feat: backend MVP (auth/rbac, catalog, orders, fulfillment, invoices) + specs + scaffolds

This commit is contained in:
Chengdong Zhang
2026-09-17 12:43:22 +08:00
commit dc9fd31c5e
96 changed files with 17550 additions and 0 deletions
@@ -0,0 +1,21 @@
# Spec delta: rbac
## ADDED Requirements
### Requirement: Role model
The system SHALL support roles `platform_admin`, `shop_owner`, `shop_staff`, `customer`. Shop roles MUST carry a `shop_id` scope.
#### Scenario: seeded platform admin
- **WHEN** migrations run on a fresh database
- **THEN** a `platform_admin` account exists and can log in
### Requirement: Role enforcement
Protected routes SHALL declare required roles; the API MUST reject requests with insufficient role using 403.
#### Scenario: customer hits admin route
- **WHEN** a `customer` token calls an `/api/admin/*` route
- **THEN** the API returns 403 with code `FORBIDDEN`
#### Scenario: shop scope isolation
- **WHEN** a `shop_owner` of shop A accesses `/api/shop/*` resources of shop B
- **THEN** the API returns 403 or 404, never the data