barsa d3b94b1ed3 feat(auth): implement permission-based access control and centralized error handling
- Introduced PermissionsGuard to enforce permission checks on routes.
- Added RequirePermissions decorator for specifying required permissions on handlers.
- Created AUTH_ERRORS constants for consistent error messages across the auth module.
- Updated CsrfService to reduce CSRF token expiry time for enhanced security.
- Refactored auth cookie handling into utility functions for better maintainability.
- Enhanced TokenBlacklistService to default to fail-closed in production environments.
- Updated various DTOs and schemas for consistency and clarity.
- Removed legacy code and types related to SIM requests.
- Improved logging and error handling in GlobalAuthGuard.
- Added middleware for public path checks and optimistic authentication.
2026-01-19 10:40:50 +09:00
..
2025-08-22 17:02:49 +09:00

Portal Structure Overview

This app follows a feature-first architecture with a consolidated lib for shared utilities.

Structure:

src/
  app/           # Next.js App Router
  components/    # Design system (ui, layout, common)
  features/      # Feature modules (auth, billing, subscriptions, ...)
  lib/           # Core utils and services (api, query, env, utils, types)
  providers/     # App-wide providers (e.g., QueryProvider)
  styles/        # Global styles

Key changes:

  • Merged former core/ and shared/ into lib/.
  • Moved components/providers/query-provider.tsx to providers/query-provider.tsx.
  • Introduced path aliases: @/lib/*, @/providers/*.

Migration tips:

  • Prefer importing from @/lib/... going forward.
  • All @/shared/* or @/core/* imports have been removed; use @/lib/*.