## Error handling
Requested: a centralized error-handling service on the API, custom error
codes shared across apps, and a client-side error service for i18n labels.
- packages/shared/src/errors/error-codes.ts — ErrorCode enum + ApiErrorResponse
contract. Single source of truth: neither side hardcodes a raw error string
the other has to guess at.
- apps/api: HttpError now carries an ErrorCode (not just a message).
ErrorHandlerService (new) centralizes every "how do we turn a thrown error
into an HTTP response" decision — app.ts's error middleware is now a thin
adapter calling into it. API messages reverted to English/dev-facing (they
were French from an earlier pass) since user-facing text is now generated
client-side from the code.
- apps/web: ApiClient (class, singleton instance) throws ApiError carrying
the code. ErrorMessageService (new) maps every ErrorCode to a localized
label, structured with a Locale type from the start (only "fr" exists, but
adding a language later is "add a locale to the map", not "hunt down every
hardcoded string"). LoginPage/SignupPage now display
errorMessageService.getLabel(err.code), never err.message directly.
- Tests strengthened to assert on `code`, not just HTTP status (Mocha +
Cucumber, new "the response error code should be" step). Cypress mocks
updated to the new {code, message} response shape.
## Code quality pass
Per explicit feedback: heavy JSDoc on every interface/type/class/function/
method/member touched in this PR, explicit public/private visibility on
every class member (ApiClient, ErrorMessageService, ErrorHandlerService,
HttpError), no HTML/logic mixing (styling extracted out of components
entirely, never inline).
ApiClient/ErrorMessageService were initially written as static-only classes;
switched to instance-based singletons (matching ErrorHandlerService's
existing pattern) after Biome's noStaticOnlyClass rule flagged the
static-only shape as an anti-pattern — same "class with visibility
modifiers" outcome, without fighting the linter.
## SCSS + theming
- apps/web/src/styles/_theme.scss — design tokens as CSS custom properties
on :root (colors, spacing, typography), not plain Sass variables — makes
them available at runtime, not just compile time, so a future theme
switch (e.g. dark mode) is "redefine these variables" rather than
rebuilding stylesheets.
- apps/web/src/styles/global.scss replaces the old single index.css:
reset + theme import only, loaded once from main.tsx.
- Per-page/component styles colocated (HomePage.tsx + HomePage.scss);
styles shared by multiple pages within one feature live in that feature's
folder (features/auth/auth-form.scss, used by both Login/SignupPage) —
not duplicated per page, not dumped in the global stylesheet either.
- Component-level .scss files intentionally don't `@use` the theme
partial: they only consume CSS custom properties (global at runtime via
global.scss), not Sass-level symbols, so importing it would do nothing —
documented inline rather than left as a silently-redundant import.
- vite.config.ts opts into Sass's modern compiler API to silence a
legacy-js-api deprecation warning on every build.
## specs/ updates
- New specs/error-handling.md — the ErrorCode/ApiErrorResponse contract,
both services, with a flow diagram.
- New specs/frontend-architecture.md — apps/web folder structure, routing/
auth-guard flow, SCSS/theming conventions.
- specs/batch-cooking-architecture.md links to both (original doc content
otherwise untouched — it's the user's own hand-authored source doc).
## Verification
Full lint/mocha/cucumber/build green. Manually re-verified the whole auth
flow in a real browser against native dev servers (not just the automated
suites): signup, the EMAIL_ALREADY_IN_USE → "Cet email est déjà utilisé"
translation end-to-end (confirmed the raw API response carries the English
dev message + code, and the UI shows the French label), wrong-password
INVALID_CREDENTIALS → its label, and confirmed the theme tokens actually
apply (computed button background-color matches --color-primary, card
max-width matches the token value) rather than trusting the build succeeding.
112 lines
3.7 KiB
TypeScript
112 lines
3.7 KiB
TypeScript
import { ErrorCode } from "@batch-cooking/shared";
|
|
import { expect } from "chai";
|
|
import request from "supertest";
|
|
import { createApp } from "../src/app.js";
|
|
import { prisma } from "../src/db/prisma.js";
|
|
import { resetDatabase } from "../test-support/reset-db.js";
|
|
|
|
/** Valid signup payload reused across tests. */
|
|
const validSignup = {
|
|
firstName: "Nicolas",
|
|
lastName: "Lefevre",
|
|
email: "nicolas@example.com",
|
|
password: "correct-horse-battery-staple",
|
|
};
|
|
|
|
describe("Auth", () => {
|
|
const app = createApp();
|
|
|
|
beforeEach(async () => {
|
|
await resetDatabase();
|
|
});
|
|
|
|
after(async () => {
|
|
await prisma.$disconnect();
|
|
});
|
|
|
|
describe("POST /auth/signup", () => {
|
|
it("creates a profile and its house, and sets a session cookie", async () => {
|
|
const res = await request(app).post("/auth/signup").send(validSignup);
|
|
|
|
expect(res.status).to.equal(201);
|
|
expect(res.body).to.include({
|
|
firstName: "Nicolas",
|
|
lastName: "Lefevre",
|
|
email: "nicolas@example.com",
|
|
});
|
|
expect(res.body).to.not.have.property("passwordHash");
|
|
expect(res.body.houseId).to.be.a("number");
|
|
expect(res.headers["set-cookie"]?.[0]).to.include("session=");
|
|
});
|
|
|
|
it("rejects a duplicate email with 409 EMAIL_ALREADY_IN_USE", async () => {
|
|
await request(app).post("/auth/signup").send(validSignup);
|
|
const res = await request(app).post("/auth/signup").send(validSignup);
|
|
|
|
expect(res.status).to.equal(409);
|
|
expect(res.body.code).to.equal(ErrorCode.EMAIL_ALREADY_IN_USE);
|
|
});
|
|
|
|
it("rejects an invalid payload with 400 VALIDATION_ERROR", async () => {
|
|
const res = await request(app)
|
|
.post("/auth/signup")
|
|
.send({ firstName: "X", lastName: "Y", email: "not-an-email", password: "short" });
|
|
|
|
expect(res.status).to.equal(400);
|
|
expect(res.body.code).to.equal(ErrorCode.VALIDATION_ERROR);
|
|
expect(res.body.details).to.have.keys(["email", "password"]);
|
|
});
|
|
});
|
|
|
|
describe("POST /auth/login", () => {
|
|
beforeEach(async () => {
|
|
await request(app).post("/auth/signup").send(validSignup);
|
|
});
|
|
|
|
it("logs in with correct credentials", async () => {
|
|
const res = await request(app)
|
|
.post("/auth/login")
|
|
.send({ email: validSignup.email, password: validSignup.password });
|
|
|
|
expect(res.status).to.equal(200);
|
|
expect(res.body.email).to.equal(validSignup.email);
|
|
});
|
|
|
|
it("rejects a wrong password with 401 INVALID_CREDENTIALS", async () => {
|
|
const res = await request(app)
|
|
.post("/auth/login")
|
|
.send({ email: validSignup.email, password: "wrong-password" });
|
|
|
|
expect(res.status).to.equal(401);
|
|
expect(res.body.code).to.equal(ErrorCode.INVALID_CREDENTIALS);
|
|
});
|
|
|
|
it("rejects an unknown email with 401 INVALID_CREDENTIALS", async () => {
|
|
const res = await request(app)
|
|
.post("/auth/login")
|
|
.send({ email: "nobody@example.com", password: validSignup.password });
|
|
|
|
expect(res.status).to.equal(401);
|
|
expect(res.body.code).to.equal(ErrorCode.INVALID_CREDENTIALS);
|
|
});
|
|
});
|
|
|
|
describe("GET /auth/me", () => {
|
|
it("rejects requests without a session cookie with 401 NOT_AUTHENTICATED", async () => {
|
|
const res = await request(app).get("/auth/me");
|
|
|
|
expect(res.status).to.equal(401);
|
|
expect(res.body.code).to.equal(ErrorCode.NOT_AUTHENTICATED);
|
|
});
|
|
|
|
it("returns the current profile when authenticated", async () => {
|
|
const agent = request.agent(app);
|
|
await agent.post("/auth/signup").send(validSignup);
|
|
|
|
const res = await agent.get("/auth/me");
|
|
|
|
expect(res.status).to.equal(200);
|
|
expect(res.body.email).to.equal(validSignup.email);
|
|
});
|
|
});
|
|
});
|