Add SSO handoff tickets and expand seeded countries for address forms.

Support one-time Redis-backed dashboard sign-in handoff and seed European, Middle East, and Far East countries with major cities.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Alireza Hassani
2026-08-19 19:46:57 +03:30
co-authored by Cursor
parent 7277817b6e
commit f61bba317e
6 changed files with 319 additions and 1 deletions
+4 -1
View File
@@ -1,7 +1,7 @@
# Meshkee CMS API — Project Context
> Living reference for developers and AI assistants working on this codebase.
> Last updated: August 18, 2026
> Last updated: August 19, 2026
## What This Project Is
@@ -260,6 +260,7 @@ All routes are prefixed with `/api/v1`.
| POST | `/auth/refresh` | Refresh token |
| POST | `/auth/send-otp` | Send OTP (Redis-backed) |
| POST | `/auth/verify-otp` | Verify OTP (marks cell verified; no tokens) |
| POST | `/auth/handoff/consume` | One-time SSO ticket → tokens (customer → business dashboard) |
| GET | `/tenants/:host` | Resolve business from domain |
| GET | `/tenants/:host/store-specials` | Active store specials |
| GET | `/tenants/:host/website/category-groups` | Homepage category rows |
@@ -276,6 +277,7 @@ All routes are prefixed with `/api/v1`.
| GET | `/auth/me` | Any user |
| PATCH | `/auth/profile` | Any user |
| POST | `/auth/change-password` | Any user |
| POST | `/auth/handoff` | Staff/owner/super-admin; issues a 60s one-time SSO ticket |
| GET | `/roles?scope=global\|team` | Super admin / team.read |
| GET | `/business-categories` | Super admin or `business_categories.read` |
@@ -419,6 +421,7 @@ Each resource typically has: `read`, `create`, `update`, `delete` (+ `publish` f
- `POST /auth/login-otp` → passwordless login (consumes OTP, verifies cell, returns tokens)
- `POST /auth/reset-password` → forgot password (OTP + `newPassword`, verifies cell)
- Password login (`POST /auth/login`) rejects unverified cells when SMS is enabled
- Dashboard SSO: `POST /auth/handoff` (JWT) stores a one-time Redis ticket (`sso:handoff:{ticket}`, 60s). Business dashboard calls `POST /auth/handoff/consume` and receives tokens.
- JWT payload: `sub`, `cellNumber`, `roles`, `dashboard`, `type`
- SMS provider: Gama (`sms.igama.ir`) SendQuick via service shortcode (`SMS_GAMA_*`)
- Partner gateway (external sites like Balout): `POST /api/v1/public/sms/send` with `X-Api-Key` + body `{ domain, to, message }`; partners configured in `SMS_PARTNERS` (`domain:apiKey` pairs). Rate limits: 30/partner/min and 5/destination/min. Not part of storefront website-api docs.