[type="submit"]');
await expect(page).toHaveURL(/\/meals$/);
await expect(page.locator(".meal-category-name").filter({ hasText: "Breakfast" })).toBeVisible();
});
test("a user can delete a meal category and its meals become uncategorized", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
// Create a custom category and a meal in it.
await page.goto("/meals");
await page.fill('form[action="/meals/categories"] input[name="name"]', "Breakfast");
await page.click('form[action="/meals/categories"] button[type="submit"]');
await expect(page).toHaveURL(/\/meals$/);
await createMeal(page, "Pancakes", "", "Breakfast");
// Delete the category.
await page.goto("/meals");
const row = page.locator(".meal-category-row").filter({ hasText: "Breakfast" });
await row.locator(".meal-category-delete").click();
await expect(page).toHaveURL(/\/meals$/);
// The category is gone and the meal is now uncategorized.
await expect(page.locator(".meal-category-name").filter({ hasText: "Breakfast" })).toHaveCount(0);
const uncategorized = page.locator(".category-group").filter({ hasText: "Uncategorized" });
await expect(uncategorized.locator(".list-card").filter({ hasText: "Pancakes" })).toBeVisible();
});
test("a user can change a meal's category via the edit modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await page.click('button:has-text("Edit")');
const dialog = page.locator("dialog#meal-edit-modal");
await expect(dialog).toBeVisible();
await dialog.locator("#meal-edit-category").selectOption({ label: "Chicken" });
await dialog.locator("#meal-edit-save").click();
await expect(page).toHaveURL(/\/meals\/\d+/);
await page.goto("/meals");
const chicken = page.locator(".category-group").filter({
has: page.locator(".category-heading", { hasText: "Chicken" }),
});
await expect(chicken.locator(".list-card").filter({ hasText: "Beef Stew" })).toBeVisible();
const beef = page.locator(".category-group").filter({
has: page.locator(".category-heading", { hasText: "Beef" }),
});
await expect(beef.locator(".list-card").filter({ hasText: "Beef Stew" })).toHaveCount(0);
});
test("a meal's category is shown on its page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await expect(page.locator(".meal-category-label")).toHaveText("(Beef)");
});
test("the add-meal picker groups meals by category", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await createMeal(page, "Chicken Curry", "", "Chicken");
// Go to a list to open the picker.
await page.goto("/lists");
await page.fill("#list-name", "Weekly shop");
await page.click('button:has-text("Create list")');
await expect(page).toHaveURL(/\/lists\/\d+/);
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
const beef = picker.locator(".category-group").filter({ hasText: "Beef" });
await expect(beef.locator(".meal-picker-button").filter({ hasText: "Beef Stew" })).toBeVisible();
const chicken = picker.locator(".category-group").filter({ hasText: "Chicken" });
await expect(chicken.locator(".meal-picker-button").filter({ hasText: "Chicken Curry" })).toBeVisible();
});
+89
View File
@@ -0,0 +1,89 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createMeal, addIngredient } from "../helpers";
test("a user can add an ingredient to a meal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await addIngredient(page, "Penne", "500g");
const row = page.locator(".ingredient-list").filter({ hasText: "Penne" });
await expect(row.locator(".item-qty")).toHaveText("(500g)");
await expect(row.locator("strong")).toHaveText("Penne");
});
test("a user can edit a meal name and description via the modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "A classic.");
await page.click('button:has-text("Edit")');
const dialog = page.locator("dialog#meal-edit-modal");
await expect(dialog).toBeVisible();
await dialog.locator("#meal-edit-name").fill("Pasta al Pomodoro");
await dialog.locator("#meal-edit-description").fill("## Ingredients\n\nA simple tomato sauce.");
await dialog.locator("#meal-edit-save").click();
await expect(page.locator("h1")).toContainText("Pasta al Pomodoro");
await expect(page.locator(".markdown h2")).toContainText("Ingredients");
});
test("a user can delete a meal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
page.on("dialog", (dialog) => dialog.accept());
await page.click('button:has-text("Delete")');
await expect(page).toHaveURL(/\/meals$/);
await expect(page.locator(".list-card").filter({ hasText: "Spaghetti Bolognese" })).toHaveCount(0);
});
test("a user can edit an ingredient via the actions modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await addIngredient(page, "Penne", "500g");
const row = page.locator(".ingredient-list").filter({ hasText: "Penne" });
await row.locator(".item-actions-button").click();
const dialog = row.locator("dialog.item-modal");
await expect(dialog).toBeVisible();
await dialog.locator('[id^="ingredient-edit-name"]').fill("Rigatoni");
await dialog.locator('[id^="ingredient-edit-quantity"]').fill("400g");
await dialog.locator('[id^="ingredient-edit-save"]').click();
const updated = page.locator(".ingredient-list").filter({ hasText: "Rigatoni" });
await expect(updated).toBeVisible();
await expect(updated.locator(".item-qty")).toHaveText("(400g)");
});
test("a user can delete an ingredient via the actions modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await addIngredient(page, "Penne");
const row = page.locator(".ingredient-list").filter({ hasText: "Penne" });
await row.locator(".item-actions-button").click();
const dialog = row.locator("dialog.item-modal");
await expect(dialog).toBeVisible();
await dialog.locator('[id^="ingredient-edit-delete"]').click();
await expect(page.locator(".ingredient-list").filter({ hasText: "Penne" })).toHaveCount(0);
});
test("ingredients are grouped under their categories", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
// Add an ingredient in the default "Produce" category.
await page.fill("#ingredient-name", "Tomato");
await page.selectOption("#ingredient-category", { label: "Produce" });
await page.click("#add-ingredient-button");
// Add one without a category.
await addIngredient(page, "Penne");
await expect(page.locator(".category-heading").filter({ hasText: "Produce" })).toBeVisible();
await expect(page.locator(".category-heading").filter({ hasText: "Uncategorized" })).toBeVisible();
});
+46
View File
@@ -0,0 +1,46 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin } from "../helpers";
/**
* Enables a virtual WebAuthn authenticator on the given context so the browser
* can complete passkey ceremonies without a real device.
*/
async function enableVirtualAuthenticator(context: any) {
const cdp = await context.newCDPSession(context.pages()[0]);
await cdp.send("WebAuthn.enable", { enableUI: false });
await cdp.send("WebAuthn.addVirtualAuthenticator", {
options: {
protocol: "ctap2",
transport: "internal",
hasResidentKey: true,
hasUserVerification: true,
isUserVerified: true,
},
});
}
test("a user can register a passkey and sign in with it", async ({ page, browser, server }) => {
const context = await browser.newContext({ baseURL: server.baseURL });
const p = await context.newPage();
await enableVirtualAuthenticator(context);
// Register with a password first.
await registerAndLogin(p, "alice@example.com");
// Add a passkey from the account page.
await p.goto("/account");
await p.click("#add-passkey");
await expect(p.locator(".passkey-row")).toHaveCount(1);
// Log out.
await p.click('button:has-text("Sign out")');
await expect(p).toHaveURL(/\/login/);
// Sign in with the passkey without entering an email (userless sign-in).
await p.click("#passkey-login");
await expect(p).toHaveURL(/\/lists/);
await context.close();
});
+31
View File
@@ -0,0 +1,31 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, addItem } from "../helpers";
test("a list updates live for another user via websocket", async ({ page, browser, server }) => {
// User A registers and creates a list.
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
const listUrl = page.url();
// User B registers in a separate context (separate session).
const contextB = await browser.newContext({ baseURL: server.baseURL });
const pageB = await contextB.newPage();
await registerAndLogin(pageB, "bob@example.com");
// Both users open the same list.
await page.goto(listUrl);
await pageB.goto(listUrl);
// Give the websocket connections a moment to establish.
await page.waitForTimeout(500);
// User A adds an item.
await addItem(page, "Apple", "2");
// It should appear on User B's page without any reload.
await expect(pageB.locator(".item-row").filter({ hasText: "Apple" })).toBeVisible();
await expect(pageB.locator(".item-row").filter({ hasText: "Apple" }).locator(".item-qty")).toHaveText("(2)");
await contextB.close();
});
+81
View File
@@ -0,0 +1,81 @@
CREATE TABLE users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
email TEXT NOT NULL UNIQUE COLLATE NOCASE,
display_name TEXT NOT NULL,
password_hash TEXT NOT NULL,
user_handle BLOB NOT NULL UNIQUE,
created_at INTEGER NOT NULL
);
CREATE TABLE sessions (
token_hash BLOB PRIMARY KEY,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
csrf_token BLOB NOT NULL,
expires_at INTEGER NOT NULL
);
CREATE TABLE passkeys (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
credential_id TEXT NOT NULL UNIQUE,
credential TEXT NOT NULL,
counter INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE lists (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
revision INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL UNIQUE COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE invitations (
token_hash BLOB PRIMARY KEY,
created_by INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
expires_at INTEGER NOT NULL
);
CREATE TABLE items (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
checked INTEGER NOT NULL DEFAULT 0,
version INTEGER NOT NULL DEFAULT 1,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE meals (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
description TEXT NOT NULL DEFAULT '',
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE meal_ingredients (
id INTEGER PRIMARY KEY AUTOINCREMENT,
meal_id INTEGER NOT NULL REFERENCES meals(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
position INTEGER NOT NULL DEFAULT 0
);
CREATE INDEX items_list_idx ON items(list_id);
CREATE INDEX meal_ingredients_meal_idx ON meal_ingredients(meal_id);
CREATE INDEX sessions_user_idx ON sessions(user_id);
CREATE INDEX passkeys_user_idx ON passkeys(user_id);
@@ -0,0 +1,10 @@
CREATE TABLE meal_categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL UNIQUE COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
ALTER TABLE meals ADD COLUMN category_id INTEGER REFERENCES meal_categories(id) ON DELETE SET NULL;
CREATE INDEX meals_category_idx ON meals(category_id);
+12
View File
@@ -0,0 +1,12 @@
CREATE TABLE list_meals (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
meal_id INTEGER REFERENCES meals(id) ON DELETE SET NULL,
name TEXT NOT NULL,
created_at INTEGER NOT NULL
);
ALTER TABLE items ADD COLUMN list_meal_id INTEGER REFERENCES list_meals(id) ON DELETE CASCADE;
CREATE INDEX list_meals_list_idx ON list_meals(list_id);
CREATE INDEX items_list_meal_idx ON items(list_meal_id);
@@ -0,0 +1 @@
ALTER TABLE lists ADD COLUMN archived_at INTEGER;
-858
View File
@@ -1,858 +0,0 @@
use std::{
path::Path,
sync::{Arc, Mutex},
time::{SystemTime, UNIX_EPOCH},
};
use rand::{RngCore, rngs::OsRng};
use rusqlite::{Connection, OptionalExtension, params};
use sha2::{Digest, Sha256};
use thiserror::Error;
#[derive(Debug, Error)]
pub enum DbError {
#[error("database error: {0}")]
Message(String),
#[error("record not found")]
NotFound,
#[error("record already exists")]
Conflict,
#[error("database worker failed: {0}")]
Worker(String),
}
pub type DbResult<T> = Result<T, DbError>;
#[derive(Clone)]
pub struct Database {
connection: Arc<Mutex<Connection>>,
}
#[derive(Clone, Debug)]
pub struct User {
pub id: i64,
pub email: String,
pub display_name: String,
}
#[derive(Clone, Debug)]
pub struct SessionUser {
pub user: User,
pub csrf_token: String,
}
#[derive(Clone, Debug)]
pub struct GroceryList {
pub id: i64,
pub name: String,
pub revision: i64,
}
#[derive(Clone, Debug)]
pub struct Item {
pub id: i64,
pub list_id: i64,
pub name: String,
pub quantity: String,
pub note: String,
pub category_id: Option<i64>,
pub checked: bool,
pub version: i64,
}
#[derive(Clone, Debug)]
pub struct Category {
pub id: i64,
pub name: String,
}
impl Database {
pub fn open(path: impl AsRef<Path>) -> DbResult<Self> {
let connection = Connection::open(path).map_err(sql_error)?;
configure(&connection)?;
migrate(&connection)?;
Ok(Self {
connection: Arc::new(Mutex::new(connection)),
})
}
#[cfg(test)]
pub fn open_in_memory() -> DbResult<Self> {
Self::open(":memory:")
}
async fn call<T, F>(&self, operation: F) -> DbResult<T>
where
T: Send + 'static,
F: FnOnce(&mut Connection) -> DbResult<T> + Send + 'static,
{
let connection = Arc::clone(&self.connection);
tokio::task::spawn_blocking(move || {
let mut connection = connection
.lock()
.map_err(|error| DbError::Worker(error.to_string()))?;
operation(&mut connection)
})
.await
.map_err(|error| DbError::Worker(error.to_string()))?
