Commit Graph

214 Commits

Author SHA1 Message Date
pavlov346346-source
37a8dd5bb3 fix: bump stale cache-busting version on core script tags
The signature-offer-pdf-v18.js script tag's ?v= query string was never
updated across ~9 content commits since the file was created, so browsers
kept serving a stale cached copy indefinitely. All other script/style tags
shared an equally stale v17.7.3 tag. Bumped every tag in index.html to a
single fresh version string so all recent fixes (template selection,
merged addon card, controlLines/extraServices wiring) actually reach users
without a manual hard refresh.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 13:33:41 +03:00
pavlov346346-source
14e3d6b45b fix: merge addon pills into one card, wire it to editable Settings
Two related fixes reported directly against live screenshots:

1. addonRow rendered each addon ("Напитки", "Чайная станция", ...) as
   its own tall bordered pill sitting side by side -- disjointed, and
   unlike the single-card "Полезные дополнения" treatment in the
   referenced design. Now draws one card with a heading
   ("Рекомендуем добавить") containing all the icon+label items,
   matching how checklistCard already works.

2. The addon list and the "Всё под контролем" checklist were hardcoded
   constants in the canvas module, completely bypassing the app's
   existing editable Client Offer Settings (Настройки → Предложение →
   "Дополнительно к заказу", textarea-backed extraServices/controlLines
   the user can already edit for the old templates). preparedSnapshot
   now attaches the resolved controlLines/extraServices/titles onto
   every snapshot; the 8 signature templates read them via a local
   shadowing const (falls back to the previous defaults when nothing
   is configured), so editing that Settings textarea now actually
   changes what shows up in these templates too, on all 8 of them from
   one change since addonRow/checklistCard are shared helpers.

Verified locally: default list (6 items) lays out cleanly in one card
with 2-line wrapping where needed; a snapshot with custom
controlLines/extraServices renders those exact custom strings instead
of the defaults, confirming the wiring actually works end to end and
isn't just falling back silently.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 11:28:18 +03:00
pavlov346346-source
44bf5e9af1 feat: add 2 new templates modeled on the referenced menu.furset.ru design
User pointed at https://menu.furset.ru/view/23855347 as a design they
like and asked for a couple more templates in that direction. Added:

- premium-dark: near-black background, warm gold accents, real
  line-drawn icon badges (calendar/people/box -- not emoji) for the
  date/guests/boxes stats, bullet-point value props under the title,
  minimal flat menu list -- closely matching that reference's visual
  language instead of the card-heavy style of the existing templates.
- premium-emerald: the same layout in an emerald-green palette, as
  the second "couple" of designs requested, sharing the cover code
  with premium-dark and only differing by PALETTES entry.

Both plug into the existing shared renderContentPages engine, so they
get proper multi-page menu + pricing pages for free, consistent with
all 6 existing signature templates. New icon-drawing helpers
(iconBadge/iconCalendar/iconPeople/iconGauge/iconBox, statBadgeRow,
bulletList) live in the shared helper section for reuse.

Verified locally: both render in <70ms combined, produce 3 pages each
for a normal order, and hold up under the same adversarial-data pass
used for the other 6 (long names, 350 guests, seven-figure price,
item with no photo/price/category) -- no overlap, no crashes, generous
ellipsis truncation throughout. Fixed one real bug found while
testing: the date value in the stat badge ("8 августа 2026 г.") was
getting ellipsis-truncated at font-size 20px; reduced to 16px so it
fits cleanly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 11:11:43 +03:00
pavlov346346-source
28fd97bcf3 fix: replace gourmet-hero's fake category tabs with real ones
Same issue as the cards just removed from cream-elegance: a hardcoded
['РЫБНЫЕ','МЯСНЫЕ','ВЕГЕТАРИАНСКИЕ','САЛАТЫ','ДЕСЕРТЫ'] tab row that
had nothing to do with what was actually in the order (an order with
zero vegetarian items still showed a "ВЕГЕТАРИАНСКИЕ" tab as if
active/relevant). Now derives the chip row from the distinct
categoryName values actually present on the order's items, and
renders nothing if that data isn't available.

