Add stage 2: Vue/TypeScript PWA shell with auth-gated routing

Backend: new migration adds users.email_verified_at (null = unverified);
registration leaves it null, and the register/login/me payloads now expose
email_verified and email_verified_at.

Frontend (web/): Vite + Vue 3 + TypeScript PWA (vite-plugin-pwa). Pinia auth
store keeps the token in localStorage and validates it via GET /api/me on
load. vue-router guards redirect unauthenticated visitors to /login,
preserving the intended path; /register creates an account and signs in
immediately (with the email unverified). Placeholder home page, minimal
styling, generated icons. Dev server proxies /api to the API.

docker-compose.yml gains an optional "web" service (profile: frontend) so
`docker compose --profile frontend up -d` runs the dev server alongside the
API; `docker compose up -d` still starts the API alone.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-03 18:12:31 +01:00
co-authored by Claude Sonnet 5
parent e91fc89e23
commit 5e3b8dbd7e
35 changed files with 7454 additions and 10 deletions
+20
View File
@@ -19,5 +19,25 @@ services:
- storage:/var/www/storage
restart: unless-stopped
# Optional Vite dev server. Start it with: docker compose --profile frontend up -d
# Without the profile, `docker compose up -d` runs the API alone.
web:
build: ./web
image: php-todo-web
profiles: ["frontend"]
ports:
- "5173:5173"
environment:
# /api is proxied to the API container on the compose network.
VITE_PROXY_TARGET: "http://app:80"
volumes:
- ./web:/app
# Keep the image's platform-specific node_modules; don't let the host's shadow them.
- web_node_modules:/app/node_modules
depends_on:
- app
restart: unless-stopped
volumes:
storage:
web_node_modules: