feat: wave 2 migration (P3, P5, P7 openspec changes)

Implements, verifies, and archives the three remaining Wave 2 changes from
openspec/MIGRATION-PLAN.md.

- add-wallet-settlement (P3): demo recharge, guarded withdrawal freeze and
  one-time admin review, paginated own fund entries, idempotent per-shop
  weekly/monthly settlement statements with commission rate and one-time
  payout confirmation.
- add-merchant-onboarding (P5): personal/enterprise applications with one live
  application per user, guarded review with mandatory rejection reason, and
  transactional shop + owner provisioning returning one-time credentials;
  mall onboarding/status pages and an admin review console.
- add-membership-messaging (P7): platform member levels, append-only growth
  accrual on order completion with guarded one-way leveling, order/shipment/
  refund system messages with unread/read state and soft deletion, plus the
  mall header unread badge.

Backend: migrations 0019-0023, new wallet, settlement, merchant_onboarding,
membership and messaging modules, event hooks in order/fulfillment/aftersale,
and integration suites for each. Shared contract extended and all three
frontends updated; code indexes, domain docs, backend guidelines and the
migration tracker synced.

Verification: cargo test -p vmall-api green twice consecutively; mall, admin
and shop-admin builds pass; browser smoke on every new surface; openspec
validate --all --strict green (33 passed).

The three changes share the @vmall/shared contract, the mall mock adapter and
per-app locale/nav files, so they are committed together to keep every commit
buildable.
This commit is contained in:
2026-09-25 15:25:29 +00:00
parent 772aafa3fb
commit 9904696e76
120 changed files with 14097 additions and 125 deletions
+14 -1
View File
@@ -5,6 +5,7 @@ const { t } = useI18n();
const { $api } = useNuxtApp();
const session = useSessionStore();
const router = useRouter();
const route = useRoute();
const displayName = ref("");
const email = ref("");
@@ -13,6 +14,18 @@ const confirmPassword = ref("");
const errorKey = ref("");
const submitting = ref(false);
/**
* Where to go after registering. Same-origin absolute paths only, so a crafted
* query cannot turn registration into an open redirect.
*/
const redirectTarget = computed((): string => {
const raw = route.query.redirect;
const value = Array.isArray(raw) ? raw[0] : raw;
return typeof value === "string" && value.startsWith("/") && !value.startsWith("//")
? value
: "/";
});
/** Mirrors the auth API's rule so a short password fails here, not as a 400. */
const MIN_PASSWORD_LENGTH = 8;
@@ -43,7 +56,7 @@ async function submit(): Promise<void> {
try {
const auth = await $api.register(email.value, password.value, displayName.value);
session.setAuth(auth);
await router.push("/");
await router.push(redirectTarget.value);
} catch (error) {
errorKey.value =
error instanceof ApiError && error.status === 409 ? "auth.emailTaken" : "auth.requestFailed";