Verified this pass end-to-end rather than just by inspection:
- Real "Скачать PDF" pipeline (sunClientOfferDebugPdf) produces a
  valid application/pdf blob with a correct %PDF-1.4 header, not just
  canvases.
- Confirmed Canvas text genuinely falls back through the font stack
  (measured identical metrics for an unregistered font vs. Georgia
  directly, and document.fonts.load() resolves instantly for a
  never-registered family) -- so a blocked/unreachable Google Fonts
  degrades silently to Georgia/Arial instead of hanging or erroring,
  which matters given this app already had to work around Russia
  connectivity issues elsewhere.
- Re-rendered all 6 templates against deliberately adversarial data
  (150+ word event name, 44-char client name, 350 guests, a
  million-ruble price, an item with no photo/price/category, a long
  promo code) -- no crashes, no overlap, graceful ellipsis truncation
  throughout.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 10:57:29 +03:00
pavlov346346-source
b702b4b69e fix: remove static category cards from cream-elegance cover
They were hardcoded labels (Рыбные закуски / Мясные закуски / Для
вегетарианцев / Мини-салаты) with a generic "Собрано под ваше
событие" caption that didn't reflect the actual order — confusing and
requested to be removed. The freed space now goes to a bigger 3x2
photo grid of the order's real items instead of leaving a gap.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 10:41:10 +03:00
pavlov346346-source
d78ca14baf feat: bring the other 4 signature templates up to the same quality bar
- Fix the price band on cream-elegance: it was a solid muddy olive
  fill that didn't read as "this is your total" (reported directly by
  the user). It's now a white card with a gold border, matching the
  rest of that template's light card language; the dark templates'
  solid-fill price band is unchanged since that already reads well
  against a dark background.
- Give emerald-circles, midnight-checklist, gourmet-hero and
  diamond-gold the same treatment as the first 2: real fonts
  (Playfair Display/Montserrat or Unbounded/Manrope depending on
  aesthetic) instead of Arial/Georgia, the same center-alignment fixes
  applied everywhere text used align:'center', and their own
  fully-styled inner pages (menu + pricing) via the shared
  renderContentPages engine instead of the old generic base renderer.
- Fix two real regressions the font swap introduced and caught by
  rendering each template locally: gourmet-hero's headline was
  overflowing width and getting ellipsis-truncated ("КЕЙТЕРИНГ..."),
  and diamond-gold's heading was wrapping to a second line that
  collided with the subtitle below it. Both fixed with size/width
  adjustments verified by direct canvas measurement.
- All 6 signature templates are selectable in Settings again.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 10:14:25 +03:00
pavlov346346-source
51e2fa4c33 feat: give cream-elegance and neon-menu their own matching inner pages
The cover for these 2 templates was fully custom, but the item-list
and pricing pages behind it still came from the old generic base
renderer (Arial, different card style, different page chrome) — so a
downloaded offer read as a nice cover stapled to a plain, differently
styled document ("два предложения").

Both templates now render their own item-list pages (photo, name,
category/weight, qty and line total, paginated ~10 rows/page) and a
matching pricing-breakdown page (base cost, discount, promo, delivery,
total, per-guest), using the same fonts, palette and card language as
the cover, with a shared footer/page-number treatment across every
page. The other 4 signature templates and the 13 classic ones are
untouched and keep using the original base renderer.

Verified locally: 8 items -> 3 pages (cover + 1 menu + pricing),
15 items -> 4 pages (cover + 2 menu + pricing), 0 items -> 3 pages,
no errors, base renderer confirmed never invoked for these 2 ids.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 09:58:07 +03:00
pavlov346346-source
c0bb18d5f7 fix: polish the 2 kept offer templates — alignment, fonts, gallery
- Fix a systemic centering bug: several canvas text() calls used
  align:'center' but passed the box's left edge as x instead of its
  midpoint, so headings, badge numbers, checkmarks and chip labels
  rendered pinned to the left instead of centered (most visible on
  cream-elegance's "МЕНЮ" heading and neon-menu's guest badge).
- Fix cream-elegance's category icons: the emoji glyph was never
  actually passed into iconCircle, so the icon circles rendered empty.
- Even out cream-elegance's bottom row (stat cards vs price band had
  mismatched heights).
- Load distinctive Cyrillic-friendly type pairs instead of default
  Arial/Georgia: Playfair Display + Montserrat for cream-elegance,
  Unbounded + Manrope for neon-menu, awaited via the Font Loading API
  before each render so text never draws in the fallback face.
- Narrow the Settings gallery to just these two templates per request
  ("остановимся на 2х пдф пока"); the other 4 signature designs and
  the original 13 classic templates stay intact and renderable for any
  order that already used one, just not offered for new ones.