}
pub async fn create_user(
&self,
email: String,
display_name: String,
password_hash: String,
) -> DbResult<User> {
self.call(move |connection| {
let result = connection.execute(
"INSERT INTO users (email, display_name, password_hash, created_at)
VALUES (?1, ?2, ?3, ?4)",
params![email, display_name, password_hash, now()],
);
match result {
Ok(_) => {
let id = connection.last_insert_rowid();
Ok(User {
id,
email,
display_name,
})
}
Err(error) if error.to_string().contains("UNIQUE") => Err(DbError::Conflict),
Err(error) => Err(sql_error(error)),
}
})
.await
}
pub async fn find_user_by_email(&self, email: String) -> DbResult<Option<(User, String)>> {
self.call(move |connection| {
connection
.query_row(
"SELECT id, email, display_name, password_hash
FROM users WHERE email = ?1 COLLATE NOCASE",
params![email],
|row| {
Ok((
User {
id: row.get(0)?,
email: row.get(1)?,
display_name: row.get(2)?,
},
row.get(3)?,
))
},
)
.optional()
.map_err(sql_error)
})
.await
}
pub async fn has_users(&self) -> DbResult<bool> {
self.call(|connection| {
connection
.query_row("SELECT EXISTS(SELECT 1 FROM users)", [], |row| {
Ok(row.get::<_, i64>(0)? != 0)
})
.map_err(sql_error)
})
.await
}
pub async fn create_session(&self, user_id: i64) -> DbResult<(String, String)> {
self.call(move |connection| {
let session_token = new_secret();
let csrf_token = new_secret();
connection
.execute(
"INSERT INTO sessions (token_hash, user_id, csrf_token, expires_at)
VALUES (?1, ?2, ?3, ?4)",
params![
hash_secret(&session_token),
user_id,
csrf_token,
now() + 60 * 60 * 24 * 30
],
)
.map_err(sql_error)?;
Ok((session_token, csrf_token))
})
.await
}
pub async fn session_user(&self, session_token: String) -> DbResult<Option<SessionUser>> {
self.call(move |connection| {
connection
.query_row(
"SELECT u.id, u.email, u.display_name, s.csrf_token
FROM sessions s
JOIN users u ON u.id = s.user_id
WHERE s.token_hash = ?1 AND s.expires_at > ?2",
params![hash_secret(&session_token), now()],
|row| {
Ok(SessionUser {
user: User {
id: row.get(0)?,
email: row.get(1)?,
display_name: row.get(2)?,
},
csrf_token: row.get(3)?,
})
},
)
.optional()
.map_err(sql_error)
})
.await
}
pub async fn delete_session(&self, session_token: String) -> DbResult<()> {
self.call(move |connection| {
connection
.execute(
"DELETE FROM sessions WHERE token_hash = ?1",
params![hash_secret(&session_token)],
)
.map_err(sql_error)?;
Ok(())
})
.await
}
pub async fn list_summaries(&self) -> DbResult<Vec<GroceryList>> {
self.call(move |connection| {
let mut statement = connection
.prepare(
"SELECT l.id, l.name, l.revision
FROM lists l
ORDER BY l.created_at DESC",
)
.map_err(sql_error)?;
let rows = statement
.query_map([], |row| {
Ok(GroceryList {
id: row.get(0)?,
name: row.get(1)?,
revision: row.get(2)?,
})
})
.map_err(sql_error)?;
rows.collect::<Result<Vec<_>, _>>().map_err(sql_error)
})
.await
}
pub async fn create_list(&self, name: String) -> DbResult<GroceryList> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
transaction
.execute(
"INSERT INTO lists (name, revision, created_at)
VALUES (?1, 0, ?2)",
params![name, now()],
)
.map_err(sql_error)?;
let list_id = transaction.last_insert_rowid();
for (position, category_name) in DEFAULT_CATEGORIES.iter().enumerate() {
transaction
.execute(
"INSERT INTO categories (list_id, name, position, created_at)
VALUES (?1, ?2, ?3, ?4)",
params![list_id, category_name, position as i64, now()],
)
.map_err(sql_error)?;
}
transaction.commit().map_err(sql_error)?;
Ok(GroceryList {
id: list_id,
name,
revision: 0,
})
})
.await
}
pub async fn list_access(&self, list_id: i64) -> DbResult<Option<GroceryList>> {
self.call(move |connection| {
connection
.query_row(
"SELECT l.id, l.name, l.revision
FROM lists l
WHERE l.id = ?1",
params![list_id],
|row| {
Ok(GroceryList {
id: row.get(0)?,
name: row.get(1)?,
revision: row.get(2)?,
})
},
)
.optional()
.map_err(sql_error)
})
.await
}
pub async fn items(&self, list_id: i64) -> DbResult<Vec<Item>> {
self.call(move |connection| {
let mut statement = connection
.prepare(
"SELECT id, list_id, name, quantity, note, category_id, checked, version
FROM items
WHERE list_id = ?1
ORDER BY position ASC, created_at ASC",
)
.map_err(sql_error)?;
let rows = statement
.query_map(params![list_id], |row| {
Ok(Item {
id: row.get(0)?,
list_id: row.get(1)?,
name: row.get(2)?,
quantity: row.get(3)?,
note: row.get(4)?,
category_id: row.get(5)?,
checked: row.get::<_, i64>(6)? != 0,
version: row.get(7)?,
})
})
.map_err(sql_error)?;
rows.collect::<Result<Vec<_>, _>>().map_err(sql_error)
})
.await
}
pub async fn categories(&self, list_id: i64) -> DbResult<Vec<Category>> {
self.call(move |connection| {
let mut statement = connection
.prepare(
"SELECT id, name
FROM categories
WHERE list_id = ?1
ORDER BY position ASC, name COLLATE NOCASE ASC",
)
.map_err(sql_error)?;
let rows = statement
.query_map(params![list_id], |row| {
Ok(Category {
id: row.get(0)?,
name: row.get(1)?,
})
})
.map_err(sql_error)?;
rows.collect::<Result<Vec<_>, _>>().map_err(sql_error)
})
.await
}
pub async fn create_category(&self, list_id: i64, name: String) -> DbResult<i64> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
let position: i64 = transaction
.query_row(
"SELECT COALESCE(MAX(position), -1) + 1
FROM categories WHERE list_id = ?1",
params![list_id],
|row| row.get(0),
)
.map_err(sql_error)?;
let result = transaction.execute(
"INSERT INTO categories (list_id, name, position, created_at)
VALUES (?1, ?2, ?3, ?4)",
params![list_id, name, position, now()],
);
match result {
Ok(_) => {}
Err(error) if error.to_string().contains("UNIQUE") => {
return Err(DbError::Conflict);
}
Err(error) => return Err(sql_error(error)),
}
let revision = bump_revision(&transaction, list_id)?;
transaction.commit().map_err(sql_error)?;
Ok(revision)
})
.await
}
pub async fn add_item(
&self,
list_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DbResult<i64> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
ensure_category(&transaction, list_id, category_id)?;
let position: i64 = transaction
.query_row(
"SELECT COALESCE(MAX(position), -1) + 1 FROM items WHERE list_id = ?1",
params![list_id],
|row| row.get(0),
)
.map_err(sql_error)?;
transaction
.execute(
"INSERT INTO items
(list_id, name, quantity, note, category_id, checked, version, position, created_at, updated_at)
VALUES (?1, ?2, ?3, ?4, ?5, 0, 1, ?6, ?7, ?7)",
params![list_id, name, quantity, note, category_id, position, now()],
)
.map_err(sql_error)?;
let revision = bump_revision(&transaction, list_id)?;
transaction.commit().map_err(sql_error)?;
Ok(revision)
})
.await
}
pub async fn set_item_checked(
&self,
list_id: i64,
item_id: i64,
checked: bool,
) -> DbResult<i64> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
let changed = transaction
.execute(
"UPDATE items
SET checked = ?1, version = version + 1, updated_at = ?2
WHERE id = ?3 AND list_id = ?4",
params![checked as i64, now(), item_id, list_id],
)
.map_err(sql_error)?;
if changed == 0 {
return Err(DbError::NotFound);
}
let revision = bump_revision(&transaction, list_id)?;
transaction.commit().map_err(sql_error)?;
Ok(revision)
})
.await
}
pub async fn update_item(
&self,
list_id: i64,
item_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DbResult<i64> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
ensure_category(&transaction, list_id, category_id)?;
let changed = transaction
.execute(
"UPDATE items
SET name = ?1, quantity = ?2, note = ?3, category_id = ?4,
version = version + 1, updated_at = ?5
WHERE id = ?6 AND list_id = ?7",
params![name, quantity, note, category_id, now(), item_id, list_id],
)
.map_err(sql_error)?;
if changed == 0 {
return Err(DbError::NotFound);
}
let revision = bump_revision(&transaction, list_id)?;
transaction.commit().map_err(sql_error)?;
Ok(revision)
})
.await
}
pub async fn delete_item(&self, list_id: i64, item_id: i64) -> DbResult<i64> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
let changed = transaction
.execute(
"DELETE FROM items WHERE id = ?1 AND list_id = ?2",
params![item_id, list_id],
)
.map_err(sql_error)?;
if changed == 0 {
return Err(DbError::NotFound);
}
let revision = bump_revision(&transaction, list_id)?;
transaction.commit().map_err(sql_error)?;
Ok(revision)
})
.await
}
pub async fn create_invitation(&self, created_by: i64, token: String) -> DbResult<i64> {
self.call(move |connection| {
let expires_at = now() + 60 * 60 * 24 * 7;
connection
.execute(
"INSERT INTO invitations (token_hash, created_by, expires_at)
VALUES (?1, ?2, ?3)",
params![hash_secret(&token), created_by, expires_at],
)
.map_err(sql_error)?;
Ok(expires_at)
})
.await
}
pub async fn invitation(&self, token: String) -> DbResult<bool> {
self.call(move |connection| {
let valid = connection
.query_row(
"SELECT 1 FROM invitations
WHERE token_hash = ?1 AND expires_at > ?2",
params![hash_secret(&token), now()],
|_| Ok(()),
)
.optional()
.map_err(sql_error)?
.is_some();
Ok(valid)
})
.await
}
pub async fn accept_invitation(&self, token: String) -> DbResult<()> {
self.call(move |connection| {
let transaction = connection.transaction().map_err(sql_error)?;
let valid = transaction
.query_row(
"SELECT 1 FROM invitations
WHERE token_hash = ?1 AND expires_at > ?2",
params![hash_secret(&token), now()],
|_| Ok(()),
)
.optional()
.map_err(sql_error)?
.is_some();
if !valid {
return Err(DbError::NotFound);
}
transaction
.execute(
"DELETE FROM invitations WHERE token_hash = ?1",
params![hash_secret(&token)],
)
.map_err(sql_error)?;
transaction.commit().map_err(sql_error)?;
Ok(())
})
.await
}
}
fn configure(connection: &Connection) -> DbResult<()> {
connection
.pragma_update(None, "foreign_keys", true)
.map_err(sql_error)?;
connection
.pragma_update(None, "journal_mode", "WAL")
.map_err(sql_error)?;
connection
.busy_timeout(std::time::Duration::from_secs(5))
.map_err(sql_error)?;
Ok(())
}
fn migrate(connection: &Connection) -> DbResult<()> {
connection
.execute_batch(
"CREATE TABLE IF NOT EXISTS users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
email TEXT NOT NULL UNIQUE COLLATE NOCASE,
display_name TEXT NOT NULL,
password_hash TEXT NOT NULL,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS sessions (
token_hash TEXT PRIMARY KEY,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
csrf_token TEXT NOT NULL,
expires_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS lists (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
revision INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
name TEXT NOT NULL COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL,
UNIQUE (list_id, name)
);
CREATE TABLE IF NOT EXISTS invitations (
token_hash TEXT PRIMARY KEY,
created_by INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
expires_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS items (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
checked INTEGER NOT NULL DEFAULT 0,
version INTEGER NOT NULL DEFAULT 1,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE INDEX IF NOT EXISTS items_list_idx ON items(list_id);
CREATE INDEX IF NOT EXISTS categories_list_idx ON categories(list_id);
CREATE INDEX IF NOT EXISTS sessions_user_idx ON sessions(user_id);",
)
.map_err(sql_error)?;
Ok(())
}
fn ensure_category(
transaction: &rusqlite::Transaction<'_>,
list_id: i64,
category_id: Option<i64>,
) -> DbResult<()> {
let Some(category_id) = category_id else {
return Ok(());
};
let exists = transaction
.query_row(
"SELECT 1 FROM categories WHERE id = ?1 AND list_id = ?2",
params![category_id, list_id],
|_| Ok(()),
)
.optional()
.map_err(sql_error)?;
if exists.is_none() {
return Err(DbError::NotFound);
}
Ok(())
}
const DEFAULT_CATEGORIES: &[&str] = &[
"Produce",
"Meat & seafood",
"Dairy & eggs",
"Pantry",
"Frozen",
"Household",
];
fn bump_revision(transaction: &rusqlite::Transaction<'_>, list_id: i64) -> DbResult<i64> {
transaction
.execute(
"UPDATE lists SET revision = revision + 1 WHERE id = ?1",
params![list_id],
)
.map_err(sql_error)?;
transaction
.query_row(
"SELECT revision FROM lists WHERE id = ?1",
params![list_id],
|row| row.get(0),
)
.map_err(sql_error)
}
fn sql_error(error: impl std::fmt::Display) -> DbError {
DbError::Message(error.to_string())
}
fn now() -> i64 {
SystemTime::now()
.duration_since(UNIX_EPOCH)
.unwrap_or_default()
.as_secs() as i64
}
pub fn new_secret() -> String {
let mut bytes = [0_u8; 32];
OsRng.fill_bytes(&mut bytes);
hex::encode(bytes)
}
pub fn hash_secret(secret: &str) -> String {
let mut hasher = Sha256::new();
hasher.update(secret.as_bytes());
hex::encode(hasher.finalize())
}
#[cfg(test)]
mod tests {
use super::*;
#[tokio::test]
async fn creates_a_list_and_item() {
let database = Database::open_in_memory().unwrap();
let list = database
.create_list("Weekly shop".into())
.await
.unwrap();
database
.add_item(
list.id.clone(),
"Milk".into(),
"2 litres".into(),
String::new(),
None,
)
.await
.unwrap();
let items = database.items(list.id).await.unwrap();
assert_eq!(items.len(), 1);
assert_eq!(items[0].name, "Milk");
}
#[tokio::test]
async fn sessions_and_invitations_are_scoped_to_users() {
let database = Database::open_in_memory().unwrap();
let owner = database
.create_user("owner@example.com".into(), "Owner".into(), "hash".into())
.await
.unwrap();
let list = database
.create_list("Household".into())
.await
.unwrap();
assert_eq!(database.categories(list.id.clone()).await.unwrap().len(), 6);
let (session_token, csrf_token) = database.create_session(owner.id.clone()).await.unwrap();
let session = database
.session_user(session_token.clone())
.await
.unwrap()
.unwrap();
assert_eq!(session.user.id, owner.id);
assert_eq!(session.csrf_token, csrf_token);
// Any registered account can access every list.
assert_eq!(
database
.list_access(list.id.clone())
.await
.unwrap()
.unwrap()
.name,
"Household"
);
let invitation_token = "test-invitation".to_owned();
database
.create_invitation(owner.id.clone(), invitation_token.clone())
.await
.unwrap();
assert!(
database
.invitation(invitation_token.clone())
.await
.unwrap()
);
database
.accept_invitation(invitation_token.clone())
.await
.unwrap();
assert!(
!database
.invitation(invitation_token)
.await
.unwrap()
);
// A list created later is also accessible to every account.
let future_list = database
.create_list("Future shop".into())
.await
.unwrap();
assert_eq!(
database
.list_access(future_list.id)
.await
.unwrap()
.unwrap()
.name,
"Future shop"
);
}
#[tokio::test]
async fn checked_state_is_set_not_toggled() {
let database = Database::open_in_memory().unwrap();
let list = database.create_list("List".into()).await.unwrap();
database
.add_item(
list.id.clone(),
"Coffee".into(),
String::new(),
String::new(),
None,
)
.await
.unwrap();
let item = database.items(list.id.clone()).await.unwrap().remove(0);
database
.set_item_checked(list.id.clone(), item.id.clone(), true)
.await
.unwrap();
database
.set_item_checked(list.id.clone(), item.id.clone(), true)
.await
.unwrap();
let item = database.items(list.id).await.unwrap().remove(0);
assert!(item.checked);
assert_eq!(item.version, 3);
}
#[tokio::test]
async fn checking_an_item_does_not_change_list_order() {
let database = Database::open_in_memory().unwrap();
let list = database.create_list("List".into()).await.unwrap();
database
.add_item(
list.id.clone(),
"First".into(),
String::new(),
String::new(),
None,
)
.await
.unwrap();
database
.add_item(
list.id.clone(),
"Second".into(),
String::new(),
String::new(),
None,
)
.await
.unwrap();
let first_item = database.items(list.id.clone()).await.unwrap().remove(0);
database
.set_item_checked(list.id.clone(), first_item.id, true)
.await
.unwrap();
let items = database.items(list.id).await.unwrap();
assert_eq!(items[0].name, "First");
assert!(items[0].checked);
assert_eq!(items[1].name, "Second");
}
}
+115
View File
@@ -0,0 +1,115 @@
use thiserror::Error;
#[derive(Debug, Error)]
pub enum DomainError {
#[error("database error: {0}")]
Database(String),
#[error("password error: {0}")]
Password(String),
#[error("record not found")]
NotFound,
#[error("record already exists")]
Conflict,
}
pub type DomainResult<T> = Result<T, DomainError>;
#[derive(Clone, Debug)]
pub struct User {
pub id: i64,
pub email: String,
pub display_name: String,
/// Opaque, random user handle used as the WebAuthn userHandle. Kept
/// high-entropy and unpredictable per the WebAuthn spec to avoid user
/// enumeration and cross-site correlation. Stored as raw bytes.
pub user_handle: Vec<u8>,
}
#[derive(Clone, Debug)]
pub struct Passkey {
pub id: i64,
pub user_id: i64,
pub credential_id: String,
pub credential: String,
/// WebAuthn sign counter, persisted for future cloned-authenticator
/// detection. Not currently read by application logic.
#[allow(dead_code)]
pub counter: i64,
}
#[derive(Clone, Debug)]
pub struct SessionUser {
pub user: User,
pub csrf_token: String,
}
#[derive(Clone, Debug)]
pub struct GroceryList {
pub id: i64,
pub name: String,
pub revision: i64,
/// Unix timestamp of when the list was created.
pub created_at: i64,
/// Unix timestamp of when the list was archived; `None` when active.
pub archived_at: Option<i64>,
}
#[derive(Clone, Debug)]
pub struct Item {
pub id: i64,
pub list_id: i64,
pub name: String,
pub quantity: String,
pub note: String,
pub category_id: Option<i64>,
pub checked: bool,
pub version: i64,
}
#[derive(Clone, Debug)]
pub struct Category {
pub id: i64,
pub name: String,
}
#[derive(Clone, Debug)]
pub struct MealCategory {
pub id: i64,
pub name: String,
}
#[derive(Clone, Debug)]
pub struct Meal {
pub id: i64,
pub name: String,
pub description: String,
pub category_id: Option<i64>,
pub ingredients: Vec<MealIngredient>,
}
#[derive(Clone, Debug)]
pub struct MealIngredient {
pub id: i64,
pub name: String,
pub quantity: String,
pub note: String,
pub category_id: Option<i64>,
}
#[derive(Clone, Debug)]
pub struct ListMeal {
pub id: i64,
/// The catalog meal this instance came from; `None` once the meal is deleted.
#[allow(dead_code)]
pub meal_id: Option<i64>,
pub name: String,
/// When the meal was added to the list.
#[allow(dead_code)]
pub created_at: i64,
}
#[derive(Clone, Debug)]
pub struct PresenceUser {
pub user_id: i64,
pub display_name: String,
}
+1347
View File
File diff suppressed because it is too large Load Diff
+11 -29
View File
@@ -1,19 +1,11 @@
use std::collections::HashMap;
use std::sync::Arc;
use async_trait::async_trait;
use tokio::sync::{Mutex, broadcast};
#[derive(Clone, Debug)]
pub struct PresenceUser {
pub user_id: i64,
pub display_name: String,
}
#[derive(Clone, Debug)]
pub enum HubEvent {
ListChanged { list_id: i64, revision: i64 },
PresenceChanged { list_id: i64 },
}
use crate::domain::PresenceUser;
use crate::ports::{HubEvent, RealtimeNotifier, Subscription};
#[derive(Debug)]
struct ConnectionInfo {
@@ -26,24 +18,14 @@ struct Room {
connections: HashMap<String, ConnectionInfo>,
}
pub struct Subscription {
pub connection_id: String,
pub receiver: broadcast::Receiver<HubEvent>,
pub presence: Vec<PresenceUser>,
}
#[derive(Clone, Default)]
pub struct Hub {
pub struct InMemoryHub {
rooms: Arc<Mutex<HashMap<i64, Room>>>,
}
impl Hub {
pub async fn join(
&self,
list_id: i64,
user_id: i64,
display_name: String,
) -> Subscription {
#[async_trait]
impl RealtimeNotifier for InMemoryHub {
async fn join(&self, list_id: i64, user_id: i64, display_name: String) -> Subscription {
let mut rooms = self.rooms.lock().await;
let room = rooms.entry(list_id).or_insert_with(|| {
let (sender, _) = broadcast::channel(64);
@@ -53,7 +35,7 @@ impl Hub {
}
});
let connection_id = crate::db::new_secret();
let connection_id = hex::encode(crate::security::new_secret());
let already_present = room
.connections
.values()
@@ -79,7 +61,7 @@ impl Hub {
}
}
pub async fn leave(&self, list_id: i64, connection_id: &str) {
async fn leave(&self, list_id: i64, connection_id: &str) {
let mut rooms = self.rooms.lock().await;
let mut remove_room = false;
if let Some(room) = rooms.get_mut(&list_id) {
@@ -100,7 +82,7 @@ impl Hub {
}
}
pub async fn publish_list_changed(&self, list_id: i64, revision: i64) {
async fn publish_list_changed(&self, list_id: i64, revision: i64) {
let rooms = self.rooms.lock().await;
if let Some(room) = rooms.get(&list_id) {
let _ = room
@@ -109,7 +91,7 @@ impl Hub {
}
}
pub async fn presence(&self, list_id: i64) -> Vec<PresenceUser> {
async fn presence(&self, list_id: i64) -> Vec<PresenceUser> {
let rooms = self.rooms.lock().await;
rooms
.get(&list_id)
+139 -876
View File
File diff suppressed because it is too large Load Diff
+316
View File
@@ -0,0 +1,316 @@
use async_trait::async_trait;
use sqlx::SqliteConnection;
use crate::domain::{
Category, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory, MealIngredient,
Passkey, PresenceUser, SessionUser, User,
};
/// Repositories take `&mut SqliteConnection` (which a `Transaction` derefs to),
/// so several repositories can commit together atomically within a single
/// transaction coordinated by the unit of work.
#[async_trait]
pub trait UserRepository: Send + Sync {
async fn create_user(
&self,
txn: &mut SqliteConnection,
email: String,
display_name: String,
password_hash: String,
) -> DomainResult<User>;
async fn find_user_by_email(
&self,
txn: &mut SqliteConnection,
email: String,
) -> DomainResult<Option<(User, String)>>;
async fn find_user_by_handle(
&self,
txn: &mut SqliteConnection,
user_handle: Vec<u8>,
) -> DomainResult<Option<User>>;
async fn update_password_hash(
&self,
txn: &mut SqliteConnection,
user_id: i64,
password_hash: String,
) -> DomainResult<()>;
async fn has_users(&self, txn: &mut SqliteConnection) -> DomainResult<bool>;
}
#[async_trait]
pub trait PasskeyRepository: Send + Sync {
async fn create_passkey(
&self,
txn: &mut SqliteConnection,
user_id: i64,
credential_id: String,
credential: String,
counter: i64,
) -> DomainResult<Passkey>;
async fn find_by_credential_id(
&self,
txn: &mut SqliteConnection,
credential_id: String,
) -> DomainResult<Option<Passkey>>;
async fn list_for_user(
&self,
txn: &mut SqliteConnection,
user_id: i64,
) -> DomainResult<Vec<Passkey>>;
async fn delete_passkey(
&self,
txn: &mut SqliteConnection,
user_id: i64,
passkey_id: i64,
) -> DomainResult<()>;
}
#[async_trait]
pub trait SessionRepository: Send + Sync {
async fn create_session(
&self,
txn: &mut SqliteConnection,
user_id: i64,
) -> DomainResult<(String, String)>;
async fn session_user(
&self,
txn: &mut SqliteConnection,
session_token: String,
) -> DomainResult<Option<SessionUser>>;
async fn delete_session(
&self,
txn: &mut SqliteConnection,
session_token: String,
) -> DomainResult<()>;
}
#[async_trait]
pub trait ListRepository: Send + Sync {
async fn list_summaries(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<GroceryList>>;
async fn list_archived_summaries(
&self,
txn: &mut SqliteConnection,
) -> DomainResult<Vec<GroceryList>>;
async fn create_list(
&self,
txn: &mut SqliteConnection,
name: String,
) -> DomainResult<GroceryList>;
async fn get_list(
&self,
txn: &mut SqliteConnection,
list_id: i64,
) -> DomainResult<Option<GroceryList>>;
async fn set_archived(
&self,
txn: &mut SqliteConnection,
list_id: i64,
archived: bool,
) -> DomainResult<()>;
}
#[async_trait]
pub trait CategoryRepository: Send + Sync {
async fn categories(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Category>>;
async fn create_category(&self, txn: &mut SqliteConnection, name: String) -> DomainResult<i64>;
}
/// A single item to insert in bulk, without a per-item revision bump.
#[derive(Clone, Debug)]
pub struct NewItem {
pub name: String,
pub quantity: String,
pub note: String,
pub category_id: Option<i64>,
/// When set, links this item to the `list_meals` row it came from, so the
/// item is removed together with that meal instance.
pub list_meal_id: Option<i64>,
}
#[async_trait]
pub trait ItemRepository: Send + Sync {
async fn items(&self, txn: &mut SqliteConnection, list_id: i64) -> DomainResult<Vec<Item>>;
async fn add_item(
&self,
txn: &mut SqliteConnection,
list_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64>;
async fn add_items_bulk(
&self,
txn: &mut SqliteConnection,
list_id: i64,
items: Vec<NewItem>,
) -> DomainResult<i64>;
async fn set_item_checked(
&self,
txn: &mut SqliteConnection,
list_id: i64,
item_id: i64,
checked: bool,
) -> DomainResult<i64>;
async fn update_item(
&self,
txn: &mut SqliteConnection,
list_id: i64,
item_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64>;
async fn delete_item(
&self,
txn: &mut SqliteConnection,
list_id: i64,
item_id: i64,
) -> DomainResult<i64>;
}
#[async_trait]
pub trait ListMealRepository: Send + Sync {
async fn list_meals(
&self,
txn: &mut SqliteConnection,
list_id: i64,
) -> DomainResult<Vec<ListMeal>>;
async fn add_meal(
&self,
txn: &mut SqliteConnection,
list_id: i64,
meal_id: i64,
name: String,
) -> DomainResult<i64>;
async fn remove_meal(
&self,
txn: &mut SqliteConnection,
list_id: i64,
list_meal_id: i64,
) -> DomainResult<i64>;
}
#[async_trait]
pub trait InvitationRepository: Send + Sync {
async fn create_invitation(
&self,
txn: &mut SqliteConnection,
created_by: i64,
token: String,
) -> DomainResult<i64>;
async fn invitation(&self, txn: &mut SqliteConnection, token: String) -> DomainResult<bool>;
async fn accept_invitation(
&self,
txn: &mut SqliteConnection,
token: String,
) -> DomainResult<()>;
}
#[async_trait]
pub trait MealCategoryRepository: Send + Sync {
async fn meal_categories(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<MealCategory>>;
async fn create_meal_category(
&self,
txn: &mut SqliteConnection,
name: String,
) -> DomainResult<i64>;
async fn delete_meal_category(
&self,
txn: &mut SqliteConnection,
category_id: i64,
) -> DomainResult<()>;
}
#[async_trait]
pub trait MealRepository: Send + Sync {
async fn create_meal(
&self,
txn: &mut SqliteConnection,
name: String,
description: String,
category_id: Option<i64>,
) -> DomainResult<Meal>;
async fn get_meal(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
) -> DomainResult<Option<Meal>>;
async fn list_meals(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Meal>>;
async fn update_meal(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
name: String,
description: String,
category_id: Option<i64>,
) -> DomainResult<()>;
async fn delete_meal(&self, txn: &mut SqliteConnection, meal_id: i64) -> DomainResult<()>;
}
#[async_trait]
pub trait MealIngredientRepository: Send + Sync {
async fn ingredients_for_meal(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
) -> DomainResult<Vec<MealIngredient>>;
async fn add_ingredient(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64>;
async fn update_ingredient(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
ingredient_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<()>;
async fn delete_ingredient(
&self,
txn: &mut SqliteConnection,
meal_id: i64,
ingredient_id: i64,
) -> DomainResult<()>;
}
#[async_trait]
pub trait PasswordHasher: Send + Sync {
fn hash(&self, password: &str) -> DomainResult<String>;
fn verify(&self, password: &str, encoded_hash: &str) -> DomainResult<bool>;
}
#[async_trait]
pub trait TokenGenerator: Send + Sync {
fn generate(&self) -> String;
}
#[async_trait]
pub trait RealtimeNotifier: Send + Sync {
async fn join(&self, list_id: i64, user_id: i64, display_name: String) -> Subscription;
async fn leave(&self, list_id: i64, connection_id: &str);
async fn publish_list_changed(&self, list_id: i64, revision: i64);
async fn presence(&self, list_id: i64) -> Vec<PresenceUser>;
}
pub struct Subscription {
pub connection_id: String,
pub receiver: tokio::sync::broadcast::Receiver<HubEvent>,
pub presence: Vec<PresenceUser>,
}
#[derive(Clone, Debug)]
pub enum HubEvent {
ListChanged { list_id: i64, revision: i64 },
PresenceChanged { list_id: i64 },
}
+50
View File
@@ -0,0 +1,50 @@
use argon2::{
Argon2,
password_hash::{
PasswordHash, PasswordHasher as Argon2Hasher, PasswordVerifier, SaltString,
rand_core::OsRng,
},
};
use async_trait::async_trait;
use rand::RngCore;
use crate::domain::{DomainError, DomainResult};
use crate::ports::{PasswordHasher, TokenGenerator};
pub struct Argon2PasswordHasher;
#[async_trait]
impl PasswordHasher for Argon2PasswordHasher {
fn hash(&self, password: &str) -> DomainResult<String> {
let salt = SaltString::generate(&mut OsRng);
Argon2::default()
.hash_password(password.as_bytes(), &salt)
.map(|hash| hash.to_string())
.map_err(|error| DomainError::Password(error.to_string()))
}
fn verify(&self, password: &str, encoded_hash: &str) -> DomainResult<bool> {
let hash = PasswordHash::new(encoded_hash)
.map_err(|error| DomainError::Password(error.to_string()))?;
Ok(Argon2::default()
.verify_password(password.as_bytes(), &hash)
.is_ok())
}
}
pub struct RandomTokenGenerator;
#[async_trait]
impl TokenGenerator for RandomTokenGenerator {
fn generate(&self) -> String {
hex::encode(new_secret())
}
}
/// Generates 32 cryptographically random bytes. Callers that need a
/// client-facing string should hex-encode the result.
pub fn new_secret() -> Vec<u8> {
let mut bytes = [0_u8; 32];
OsRng.fill_bytes(&mut bytes);
bytes.to_vec()
}
+30 -4
View File
@@ -1,9 +1,11 @@
use std::path::Path;
use std::sync::Arc;
use serde::Deserialize;
use tracing::{info, warn};
use crate::db::Database;
use crate::ports::{PasswordHasher, UserRepository};
use crate::sqlite::SqliteDatabase;
#[derive(Debug, Deserialize)]
pub struct SeedConfig {
@@ -21,7 +23,12 @@ pub struct SeedUser {
/// Reads the seed config file and creates the configured default user if the
/// database has no users yet. The file is optional; if it does not exist (or
/// cannot be parsed) seeding is skipped.
