Add stage 2: Vue/TypeScript PWA shell with auth-gated routing

Backend: new migration adds users.email_verified_at (null = unverified);
registration leaves it null, and the register/login/me payloads now expose
email_verified and email_verified_at.

Frontend (web/): Vite + Vue 3 + TypeScript PWA (vite-plugin-pwa). Pinia auth
store keeps the token in localStorage and validates it via GET /api/me on
load. vue-router guards redirect unauthenticated visitors to /login,
preserving the intended path; /register creates an account and signs in
immediately (with the email unverified). Placeholder home page, minimal
styling, generated icons. Dev server proxies /api to the API.

docker-compose.yml gains an optional "web" service (profile: frontend) so
`docker compose --profile frontend up -d` runs the dev server alongside the
API; `docker compose up -d` still starts the API alone.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-03 18:12:31 +01:00
co-authored by Claude Sonnet 5
parent e91fc89e23
commit 5e3b8dbd7e
35 changed files with 7454 additions and 10 deletions
+7 -3
View File
@@ -64,7 +64,7 @@ final class AuthController extends Controller
*/
public function me(Request $request, Response $response): Response
{
/** @var array{id: int, email: string, created_at: string} $user */
/** @var array{id: int, email: string, email_verified_at: string|null, created_at: string} $user */
$user = $request->getAttribute('user');
return $this->json($response, ['user' => $this->presentUser($user)]);
@@ -110,7 +110,7 @@ final class AuthController extends Controller
/**
* Build the standard authentication payload returned by register and login.
*
* @param array{id: int, email: string, created_at: string} $user
* @param array{id: int, email: string, email_verified_at: string|null, created_at: string} $user
* @return array<string, mixed>
*/
private function session(array $user): array
@@ -125,14 +125,18 @@ final class AuthController extends Controller
}
/**
* @param array{id: int, email: string, created_at?: string} $user
* @param array{id: int, email: string, email_verified_at?: string|null, created_at?: string} $user
* @return array<string, mixed>
*/
private function presentUser(array $user): array
{
$verifiedAt = $user['email_verified_at'] ?? null;
return [
'id' => (int) $user['id'],
'email' => $user['email'],
'email_verified' => $verifiedAt !== null,
'email_verified_at' => $verifiedAt,
'created_at' => $user['created_at'] ?? null,
];
}