Verified via a local static server (public/, http-server) with a real
uploaded box photo run through window.SunSignatureOfferPDFV18 and the
production sunClientOfferDebugPdfPages pipeline directly — 3 pages,
no duplicate cover, both fonts confirmed loaded via document.fonts.check.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 08:49:39 +03:00
pavlov346346-source
90482d0e7d fix: stop signature PDF pages from double-rendering a cover
renderOfferPdfPages routed the signature templates' inner pages back
through the classic module's own renderPages, which drew its own
extra cover page on top of the real content pages -- doubling the
render work and producing an extra page. Route straight to the plain
base renderer instead. Also await the gourmet-hero template's photo
cards instead of firing them off unawaited.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 18:42:32 +03:00
pavlov346346-source
b92b52e03e feat: add 6 new client-offer PDF templates, archive the old 13
New "signature" template pack (cream-elegance, neon-menu,
emerald-circles, midnight-checklist, gourmet-hero, diamond-gold)
replaces the visible template gallery in Settings. The previous 13
classic/archive templates keep rendering correctly for any existing
order that already used one, but are no longer selectable for new
orders — nothing was deleted.

Also adds a Settings option to upload a custom logo and company name
for PDF documents, replacing the hardcoded "Солнце Кейтеринг" branding
wherever a logo fails to load.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 18:27:23 +03:00
pavlov346346-source
3610927a33 fix: restore write permissions in local-only mode
RBAC permission checks (has()) always deferred to the cloud
workspace's role, which is null when using "work locally without
internet" — so every guarded action (save/delete order, edit catalog,
etc.) was blocked with "no permission" even though there is no
workspace to restrict against. Local-only mode now grants full access,
matching how nav permissions already behave with no cloud session.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 17:49:05 +03:00
pavlov346346-source
26681195b0 fix: accept emergency export format in Settings backup restore
The Settings "load from file" button only understood its own
sun-catering-backup format. Extend it to also read the
caterium-full-export format produced by the browser-console
emergency export (localStorage + IndexedDB), so an already-downloaded
export file can be restored directly through the UI.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 17:30:31 +03:00
pavlov346346-source
345ee8e052 feat: add JSON file backup export/import to Settings
Lets users download the local database as a JSON file and restore it
from a file, independent of cloud sync — needed while Supabase is
unreachable to move data between computers or recover after an outage.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 17:29:32 +03:00
pavlov346346-source
98ba823f16 merge: reconcile production promo-code work with main
Bring the 13 commits pushed directly to production (trial promo
codes, owner onboarding, service worker/PWA cache fixes, auth
proxy fallback) back into main, so the two branches share one
history again. The direct-to-production pushes had diverged from
main, which silently broke the auto-promote pipeline (plain
non-force push rejected as non-fast-forward).
2026-09-15 17:07:07 +03:00
pavlov346346-source
caa13eca59 feat: add "work locally without internet" option to login gate
When Supabase is unreachable, employees were stuck on the login
screen with no way in, even though the app is fully usable offline
(orders, catalog, stock, etc. all live in localStorage already).

Adds a low-key link on the login screen that sets a local-only flag
and skips the auth gate entirely until a real cloud sign-in succeeds
(which clears the flag). Deliberately does not touch any cloud/session
state, so it can't trigger an automatic cloud pull that would overwrite
data created while working offline.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 16:57:56 +03:00
pavlov346346-source
79b470d03f fix: fall back to direct Supabase auth on proxy 500 2026-09-14 17:26:32 +03:00
pavlov346346-source
708b90e87d fix: align safe service worker with release cache guard 2026-09-14 17:10:16 +03:00
pavlov346346-source
30a534b67f fix: keep safe navigation compatible with release guard 2026-09-14 17:01:37 +03:00
pavlov346346-source
5b827b4e09 fix: reopen app after persisted login session 2026-09-14 16:57:45 +03:00
pavlov346346-source
0249734252 fix: stop service worker from rewriting app HTML 2026-09-14 16:43:56 +03:00
pavlov346346-source
74a6261d5b test: syntax-check trial promo module 2026-09-14 16:39:41 +03:00
pavlov346346-source
77485cafca fix: keep promo onboarding server-authoritative 2026-09-14 12:23:00 +03:00
pavlov346346-source
e6fff9e58d fix: restore validated PWA cache key for onboarding release 2026-09-14 12:07:10 +03:00
pavlov346346-source
b09276f2fc Add v17.8.2 owner workspace onboarding migration 2026-09-14 10:57:45 +03:00
pavlov346346-source
9d38b5550b Fix company owner and employee onboarding 2026-09-14 10:57:28 +03:00
pavlov346346-source
f514b22798 feat: load trial promo developer UI in production PWA 2026-09-14 02:49:05 +03:00
pavlov346346-source
afb502c345 feat: add trial promo management to developer console 2026-09-13 18:44:18 +03:00
pavlov346346-source
170c078998 feat: require trial promo code during Caterium signup 2026-09-13 18:43:54 +03:00
pavlov346346-source
834557e865 fix: show real error text instead of "[object Object]" in auth gate
String(err) on a plain object (a PostgrestError-shaped object without a
.message, or any non-Error rejection) renders as the literal string
"[object Object]" with no useful information. Added errText() that
prefers err.message, falls back to JSON-stringifying the object, and
only then falls back to a generic message - and applied it to the three
catch blocks in the login/company-creation gate flow (auth(), the
pending-registration finisher, and the "retry workspace access" button),
which is what surfaced the raw "[object Object]" during login.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-13 17:30:17 +03:00
pavlov346346-source
fe029715eb ops: add api.caterium.ru proxy script to repo, fix auth CORS
The deployed PHP reverse proxy at api.caterium.ru only forwarded/allowed
a fixed set of CORS request headers, missing x-supabase-api-version which
supabase-js v2.112.4's auth client sends on every request. That made the
browser reject the preflight and fail the actual login call client-side
with a generic "Failed to fetch" (not a server error, so it never showed
up in server logs) - every login was broken since the proxy went live.

Fixed on the live server and committed the previously SCP-only script
here so future edits go through git instead of being SSH-only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-13 17:08:58 +03:00
pavlov346346-source
5d73b2c37e Route Supabase REST/Auth/Storage/Functions traffic through api.caterium.ru proxy
The api.caterium.ru PHP reverse proxy has been deployed and verified end-to-end
(curl tests plus live authenticated RPC calls through a real browser session).
This switches the client's Supabase fetch calls to go through the proxy so
requests from Russia work without a VPN. Realtime's WebSocket connection is
unaffected since it doesn't go through fetch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-13 02:50:37 +03:00
pavlov346346-source
aafad18d6a fix: remove the racy forced password-change gate for new employees
showPasswordChangeGate() replaced the auth gate's content and returned,
but the same login also fires onAuthStateChange, which kicks off
loadMemberships() independently. Once that resolved (workspace found),
ensureAuthGate()'s periodic poll (every 5s, plus assorted event-driven
calls) saw signedIn+workspace and tore the gate down immediately,
regardless of whether a password-change form was currently blocking
it - the employee would see the "create a new password" screen flash
and vanish before they could use it, dropping them straight into the
app still on their temporary password.

