msolarczek
a8fedc390f
Merge lane/testphase in feature/craftvia-mvp
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
# Conflicts:
# prisma/schema.prisma
# scripts/test-e2e-tenant-isolation.ts
# src/server/backup/topology.ts
# src/server/db.ts
# src/server/dsgvo/pii-fields.ts
2026-09-15 19:16:19 +02:00
msolarczek and Claude Opus 5
c3712598c1
Transaktionen: Wartezeit 10 s und Zeitlimit 20 s statt Prisma-Standard
...
Unter paralleler Last scheiterten Tests sporadisch mit „Unable to start a transaction in the given time“.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-15 19:14:31 +02:00
msolarczek and Claude Opus 5
d9290a187c
L15 Testphase & Onboarding: Selbstanmeldung mit Double-Opt-in, Plattform-Wizard, Nur-Lesen-Sperre, Export, Lebenszyklus-Job
...
- Datenmodell: Testphasen-Lebenszyklus am Mandanten (plan, trialEndsAt, readOnlySince, deletionDueAt,
Versandmarker), TrialSignup (Plattform, Hashes statt Klartext), TenantExport (RLS), Onboarding-Status
- /testen: 5-Schritte-Wizard (Betrieb, Admin-Konto, Enddatum, Einrichtung, Zusammenfassung),
Bestätigung per POST, direkte Anmeldung über login-ticket; Rate-Limit je IP/E-Mail, Honeypot,
Enumeration-Schutz, Slug-Kollisionen
- Plattform: Wizard „Testmandant anlegen“ mit Einladung, Badges/Filter, Enddatum ändern,
umwandeln, beenden, Löschung vormerken/abbrechen (Bestätigung + Audit)
- Schreibsperre nach Ablauf zentral in moduleGuard und requireApiContext (non-GET über withApi),
Upload-Routen, Einstellungen/Nutzerverwaltung, Worker-Jobs; Banner Backoffice + mobil
- Datenexport (ZIP mit CSV/JSON + Dateien) als Worker-Job, auch im Nur-Lesen-Zustand
- Täglicher Job trial-lifecycle: Erinnerungen 7/3/1, Ablauf, Löschhinweis, Löschung über das Offboarding
- Erste-Schritte-Checkliste im Dashboard, Mail-Vorlagen de/en, Tests + Smoke, Betriebsdoku
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-15 19:01:47 +02:00
msolarczek and Claude Opus 5
68f4eb32dc
L16 Lotse-Chat für Monteure: Datenmodell, Provider mit Tool-Schleife, Vorschläge und Bestätigen über bestehende Services
...
Chatverlauf (LotseConversation/-Message) und Aktionskarten (LotseActionProposal) als
Mandantentabellen mit RLS; Schalter lotseChatEnabled. Tool-Use-Schleife mit Runden- und
Tokengrenze, Datenminimierung per Platzhalter, Auftragszuordnung im Sichtbarkeits-Scope,
Bestätigen/Verwerfen/Alle bestätigen mit Hash, Ablauf und Idempotenz, Transkriptions-API.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-15 18:57:20 +02:00
msolarczek and Claude Opus 5
6358d5762c
L14 Abrechnungsübersicht: Datenmodell, Migration, Rechte und Modul
...
Neue Tenant-Tabellen work_order_milestones und billing_records (RLS, TENANT_MODELS, PII-Felder), Partial-Unique-Indizes je Quelle, billing_record_id an time_entries/material_usages. Rechte billing:read/billing:write (Backoffice, Mandantenadmin), Modul billing, Events milestone.*.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-15 10:35:20 +02:00
msolarczek and Claude Opus 5
4a25f2cc3b
Fundament: atomare Mandanten-Transaktionen, iframe-Vorschau, Uploads bis 25 MB, DSGVO-Felder
...
- db.ts: tenantTransaction() – atomar auch bei RLS_ENFORCED=true (AsyncLocalStorage
bindet Operationen an eine craftvia_app-Transaktion, Kontext einmal gesetzt,
verschachtelte Aufrufe treten bei, fremder Mandant wird abgewiesen)
- services/context.ts: inTransaction(ctx, fn); imports/confirm.ts umgestellt
- next.config.ts: EMBEDDABLE_FILE_ROUTES mit frame-ancestors 'self'/SAMEORIGIN
(PDF-Vorschau Prüfmaske), proxyClientMaxBodySize 26mb (Import bis 25 MB)
- test-rls-enforcement: RLS-URL-Default aus DATABASE_URL (Lane-DBs)
- dsgvo/pii-fields: 26 Personenreferenzen des Craftvia-Domänenmodells
- ARCHITEKTUR §4.8: Transaktions-, Header-, Upload-, Versions- und PII-Regeln
- Test test-tenant-transaction (Commit/Rollback/Fremdmandant/Verschachtelung),
grün im Owner- und im RLS-Modus
Gate: tsc, lint, build, 31/31 Tests grün.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-14 12:29:57 +02:00
msolarczek and Claude Opus 5
bf4456718e
Architektur: Craftvia-Domänenmodell, Verträge und Team-Schnitte
...
- Migration 0002_craftvia_domain: 27 Fachtabellen inkl. RLS (enable_tenant_rls)
- TENANT_MODELS (db.ts, backup/topology.ts) um alle Fachmodelle ergänzt
- moduleGuard liefert DB-autoritative Rechte; ServiceCtx für Domänen-Services
- Verträge: Statusmaschine, Events, Nummernkreise, Sichtbarkeits-Scopes,
Job-Queues + Worker, KI-Provider-Interfaces, Sync-Envelope
- docs/craftvia/ARCHITEKTUR.md mit Lanes, Ownership und DoD
Gate: tsc, lint, build, 22/22 Tests grün.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-14 11:49:21 +02:00
msolarczek and Claude Opus 5
8491c7f173
Fundament: ISMS-Module entfernt; Craftvia-Rollen, Module, Navigation, i18n-Split
...
- ISMS-Routen, Actions, Server-/Lib-Code, Komponenten, Prisma-Modelle, Seeds,
Importer, Skripte und ISMS-Tests entfernt (Fundament bleibt: Auth, Identity,
MFA/WebAuthn, RBAC, Audit, Mail, Storage, Backup/DSGVO, Plattform-Admin)
- Schema auf Fundament-Modelle reduziert; TenantSettings generisch (+phone/email)
- TENANT_MODELS (db.ts, backup/topology.ts) und PII-Felder ausgedünnt
- RBAC: Rollen tenant-admin/backoffice/team-lead/technician + Craftvia-Permissions
- Modul-Katalog (customers, sites, teams, work_orders, imports, field, reports,
emergency, documents, notifications, lotse) + Navigation aus src/lib/nav.ts
- Modul-Routen mit requireModule-Layout und Platzhalterseite
- Message-Katalog je Namespace (messages/<locale>/<namespace>.json), fs-Loader
- check-module-guards: Modul-Key aus src/server/actions/<moduleKey>/
- Provisionierung, Admin-Konsole, Einstellungen, Files-Route, Mail entkoppelt
- Seed minimal (demo/demo2, Nutzer je Rolle); Fundament-Tests auf Role/
NotificationPreference-Fixtures umgestellt
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-14 11:35:44 +02:00
msolarczek and Claude Opus 5
c8e6f30a27
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
...
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-14 11:05:39 +02:00