Files
sass-mohfarawati/docs/DOMAIN_RULES.md
T
MohFarawati d48497b992
CI / quality (push) Waiting to run
refactor: drop toast + over-engineered extras, add inline admin feedback
Phase 1 cleanup of the personal-site revamp. Backend/architecture untouched;
changes are limited to removing unused complexity and restoring feedback.

Removals
- Toast system: delete react-hot-toast, Toaster, QueryToastBridge, lib/toast,
  the toggle/easter-egg calls, related i18n keys and the dependency.
- Contact protection: remove Turnstile + per-IP rate limiting
  (lib/contact-guard, lib/contact-protection, admin screen, form widget,
  app-config wiring, nav entry, test).
- Speculative specs: delete orders, products, downloads, project-inquiry.

Inline feedback (replaces toast, no new deps)
- Add lib/admin-feedback (withFlash/readFlash) and components/admin/admin-flash,
  rendered centrally by AdminDashboardShell.
- Emit success/error messages for media, site-settings, portfolio, smtp,
  marquee and maintenance actions; pages read them via searchParams.
- Contact form shows validation/delivery errors inline; success still
  redirects to /success.

Docs
- Fix stale paths in frontend-system-* (components/root -> components/admin,
  lib/root-navigation -> lib/admin-navigation, drop phantom src/) and remove
  contact-protection references from docs and CLAUDE.md.
- Add docs/PHASE0_DIAGNOSIS.md (diagnosis report).

Note: proxy.ts self-fetch kept intentionally; it also drives maintenance mode.
2026-07-14 21:03:51 +02:00

91 lines
1.7 KiB
Markdown

# Domain Rules
## Portfolio
### Current implementation
- A project must belong to one category
- Categories cannot be deleted while linked projects exist
- Public portfolio pages only show published projects
- Category filters only use active categories
- Project content is localized across
`ar`
,
`en`
,
`de`
- Project sections and assets are ordered by
`sortOrder`
- Project view mode is limited to:
- `GRID`
- `STORY`
- `CASE_STUDY`
## Media
### Current implementation
- Media assets are tracked separately from portfolio records
- Media usage bindings connect assets to entity fields
- Usage binding is unique by
`usageType + entityType + entityId + fieldKey`
- Media is currently used by:
- portfolio cover
- portfolio sections
- portfolio assets
- site settings
## Contact
### Current implementation
- Contact submission requires valid name, email, and message (validated with Zod)
- Successful submission sends email only
- No submission record is stored in the database
## Admin
### Current implementation
- Admin access depends on environment configuration
- Middleware can require HTTP Basic Auth before app access
- In-app admin session is cookie-based
- Repeated failed password attempts trigger temporary lockout
## Configuration
### Current implementation
- Global settings are stored in
`AppConfig`
- Site settings, SMTP settings, contact protection, marquee settings, and maintenance mode all depend on configuration keys
## Recommended Improvements
- Add explicit domain rules for future
`products`
,
`orders`
,
`downloads`
only after data models exist
- Introduce database retention and moderation rules for contact or inquiry submissions if they become persisted