Removes the forced gate entirely (mustChangePassword/
showPasswordChangeGate) and adds a "Пароль" box to the account
settings card instead, so changing your password is a deliberate,
always-available action rather than a one-shot dialog racing the rest
of the login flow.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-13 01:59:36 +03:00
pavlov346346-source
4afde880d2 revert: back out the api.caterium.ru fetch rewrite for now
The previous commit accidentally carried over an uncommitted proxy
cutover (supabaseProxyFetch wired into createClient's global.fetch)
that was left sitting in the working tree from an earlier, paused
verification session - it was never meant to ship without first
completing the full checklist (auth, clients, orders, Storage,
Functions) against the live proxy. Reverting just that piece so
main goes back to calling cksuehzcimitsxmeloes.supabase.co directly,
keeping the "Загрузить из облака" button fix from the same commit.
The proxy cutover will come back once it's actually been verified
end-to-end.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 18:37:56 +03:00
pavlov346346-source
38a4ba47eb fix: restore the missing "Загрузить из облака" button in settings
bindCloudUI() already wires a click handler on #sunCloudPullV2
(confirm dialog -> pullRemote({replace:true, quiet:false}), which
backs up the local copy and force-replaces it with the server's
orders/clients/etc.), but renderCloudUI()'s template never actually
emitted a button with that id - the handler was permanently a no-op.
Adds the missing button to the "Профиль и аккаунт" settings card.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 18:35:20 +03:00
pavlov346346-source
5427b71651 fix: wrap catalog category pills on mobile instead of horizontal scroll
@media(max-width:720px) forced .sun-catalog-top-toolbar .cats into
flex-wrap:nowrap + overflow:auto, turning the colored category pills
(Боксы/Премиум/Напитки/Дополнения/Посуда...) into a horizontally
scrolling strip that runs off the right edge of the screen instead of
wrapping.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 18:20:41 +03:00
pavlov346346-source
870cc405dc fix: keep catalog toolbar buttons together on mobile
The previous mobile fix put the title on its own row but left the
search input as a regular flex item (flex:1 1 140px) among PDF/
"Вкладки"/"Меню". Since it greedily grows to fill whatever line it
lands on, it still forced PDF onto its own line, then itself onto the
next, then the two remaining buttons onto a third - three staggered
rows instead of the intended toolbar.

Gives the search input its own full-width row (flex-basis:100%,
order:0) and puts all catalog-head buttons (PDF, "Вкладки", "Меню") on
the next row together, sharing it evenly (flex:1 1 0) so they land on
one level instead of scattering.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 18:06:13 +03:00
pavlov346346-source
edfce3b7e6 fix: pre-apply cached brand/sidebar theme before first paint
The static :root fallback for --sun-ui-*/--sun-sidebar-* hardcodes the
"Standard Purple" preset (SIDEBAR_STANDARD's exact values). Any
workspace that has actually saved a different theme only gets it
applied once app-runtime.js's brand-theme module loads and runs
applyActual(), which reads the same localStorage cache
(sunBrandThemeV1) it always did - but by then the purple/mixed
defaults have already painted, so every load flashes the wrong colors
before snapping to the real ones.

Reads the same localStorage key synchronously in the
sun-startup-stability-guard script (already first in <head>, before
any stylesheet or the app-runtime.js bundle loads) and sets the same
CSS custom properties as inline styles on <html>. Inline element
styles always win over a stylesheet's :root selector regardless of
load order, so the correct theme is already active for the very first
paint. Workspaces with no saved theme yet are unaffected - the
existing static fallback still shows, same as today.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 17:56:19 +03:00
pavlov346346-source
1af9733154 fix: restore search/notification icons and catalog toolbar on mobile
The sidebar's search and notification button icons are drawn entirely
by mask-image rules scoped to @media(min-width:901px) (the "enterprise
sidebar" redesign styling). The existing mobile block
(@media(max-width:900px)) predates that redesign and only hides the
button labels via font-size:0 - it never defined a mobile equivalent
of the icon rules, so on phones the buttons rendered with literally
nothing visible inside them: no text (hidden), no icon (never defined
for this breakpoint).

Adds a second @media(max-width:900px) block with the same mask-image
icons for #sunGlobalSearchBtn/#sunNotificationsBtn.

