admin and Claude Sonnet 4.6
03ced28ead
feat: WeeklyRun model + FamilyProfile.pending_approval_policy
...
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com >
2026-05-07 06:21:40 -07:00
admin
ea34b9384d
feat: migration 0008 — weekly_run table + pending_approval_policy
2026-05-07 06:18:30 -07:00
admin and Claude Opus 4.7
95b8e0c1b5
feat: AM-3..AM-6 strip SWIFTLY_BEARER_TOKEN env var, delete superseded script, refresh docs
...
AM-3: SWIFTLY_BEARER_TOKEN removed from .env.example, .env.test (local),
docker-compose.yml service env, and Settings (backend/app/config.py).
The scraper docstring is updated to reflect the auto-mint path.
AM-4: scripts/refresh_swiftly_token.py (commit ccfb38a , seleniumbase
click-through capture) deleted; superseded by swiftly_auth.py.
AM-5: docs refreshed.
- spec status header → "Implemented 2026-05-06" with live-verification
evidence
- HANDOFF.md TL;DR + caveats #2/#3 collapsed; replaced with the
auto-mint failure-modes caveat; "Suggested next move" rewritten
pointing to Phase 5 orchestration; file-map and last-updated touched
- ORIENTATION.md env-var section updated (no bearer var) + footer
AM-6 verification gate (run 2026-05-06):
- pytest -q tests/ → 92/92 green (88 prior + 4 new swiftly_auth)
- POST /api/admin/scrape → status=success, items_scraped=10928 in 44s
- grocery_item rows: 9980 (after dedup-by external_id)
- ingredient_grocery_match rows: 29779 (matcher post-hook populated)
- Container env confirmed clean of SWIFTLY_BEARER_TOKEN
The system now scrapes, matches, and generates plans without any
operator-managed credential. Live JWT lifecycle: Firebase REST anon
signUp → cache for ~55min → re-mint as needed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-06 15:47:15 -07:00
admin and Claude Opus 4.7
dfd79a9d08
feat: AM-2 wire swiftly_auth.get_token() into LuckyCaliforniaScraper
...
fetch_category() now calls swiftly_auth.get_token() to mint a fresh
Firebase JWT on demand when no explicit bearer_token override is
pinned by tests. The cache short-circuit means the per-call mint
overhead is ~zero in the steady state.
- Removed the empty-token short-circuit; auto-mint makes it moot
- Updated _AUTH_ERROR_MESSAGE: 401-after-mint now points at the spec
(Lucky tightening anon-auth) rather than asking for manual capture
- Replaced test_swiftly_auth_error_when_token_missing with a positive
test that verifies fetch_category mints when bearer_token is None
- bearer_token constructor arg preserved for the 401-path test
Full suite: 92/92 green. Live verification via
scripts/spike_swiftly_ingest.py --confirm-live deferred to next step
per HANDOFF AM-2 halt boundary.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-06 15:27:37 -07:00
admin and Claude Opus 4.7
5e0a49e4ae
feat: AM-1 swiftly_auth module — Firebase REST anon-signUp + process cache
...
Replaces the static SWIFTLY_BEARER_TOKEN env-var lookup with a JIT
mint via the Firebase Identity Toolkit signUp endpoint, gated by the
firebaseApiKey published in luckysupermarkets.com/config.json.
- get_token(): returns cached JWT if exp > now+300s, else mints
- mint_anonymous_token(): fetches API key, posts signUp with
Origin/Referer headers, validates iss + exp on the returned JWT
- SwiftlyAuthMintError surfaces verbatim to ScrapeLog.error_message
- Process-local cache only; threading.Lock around mutate
Tests: 4 unit tests covering fresh mint, cache hit, near-expiry
re-mint, and Firebase non-200. Full suite: 92/92 green.