pub async fn seed_if_needed(db: &Database, path: &Path) {
pub async fn seed_if_needed(
db: &SqliteDatabase,
users: &Arc<dyn UserRepository>,
hasher: &Arc<dyn PasswordHasher>,
path: &Path,
) {
let Ok(contents) = std::fs::read_to_string(path) else {
return;
};
@@ -39,24 +46,43 @@ pub async fn seed_if_needed(db: &Database, path: &Path) {
warn!("seed user requires a non-empty email; skipping");
return;
}
if db.has_users().await.unwrap_or(true) {
let users_for_check = users.clone();
let has_users = match db
.run(move |txn| Box::pin(async move { users_for_check.has_users(txn).await }))
.await
{
Ok(has_users) => has_users,
Err(error) => {
warn!(%error, "could not check for existing users; skipping seed");
return;
}
};
if has_users {
info!("database already has users; skipping seed");
return;
}
let password_hash = match crate::hash_password(&user.password) {
let password_hash = match hasher.hash(&user.password) {
Ok(hash) => hash,
Err(error) => {
warn!(%error, "could not hash seed password; skipping");
return;
}
};
let users_for_create = users.clone();
match db
.run(move |txn| {
Box::pin(async move {
users_for_create
.create_user(
txn,
user.email.trim().to_lowercase(),
user.display_name.trim().to_owned(),
password_hash,
)
.await
})
})
.await
{
Ok(user) => info!(id = user.id, email = %user.email, "seeded default user"),
Err(error) => warn!(%error, "could not seed default user"),
+630
View File
@@ -0,0 +1,630 @@
use std::sync::Arc;
use crate::domain::{
DomainError, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory, SessionUser, User,
};
use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListMealRepository, ListRepository,
MealCategoryRepository, MealIngredientRepository, MealRepository, NewItem, PasswordHasher,
RealtimeNotifier, SessionRepository, TokenGenerator, UserRepository,
};
use crate::sqlite::SqliteDatabase;
pub struct AuthService {
db: SqliteDatabase,
users: Arc<dyn UserRepository>,
sessions: Arc<dyn SessionRepository>,
invitations: Arc<dyn InvitationRepository>,
hasher: Arc<dyn PasswordHasher>,
registration_mode: RegistrationMode,
}
#[derive(Clone, Copy, PartialEq, Eq)]
pub enum RegistrationMode {
Open,
InviteOnly,
}
impl AuthService {
pub fn new(
db: SqliteDatabase,
users: Arc<dyn UserRepository>,
sessions: Arc<dyn SessionRepository>,
invitations: Arc<dyn InvitationRepository>,
hasher: Arc<dyn PasswordHasher>,
registration_mode: RegistrationMode,
) -> Self {
Self {
db,
users,
sessions,
invitations,
hasher,
registration_mode,
}
}
pub async fn can_register(&self, invite: Option<&str>) -> DomainResult<bool> {
if self.registration_mode == RegistrationMode::Open {
return Ok(true);
}
let users = Arc::clone(&self.users);
let invitations = Arc::clone(&self.invitations);
let invite = invite.map(str::to_owned);
self.db
.run(move |txn| {
Box::pin(async move {
if !users.has_users(txn).await? {
return Ok(true);
}
let Some(invite) = invite.filter(|invite| !invite.is_empty()) else {
return Ok(false);
};
invitations.invitation(txn, invite).await
})
})
.await
}
pub async fn register(
&self,
display_name: String,
email: String,
password: String,
invite: Option<&str>,
) -> DomainResult<(User, String)> {
if !self.can_register(invite).await? {
return Err(DomainError::Conflict);
}
let password_hash = self.hasher.hash(&password)?;
let users = Arc::clone(&self.users);
let sessions = Arc::clone(&self.sessions);
self.db
.run(move |txn| {
Box::pin(async move {
let user = users
.create_user(txn, email, display_name, password_hash)
.await?;
let (session_token, _) = sessions.create_session(txn, user.id).await?;
Ok((user, session_token))
})
})
.await
}
pub async fn login(
&self,
email: String,
password: String,
) -> DomainResult<Option<(User, String)>> {
let users = Arc::clone(&self.users);
let sessions = Arc::clone(&self.sessions);
let hasher = Arc::clone(&self.hasher);
self.db
.run(move |txn| {
Box::pin(async move {
let Some((user, password_hash)) = users.find_user_by_email(txn, email).await?
else {
return Ok(None);
};
let valid = hasher.verify(&password, &password_hash)?;
if !valid {
return Ok(None);
}
let (session_token, _) = sessions.create_session(txn, user.id).await?;
Ok(Some((user, session_token)))
})
})
.await
}
pub async fn session_user(&self, session_token: String) -> DomainResult<Option<SessionUser>> {
let sessions = Arc::clone(&self.sessions);
self.db
.run(move |txn| {
Box::pin(async move { sessions.session_user(txn, session_token).await })
})
.await
}
pub async fn find_user_by_email(&self, email: String) -> DomainResult<Option<(User, String)>> {
let users = Arc::clone(&self.users);
self.db
.run(move |txn| Box::pin(async move { users.find_user_by_email(txn, email).await }))
.await
}
pub async fn create_session_for_user(&self, user_id: i64) -> DomainResult<(String, String)> {
let sessions = Arc::clone(&self.sessions);
self.db
.run(move |txn| Box::pin(async move { sessions.create_session(txn, user_id).await }))
.await
}
pub async fn logout(&self, session_token: String) -> DomainResult<()> {
let sessions = Arc::clone(&self.sessions);
self.db
.run(move |txn| {
Box::pin(async move { sessions.delete_session(txn, session_token).await })
})
.await
}
/// Replaces the user's password hash with a freshly hashed new password.
/// No current-password check is performed because the account page is
/// already authenticated and this app has no email capabilities.
pub async fn change_password(&self, user_id: i64, new_password: String) -> DomainResult<()> {
let users = Arc::clone(&self.users);
let hasher = Arc::clone(&self.hasher);
self.db
.run(move |txn| {
Box::pin(async move {
let new_hash = hasher.hash(&new_password)?;
users.update_password_hash(txn, user_id, new_hash).await
})
})
.await
}
}
pub struct ListService {
db: SqliteDatabase,
lists: Arc<dyn ListRepository>,
categories: Arc<dyn CategoryRepository>,
items: Arc<dyn ItemRepository>,
realtime: Arc<dyn RealtimeNotifier>,
}
impl ListService {
pub fn new(
db: SqliteDatabase,
lists: Arc<dyn ListRepository>,
categories: Arc<dyn CategoryRepository>,
items: Arc<dyn ItemRepository>,
realtime: Arc<dyn RealtimeNotifier>,
) -> Self {
Self {
db,
lists,
categories,
items,
realtime,
}
}
pub async fn list_summaries(&self) -> DomainResult<Vec<GroceryList>> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.list_summaries(txn).await }))
.await
}
pub async fn list_archived_summaries(&self) -> DomainResult<Vec<GroceryList>> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.list_archived_summaries(txn).await }))
.await
}
pub async fn create_list(&self, name: String) -> DomainResult<GroceryList> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.create_list(txn, name).await }))
.await
}
pub async fn get_list(&self, list_id: i64) -> DomainResult<Option<GroceryList>> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.get_list(txn, list_id).await }))
.await
}
pub async fn archive_list(&self, list_id: i64) -> DomainResult<()> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.set_archived(txn, list_id, true).await }))
.await
}
pub async fn unarchive_list(&self, list_id: i64) -> DomainResult<()> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.set_archived(txn, list_id, false).await }))
.await
}
pub async fn items(&self, list_id: i64) -> DomainResult<Vec<Item>> {
let items = Arc::clone(&self.items);
self.db
.run(move |txn| Box::pin(async move { items.items(txn, list_id).await }))
.await
}
pub async fn categories(&self) -> DomainResult<Vec<crate::domain::Category>> {
let categories = Arc::clone(&self.categories);
self.db
.run(move |txn| Box::pin(async move { categories.categories(txn).await }))
.await
}
pub async fn add_item(
&self,
list_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64> {
let items = Arc::clone(&self.items);
let revision = self
.db
.run(move |txn| {
Box::pin(async move {
items
.add_item(txn, list_id, name, quantity, note, category_id)
.await
})
})
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
pub async fn set_item_checked(
&self,
list_id: i64,
item_id: i64,
checked: bool,
) -> DomainResult<i64> {
let items = Arc::clone(&self.items);
let revision = self
.db
.run(move |txn| {
Box::pin(
async move { items.set_item_checked(txn, list_id, item_id, checked).await },
)
})
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
pub async fn update_item(
&self,
list_id: i64,
item_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64> {
let items = Arc::clone(&self.items);
let revision = self
.db
.run(move |txn| {
Box::pin(async move {
items
.update_item(txn, list_id, item_id, name, quantity, note, category_id)
.await
})
})
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
pub async fn delete_item(&self, list_id: i64, item_id: i64) -> DomainResult<i64> {
let items = Arc::clone(&self.items);
let revision = self
.db
.run(move |txn| Box::pin(async move { items.delete_item(txn, list_id, item_id).await }))
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
pub async fn create_category(&self, name: String) -> DomainResult<i64> {
let categories = Arc::clone(&self.categories);
self.db
.run(move |txn| Box::pin(async move { categories.create_category(txn, name).await }))
.await
}
}
pub struct MealService {
db: SqliteDatabase,
meals: Arc<dyn MealRepository>,
ingredients: Arc<dyn MealIngredientRepository>,
meal_categories: Arc<dyn MealCategoryRepository>,
lists: Arc<dyn ListRepository>,
items: Arc<dyn ItemRepository>,
list_meals: Arc<dyn ListMealRepository>,
realtime: Arc<dyn RealtimeNotifier>,
}
impl MealService {
pub fn new(
db: SqliteDatabase,
meals: Arc<dyn MealRepository>,
ingredients: Arc<dyn MealIngredientRepository>,
meal_categories: Arc<dyn MealCategoryRepository>,
lists: Arc<dyn ListRepository>,
items: Arc<dyn ItemRepository>,
list_meals: Arc<dyn ListMealRepository>,
realtime: Arc<dyn RealtimeNotifier>,
) -> Self {
Self {
db,
meals,
ingredients,
meal_categories,
lists,
items,
list_meals,
realtime,
}
}
pub async fn create_meal(
&self,
name: String,
description: String,
category_id: Option<i64>,
) -> DomainResult<Meal> {
let meals = Arc::clone(&self.meals);
self.db
.run(move |txn| {
Box::pin(
async move { meals.create_meal(txn, name, description, category_id).await },
)
})
.await
}
pub async fn get_meal(&self, meal_id: i64) -> DomainResult<Option<Meal>> {
let meals = Arc::clone(&self.meals);
self.db
.run(move |txn| Box::pin(async move { meals.get_meal(txn, meal_id).await }))
.await
}
pub async fn list_meals(&self) -> DomainResult<Vec<Meal>> {
let meals = Arc::clone(&self.meals);
self.db
.run(move |txn| Box::pin(async move { meals.list_meals(txn).await }))
.await
}
pub async fn update_meal(
&self,
meal_id: i64,
name: String,
description: String,
category_id: Option<i64>,
) -> DomainResult<()> {
let meals = Arc::clone(&self.meals);
self.db
.run(move |txn| {
Box::pin(async move {
meals
.update_meal(txn, meal_id, name, description, category_id)
.await
})
})
.await
}
pub async fn list_meal_categories(&self) -> DomainResult<Vec<MealCategory>> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| Box::pin(async move { meal_categories.meal_categories(txn).await }))
.await
}
pub async fn create_meal_category(&self, name: String) -> DomainResult<i64> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| {
Box::pin(async move { meal_categories.create_meal_category(txn, name).await })
})
.await
}
pub async fn delete_meal_category(&self, category_id: i64) -> DomainResult<()> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| {
Box::pin(
async move { meal_categories.delete_meal_category(txn, category_id).await },
)
})
.await
}
pub async fn delete_meal(&self, meal_id: i64) -> DomainResult<()> {
let meals = Arc::clone(&self.meals);
self.db
.run(move |txn| Box::pin(async move { meals.delete_meal(txn, meal_id).await }))
.await
}
pub async fn add_ingredient(
&self,
meal_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<i64> {
let ingredients = Arc::clone(&self.ingredients);
self.db
.run(move |txn| {
Box::pin(async move {
ingredients
.add_ingredient(txn, meal_id, name, quantity, note, category_id)
.await
})
})
.await
}
pub async fn update_ingredient(
&self,
meal_id: i64,
ingredient_id: i64,
name: String,
quantity: String,
note: String,
category_id: Option<i64>,
) -> DomainResult<()> {
let ingredients = Arc::clone(&self.ingredients);
self.db
.run(move |txn| {
Box::pin(async move {
ingredients
.update_ingredient(
txn,
meal_id,
ingredient_id,
name,
quantity,
note,
category_id,
)
.await
})
})
.await
}
pub async fn delete_ingredient(&self, meal_id: i64, ingredient_id: i64) -> DomainResult<()> {
let ingredients = Arc::clone(&self.ingredients);
self.db
.run(move |txn| {
Box::pin(async move {
ingredients
.delete_ingredient(txn, meal_id, ingredient_id)
.await
})
})
.await
}
/// Expands a meal's ingredients into items on a list in one unit of work,
/// recording the meal on the list and bumping the list revision exactly once.
pub async fn add_meal_to_list(&self, meal_id: i64, list_id: i64) -> DomainResult<i64> {
let meals = Arc::clone(&self.meals);
let lists = Arc::clone(&self.lists);
let items = Arc::clone(&self.items);
let list_meals = Arc::clone(&self.list_meals);
let revision = self
.db
.run(move |txn| {
Box::pin(async move {
let meal = meals
.get_meal(txn, meal_id)
.await?
