Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
936533a
chore(kickoff): add context pack (CLAUDE.md, GIT.md, diagrams, ignores)
claude Jun 11, 2026
7679a80
feat(ceo/mancom): CEO module UI mockup set (mockups.html)
claude Jun 11, 2026
5601cca
chore(repo): monorepo scaffold — workspaces, strict tsconfig, env exa…
claude Jun 11, 2026
ff249ea
feat(packages): @ubi/types shared contracts + @ubi/storage StoragePro…
claude Jun 11, 2026
42971aa
feat(api): NestJS bootstrap — strict config, RBAC guard + claims, ent…
claude Jun 11, 2026
706c573
feat(pillar-auth): standalone auth — JWT login, claims RBAC, field-ro…
claude Jun 11, 2026
6e6c042
feat(pillar-doc-tracking): document registry — QR codes, scan transmi…
claude Jun 11, 2026
1197845
feat(pillar-ai-layer): read-model registry, grounded ask endpoint, of…
claude Jun 11, 2026
d7f536e
feat(api/shared): RBAC-gated files via StorageProvider + approvals/ti…
claude Jun 11, 2026
427361a
feat(api/modules): engineering core + procurement DR + operations tow…
claude Jun 11, 2026
295df16
feat(web): React+Vite PWA shell — brand light UI, role-aware sidebar,…
claude Jun 11, 2026
d0ad94a
feat(web/pages): login, ManCom, AI insights, Ask AI, doc tracking, ap…
claude Jun 11, 2026
0796e41
docs(readme): status + run-locally instructions with demo logins
claude Jun 11, 2026
4f76ee7
feat(web/design): 'drawing comes alive' design system — drafting grid…
claude Jun 11, 2026
2225f9b
feat(web/design): apply design language across pages — SheetBar heade…
claude Jun 11, 2026
2b0819c
docs(claude-md): add §0 current-build-state — handoff for new Claude …
claude Jun 12, 2026
33a70ac
feat(api/security): gate demo seed behind SEED_DEMO, require JWT_SECR…
claude Jun 12, 2026
23e9228
feat(it/helpdesk): public no-signin ticket intake — Cloudflare Turnst…
claude Jun 12, 2026
a1d05ee
feat(web/helpdesk): public drafting-sheet ticket form + Turnstile wid…
claude Jun 12, 2026
b6a30dc
feat(web/ux): typewriter AI responses with thinking state + draft-hat…
claude Jun 12, 2026
a941264
feat(dept): standard department dashboard API + dept-head accounts
claude Jun 14, 2026
9146d91
feat(web/dept): standard department dashboard — KPI band, field monit…
claude Jun 14, 2026
35209bc
docs(audit): feature audit vs spec (IT/Property/Records) + dept-dashb…
claude Jun 14, 2026
c7328c4
feat(property): real QR EAM — asset + movement + attestation, scan-to…
claude Jun 14, 2026
3b31ed9
feat(records): vehicle-doc registry (mirrors to expiry engine) + acce…
claude Jun 14, 2026
d6900a0
feat(it): SNMP device inventory, quarterly PMS auto-built from Proper…
claude Jun 14, 2026
90ab7e6
chore(api): wire property/records/it modules, remove superseded stubs…
claude Jun 14, 2026
5b16fee
feat(web/auth): clickable demo-login chips (autofill) + department-he…
claude Jun 14, 2026
4a8f4e8
feat(web): Property/Records/IT tool pages + dept-dashboard tool links
claude Jun 14, 2026
8217c3f
docs(audit): record build-all results (property/records/it now real, …
claude Jun 14, 2026
48c0b13
feat(property): asset category + category helpers for PMS selection
claude Jun 15, 2026
1a0c99b
feat(it/pms): category-based quarterly generation, tech + completed d…
claude Jun 15, 2026
f4953a8
feat(records): Records owns document-registry monitoring (records.doc…
claude Jun 15, 2026
4dd520b
feat(web/it): PMS scheduler — Q1-Q4 tabs, category-chip generation, l…
claude Jun 15, 2026
01fb51a
feat(types): materials catalog + quantity contracts (weekly entry, ro…
claude Jun 15, 2026
3b241aa
feat(engineering/quantity): weekly accomplishment entry that auto-rol…
claude Jun 15, 2026
ad90fe0
feat(ceo): incorporate real Quantity accomplishment into ManCom (over…
claude Jun 15, 2026
49532a3