Spec: docs/specs/2026-05-06-swiftly-token-auto-mint.md
Wiring into lucky_ca_scraper deferred to AM-2.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-06 15:19:30 -07:00
admin
75e4bdb7a6
feat: POST /api/admin/meal-plans/generate + regenerate + get endpoints
2026-05-06 09:15:16 -07:00
admin
3f92e1f641
feat: planner orchestrator - load, filter, score, select, persist
2026-05-06 09:11:53 -07:00
admin
63e292a995
feat: planner top-K set enumeration with protein/cuisine diversity penalty
2026-05-06 06:48:26 -07:00
admin
77813cc7d3
feat: planner per-recipe scoring with 5 weighted signals
2026-05-06 06:44:58 -07:00
admin
95396137c6
feat: planner hard-constraint filter for the 6 spec constraints
2026-05-06 06:42:49 -07:00
admin
bf0a327561
feat: planner cost+savings estimator against ingredient_grocery_match
2026-05-06 06:40:33 -07:00
admin
c86321908c
feat: planner config (weights, thresholds, K) and shared types
2026-05-06 06:38:26 -07:00
admin
bd0e34d7e1
docs: thin phase 4 complete; refresh ORIENTATION + HANDOFF
2026-05-06 06:36:36 -07:00
admin
07ddec792c
feat: seed 30 starter recipes spanning chicken/beef/pork/fish/vegetarian
2026-05-06 06:33:55 -07:00
admin
ed3255adb6
feat: migration 0007 - seed canonical ingredients with aliases (recipes follow in P4-14)
2026-05-06 06:29:33 -07:00
admin
1f7b9bac23
feat: never-suggest CRUD endpoints (ingredient and recipe blocklist)
2026-05-06 06:26:16 -07:00
admin
3d5f0c2668
feat: manual match pin/unpin endpoints
2026-05-06 06:24:17 -07:00
admin
db4b01337e
feat: run matcher after successful scrape; failures don't flip scrape status
2026-05-06 06:21:54 -07:00
admin
6dfb84310f
feat: rapidfuzz-based ingredient<->grocery matcher with manual-pin preservation
2026-05-06 06:18:18 -07:00
admin
489ee03574
feat: POST /api/admin/recipes/resolve-ingredient with rapidfuzz top-3
2026-05-06 06:16:29 -07:00
admin and Claude Opus 4.7
f16a2f8710
feat: recipe CRUD endpoints with canonical ingredient validation
...
POST/PATCH validate every ingredient_id against the ingredient table
and return 422 with the missing list when refs don't resolve. Replaces
the prior recipes.py stub. Public read routes + admin write routes.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-06 06:14:37 -07:00
admin
b1ea011d49
feat: ingredient CRUD endpoints with admin gating
2026-05-05 20:54:31 -07:00
admin
be7f698779
feat: add RecipeCreate/Update/Read schemas with canonical ingredient refs
2026-05-05 20:50:07 -07:00
admin
c8382b37e7
feat: add IngredientCreate/Update/Read and IngredientGroceryMatchRead schemas
2026-05-05 20:48:49 -07:00
admin
8ac27d843d
feat: add IngredientGroceryMatch model and Ingredient.aliases / Recipe.calories_per_serving
2026-05-05 20:47:31 -07:00
admin
a2e3ba6190
feat: migration 0006 - ingredient.aliases, recipe.calories_per_serving, ingredient_grocery_match
2026-05-05 20:45:54 -07:00
admin
2fe609ea9f
chore: add rapidfuzz==3.6.1 for ingredient matching
2026-05-05 20:42:11 -07:00
admin and Claude Opus 4.7
8e89f793d5
feat: phase r1+r2 recovery + r3-0 swiftly api ingestion
...
R1 stabilization: pytest harness with transactional db fixture, smoke
+ alembic + auth + scrape + approval + swiftly tests, github actions
ci yaml. Bearer-token admin auth + signed-cookie session for family
ui mutations. Async POST /api/admin/scrape (BackgroundTasks, returns
202). Path canonicalization (no /list, /planned suffixes). DATABASE_URL
fail-fast on empty.
R2 deferred-risk spikes: live lucky california fetch (R2-A), full
email+per-voter approval click round trip with single-use enforcement
(R2-B, console email backend, sendgrid stub).
R3-0 phase 3 redesign: replaced playwright html scraper with requests
based swiftly json api client. 17 categories, ~10k products per scrape,
upsert by (source, external_id). 401 surfaces actionable token-refresh
message via ScrapeLog.error_message.
