Compare commits

...
11 Commits
Author SHA1 Message Date
MythEclipseandClaude 528a1622d0 fix(auth): prevent AuthInitializer from overwriting Zustand with null user
Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 19:04:29 +07:00
MythEclipseandClaude 51a4cb9ed2 fix(auth): detect HTTPS via X-Forwarded-Proto for SameSite=None cookies, fix AuthGuard null overwrite
- Cookie SameSite now dynamic: None;Secure when behind HTTPS proxy, Lax otherwise
- AuthGuard useEffect no longer overwrites Zustand store with null from background refetch
- AuthInitializer: add staleTime 30s

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 18:17:26 +07:00
MythEclipse 22307d44de fix(api): add http://tauri.localhost to CORS allowed origins 2026-06-15 17:09:40 +07:00
MythEclipseandClaude 41e0501e6b fix(tauri): add absolute API base URL default and CORS origins for Android WebView
- Set VITE_API_BASE_URL default to production API URL in api-client.ts
  so fetch() uses absolute URLs instead of relative paths that fail on Tauri
- Add tauri://localhost and https://tauri.localhost to API CORS allowed origins
- Also fix .env WEB_APP_URL from stale .tech to .my.id

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 14:32:54 +07:00
MythEclipseandClaude f675b86dc8 fix(docker): remove port exposure from docker-compose.yml
All services route through Traefik via internal network labels.
No ports need to be exposed on the host.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 14:05:44 +07:00
MythEclipseandClaude 8ed1b57f1d fix(ci): add container wait loop before health check in deploy
Containers need time to start after docker compose up -d. Replaced
instant grep check with up-to-60s retry loop.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 14:04:19 +07:00
MythEclipseandClaude bf1725a4b8 fix(docker): remove non-existent shared/node_modules COPY from API Dockerfile
packages/shared has only devDependencies (typescript). After
bun install --production, packages/shared/node_modules does not
exist. Root node_modules contains all hoisted deps.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 13:58:23 +07:00
MythEclipseandClaude 8954535e08 fix(ci): add tauri package.json to Dockerfiles and fix Android NDK/build issues
Build and Deploy: workspace has 4 members (api/web/shared/tauri) but
Dockerfiles only copied 3 package.json files. Missing tauri workspace
member caused bun install --production to fail with frozen lockfile
error.

Build Android APK:
- Remove explicit NDK 28 install (runner has NDK 29 pre-installed, dual
  NDK presence broke ANDROID_NDK_HOME resolution)
- Auto-pin NDK version from runner's SDK
- rm -rf gen/android before tauri android init (stale cache recovery)
- Remove gen/android/.gradle from Gradle cache (causes stale state)
- Use --apk flag for faster APK-only build

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 13:54:55 +07:00
MythEclipseandClaude b93be6c6cb fix(docker): copy bun.lock and workspace node_modules to API runner stage
Bun workspace symlinks (apps/api/node_modules/*) pointed to root
.bun cache but were never copied from deps→runner. Added bun.lock,
apps/api/node_modules, and packages/shared/node_modules to the
runner COPY chain so  and  resolve at runtime.

Also added bun.lock to web Dockerfile for deterministic installs.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 03:30:18 +07:00
MythEclipseandClaude 2d39468279 perf(ci): add Bun and Gradle caching to Android workflow
Cache Bun dependencies (install cache + node_modules) and Gradle caches
(wrapper, dependencies, build artifacts) to dramatically speed up CI builds.
Gradle key uses Cargo.lock since gradle files don't exist at checkout time.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 01:43:25 +07:00
MythEclipseandClaude 78db3a03ac chore: change base URL to zeavisedu.asepharyana.my.id
Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 01:35:58 +07:00
19 changed files with 2020 additions and 34 deletions
+30 -4
View File
@@ -18,7 +18,7 @@ on:
workflow_dispatch: workflow_dispatch:
env: env:
VITE_API_BASE_URL: ${{ vars.VITE_API_BASE_URL || 'https://zeavisedu.asepharyana.tech' }} VITE_API_BASE_URL: ${{ vars.VITE_API_BASE_URL || 'https://zeavisedu.asepharyana.my.id' }}
jobs: jobs:
build-apk: build-apk:
@@ -40,6 +40,18 @@ jobs:
with: with:
bun-version: latest bun-version: latest
- name: Cache Bun dependencies
uses: actions/cache@v4
with:
path: |
~/.bun/install/cache
node_modules
apps/*/node_modules
packages/*/node_modules
key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock', '**/package.json') }}
restore-keys: |
${{ runner.os }}-bun-
- name: Install dependencies - name: Install dependencies
run: bun install run: bun install
@@ -52,7 +64,9 @@ jobs:
- name: Setup Android SDK - name: Setup Android SDK
uses: android-actions/setup-android@v3 uses: android-actions/setup-android@v3
with: with:
packages: 'platforms;android-36 build-tools;36.0.0 ndk;28.0.13004108' packages: 'platforms;android-36 build-tools;36.0.0'
- name: Pin NDK version
run: echo "ANDROID_NDK_HOME=${ANDROID_SDK_ROOT}/ndk/$(ls ${ANDROID_SDK_ROOT}/ndk | sort -V | head -1)" >> $GITHUB_ENV
- name: Setup Rust with Android targets - name: Setup Rust with Android targets
uses: dtolnay/rust-toolchain@stable uses: dtolnay/rust-toolchain@stable
@@ -74,6 +88,16 @@ jobs:
restore-keys: | restore-keys: |
${{ runner.os }}-cargo-android- ${{ runner.os }}-cargo-android-
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-android-${{ hashFiles('apps/tauri/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-gradle-android-
- name: Install Tauri CLI - name: Install Tauri CLI
run: cd apps/tauri && bun install run: cd apps/tauri && bun install
@@ -108,7 +132,9 @@ jobs:
JAVA_HOME: ${{ env.JAVA_HOME_21_X64 }} JAVA_HOME: ${{ env.JAVA_HOME_21_X64 }}
ANDROID_HOME: ${{ env.ANDROID_SDK_ROOT }} ANDROID_HOME: ${{ env.ANDROID_SDK_ROOT }}
NDK_HOME: ${{ env.ANDROID_NDK_HOME }} NDK_HOME: ${{ env.ANDROID_NDK_HOME }}
run: bun tauri android init run: |
rm -rf gen/android
bun tauri android init
- name: Build Tauri Android APK - name: Build Tauri Android APK
working-directory: apps/tauri working-directory: apps/tauri
@@ -116,7 +142,7 @@ jobs:
JAVA_HOME: ${{ env.JAVA_HOME_21_X64 }} JAVA_HOME: ${{ env.JAVA_HOME_21_X64 }}
ANDROID_HOME: ${{ env.ANDROID_SDK_ROOT }} ANDROID_HOME: ${{ env.ANDROID_SDK_ROOT }}
NDK_HOME: ${{ env.ANDROID_NDK_HOME }} NDK_HOME: ${{ env.ANDROID_NDK_HOME }}
run: bun tauri android build run: bun tauri android build --apk
- name: Decode keystore - name: Decode keystore
if: github.event_name != 'pull_request' if: github.event_name != 'pull_request'
+14 -5
View File
@@ -177,7 +177,7 @@ jobs:
cat << 'ENVEOF' cat << 'ENVEOF'
DATABASE_URL=${{ secrets.DATABASE_URL }} DATABASE_URL=${{ secrets.DATABASE_URL }}
SESSION_SECRET=${{ secrets.SESSION_SECRET }} SESSION_SECRET=${{ secrets.SESSION_SECRET }}
WEB_APP_URL=https://zeavisedu.asepharyana.tech WEB_APP_URL=https://zeavisedu.asepharyana.my.id
ML_SERVICE_URL=http://zeavis-ml:8000 ML_SERVICE_URL=http://zeavis-ml:8000
ENVEOF ENVEOF
} > .env } > .env
@@ -189,8 +189,17 @@ jobs:
docker rm -f zeavis-web zeavis-api zeavis-ml zeavis-node-exporter 2>/dev/null || true docker rm -f zeavis-web zeavis-api zeavis-ml zeavis-node-exporter 2>/dev/null || true
docker compose pull docker compose pull
docker compose up -d docker compose up -d
# Wait for containers to be healthy (up to 60s)
wait_container() {
local name=$1
for i in $(seq 1 30); do
docker compose ps | grep -q "${name}.*Up" && return 0
sleep 2
done
return 1
}
wait_container zeavis-web || exit 1
wait_container zeavis-api || exit 1
wait_container zeavis-ml || exit 1
wait_container zeavis-node-exporter || echo "⚠️ node_exporter not running (non-fatal)"
docker compose ps docker compose ps
docker compose ps | grep -q "zeavis-web.*Up" || exit 1
