Skip to content

feat: implement auth, user profiles, invoices, and escrow lifecycle (Issues #15-18) - #35

Merged
Levi-Ojukwu merged 22 commits into
mainfrom
feat/resolve-issues-15-18
Jul 10, 2026
Merged

Levi-Ojukwu merged 22 commits into
mainfrom
feat/resolve-issues-15-18

Conversation

@TheCodingChef-eth

Copy link
Copy Markdown
Contributor

Summary

Implements four core features for the StellFlow backend platform:

closes #15 - User Authentication

  • Auth controller with register, login, logout, and refresh token endpoints
  • bcryptjs password hashing, JWT access/refresh token issuance
  • HTTP-only cookie refresh tokens with 7-day expiry
  • Zod input validation for all auth endpoints

closes #16 - User Profile CRUD

  • Profile endpoints: get, update, delete with role-based access (FREELANCER, CLIENT, ADMIN)
  • Avatar upload handling via profile image URL
  • Profile completeness tracking (calculated from filled fields)

closes #17 - Invoice Management

  • Full CRUD: create, list (with pagination/filters), update, delete
  • Zod validation for invoice data
  • Role-based permissions: only freelancers create, only creators update/delete
  • Status transition validation: DRAFT → PENDING → FUNDED → IN_ESCROW → COMPLETED
  • Pagination with configurable page/limit, search by title/description
    ###closes Implement escrow lifecycle endpoints #18 - Escrow Lifecycle
  • Create, fund, release, and refund escrows with Stellar integration
  • State machine validation for escrow status transitions
  • Payment record tracking on each state change
  • Invoice status synchronization on escrow events
  • Role-based access: clients create/fund, freelancers/admin release, admin refund

Infrastructure

  • Zod validation middleware (body, query, params)
  • JWT authentication middleware with role authorization
  • Global error handler with custom error classes
  • Cookie-parser for refresh token support
  • Centralized config with refresh token settings

SweetBoy-eth and others added 22 commits July 10, 2026 08:52
Add AppError, NotFoundError, UnauthorizedError, ForbiddenError,
BadRequestError, and ConflictError classes with HTTP status codes.
Add getPaginationParams, getPaginationMeta, and getSkipTake helpers
for consistent pagination across list endpoints.
Add register, login, and refresh token schemas with input
validation for auth endpoints.
Add updateProfile and avatarUpload schemas for profile
management endpoints.
Add create, update, and list invoice schemas with validation
for invoice management endpoints.
Add create, fund, release, and refund escrow schemas with
validation for escrow management endpoints.
Add authenticate middleware to verify JWT tokens and authorize
middleware for role-based access control (FREELANCER, CLIENT, ADMIN).
Generic validate middleware that parses and validates body,
query, or params against Zod schemas with error formatting.
Catch AppError instances and unhandled errors, returning
consistent JSON error responses with appropriate status codes.
Add service layer for escrow contract creation, funding,
fund release, and refund operations on Stellar network.
Add auth endpoints with bcryptjs password hashing, JWT access/refresh
token issuance, HTTP-only cookie refresh tokens, and input validation.
Add getProfile, updateProfile, deleteProfile, and uploadAvatar
endpoints with profile completeness tracking.
Add create, list, get, update, delete endpoints with role-based
permissions, status transition validation, and pagination/filters.
Add create, fund, release, refund endpoints with state machine
validation, payment tracking, and invoice status synchronization.
Wire auth endpoints with Zod validation middleware and JWT
authentication where required.
Wire user endpoints with JWT authentication and Zod validation
for profile updates and avatar uploads.
Wire invoice endpoints with JWT auth and Zod validation for
create and update operations.
Wire escrow endpoints for create, fund, release, refund with
JWT authentication and Zod validation.
Add refreshSecret and refreshExpiresIn to config for
refresh token support with 7-day expiry.
Add cookie-parser middleware, mount API routes under /api prefix,
and register global error handler for consistent error responses.
@Levi-Ojukwu
Levi-Ojukwu merged commit 65b2d41 into main Jul 10, 2026
1 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants