feat: implement auth, user profiles, invoices, and escrow lifecycle (Issues #15-18) - #35
Merged
Merged
Conversation
Add AppError, NotFoundError, UnauthorizedError, ForbiddenError, BadRequestError, and ConflictError classes with HTTP status codes.
Add getPaginationParams, getPaginationMeta, and getSkipTake helpers for consistent pagination across list endpoints.
Add register, login, and refresh token schemas with input validation for auth endpoints.
Add updateProfile and avatarUpload schemas for profile management endpoints.
Add create, update, and list invoice schemas with validation for invoice management endpoints.
Add create, fund, release, and refund escrow schemas with validation for escrow management endpoints.
Add authenticate middleware to verify JWT tokens and authorize middleware for role-based access control (FREELANCER, CLIENT, ADMIN).
Generic validate middleware that parses and validates body, query, or params against Zod schemas with error formatting.
Catch AppError instances and unhandled errors, returning consistent JSON error responses with appropriate status codes.
Add service layer for escrow contract creation, funding, fund release, and refund operations on Stellar network.
Add auth endpoints with bcryptjs password hashing, JWT access/refresh token issuance, HTTP-only cookie refresh tokens, and input validation.
Add getProfile, updateProfile, deleteProfile, and uploadAvatar endpoints with profile completeness tracking.
Add create, list, get, update, delete endpoints with role-based permissions, status transition validation, and pagination/filters.
Add create, fund, release, refund endpoints with state machine validation, payment tracking, and invoice status synchronization.
Wire auth endpoints with Zod validation middleware and JWT authentication where required.
Wire user endpoints with JWT authentication and Zod validation for profile updates and avatar uploads.
Wire invoice endpoints with JWT auth and Zod validation for create and update operations.
Wire escrow endpoints for create, fund, release, refund with JWT authentication and Zod validation.
Add refreshSecret and refreshExpiresIn to config for refresh token support with 7-day expiry.
Add cookie-parser middleware, mount API routes under /api prefix, and register global error handler for consistent error responses.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements four core features for the StellFlow backend platform:
closes #15 - User Authentication
closes #16 - User Profile CRUD
closes #17 - Invoice Management
###closes Implement escrow lifecycle endpoints #18 - Escrow Lifecycle
Infrastructure