docker compose ps | grep -q "zeavis-api.*Up" || exit 1
docker compose ps | grep -q "zeavis-ml.*Up" || exit 1
docker compose ps | grep -q "zeavis-node-exporter.*Up" || echo "⚠️ node_exporter not running (non-fatal)"
+4 -1
View File
@@ -1,9 +1,10 @@
FROM oven/bun:1.3.14 AS deps FROM oven/bun:1.3.14 AS deps
WORKDIR /app WORKDIR /app
COPY package.json bunfig.toml tsconfig.base.json ./ COPY package.json bun.lock bunfig.toml tsconfig.base.json ./
COPY apps/api/package.json apps/api/package.json COPY apps/api/package.json apps/api/package.json
COPY apps/web/package.json apps/web/package.json COPY apps/web/package.json apps/web/package.json
COPY apps/tauri/package.json apps/tauri/package.json
COPY packages/shared/package.json packages/shared/package.json COPY packages/shared/package.json packages/shared/package.json
RUN bun install --production RUN bun install --production
@@ -13,6 +14,8 @@ ENV NODE_ENV=production
ENV API_PORT=3000 ENV API_PORT=3000
COPY --from=deps /app/node_modules ./node_modules COPY --from=deps /app/node_modules ./node_modules
COPY --from=deps /app/apps/api/node_modules apps/api/node_modules
COPY --from=deps /app/bun.lock ./bun.lock
COPY package.json bunfig.toml tsconfig.base.json ./ COPY package.json bunfig.toml tsconfig.base.json ./
COPY apps/api apps/api COPY apps/api apps/api
COPY packages/shared packages/shared COPY packages/shared packages/shared
+8
View File
@@ -8,6 +8,13 @@ const googleOAuthEnabled = Boolean(
); );
const webAppUrl = Bun.env.WEB_APP_URL ?? 'http://localhost:5173'; const webAppUrl = Bun.env.WEB_APP_URL ?? 'http://localhost:5173';
const allowedOrigins = [
webAppUrl,
'https://tauri.localhost',
'http://tauri.localhost',
'tauri://localhost',
'http://localhost:5173',
];
const secureCookies = Bun.env.SECURE_COOKIES === 'true' || webAppUrl.startsWith('https://'); const secureCookies = Bun.env.SECURE_COOKIES === 'true' || webAppUrl.startsWith('https://');
export const env = { export const env = {
@@ -24,6 +31,7 @@ export const env = {
googleClientSecret: Bun.env.GOOGLE_CLIENT_SECRET, googleClientSecret: Bun.env.GOOGLE_CLIENT_SECRET,
googleRedirectUri: Bun.env.GOOGLE_REDIRECT_URI, googleRedirectUri: Bun.env.GOOGLE_REDIRECT_URI,
webAppUrl, webAppUrl,
allowedOrigins,
secureCookies, secureCookies,
}; };
+1 -1
View File
@@ -17,7 +17,7 @@ assertRequiredEnv();
const app = new Elysia() const app = new Elysia()
.use(cors({ .use(cors({
origin: env.webAppUrl, origin: env.allowedOrigins,
credentials: true, credentials: true,
})) }))
.use(metricsRoutes) .use(metricsRoutes)
+16 -4
View File
@@ -28,14 +28,26 @@ function hashToken(token: string) {
return createHash('sha256').update(`${env.sessionSecret}:${token}`).digest('hex'); return createHash('sha256').update(`${env.sessionSecret}:${token}`).digest('hex');
} }
export function createSessionCookie(token: string) { function isSecureRequest(headers?: { get(name: string): string | null }) {
if (env.secureCookies) return true;
// Detect HTTPS behind proxy (X-Forwarded-Proto)
const proto = headers?.get('x-forwarded-proto');
if (proto === 'https') return true;
return false;
}
function buildSameSite(headers?: { get(name: string): string | null }) {
return isSecureRequest(headers) ? 'SameSite=None; Secure' : 'SameSite=Lax';
}
export function createSessionCookie(token: string, headers?: { get(name: string): string | null }) {
const maxAge = 60 * 60 * 24 * 30; const maxAge = 60 * 60 * 24 * 30;
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax'; const sameSite = buildSameSite(headers);
return `${sessionCookieName}=${token}; HttpOnly; Path=/; ${sameSite}; Max-Age=${maxAge}`; return `${sessionCookieName}=${token}; HttpOnly; Path=/; ${sameSite}; Max-Age=${maxAge}`;
} }
export function clearSessionCookie() { export function clearSessionCookie(headers?: { get(name: string): string | null }) {
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax'; const sameSite = buildSameSite(headers);
return `${sessionCookieName}=; HttpOnly; Path=/; ${sameSite}; Max-Age=0`; return `${sessionCookieName}=; HttpOnly; Path=/; ${sameSite}; Max-Age=0`;
} }
+7 -6
View File
@@ -38,7 +38,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
features: getAuthFeatures(), features: getAuthFeatures(),
}; };
}) })