feat(web/quantity): simple weekly entry (one number/project/week), pr…
claude Jun 15, 2026
cd8ea40
feat(equipment): weekly machinery/activity schedule + push to Omega (…
claude Jun 15, 2026
ed834da
feat(procurement): materials-schedule intake — approved (PE→PM→VPO) s…
claude Jun 15, 2026
db5bde8
chore(api): wire EquipmentModule + seed a sample equipment schedule
claude Jun 15, 2026
aeb2543
feat(web): Equipment schedule page (data entry → push to Omega) + Pro…
claude Jun 15, 2026
921452f
feat(web/docs): register-new-transmittal form (was lookup/transmit/re…
claude Jun 15, 2026
515d7ed
feat(web/nav): surface Ask AI to all signed-in users (answers stay RB…
claude Jun 15, 2026
30a9a58
feat(web): floating icon-only Ask-AI assistant docked bottom-right on…
claude Jun 15, 2026
5929652
ops(cd): Claude-driven deployment kit — DEPLOY.md playbook (deploy+fi…
claude Jun 15, 2026
cfadafa
fix(seed): always run idempotent module seeds — engineering/quantity/…
claude Jun 15, 2026
f6ad6e6
fix(deploy-feedback): hide demo logins in prod builds, correct restar…
claude Jun 15, 2026
439ef93
ops(cd): INSTALL-AUTOMATION.md — stand up webhook (instant) + timer (…
claude Jun 15, 2026
5797fc1
chore(repo): relax node engines to >=20.19 (matches box; clears EBADE…
claude Jun 15, 2026
7cdcb91
fix(ops/cd): loop guard in repo — skip deploy when tip is our own ops…
claude Jun 15, 2026
039323d
feat(web/login): show demo tap-to-login chips by default for POC (fli…
claude Jun 15, 2026
1943688
chore(web): block search engines for POC — robots.txt + noindex meta …
claude Jun 15, 2026
f085850
chore(seed): CEO display name -> Car Go; ensureUser now syncs demo di…
claude Jun 15, 2026
985e8a4
chore(auth): rotate all account passwords (managed bcrypt hashes), hi…
claude Jun 15, 2026
2694154
fix(web/login): hard-disable demo chips in prod (repo-authoritative, …
claude Jun 15, 2026
e0b0bf9
chore(auth): set all account passwords to a shared pilot password (Ul…
claude Jun 15, 2026
a906575
chore(claude): default model to opus for this project (was opening on…
claude Jun 15, 2026
3eda0e1
feat(fleet): Cartrack Fleet integration — live GPS map (Leaflet), veh…
claude Jun 16, 2026
c05e384
feat(fleet): full Cartrack feature set — tabs for live map, trips, dr…
claude Jun 16, 2026
ae7aff5
ops(release): apply Cartrack fleet env on box + restart (owner-author…
claude Jun 16, 2026
a80abc5
docs(ops): pre-production audit checklist (rotate Cartrack key/PAT/pa…
claude Jun 16, 2026
c2f83f6
feat(survey+mqc+hardening): real Survey & MQC modules + helmet + migr…
claude Jun 16, 2026
8b3851c
ops(release): prep 2026-06-16 deploy notes (survey+mqc+helmet)
claude Jun 16, 2026
1b6aefa
feat(omega): Omega module — server-side Cartrack poller + analytics D…
claude Jun 17, 2026
eebdd7d
feat(omega/fleet): fuel level — display + low-fuel alerts + analytics…
claude Jun 17, 2026
d56c42e
docs(claude): clarify CD chain — production branch = deploy signal, S…
claude Jun 17, 2026
8430409
docs(handoff): session state 2026-06-18 — Omega on production branch,…
claude Jun 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .claude/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"model": "opus"
}
51 changes: 51 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# ── API ──────────────────────────────────────────────────────────────
PORT=3000
# REQUIRED in production — boot fails on dev defaults when NODE_ENV=production.
JWT_SECRET=change-me
JWT_EXPIRES=8h
# Pin in production, e.g. CORS_ORIGIN=https://edge.ubi-as.com (comma-separated ok).
CORS_ORIGIN=
# Demo seed (PUBLIC passwords) — dev/staging only. NEVER true in production.
SEED_DEMO=true
# Field roles get a long offline grace; sensitive roles short sessions.
JWT_EXPIRES_FIELD=72h