.ok_or(DomainError::NotFound)?;
if lists.get_list(txn, list_id).await?.is_none() {
return Err(DomainError::NotFound);
}
let list_meal_id = list_meals
.add_meal(txn, list_id, meal.id, meal.name.clone())
.await?;
let new_items = meal
.ingredients
.into_iter()
.map(|ingredient| NewItem {
name: ingredient.name,
quantity: ingredient.quantity,
note: ingredient.note,
category_id: ingredient.category_id,
list_meal_id: Some(list_meal_id),
})
.collect();
items.add_items_bulk(txn, list_id, new_items).await
})
})
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
/// Lists the meals that have been added to a list, most recent first.
pub async fn list_meals_on_list(&self, list_id: i64) -> DomainResult<Vec<ListMeal>> {
let list_meals = Arc::clone(&self.list_meals);
self.db
.run(move |txn| Box::pin(async move { list_meals.list_meals(txn, list_id).await }))
.await
}
/// Removes a meal instance from a list, deleting the items that came from it
/// and bumping the list revision exactly once.
pub async fn remove_meal_from_list(
&self,
list_id: i64,
list_meal_id: i64,
) -> DomainResult<i64> {
let list_meals = Arc::clone(&self.list_meals);
let revision = self
.db
.run(move |txn| {
Box::pin(async move { list_meals.remove_meal(txn, list_id, list_meal_id).await })
})
.await?;
self.realtime.publish_list_changed(list_id, revision).await;
Ok(revision)
}
}
pub struct InvitationService {
db: SqliteDatabase,
invitations: Arc<dyn InvitationRepository>,
tokens: Arc<dyn TokenGenerator>,
}
impl InvitationService {
pub fn new(
db: SqliteDatabase,
invitations: Arc<dyn InvitationRepository>,
tokens: Arc<dyn TokenGenerator>,
) -> Self {
Self {
db,
invitations,
tokens,
}
}
pub async fn create_invitation(&self, created_by: i64) -> DomainResult<String> {
let token = self.tokens.generate();
let invitations = Arc::clone(&self.invitations);
self.db
.run(move |txn| {
Box::pin(async move {
invitations
.create_invitation(txn, created_by, token.clone())
.await?;
Ok(token)
})
})
.await
}
pub async fn invitation(&self, token: String) -> DomainResult<bool> {
let invitations = Arc::clone(&self.invitations);
self.db
.run(move |txn| Box::pin(async move { invitations.invitation(txn, token).await }))
.await
}
pub async fn accept_invitation(&self, token: String) -> DomainResult<()> {
let invitations = Arc::clone(&self.invitations);
self.db
.run(move |txn| {
Box::pin(async move { invitations.accept_invitation(txn, token).await })
})
.await
}
}
+2775
View File
File diff suppressed because it is too large Load Diff
+785 -60
View File
File diff suppressed because it is too large Load Diff
+340
View File
@@ -0,0 +1,340 @@
use std::collections::HashMap;
use std::sync::{Arc, Mutex};
use webauthn_rs::{
Webauthn,
core::{AuthenticationState, RegistrationState, WebauthnConfig},
error::WebauthnError as WanError,
proto::{
CreationChallengeResponse, Credential, PublicKeyCredential, RegisterPublicKeyCredential,
RequestChallengeResponse, UserVerificationPolicy,
},
};
use crate::domain::{DomainError, DomainResult, Passkey as DbPasskey, User};
use crate::ports::{PasskeyRepository, UserRepository};
use crate::security::new_secret;
use crate::sqlite::SqliteDatabase;
/// Site-specific WebAuthn configuration, derived from env vars.
pub struct AppWebauthnConfig {
rp_id: String,
rp_name: String,
origin: url::Url,
require_resident_key: bool,
}
impl AppWebauthnConfig {
pub fn new(rp_id: String, rp_name: String, origin: url::Url) -> Self {
Self {
rp_id,
rp_name,
origin,
// Resident (discoverable) keys let users sign in without typing an
// email, because the authenticator can select the credential on its
// own and return the user handle.
require_resident_key: true,
}
}
}
impl WebauthnConfig for AppWebauthnConfig {
fn get_relying_party_name(&self) -> &str {
&self.rp_name
}
fn get_origin(&self) -> &url::Url {
&self.origin
}
fn get_relying_party_id(&self) -> &str {
&self.rp_id
}
fn get_require_resident_key(&self) -> bool {
self.require_resident_key
}
}
/// A single-use, in-memory challenge store. Registrations are keyed by user id;
/// authentications are keyed by a random token so that userless (discoverable)
/// ceremonies can be correlated back to the finish request.
#[derive(Default)]
struct ChallengeStore {
registrations: HashMap<i64, RegistrationState>,
authentications: HashMap<String, AuthenticationState>,
}
pub struct WebAuthnService {
db: SqliteDatabase,
webauthn: Webauthn<AppWebauthnConfig>,
users: Arc<dyn UserRepository>,
passkeys: Arc<dyn PasskeyRepository>,
challenges: Mutex<ChallengeStore>,
}
impl WebAuthnService {
pub fn new(
db: SqliteDatabase,
config: AppWebauthnConfig,
users: Arc<dyn UserRepository>,
passkeys: Arc<dyn PasskeyRepository>,
) -> Self {
let webauthn = Webauthn::new(config);
Self {
db,
webauthn,
users,
passkeys,
challenges: Mutex::new(ChallengeStore::default()),
}
}
/// Start a passkey registration ceremony for an authenticated user.
pub fn start_registration(&self, user: &User) -> DomainResult<CreationChallengeResponse> {
// Use the user's opaque, random user handle as the WebAuthn userHandle
// so that userless (discoverable) sign-in can resolve the owning user
// from the assertion's userHandle without exposing the numeric id.
let (challenge, state) = self
.webauthn
.generate_challenge_register_options(
user.user_handle.clone(),
user.email.clone(),
user.display_name.clone(),
None,
Some(UserVerificationPolicy::Required),
None,
)
.map_err(webauthn_error)?;
self.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.registrations
.insert(user.id, state);
Ok(challenge)
}
/// Finish a passkey registration ceremony and persist the credential.
pub async fn finish_registration(
&self,
user: &User,
response: RegisterPublicKeyCredential,
) -> DomainResult<()> {
let state = self
.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.registrations
.remove(&user.id)
.ok_or(DomainError::NotFound)?;
let passkeys = Arc::clone(&self.passkeys);
let credential_id = response.raw_id.0.clone();
let user_id = user.id;
let credential = self
.webauthn
.register_credential(&response, &state, |_| Ok(false))
.map_err(webauthn_error)?;
let serialized = serde_json::to_string(&credential.0)
.map_err(|e| DomainError::Database(e.to_string()))?;
let credential_id_b64 = base64_url(&credential_id);
let counter = credential.0.counter as i64;
self.db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
passkeys
.create_passkey(txn, user_id, credential_id_b64, serialized, counter)
.await?;
Ok(())
})
})
.await
}
/// Start a passkey authentication ceremony for a user identified by email.
/// Returns the challenge and a token used to correlate the finish request.
pub async fn start_authentication(
&self,
user_id: i64,
) -> DomainResult<(RequestChallengeResponse, String)> {
let passkeys = Arc::clone(&self.passkeys);
let db = self.db.clone();
let credentials: Vec<Credential> = db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
let rows = passkeys.list_for_user(txn, user_id).await?;
let mut creds = Vec::new();
for row in rows {
let cred: Credential = serde_json::from_str(&row.credential)
.map_err(|e| DomainError::Database(e.to_string()))?;
creds.push(cred);
}
Ok(creds)
})
})
.await?;
if credentials.is_empty() {
return Err(DomainError::NotFound);
}
let (challenge, state) = self
.webauthn
.generate_challenge_authenticate(credentials)
.map_err(webauthn_error)?;
let token = hex::encode(new_secret());
self.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications
.insert(token.clone(), state);
Ok((challenge, token))
}
/// Start a userless passkey authentication ceremony. No email is required:
/// the authenticator selects a discoverable credential and returns a user
/// handle that we resolve to the owning user on finish.
pub async fn start_userless_authentication(
&self,
) -> DomainResult<(RequestChallengeResponse, String)> {
let (challenge, mut state) = self
.webauthn
.generate_challenge_authenticate_options(vec![], None)
.map_err(webauthn_error)?;
// With no allowCredentials the browser will offer any discoverable
// credential for this RP; the credential set is populated from the
// user handle once the assertion is received.
state.set_allowed_credentials(vec![]);
let token = hex::encode(new_secret());
self.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications
.insert(token.clone(), state);
Ok((challenge, token))
}
/// Finish a passkey authentication ceremony, resolving the owning user from
/// the credential id (and, for userless ceremonies, the user handle).
pub async fn finish_authentication(
&self,
token: String,
response: PublicKeyCredential,
) -> DomainResult<i64> {
let mut state = self
.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications
.remove(&token)
.ok_or(DomainError::NotFound)?;
// For userless ceremonies the assertion carries a user handle that
// identifies the user; load that user's credentials so the signature
// can be verified against the correct key.
if let Some(user_handle) = response.get_user_handle() {
let handle = user_handle.to_vec();
let users = Arc::clone(&self.users);
let db = self.db.clone();
let user_id = db
.run(move |txn| {
let users = users.clone();
Box::pin(async move {
let user = users
.find_user_by_handle(txn, handle)
.await?
.ok_or(DomainError::NotFound)?;
Ok(user.id)
})
})
.await?;
let passkeys = Arc::clone(&self.passkeys);
let credentials: Vec<Credential> = db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
let rows = passkeys.list_for_user(txn, user_id).await?;
let mut creds = Vec::new();
for row in rows {
let cred: Credential = serde_json::from_str(&row.credential)
.map_err(|e| DomainError::Database(e.to_string()))?;
creds.push(cred);
}
Ok(creds)
})
})
.await?;
state.set_allowed_credentials(credentials);
}
let (cred_id, auth_data) = self
.webauthn
.authenticate_credential(&response, &state)
.map_err(|e| {
tracing::error!(%e, "webauthn authenticate_credential failed");
webauthn_error(e)
})?;
let passkeys = Arc::clone(&self.passkeys);
let db = self.db.clone();
let credential_id_b64 = base64_url(cred_id);
let user_id = db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
let stored = passkeys
.find_by_credential_id(txn, credential_id_b64)
.await?
.ok_or(DomainError::NotFound)?;
let mut cred: Credential = serde_json::from_str(&stored.credential)
.map_err(|e| DomainError::Database(e.to_string()))?;
cred.counter = auth_data.counter;
let serialized = serde_json::to_string(&cred)
.map_err(|e| DomainError::Database(e.to_string()))?;
sqlx::query("UPDATE passkeys SET credential = ?1 WHERE id = ?2")
.bind(&serialized)
.bind(stored.id)
.execute(&mut *txn)
.await
.map_err(db_error)?;
Ok(stored.user_id)
})
})
.await?;
Ok(user_id)
}
/// List the passkeys registered to a user.
pub async fn list_passkeys(&self, user_id: i64) -> DomainResult<Vec<DbPasskey>> {
let passkeys = Arc::clone(&self.passkeys);
self.db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move { passkeys.list_for_user(txn, user_id).await })
})
.await
}
/// Delete a passkey owned by a user.