.post('/register', async ({ body, set }) => { .post('/register', async ({ body, set, request }) => {
const req = body as Partial<RegisterRequest> | undefined; const req = body as Partial<RegisterRequest> | undefined;
const email = normalizeEmail(req?.email); const email = normalizeEmail(req?.email);
const name = normalizeName(req?.name); const name = normalizeName(req?.name);
@@ -62,7 +62,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
const user = inserted[0]; const user = inserted[0];
const token = await createSession(user.id); const token = await createSession(user.id);
set.headers['Set-Cookie'] = createSessionCookie(token); set.headers['Set-Cookie'] = createSessionCookie(token, request.headers);
authCounter.labels('register', 'true').inc(); authCounter.labels('register', 'true').inc();
@@ -79,7 +79,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
return serviceUnavailable('Database unavailable'); return serviceUnavailable('Database unavailable');
} }
}) })
.post('/login', async ({ body, set }) => { .post('/login', async ({ body, set, request }) => {
const req = body as Partial<AuthRequest> | undefined; const req = body as Partial<AuthRequest> | undefined;
const email = normalizeEmail(req?.email); const email = normalizeEmail(req?.email);
@@ -98,7 +98,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
} }
const token = await createSession(user.id); const token = await createSession(user.id);
set.headers['Set-Cookie'] = createSessionCookie(token); set.headers['Set-Cookie'] = createSessionCookie(token, request.headers);
authCounter.labels('login', 'true').inc(); authCounter.labels('login', 'true').inc();
@@ -116,8 +116,9 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
} }
}) })
.post('/logout', async ({ request, set }) => { .post('/logout', async ({ request, set }) => {
await deleteSession(readSessionToken(request.headers.get('cookie'))); const cookieHeader = request.headers.get('cookie');
set.headers['Set-Cookie'] = clearSessionCookie(); await deleteSession(readSessionToken(cookieHeader));
set.headers['Set-Cookie'] = clearSessionCookie(request.headers);
return { ok: true }; return { ok: true };
}) })
.get('/google', ({ set }) => { .get('/google', ({ set }) => {
+3
View File
@@ -0,0 +1,3 @@
# Default ignored files
/shelf/
/workspace.xml
File diff suppressed because it is too large Load Diff
+13
View File
@@ -0,0 +1,13 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="DeviceTable">
<option name="columnSorters">
<list>
<ColumnSorterState>
<option name="column" value="Name" />
<option name="order" value="ASCENDING" />
</ColumnSorterState>
</list>
</option>
</component>
</project>
+17
View File
@@ -0,0 +1,17 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="DiscordProjectSettings">
<option name="show" value="ASK" />
<option name="description" value="" />
<option name="applicationTheme" value="default" />
<option name="iconsTheme" value="default" />
<option name="button1Title" value="" />
<option name="button1Url" value="" />
<option name="button2Title" value="" />
<option name="button2Url" value="" />
<option name="customApplicationId" value="" />
</component>
<component name="ProjectRootManager" version="2">
<output url="file://$PROJECT_DIR$/out" />
</component>
</project>
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="ProjectModuleManager">
<modules>
<module fileurl="file://$PROJECT_DIR$/.idea/tauri.iml" filepath="$PROJECT_DIR$/.idea/tauri.iml" />
</modules>
</component>
</project>
+9
View File
@@ -0,0 +1,9 @@
<?xml version="1.0" encoding="UTF-8"?>
<module type="JAVA_MODULE" version="4">
<component name="NewModuleRootManager" inherit-compiler-output="true">
<exclude-output />
<content url="file://$MODULE_DIR$" />
<orderEntry type="inheritedJdk" />
<orderEntry type="sourceFolder" forTests="false" />
</component>
</module>
+6
View File
@@ -0,0 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="VcsDirectoryMappings">
<mapping directory="$PROJECT_DIR$/../.." vcs="Git" />
</component>
</project>
+2 -1
View File
@@ -1,10 +1,11 @@
FROM oven/bun:1.3.14 AS builder FROM oven/bun:1.3.14 AS builder
WORKDIR /app WORKDIR /app
COPY package.json bunfig.toml tsconfig.base.json ./ COPY package.json bun.lock bunfig.toml tsconfig.base.json ./