Also fixes the catalog toolbar (PDF / search / "Вкладки" / "Меню"):
on narrow screens flex-wrap put the title, buttons, and a
min-width:180px search input on uneven wrapped lines with no
consistent baseline. The title now takes its own full-width line
(order:-1, flex-basis:100%), the search input can shrink instead of
forcing overflow, and the toolbar buttons get an explicit
align-self:center so they land on one level together.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 17:45:31 +03:00
pavlov346346-source
09d54682c2 fix: add timeout and error handling to loadMemberships
Every other cloud RPC call goes through sunCloudAwait (12s timeout),
but loadMemberships() (which resolves which workspace to open right
after login, showing "Загружаю рабочую базу...") called client.rpc/
.from directly with no timeout and no catch. A single slow or dropped
request left the auth gate stuck on that message forever instead of
surfacing a retryable error - there's already a "Проверить ещё раз"
button wired to reloadMemberships(), but nothing ever told the user
they needed to press it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 15:50:04 +03:00
pavlov346346-source
571f8e199d fix: compact print layout for the order blank and receipt
.sun-doc-grid (client/phone/date/address) fell back to whatever the
last matching max-width media query set, and print rendering commonly
evaluates those against the page's content width - narrow enough to
trip the existing max-width:700px breakpoint and stack every field
onto its own line instead of the intended 2-column grid. Combined with
generous screen-sized padding/font-sizes carried into print, a normal
order routinely spilled onto a second page.

Adds an explicit @media print block that puts client/phone/date/address
in a single row regardless of viewport width (grid-auto-flow:column),
sets an explicit @page size/margin instead of relying on the browser
default, and shrinks fonts/padding throughout (header, field grid,
table rows, summary, footer) for both the order blank (.sun-doc) and
the receipt (.sun-receipt, which reuses the same grid). Verified with a
standalone reproduction of the markup/CSS - a 2-line order now renders
as one compact page instead of stacking every field before ever
reaching the table.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:45:31 +03:00
pavlov346346-source
2e2f02efc3 fix: match the early login boot placeholder to the cream login redesign
performance.js paints a full-screen boot placeholder immediately on
page load (before app-runtime.js and the real auth gate exist), so it
never got updated when login-signature-v1776.js was redesigned from a
dark two-column layout with an offer-gallery/002.jpg table photo to
the light single-column "cream login" with the Caterium SVG mark.

Result: every signed-out visitor saw the old dark/photo screen flash
for a moment, then get replaced by the new light screen once the real
gate rendered - the flicker was two genuinely different, undeployed-
in-sync designs, not a caching artifact. Rebuilt the boot placeholder's
markup and inline critical CSS to mirror login-signature-v1776.js's
current design (same background, mark, type, and copy) so the first
paint already matches what replaces it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:40:33 +03:00
pavlov346346-source
195e0ba5c3 fix: reconcile version/test drift from the unreviewed production merge
The just-merged production-only commits were never run through QA
(they were pushed directly to the production branch), so several
version markers and hardcoded test strings had drifted out of sync
with each other:

- package.json was bumped to 17.8.0 but package-lock.json,
  release-manifest.json and app-runtime.js's own VERSION constant were
  never updated to match - reverted to 17.7.3 since no other release
  artifact actually changed.
- service-worker.js's cache name legitimately moved to
  v81-20260912-account-center-loader (real new modules need the cache
  bust), but release-manifest.json's pwaCache field and two
  release-check.mjs assertions still expected the old v78 name.
- edge-security-v1774.mjs and static-security.mjs asserted the old
  employee role list (with "admin") and old PWA cache name that
  production's own commits had already changed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:40:22 +03:00
pavlov346346-source
12ba761af9 Merge production (account center + login redesign) into main
production had diverged from main with 20 unreviewed direct-push
commits never merged back (account center feature, owner-only employee
roles, and a login-screen redesign - the exact "cream login" work that
replaced the old dark table-photo screen). Neither QA nor the
audit fixes on main had ever seen this code.

Conflict resolution:
- service-worker.js: kept production's newer cache-refresh mechanism
  (CRITICAL_FRESH, forceFresh, withAccountCenter, v81 cache name) and
  combined both sides' CORE asset lists (account-center-v1780.js +
  login-signature-v1776.js from production, auth-security-v1774.js +
  order-enhancements-v1775.js from main).
- deploy-timeweb.yml: kept main's version, which already independently
  verifies service-worker.js's sha256 alongside the login/logo files -
  strictly more thorough than production's version of the same check.

Also fixes fallout from production's commits never having been
QA-tested before landing: package.json was bumped to 17.8.0 with
nothing else in the codebase updated to match (reverted to 17.7.3,
matching package-lock.json/release-manifest.json/app-runtime.js, since
no other release artifact actually changed), and three tests
(static-security.mjs, edge-security-v1774.mjs, release-check.mjs) had
hardcoded strings (old PWA cache name, old employee role list) that no
longer matched the code they were checking.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:36:52 +03:00
pavlov346346-source
a281150f12 docs: record the missing sun_employee_prepare/finalize_v28 migration
sun_employee_prepare_v28 and sun_employee_finalize_v28 - the RPCs
caterium-create-employee's whole authorization model rests on - were
applied directly to the production database and were never committed,
so the actual authorization logic wasn't auditable from the repo.
Recorded verbatim via pg_get_functiondef() against the live database
on 2026-09-12 (read-only; nothing was re-applied). Confirmed both
match what the security audit inferred from the Edge Function's
error-message handling: caller identity + workspace-owner/platform-admin
check + plan/feature gates + member limits, all enforced here rather
than in the Edge Function itself.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:16:16 +03:00
pavlov346346-source
aeca9eae99 fix: lock down caterium-platform-auth-admin CORS to allowlisted origins
This Edge Function grants platform-admin power (list every user across
every workspace, ban/unban accounts, trigger password resets for any
user_id) but answered with Access-Control-Allow-Origin: '*', unlike the
sibling caterium-create-employee function which already uses an origin
allowlist. Authorization itself was never bypassable this way (the
function still requires the caller's own Bearer token and re-checks
sun_is_platform_admin() server-side), but a wildcard CORS response
removes a real layer of defense-in-depth if a platform-admin token were
ever exposed to another origin.

Applies the same allowedOrigin()/corsHeaders() pattern already proven in
caterium-create-employee, and extends edge-security-v1774.mjs (which
already asserted the wildcard was gone from create-employee, but never
checked this function) to cover both.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:09:16 +03:00
pavlov346346-source
4106452f56 fix: stop the menu-editor button-patch interval once it succeeds
setupOldButton() polled the DOM every 4s forever after the menu editor
first opened, with no way to ever stop - the interval id was not even
kept in a variable. It now returns whether the button was found, the
interval only starts when the first attempt fails, and clears itself
on the first successful attempt (also wired into the existing
disconnect() cleanup alongside the other timers).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:09:06 +03:00
pavlov346346-source
a08633f9d0 perf: stop recomputing the full client list per client on bulk push
pushAllClients() already has every client profile from its own
listClients() call, but looped through pushClient(key) -> getClient(key)
-> listClients() again for each one - N clients meant N+1 full
order-history recomputations instead of one. pushClient now accepts an
optional already-known profile so the bulk path skips the redundant
lookup; single-key callers (scheduleServerPush's debounce) are
unaffected.

compareClientSources() had the same shape of duplicate work: it called
buildClients()/serverListClients() directly and then again inside
mergeClientSources(). mergeClientSources() now accepts already-computed
local/server arrays instead of always recomputing both.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:08:57 +03:00
pavlov346346-source
60d00e9f56 fix: correct stale data-layer references in manifest and SW cache
release-manifest.json still pointed "dataLayer" at the removed
data-layer-v1771.js instead of the actually-loaded v1773.

service-worker.js's offline cache list never included
auth-security-v1774.js, order-enhancements-v1775.js or
login-signature-v1776.js despite performance.js loading all three at
runtime - PWA/offline mode could serve a stale or missing module.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:08:47 +03:00
pavlov346346-source
a98e636937 fix: gate production promotion on QA success; remove dead data-layer files
promote-production.yml triggered on push to main independently of
qa.yml, with no branch protection configured on the repo - a failing
QA run (npm audit, static security tests, e2e) never blocked
production. Switch it to the same workflow_run pattern deploy-timeweb.yml
already uses: only promote the exact commit QA just passed.

Also removes public/core/data-layer-v1770/1771/1772.js: only v1773 is
ever loaded (index.html, performance.js's loadDataLayer, service-worker
cache all reference v1773 only) - the older three were dead weight
shipped to every visitor.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:08:38 +03:00
pavlov346346-source
ce1930ef5d fix: always load account center for authenticated users 2026-09-12 10:11:09 +03:00