# ── Stateful endpoints — EXTERNALIZED FROM LINE ONE (hard rule 6) ────
# Co-located on one box today, but always addressed as endpoints so the
# stack splits later via config, not code.
DB_HOST=127.0.0.1
DB_PORT=5432
DB_USER=ubi
DB_PASS=ubi_dev
DB_NAME=ubi_suite
# Dev convenience only — use migrations before production.
DB_SYNC=true

REDIS_HOST=127.0.0.1
REDIS_PORT=6379

# ── Storage (hard rule 3: binaries never in Postgres) ────────────────
# Swappable driver: local now → drive/s3/hci later, no rewrite.
STORAGE_DRIVER=local
STORAGE_ROOT=./uploads

# ── Sign in with Google (optional, layered on standalone auth) ───────
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=

# ── Cloudflare Turnstile (public helpdesk form) ──────────────────────
# Server-side secret. When set, /api/public/helpdesk REQUIRES a valid
# captcha token. The matching site key goes to the web app:
# apps/web/.env → VITE_TURNSTILE_SITE_KEY=<site key>
TURNSTILE_SECRET_KEY=

# ── External systems (integration stubs) ─────────────────────────────
ACUMATICA_BASE_URL=
OAEC_BASE_URL=

# ── Cartrack Fleet API (live GPS / fleet management) ─────────────────
# Base: https://fleetapi-<region>.cartrack.com/rest · HTTP Basic auth.
# Without USER+PASS the Fleet module serves a labeled demo fleet.
CARTRACK_REGION=ph
CARTRACK_USER=
CARTRACK_PASS=
20 changes: 20 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# deps & build
node_modules/
dist/
build/
.vite/
.turbo/
coverage/

# env & secrets (never commit)
.env
.env.*
!.env.example

# local file storage — binaries go through StorageProvider, never git
uploads/

# misc
*.log
.DS_Store
*.local
88 changes: 88 additions & 0 deletions AUDIT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
# Feature Audit vs Original Spec — updated 2026-06-16

> Tracks modules against `CLAUDE.md` Part II.

## Legend
✅ built · 🟡 stub / read-surface only · ❌ not started

---

## Production hardening (CLAUDE.md §0 item 1)
| Item | Status | Notes |
|---|---|---|
| Helmet security headers | ✅ | added to `main.ts` — all responses get standard security headers |
| TypeORM migration infrastructure | ✅ | `data-source.ts` + `migration:generate/run/revert` scripts in `apps/api/package.json`; **DB_SYNC must be set false and migrations run before production** |
| TypeORM initial migration file | ❌ | run `npm run migration:generate` against a live DB once to capture the current schema |
| Nginx/systemd/deploy docs | ✅ | `ops/nginx.sample.conf`, `ops/systemd/`, `ops/DEPLOY.md`, `ops/INSTALL-AUTOMATION.md` |
| Postgres + uploads backups | ❌ | not started — add a cron/systemd timer calling `pg_dump` + rsync uploads/ |
| Pre-prod audit checklist | ✅ | `ops/PRE-PROD-AUDIT.md` — rotate secrets, disable demo seed, verify RBAC |