COPY packages/shared/package.json packages/shared/package.json COPY packages/shared/package.json packages/shared/package.json
COPY apps/web/package.json apps/web/package.json COPY apps/web/package.json apps/web/package.json
COPY apps/api/package.json apps/api/package.json COPY apps/api/package.json apps/api/package.json
COPY apps/tauri/package.json apps/tauri/package.json
RUN bun install RUN bun install
COPY packages/shared packages/shared COPY packages/shared packages/shared
+9 -4
View File
@@ -10,27 +10,32 @@ type AuthGuardProps = {
}; };
export function AuthGuard({ children, requireExpert = false }: AuthGuardProps) { export function AuthGuard({ children, requireExpert = false }: AuthGuardProps) {
const user = useAuthStore((state) => state.user);
const setUser = useAuthStore((state) => state.setUser); const setUser = useAuthStore((state) => state.setUser);
const query = useQuery({ const query = useQuery({
queryKey: ['auth', 'me'], queryKey: ['auth', 'me'],
queryFn: () => apiClient.getMe(), queryFn: () => apiClient.getMe(),
staleTime: 30_000,
}); });
useEffect(() => { useEffect(() => {
if (query.data) { if (query.data?.user) {
setUser(query.data.user); setUser(query.data.user);
} }
}, [query.data, setUser]); }, [query.data, setUser]);
if (query.isLoading) { // Tunjukkan loading hanya jika belum ada user di store
if (query.isLoading && !user) {
return <main className="min-h-screen p-8 text-center text-muted-foreground">Memeriksa sesi...</main>; return <main className="min-h-screen p-8 text-center text-muted-foreground">Memeriksa sesi...</main>;
} }
if (!query.data?.user) { // Cek store dulu, baru query — mencegah redirect saat refetch background
const currentUser = query.data?.user ?? user;
if (!currentUser) {
return <Navigate to="/login" replace />; return <Navigate to="/login" replace />;
} }
if (requireExpert && query.data.user.role !== 'expert') { if (requireExpert && currentUser.role !== 'expert') {
return <Navigate to="/dashboard" replace />; return <Navigate to="/dashboard" replace />;
} }
+2 -1
View File
@@ -9,10 +9,11 @@ export function AuthInitializer() {
queryKey: ['auth', 'me'], queryKey: ['auth', 'me'],
queryFn: () => apiClient.getMe(), queryFn: () => apiClient.getMe(),
retry: false, retry: false,
staleTime: 30_000,
}); });
useEffect(() => { useEffect(() => {
if (query.data) { if (query.data?.user) {
setUser(query.data.user); setUser(query.data.user);
} }
}, [query.data, setUser]); }, [query.data, setUser]);
+1 -1
View File
@@ -14,7 +14,7 @@ import type {
} from '@zeavis/shared'; } from '@zeavis/shared';
import { recordApiCall } from './telemetry'; import { recordApiCall } from './telemetry';
const apiBaseUrl = import.meta.env.VITE_API_BASE_URL ?? ''; const apiBaseUrl = import.meta.env.VITE_API_BASE_URL ?? 'https://zeavisedu.asepharyana.my.id';
export interface ApiError extends Error { export interface ApiError extends Error {
status: number; status: number;
-6
View File
@@ -38,8 +38,6 @@ services:
API_PORT: "3000" API_PORT: "3000"
WEB_APP_URL: https://zeavisedu.asepharyana.my.id WEB_APP_URL: https://zeavisedu.asepharyana.my.id
ML_SERVICE_URL: ${ML_SERVICE_URL:-http://zeavis-ml:8000} ML_SERVICE_URL: ${ML_SERVICE_URL:-http://zeavis-ml:8000}
ports:
- "3000:3000"
labels: labels:
traefik.enable: "true" traefik.enable: "true"
traefik.http.routers.zeavis-api.rule: Host(`api-zeavisedu.asepharyana.my.id`) traefik.http.routers.zeavis-api.rule: Host(`api-zeavisedu.asepharyana.my.id`)
@@ -53,8 +51,6 @@ services:
image: prom/node-exporter:v1.8.2 image: prom/node-exporter:v1.8.2
container_name: zeavis-node-exporter container_name: zeavis-node-exporter
restart: unless-stopped restart: unless-stopped
ports:
- "9100:9100"
command: command:
- "--path.rootfs=/host" - "--path.rootfs=/host"
- "--web.listen-address=:9100" - "--web.listen-address=:9100"
@@ -77,8 +73,6 @@ services:
environment: environment:
MODEL_PATH: /app/model/model.onnx MODEL_PATH: /app/model/model.onnx
MODEL_INPUT_SIZE: "224" MODEL_INPUT_SIZE: "224"
ports:
- "8000:8000"
labels: labels:
traefik.enable: "true" traefik.enable: "true"
traefik.http.routers.zeavis-ml.rule: Host(`ml-zeavisedu.asepharyana.my.id`) traefik.http.routers.zeavis-ml.rule: Host(`ml-zeavisedu.asepharyana.my.id`)