pub async fn delete_passkey(&self, user_id: i64, passkey_id: i64) -> DomainResult<()> {
let passkeys = Arc::clone(&self.passkeys);
self.db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move { passkeys.delete_passkey(txn, user_id, passkey_id).await })
})
.await
}
}
fn base64_url(bytes: &[u8]) -> String {
use base64::Engine;
base64::engine::general_purpose::URL_SAFE_NO_PAD.encode(bytes)
}
fn webauthn_error(error: WanError) -> DomainError {
DomainError::Database(error.to_string())
}
fn db_error(error: sqlx::Error) -> DomainError {
DomainError::Database(error.to_string())
}
+34
View File
@@ -0,0 +1,34 @@
function b64ToBytes(b64) {
const bin = atob(b64.replace(/-/g, "+").replace(/_/g, "/"));
const bytes = new Uint8Array(bin.length);
for (let i = 0; i < bin.length; i++) bytes[i] = bin.charCodeAt(i);
return bytes;
}
document.getElementById("passkey-login").addEventListener("click", async () => {
const email = document.getElementById("email").value.trim();
const start = await fetch("/auth/passkey/login/start", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ email }),
});
if (!start.ok) {
alert("No passkey found for that account.");
return;
}
const data = await start.json();
const pk = data.publicKey;
pk.challenge = b64ToBytes(pk.challenge);
if (pk.allowCredentials) {
pk.allowCredentials.forEach((c) => (c.id = b64ToBytes(c.id)));
}
const credential = await navigator.credentials.get({ publicKey: pk });
const finish = await fetch("/auth/passkey/login/finish", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ token: data.token, response: credential }),
});
if (finish.ok) {
window.location.href = "/lists";
}
});
+32
View File
@@ -0,0 +1,32 @@
function b64ToBytes(b64) {
const bin = atob(b64.replace(/-/g, "+").replace(/_/g, "/"));
const bytes = new Uint8Array(bin.length);
for (let i = 0; i < bin.length; i++) bytes[i] = bin.charCodeAt(i);
return bytes;
}
document.getElementById("add-passkey").addEventListener("click", async () => {
const csrf = document.getElementById("add-passkey").dataset.csrf;
const start = await fetch("/auth/passkey/register/start", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ csrf }),
});
const options = await start.json();
const pk = options.publicKey;
pk.challenge = b64ToBytes(pk.challenge);
pk.user.id = b64ToBytes(pk.user.id);
if (pk.excludeCredentials) {
pk.excludeCredentials.forEach((c) => (c.id = b64ToBytes(c.id)));
}
const credential = await navigator.credentials.create(options);
const response = { csrf, response: credential };
const finish = await fetch("/auth/passkey/register/finish", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify(response),
});
if (finish.ok) {
window.location.href = "/account";
}
});
+16
View File
@@ -0,0 +1,16 @@
// Toggle password visibility so users can check for typos, especially on mobile.
document.querySelectorAll(".password-toggle").forEach(function (button) {
button.addEventListener("pointerdown", function (event) {
// Toggle on press (not click) for an instant response. preventScroll avoids
// a scroll-to-input animation that makes rapid toggling feel laggy, and
// keeping focus on the input keeps the mobile keyboard open.
event.preventDefault();
var input = document.getElementById(button.getAttribute("data-toggle-for"));
if (!input) return;
var showing = input.type === "text";
input.type = showing ? "password" : "text";
button.textContent = showing ? "Show" : "Hide";
button.setAttribute("aria-label", showing ? "Show password" : "Hide password");
input.focus({ preventScroll: true });
});
});
+239 -11
View File
@@ -39,8 +39,20 @@ a { color: inherit; }
.brand { display: inline-flex; align-items: center; gap: 10px; text-decoration: none; font-weight: 800; letter-spacing: -.03em; }
.brand-mark { display: grid; place-items: center; width: 32px; height: 32px; border-radius: 11px 11px 11px 3px; background: var(--deep-sage); color: white; transform: rotate(-6deg); }
.site-nav { display: flex; align-items: center; gap: 6px; }
.site-nav a {
padding: 8px 14px;
border-radius: 11px;
color: var(--muted);
text-decoration: none;
font-size: .9rem;
font-weight: 700;
transition: color .16s ease, background .16s ease;
}
.site-nav a:hover { color: var(--ink); background: #eef2ea; }
.account-nav { display: flex; align-items: center; gap: 16px; color: var(--muted); font-size: .9rem; }
.user-name { color: var(--ink); font-weight: 700; }
.user-name { color: var(--ink); font-weight: 700; text-decoration: none; }
.user-name:hover { color: var(--deep-sage); }
.text-button { border: 0; padding: 0; color: var(--deep-sage); background: transparent; cursor: pointer; font-weight: 700; }
.site-main { width: min(1120px, calc(100% - 40px)); margin: 30px auto 80px; }
@@ -55,14 +67,27 @@ h3 { margin-bottom: 6px; font-size: 1rem; }
.muted { color: var(--muted); }
.page-heading { display: flex; justify-content: space-between; align-items: end; margin-bottom: 34px; }
.page-heading h1.page-title { font-size: clamp(1.6rem, 3.2vw, 2.3rem); }
.dashboard-grid { display: grid; grid-template-columns: minmax(0, 1.5fr) minmax(260px, .8fr); gap: 22px; align-items: start; }
.panel { padding: 26px; border: 1px solid rgba(221, 225, 210, .9); border-radius: 24px; background: rgba(255, 253, 248, .88); box-shadow: var(--shadow); }
.panel-heading { display: flex; justify-content: space-between; align-items: center; gap: 12px; margin-bottom: 22px; }
.archive-link { margin-left: auto; color: var(--muted); font-size: .78rem; font-weight: 700; text-decoration: none; }
.archive-link:hover { color: var(--deep-sage); }
.count-badge { display: inline-grid; place-items: center; min-width: 27px; height: 27px; padding: 0 8px; border-radius: 99px; color: var(--deep-sage); background: #e8f0e1; font-size: .78rem; font-weight: 800; }
.stack { display: grid; gap: 9px; }
.stack label { color: var(--muted); font-size: .82rem; font-weight: 700; }
input { width: 100%; min-height: 46px; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; }
input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
.password-field { position: relative; }
.password-field input { padding-right: 64px; }
.password-toggle { position: absolute; top: 50%; right: 8px; transform: translateY(-50%); min-height: 32px; padding: 5px 10px; border: 0; border-radius: 9px; cursor: pointer; color: var(--deep-sage); background: #e7f0e1; font-weight: 800; font-size: .78rem; }
.password-toggle:hover { background: #dbe9d2; }
select { width: 100%; min-height: 46px; padding: 10px 34px 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; font: inherit; appearance: none; -webkit-appearance: none; background-image: url("data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='16' height='16' viewBox='0 0 16 16'><path d='M4 6l4 4 4-4' fill='none' stroke='%2355715d' stroke-width='2' stroke-linecap='round' stroke-linejoin='round'/></svg>"); background-repeat: no-repeat; background-position: right 12px center; }
select:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
select option { color: var(--ink); background: #fff; }
select option:checked { color: var(--deep-sage); font-weight: 700; }
textarea { width: 100%; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; font: inherit; resize: vertical; }
textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
.button { display: inline-flex; align-items: center; justify-content: center; min-height: 44px; padding: 10px 17px; border: 0; border-radius: 12px; cursor: pointer; text-decoration: none; font-weight: 800; transition: transform .16s ease, box-shadow .16s ease, background .16s ease; }
.button:hover { transform: translateY(-1px); }
.button-primary { color: #fff; background: var(--deep-sage); box-shadow: 0 8px 18px rgba(85, 113, 93, .2); }
@@ -77,16 +102,29 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
.list-card-copy { display: grid; flex: 1; gap: 2px; }
.list-card-copy small { color: var(--muted); font-size: .75rem; }
.list-card-arrow { color: var(--muted); font-size: 1.25rem; }
.archived-list-card { opacity: .72; }
.archived-list-card .list-card-icon { color: var(--muted); background: #eef0ea; }
.archived-list-card .list-card-copy { align-items: flex-start; }
.archived-list-card form { margin-left: auto; }
.archived-banner { margin-bottom: 18px; padding: 11px 14px; border: 1px solid var(--line); border-radius: 12px; color: var(--muted); background: #f1f3ec; font-size: .82rem; font-weight: 700; }
.empty-state { padding: 35px 18px 24px; text-align: center; color: var(--muted); }
.empty-mark { display: grid; place-items: center; width: 50px; height: 50px; margin: 0 auto 15px; border-radius: 18px; color: var(--deep-sage); background: #edf3e8; font-size: 1.8rem; }
.empty-state h3 { color: var(--ink); }
.auth-card { width: min(100%, 480px); margin: 7vh auto 0; padding: clamp(27px, 6vw, 54px); border: 1px solid var(--line); border-radius: 28px; background: rgba(255, 253, 248, .9); box-shadow: var(--shadow); }
.auth-card .button { margin-top: 11px; }
#passkey-login { width: 100%; }
.auth-divider { display: flex; align-items: center; gap: 12px; margin: 20px 0 4px; color: var(--muted); font-size: .8rem; }
.auth-divider::before, .auth-divider::after { content: ""; flex: 1; height: 1px; background: var(--line); }
.passkey-list { display: grid; gap: 8px; margin-bottom: 16px; }
.passkey-row { display: flex; align-items: center; gap: 12px; padding: 12px; border: 1px solid var(--line); border-radius: 14px; background: #fff; }
.passkey-row .item-copy { flex: 1; }
.passkey-row small { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.auth-switch { margin: 25px 0 0; color: var(--muted); font-size: .9rem; text-align: center; }
.auth-switch a { color: var(--deep-sage); font-weight: 800; }
.alert { margin-bottom: 18px; padding: 12px 14px; border-radius: 12px; font-size: .9rem; }
.alert-error { color: #874d40; background: #fbe7e0; }
.alert-success { color: #3d6b4f; background: #e4f2e6; }
.list-topbar { display: flex; justify-content: space-between; align-items: center; margin-bottom: 27px; }
.back-link { color: var(--muted); font-size: .85rem; font-weight: 700; text-decoration: none; }
@@ -94,12 +132,20 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
.list-topbar-actions { display: flex; align-items: center; gap: 12px; }
.live-pill { display: inline-flex; align-items: center; gap: 7px; color: var(--deep-sage); font-size: .78rem; font-weight: 800; }
.live-dot { width: 8px; height: 8px; border-radius: 50%; background: #75ae6e; box-shadow: 0 0 0 4px rgba(117, 174, 110, .15); }
.add-meal-button {
color: #fff;
background: var(--deep-sage);
box-shadow: 0 8px 18px rgba(85, 113, 93, .25);
}
.add-meal-button:hover { transform: translateY(-2px); box-shadow: 0 12px 24px rgba(85, 113, 93, .32); }
.add-meal-button:active { transform: translateY(0); }
.list-layout { display: grid; grid-template-columns: minmax(0, 1.5fr) minmax(265px, .72fr); gap: 22px; align-items: start; }
.list-panel { min-width: 0; }
.list-heading { display: flex; justify-content: space-between; margin-bottom: 25px; }
.list-heading h1 { max-width: 100%; margin-bottom: 5px; overflow-wrap: anywhere; font-size: clamp(1.45rem, 2.8vw, 2.05rem); }
.list-meta { margin: 0; color: var(--muted); font-size: .85rem; }
.add-item-form { display: grid; grid-template-columns: minmax(0, 1fr) 90px 145px auto; gap: 8px; margin-bottom: 19px; }
.meal-category-label { margin-left: 10px; color: var(--muted); font-size: .8em; font-weight: 500; white-space: nowrap; }
.add-item-form { display: grid; grid-template-columns: minmax(0, 1fr) 145px 90px auto; gap: 8px; margin-bottom: 19px; }
.add-item-form input { min-height: 50px; }
.add-item-form select { min-height: 50px; }
.add-button { min-height: 50px; }