---

## Survey module — ✅ real (this session)
| Spec feature | Status | Notes |
|---|---|---|
| Monthly volume feed to ManCom | ✅ | `survey.volumes` read-model pulls from real `survey_measurement` table |
| Cross-section data capture | ✅ | `survey_cross_section` entity + endpoints |
| Station/chainage indexing | ✅ | `station_start` / `station_end` in STA 0+000 format |
| As-built / original-ground / stakeout types | ✅ | `type` field on each measurement |
| Web page | ✅ | `/survey` — volume trend chart, measurement table by project, submit form |
| Demo seed | ✅ | 8 measurements for PKG-02 (PCCP) and PKG-05 (subbase) |

## MQC module — ✅ real (this session)
| Spec feature | Status | Notes |
|---|---|---|
| DPWH minimum testing rules | ✅ | `DPWH_TEST_RULES` table for items 311(1)a/b/c, 200, 201, 301; `GET /mqc/rules/:payItemNo` |
| QC test results | ✅ | `mqc_test` entity + endpoints; `mqc.certs` read-model (pending = blocking billing) |
| Pour logs (standardised form) | ✅ | `mqc_pour_log` — station, mix design, volume, slump, air content |
| Material certificates | ✅ | `mqc_material_cert` entity + issue endpoint; `billingRef` links to Engineering billing |
| Web page | ✅ | `/mqc` — DPWH rules panel, test results tab, pour logs tab, submit forms |
| Demo seed | ✅ | 5 test results + 2 pour logs for PKG-02 / PKG-05 |

---

## IT module
| Spec feature | Status | Notes |
|---|---|---|
| AI Helpdesk (landing, queue) | ✅ | Public no-signin form + Turnstile gate; feeds shared ticketing |
| Capacity planning & controls | 🟡 | Read-model with storage/transfer/DB/UPS rows + thresholds (DB-backed stubs) |
| SNMP device monitoring + map | ❌ | Device list is real; live polling / topology map not started |
| DeskGuard v2 (client OCR + KPIs) | ❌ | Not started |
| Maintenance scheduler (PMS) | ✅ | Auto-generated from Property assets; web page at `/it/pms` |
| Environmental monitoring (DHT22/ESP32) | ❌ | Not started |

## Property module — ✅ real QR EAM
`asset` + `asset_movement` + `custodian_attestation` tables. Scan endpoint, monthly attestation, history. Tools at `/property`.

## Records module — ✅ real
`vehicle_doc` + expiry engine + `physical_location` index (access-gated by claim). Tools at `/records`.

## Department dashboards — ✅ all 14
Standard KPI band + dept Pillar-3 read model + CCTV tile. CCTV goes live when `CCTV_BASE_URL` is set.

## Fleet (Cartrack) — ✅ integrated
Live GPS map (Leaflet), vehicle list, trips/events/geofences/drivers/fuel/maintenance proxy. ManCom live-fleet card.

## Engineering — ✅ core + quantity
Projects, DPWH pay-item library, weekly materials schedule (AI-prefilled), PE→PM→VPO approvals, quantity entry/projection/head pages.

---

## Still stub / not started
- Audit, Clinic, Admin, HR, Finance — read-surface stubs only (render in dept dashboards; deep workflows pending)
- IT SNMP live polling + topology map
- IT DeskGuard v2
- Engineering: SWA/billing tables — `engineering.swa` needs real persistence
- Field photo capture pipeline (GPS + timestamp + <500 KB compress + offline queue)
- Google OAuth
- Offline cached login (field PWA grace)
- TypeORM initial migration file (needs live DB to generate)
- Postgres + uploads backup script

## Suggested next build order
1. **Engineering SWA + billing** — real `weekly_swa` and `billing_batch` tables; SWA feeds ManCom volumes.
2. **Audit module** — findings register + exception tracker (directly feeds AI Insights).
3. **IT SNMP live polling** — SNMP-trap / polling worker + topology map.
4. **Field photo pipeline** — client-side compress + GPS/timestamp + offline queue service worker.
5. **Google OAuth** — layer on top of standalone auth.
6. **Postgres + uploads backup script** — cron/systemd timer + pg_dump + rsync.
Loading