Archived
Admin - /api/admin: products CRUD, the enquiry inbox, and presigned photo upload straight to the bucket so images never pass through the app. Gated by platform.security.authenticated-paths = /api/admin/**, so any signed-in Authentik user is staff — the alternative is a role model a two-person bakery would never maintain. - /api/me is deliberately PUBLIC. The SPA asks on every page load, and requiring a login would bounce every anonymous visitor to Authentik just to read the menu. - /admin screens: product list with edit and remove, an editor with drag-free photo reordering and upload, and an enquiry inbox that flags anything the relay refused. Gallery - swipe on touch devices, which the react-awesome-slider it replaced had and this did not, plus arrow keys and position dots — with swipe there is otherwise nothing to say a card holds more than one photo. Vertical drags are ignored so page scrolling still works. - @BatchSize on the photo collection: the products page loaded the whole catalogue and Hibernate issued a query per product for its images, forty-odd round trips for a page that needs two. Three things the tests caught, none of which are obvious: - Adding the storage starter broke every existing test. It activates on a default endpoint, so an S3 client is built even in tests and dies on blank keys. - MockMvc's webAppContextSetup leaves the security filter chain OUT, so the first version of the security test passed 200s and proved the opposite of what it claimed. It needs .apply(springSecurity()). - Turning on the security starter turns on CSRF — for the PUBLIC contact form too, which then 403s. The SPA now reads the XSRF-TOKEN cookie and sends X-XSRF-TOKEN, and there is a test asserting the form is rejected without it.
130 lines
5.1 KiB
XML
130 lines
5.1 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<project xmlns="http://maven.apache.org/POM/4.0.0"
|
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
|
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
|
|
<modelVersion>4.0.0</modelVersion>
|
|
|
|
<parent>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-parent</artifactId>
|
|
<version>0.1.9</version>
|
|
<relativePath/>
|
|
</parent>
|
|
|
|
<groupId>com.itsthevine</groupId>
|
|
<artifactId>itsthevine</artifactId>
|
|
<version>0.1.0</version>
|
|
<name>The Vine Coffeehouse + Bakery</name>
|
|
<description>Site for The Vine in Princeville, IL — menu, story, and contact form — on the Bennett platform.</description>
|
|
|
|
<dependencyManagement>
|
|
<dependencies>
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-bom</artifactId>
|
|
<version>0.1.9</version>
|
|
<type>pom</type>
|
|
<scope>import</scope>
|
|
</dependency>
|
|
<!-- Spring Boot 4.1 no longer manages the raw org.testcontainers:* module versions -->
|
|
<dependency>
|
|
<groupId>org.testcontainers</groupId>
|
|
<artifactId>testcontainers-bom</artifactId>
|
|
<version>1.21.4</version>
|
|
<type>pom</type>
|
|
<scope>import</scope>
|
|
</dependency>
|
|
</dependencies>
|
|
</dependencyManagement>
|
|
|
|
<!-- Platform releases live in the Gitea Maven registry (anonymous read). Declared here so Renovate
|
|
can discover new platform versions and open a bump PR. Maven still needs this repo in
|
|
settings.xml for PARENT resolution (see .gitea/ci-settings.xml). -->
|
|
<repositories>
|
|
<repository>
|
|
<id>gitea</id>
|
|
<url>https://git.thebennett.net/api/packages/austin/maven</url>
|
|
<releases><enabled>true</enabled></releases>
|
|
<snapshots><enabled>false</enabled></snapshots>
|
|
</repository>
|
|
</repositories>
|
|
|
|
<dependencies>
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-web</artifactId>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-data</artifactId>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-contact</artifactId>
|
|
</dependency>
|
|
<!-- Admin needs a login, and uploading a product photo needs the bucket. The public site
|
|
still reads photos straight from the bucket's public URLs. -->
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-security</artifactId>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-storage</artifactId>
|
|
</dependency>
|
|
|
|
<!-- test -->
|
|
<!-- Contract tests every app on the platform inherits. -->
|
|
<dependency>
|
|
<groupId>net.thebennett.platform</groupId>
|
|
<artifactId>platform-starter-test</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>org.springframework.boot</groupId>
|
|
<artifactId>spring-boot-starter-test</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
<!-- springSecurity() for MockMvc: without it the filter chain is absent and every protected
|
|
path answers 200, which would make a security test prove the opposite of what it says. -->
|
|
<dependency>
|
|
<groupId>org.springframework.security</groupId>
|
|
<artifactId>spring-security-test</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>org.springframework.boot</groupId>
|
|
<artifactId>spring-boot-testcontainers</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>org.testcontainers</groupId>
|
|
<artifactId>postgresql</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>org.testcontainers</groupId>
|
|
<artifactId>junit-jupiter</artifactId>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
</dependencies>
|
|
|
|
<build>
|
|
<plugins>
|
|
<plugin>
|
|
<groupId>org.springframework.boot</groupId>
|
|
<artifactId>spring-boot-maven-plugin</artifactId>
|
|
</plugin>
|
|
<!-- SPA build inherited from platform-parent (node install + npm build + copy dist -> jar). -->
|
|
<plugin>
|
|
<groupId>com.github.eirslett</groupId>
|
|
<artifactId>frontend-maven-plugin</artifactId>
|
|
</plugin>
|
|
<plugin>
|
|
<groupId>org.apache.maven.plugins</groupId>
|
|
<artifactId>maven-resources-plugin</artifactId>
|
|
</plugin>
|
|
</plugins>
|
|
</build>
|
|
</project>
|