Pre-existing defects fixed: shopping_list.py syntax error blocking app
import, MealPlan.votes orphan relationship, JSONB(astext=True) invalid
kwarg, missing requests dep, calorie_target schema drift, every SQLEnum
needed values_callable, 0001 had empty downgrade(), seed had duplicate
ingredient rows.
Migrations added: 0003 grocery_item.description, 0004 family_profile.
calorie_target, 0005 grocery_item.external_id + source + composite index.
Verified: 31/31 pytest green, alembic upgrade->downgrade->upgrade clean,
frontend npm run build clean, live scrape 9,960 grocery_item rows in 36s.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-05 14:08:19 -07:00
admin
933a0cc9db
feat: implement Lucky California scraper with Playwright + BeautifulSoup
...
- Add BaseScraper with rate limiting, retries, session management
- Add LuckyCaliforniaScraper with Playwright for dynamic content
- Add ScraperService to save scraped items to grocery_item table
- Connect /api/admin/scrape to ScraperService
- Update ORIENTATION.md phase table
2026-05-04 20:50:27 -07:00
admin
c735d21661
feat: implement Phase 2 - Alembic migrations, Pydantic schemas, and real API endpoints
...
- Add initial Alembic migration with full PostgreSQL schema (enums, tables, indexes, constraints)
- Add seed data migration with basic ingredients (70+) and family profile
- Add Pydantic schemas for all models (FamilyProfile, Recipe, MealPlan, etc.)
- Implement /api/profile endpoints (CRUD, family member management)
- Implement /api/recipes endpoints (CRUD, ingredients, filtering)
- Implement /api/meals endpoints (meal plans, voting, approval tokens)
- Implement /api/pantry endpoints (CRUD for home pantry)
- Implement /api/shopping-list endpoints (aggregation, print-ready HTML)
- Implement /api/admin endpoints (scrape trigger, logs, stats)
- Update ORIENTATION.md with Phase 2 progress
2026-05-04 20:21:20 -07:00
admin
a0b16f7418
fix: address adversarial review blockers
...
All §1 consensus blockers and §2 high-risk gaps resolved:
Schema fixes:
- Remove RecipeIngredient join table, use JSONB for ingredients
- Add family_member table for per-voter approval tracking
- Add all ENUMs for status fields (no loose VARCHAR)
- Add CHECK constraints (household_size, rating 1-5, day_of_week)
- Add name_lower for case-insensitive ingredient matching
- Add grocery_item → ingredient FK
- Fix day_of_week to ISO-8601 (1=Monday, 7=Sunday)
- Remove calorie_target (nutrition is non-goal)
Approval flow redesign:
- Email link → confirmation page (GET), not auto-approve
- Actual vote is POST from confirmation page
- Per-voter tokens (single-use, 72h TTL)
- Record which member voted
Auth model:
- VPN-only for admin endpoints
- Session-based for family web UI
Docker hardening:
- Remove direct port exposure for backend/frontend
- nginx is sole entrypoint
- Add docker-compose.dev.yml for local dev
Skeleton fixes:
- Add missing Pantry.tsx page
- Add missing index.html (Vite entrypoint)
- Add package-lock.json
- Fix SQLAlchemy 2 text() for raw SQL
- Remove create_all from startup (use migrations)
- Configure Alembic properly
Docs updates:
- Update Lucky URL to luckysupermarkets.com
- Add WCAG 2.1 AA accessibility target
- Update family profile with correct mushroom preferences
- Add external dependencies list to SPEC
Verification:
- docker compose config: PASS
- docker compose build backend: PASS
- docker compose build frontend: PASS
- backend import: PASS
- alembic context: PASS
2026-05-04 20:11:05 -07:00
admin
1328ec359d
feat: add Phase 1 infrastructure skeleton
...
Backend (FastAPI):
- docker-compose with all 4 services
- FastAPI app with health endpoints
- SQLAlchemy models for all tables
- Placeholder API endpoints for all routes
- Config and database modules
- requirements.txt with all dependencies
Frontend (React):
- package.json with React, Tailwind, React Query, React Router
- Vite config with API proxy
- Tailwind and TypeScript configs
- Basic App with routing skeleton
- Placeholder pages (Dashboard, MealDetail, Pantry)
Infrastructure:
- nginx config for reverse proxy
- Dockerfile for backend and frontend
2026-05-04 19:29:35 -07:00