@@ -107,22 +153,86 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
.item-list { display: grid; gap: 6px; }
.category-group + .category-group { margin-top: 18px; }
.category-heading { margin: 0 7px 4px; color: var(--deep-sage); font-size: .72rem; letter-spacing: .12em; text-transform: uppercase; }
.ingredients-divider { margin: 26px 0 18px; border: 0; border-top: 1px solid var(--line); }
.item-row { display: flex; align-items: center; gap: 12px; min-height: 66px; padding: 9px 7px 9px 10px; border-bottom: 1px solid #edf0e6; }
.item-row:last-child { border-bottom: 0; }
.check-form { flex: 0 0 auto; }
.check-button { display: grid; place-items: center; width: 28px; height: 28px; padding: 0; border: 2px solid #c8d6c1; border-radius: 9px; color: #fff; background: transparent; cursor: pointer; font-size: .88rem; font-weight: 900; }
.is-checked .check-button { border-color: var(--deep-sage); background: var(--deep-sage); }
.item-copy { display: grid; flex: 1; min-width: 0; gap: 2px; }
.item-copy strong { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.item-copy small { overflow: hidden; color: var(--muted); text-overflow: ellipsis; white-space: nowrap; font-size: .78rem; }
.check-button-static { cursor: default; }
.is-checked .check-button-static { border-color: var(--deep-sage); background: var(--deep-sage); }
.item-copy { display: grid; grid-template-columns: auto 1fr; flex: 1; min-width: 0; gap: 2px 7px; align-items: baseline; }
.item-copy strong { grid-column: 2; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.item-qty { grid-column: 1; grid-row: 1; color: var(--muted); font-weight: 700; white-space: nowrap; }
.item-copy small { grid-column: 1 / -1; overflow: hidden; color: var(--muted); text-overflow: ellipsis; white-space: nowrap; font-size: .78rem; }
.is-checked .item-copy strong { color: var(--muted); text-decoration: line-through; }
.item-actions { position: relative; }
.item-actions summary { padding: 7px 5px; color: var(--muted); cursor: pointer; list-style: none; font-size: .78rem; letter-spacing: 2px; }
.item-actions summary::-webkit-details-marker { display: none; }
.item-menu { position: absolute; z-index: 2; right: 0; width: min(265px, 80vw); padding: 14px; border: 1px solid var(--line); border-radius: 15px; background: var(--card); box-shadow: var(--shadow); }
.item-actions-button {
flex: 0 0 auto;
padding: 7px 8px;
border: 0;
border-radius: 9px;
color: var(--muted);
background: transparent;
cursor: pointer;
font-size: .9rem;
letter-spacing: 2px;
line-height: 1;
}
.item-actions-button:hover { color: var(--ink); background: #f0f3ea; }
/* Rendered markdown (meal descriptions) */
.markdown { line-height: 1.6; color: var(--ink); }
.markdown p { margin: 0 0 12px; }
.markdown ul, .markdown ol { margin: 0 0 12px; padding-left: 22px; }
.markdown li { margin-bottom: 4px; }
.markdown h1, .markdown h2, .markdown h3, .markdown h4 { margin: 18px 0 8px; letter-spacing: -.02em; }
.markdown h1 { font-size: 1.5rem; }
.markdown h2 { font-size: 1.25rem; }
.markdown h3 { font-size: 1.1rem; }
.markdown code { padding: 2px 5px; border-radius: 6px; background: #eef2ea; font-size: .9em; }
.markdown pre { padding: 12px; border-radius: 12px; background: #eef2ea; overflow-x: auto; }
.markdown pre code { padding: 0; background: transparent; }
.markdown blockquote { margin: 0 0 12px; padding-left: 14px; border-left: 3px solid var(--sage); color: var(--muted); }
.markdown a { color: var(--deep-sage); text-decoration: underline; }
/* Meal ingredient list */
.ingredient-list { display: grid; gap: 6px; margin: 0; padding: 0; list-style: none; }
.ingredient-list li {
display: flex;
align-items: center;
gap: 12px;
min-height: 52px;
padding: 8px 6px 8px 4px;
border-bottom: 1px solid #edf0e6;
}
.ingredient-list li:last-child { border-bottom: 0; }
/* Item / ingredient edit modal */
.item-modal {
width: min(100%, 420px);
padding: 0;
border: 1px solid rgba(221, 225, 210, .9);
border-radius: 24px;
background: rgba(255, 253, 248, .98);
box-shadow: var(--shadow);
}
.item-modal::backdrop {
background: rgba(37, 53, 46, .28);
}
.item-modal-card { padding: 22px 24px 24px; }
.item-modal-header {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 16px;
margin-bottom: 18px;
}
.item-modal-header h3 { margin: 0; font-size: 1.15rem; letter-spacing: -.02em; }
.item-modal .stack { margin-bottom: 14px; }
.edit-form { margin-bottom: 12px; }
.edit-form input { min-height: 38px; padding: 7px 10px; font-size: .85rem; }
.danger-link { padding: 0; border: 0; color: var(--coral); background: none; cursor: pointer; font-size: .8rem; font-weight: 800; }
.bordered-delete { padding: 7px 14px; border: 1px solid var(--coral); border-radius: 10px; background: none; }
.bordered-delete:hover { background: #fbeae4; }
.button-danger { width: 100%; color: var(--coral); background: #fbeae4; }
.button-danger:hover { background: #f7ddd4; }
.empty-items { padding: 34px 10px 18px; color: var(--muted); text-align: center; }
.empty-items-icon { display: block; margin-bottom: 7px; color: var(--yellow); font-size: 1.7rem; }
.empty-items p { margin-bottom: 2px; color: var(--ink); font-weight: 800; }
@@ -133,12 +243,28 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
.category-form input { min-height: 38px; padding: 7px 10px; font-size: .84rem; }
.category-list { display: flex; flex-wrap: wrap; gap: 6px; margin-top: 14px; }
.category-chip { padding: 5px 9px; border-radius: 99px; color: var(--deep-sage); background: #edf3e8; font-size: .72rem; font-weight: 800; }
/* Meal categories side panel */
.meal-category-list { display: grid; gap: 2px; margin-top: 14px; }
.meal-category-row { display: flex; align-items: center; justify-content: space-between; gap: 8px; padding: 7px 4px; border-bottom: 1px solid #edf0e6; }
.meal-category-row:last-child { border-bottom: 0; }
.meal-category-name { font-size: .9rem; font-weight: 700; }
.meal-category-delete { padding: 2px 6px; border: 0; border-radius: 7px; color: var(--muted); background: transparent; cursor: pointer; font-size: .8rem; line-height: 1; }
.meal-category-delete:hover { color: var(--coral); background: #fbeae4; }
.category-empty { margin: 13px 0 0; font-size: .8rem; }
.category-result { margin-top: 10px; }
.category-success { margin: 0; color: var(--deep-sage); font-size: .76rem; font-weight: 800; }
.presence-list { display: grid; gap: 12px; }
.presence-person { display: flex; align-items: center; gap: 10px; font-size: .9rem; font-weight: 700; }
.avatar { display: grid; place-items: center; width: 32px; height: 32px; border-radius: 11px; color: var(--deep-sage); background: #e6f0df; font-size: .7rem; font-weight: 900; }
.list-meals { display: grid; gap: 8px; }
.list-meal-row { display: flex; align-items: center; gap: 10px; padding: 6px 4px; border-bottom: 1px solid #edf0e6; }
.list-meal-row:last-child { border-bottom: 0; }
.list-meal-icon { display: grid; place-items: center; flex: 0 0 auto; width: 30px; height: 30px; border-radius: 10px; color: var(--deep-sage); background: #eef4e9; font-size: .95rem; }
.list-meal-name { flex: 1; min-width: 0; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; font-size: .9rem; font-weight: 700; }
.list-meal-remove { margin: 0; flex: 0 0 auto; }
.list-meal-remove-button { padding: 2px 7px; border: 0; border-radius: 7px; color: var(--muted); background: transparent; cursor: pointer; font-size: .8rem; line-height: 1; }
.list-meal-remove-button:hover { color: var(--coral); background: #fbeae4; }
.list-meals-panel .add-meal-button { margin-top: 12px; width: 100%; }
.sharing-panel p, .tip-panel p { color: var(--muted); font-size: .86rem; }
.invite-result { margin-top: 15px; }
.invite-link-result { padding: 11px; border-radius: 12px; background: #f1f5ec; }
@@ -153,9 +279,109 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
.sr-only { position: absolute; width: 1px; height: 1px; padding: 0; margin: -1px; overflow: hidden; clip: rect(0, 0, 0, 0); white-space: nowrap; border: 0; }
/* Meal picker modal */
.meal-picker-backdrop {
position: fixed;
inset: 0;
z-index: 50;
display: grid;
place-items: center;
padding: 20px;
background: rgba(37, 53, 46, .28);
animation: meal-picker-fade .15s ease;
}
@keyframes meal-picker-fade { from { opacity: 0; } to { opacity: 1; } }
.meal-picker-modal {
width: min(100%, 460px);
max-height: min(78vh, 620px);
display: flex;
flex-direction: column;
overflow: hidden;
border: 1px solid rgba(221, 225, 210, .9);
border-radius: 24px;
background: rgba(255, 253, 248, .98);
box-shadow: var(--shadow);
animation: meal-picker-pop .18s ease;
}
@keyframes meal-picker-pop { from { opacity: 0; transform: translateY(8px); } to { opacity: 1; transform: none; } }
.meal-picker-header {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 16px;
padding: 22px 24px 16px;
border-bottom: 1px solid #edf0e6;
}
.meal-picker-header .eyebrow { margin-bottom: 5px; }
.meal-picker-header h2 { margin-bottom: 0; font-size: 1.25rem; letter-spacing: -.02em; }
.meal-picker-close {
display: grid;
place-items: center;
flex: 0 0 auto;
width: 34px;
height: 34px;
padding: 0;
border: 1px solid var(--line);
border-radius: 11px;
color: var(--muted);
background: #fff;
cursor: pointer;
font-size: .9rem;
transition: color .16s ease, border-color .16s ease;
}
.meal-picker-close:hover { color: var(--ink); border-color: var(--sage); }
.meal-picker-list {
display: grid;
gap: 8px;
padding: 16px 24px 22px;
overflow-y: auto;
}
.meal-picker-row { margin: 0; }
.meal-picker-button {
display: flex;
align-items: center;
gap: 13px;
width: 100%;
padding: 12px 13px;
border: 1px solid var(--line);
border-radius: 16px;
color: var(--ink);
background: #fff;
cursor: pointer;
text-align: left;
transition: border-color .16s ease, transform .16s ease;
}
.meal-picker-button:hover { border-color: var(--sage); transform: translateX(2px); }
.meal-picker-icon {
display: grid;
place-items: center;
flex: 0 0 auto;
width: 38px;
height: 38px;
border-radius: 13px;
color: var(--deep-sage);
background: #eef4e9;
font-size: 1.1rem;
}
.meal-picker-copy { display: grid; flex: 1; min-width: 0; gap: 2px; }
.meal-picker-copy strong { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; font-size: .95rem; }
.meal-picker-copy small { color: var(--muted); font-size: .76rem; }
.meal-picker-add {
flex: 0 0 auto;
padding: 6px 12px;
border-radius: 99px;
color: var(--deep-sage);
background: #e7f0e1;
font-size: .74rem;
font-weight: 800;
}
.meal-picker-empty { padding: 34px 22px 30px; text-align: center; color: var(--muted); }
.meal-picker-empty h3 { color: var(--ink); }
.meal-picker-empty p { margin-bottom: 18px; }
@media (max-width: 780px) {
.site-header, .site-main, .site-footer { width: min(100% - 28px, 600px); }
.site-header { padding: 20px 0; }
.site-header { padding: 18px 0; }
.site-main { margin-top: 20px; }
.dashboard-grid, .list-layout { grid-template-columns: 1fr; }
.side-column { grid-template-columns: repeat(2, minmax(0, 1fr)); }
@@ -163,12 +389,14 @@ input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113
}
@media (max-width: 500px) {
.site-header { flex-wrap: wrap; gap: 12px 16px; }
.site-nav { order: 3; width: 100%; justify-content: center; gap: 8px; }
.site-nav a { flex: 1; text-align: center; padding: 10px 8px; }
.account-nav { gap: 9px; }
.user-name { max-width: 90px; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.panel { padding: 20px 16px; border-radius: 20px; }
.page-heading { margin-bottom: 24px; }
.list-topbar { margin-bottom: 20px; }
.list-topbar-actions .button { display: none; }
.list-heading h1 { font-size: clamp(1.45rem, 7vw, 1.75rem); }
.add-item-form { grid-template-columns: minmax(0, 1fr) 75px; }
.add-button { grid-column: 1 / -1; }