Wave 2 of replacing the fixed-data mock adapter: the auth domain joins the live
list, so credentials, roles and tokens belong to the real user.
- session: validate a restored token through /auth/me instead of trusting
localStorage, clearing it on 401/403 but keeping it when the API is merely
unreachable; the route guard now uses the validated session
- login: report a 401 as invalid credentials rather than a generic failure, and
drop the 6-character client rule so the API owns the password policy
- register: raise the rule to the API's 8 characters, remove the
verification-code field (its button only counted down and the value was never
sent), and report a duplicate email (409) distinctly
- TopBar and the user profile render their session-dependent branch client-only:
validating the session before hydration made those localStorage-backed
branches report hydration mismatches the previous code did not
Verified against the running backend: wrong password rejected, real JWT issued,
/user reachable, a short password refused with no network call, duplicate email
reported, a tampered token cleared and bounced to sign-in, a stale token kept
when the API is down, and the fixed-data rollback still signs in with the
backend stopped.
Also re-cuts docs/TBD-migrate-wave.md: auth is done, and cart, orders,
shipments and invoices must move together, because the mock adapter keeps their
state in one shared object and a partial flip fails at checkout.
OpenSpec change: openspec/changes/replace-mock-api-wave-2
Wave 1 of replacing the fixed-data mock adapter. The mall now selects its API
adapter per domain, with catalog and currency served live while auth, cart,
orders, shipments and invoices stay on fixed data.
Backend:
- seed the 6 x 2 x 2 category tree as reference data (migration 0005). The API
exposes no category write route, so this cannot come from the seed script
- filter public product listing by the category subtree with a recursive CTE,
matching the mock's existing behaviour instead of exact-match
- add sort=price with order=asc|desc, validated by hand so an unsupported value
returns the project's ApiError 400 shape rather than axum's own rejection
Mall:
- replace the all-or-nothing mockApi boolean with a liveDomains list composed
through a typed per-domain pick map
- source home floors, the category menu, search and product detail from the
catalog API; banners, promos, quick links, store card and comment/coupon
content stay local display-only content
- drop the brand facet and the sales/comments sorts: no backend model backs them
- fix salesOf/commentCountOf, which parsed digits out of the product id and so
rendered "NaN sold" for live UUID ids; they now hash the id
Seed: 24 products across 4 shops, idempotent on re-run.
Note: the mall defaults to a live catalog, so pnpm dev:mall now expects the API
to be running; set NUXT_PUBLIC_LIVE_DOMAINS to an empty array for all-mock work.
OpenSpec change: openspec/changes/replace-mock-api-wave-1
Four hero compositions (A: pinned left rail / B: right user rail /
C: short banner / D: stacked banners) for the 1200x450 home hero area,
with A marked as the confirmed direction. Referenced by
openspec/changes/pin-home-category-menu/proposal.md.