Public Access
fix: address adversarial review blockers
All §1 consensus blockers and §2 high-risk gaps resolved: Schema fixes: - Remove RecipeIngredient join table, use JSONB for ingredients - Add family_member table for per-voter approval tracking - Add all ENUMs for status fields (no loose VARCHAR) - Add CHECK constraints (household_size, rating 1-5, day_of_week) - Add name_lower for case-insensitive ingredient matching - Add grocery_item → ingredient FK - Fix day_of_week to ISO-8601 (1=Monday, 7=Sunday) - Remove calorie_target (nutrition is non-goal) Approval flow redesign: - Email link → confirmation page (GET), not auto-approve - Actual vote is POST from confirmation page - Per-voter tokens (single-use, 72h TTL) - Record which member voted Auth model: - VPN-only for admin endpoints - Session-based for family web UI Docker hardening: - Remove direct port exposure for backend/frontend - nginx is sole entrypoint - Add docker-compose.dev.yml for local dev Skeleton fixes: - Add missing Pantry.tsx page - Add missing index.html (Vite entrypoint) - Add package-lock.json - Fix SQLAlchemy 2 text() for raw SQL - Remove create_all from startup (use migrations) - Configure Alembic properly Docs updates: - Update Lucky URL to luckysupermarkets.com - Add WCAG 2.1 AA accessibility target - Update family profile with correct mushroom preferences - Add external dependencies list to SPEC Verification: - docker compose config: PASS - docker compose build backend: PASS - docker compose build frontend: PASS - backend import: PASS - alembic context: PASS
This commit is contained in:
+2
-2
@@ -36,7 +36,7 @@ FAMILY_EMAIL_1=you@example.com
|
||||
FAMILY_EMAIL_2=spouse@example.com
|
||||
|
||||
# Lucky California (for scraping)
|
||||
LUCKY_CA_URL=https://www.luckyncal.com
|
||||
LUCKY_CA_URL=https://luckysupermarkets.com
|
||||
|
||||
# AI Images (optional)
|
||||
AI_IMAGE_ENABLED=false
|
||||
@@ -217,7 +217,7 @@ docker-compose exec backend python -c "from app.database import SessionLocal; pr
|
||||
|
||||
```bash
|
||||
# Check Lucky California is accessible
|
||||
curl -I https://www.luckyncal.com
|
||||
curl -I https://luckysupermarkets.com
|
||||
|
||||
# Verify Playwright browser installed
|
||||
docker-compose exec backend python -c "from playwright.sync_api import sync_playwright; print('OK')"
|
||||
|
||||
Reference in New Issue
Block a user