Commit Graph

16 Commits

Author SHA1 Message Date
marcuspaico
876aa0f181 feat(security): CSP and hardening headers with upload serving
Implement Content-Security-Policy headers and strict content-type handling
for non-API responses, with x-content-type-options applied to all routes.
Adds security-headers test suite to verify header presence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 16:06:05 -07:00
marcuspaico
7e70bd1940 feat(labs): draw list/detail, marker history, PDF file serving 2026-08-17 15:57:24 -07:00
marcuspaico
96692163f1 fix(labs): synchronous confirm transaction — async callback broke atomicity
bun-sqlite's Database.transaction is synchronous, but async callbacks return
a pending Promise at the first await, causing immediate COMMIT before the
entire callback completes. This allowed partial inserts with no rollback.

Fixed by:
- Remove async from transaction callback
- Add .run() to each insert/update to execute synchronously
- Add regression test proving atomicity: transaction that throws mid-loop
  rolls back all changes (both tables empty after failure)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 15:52:59 -07:00
marcuspaico
038c92af45 feat(labs): draft review, confirm with normalization, discard
- Add ConfirmDraftBody schema to shared types
- Implement GET /api/labs/drafts/:id (retrieves draft with extracted data)
- Implement POST /api/labs/drafts/:id/confirm (normalizes markers, inserts lab draw + biomarkers in transaction, marks draft confirmed)
- Implement POST /api/labs/drafts/:id/discard (marks draft discarded)
- Add comprehensive test suite with 3 new tests

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 15:46:10 -07:00
marcuspaico
8e9f3d5894 feat(labs): PDF upload, text extraction, LLM draft pipeline 2026-08-17 15:41:02 -07:00
marcuspaico
89394732fd feat(llm): OpenAI-compatible chatJSON helper with injectable fetch
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 15:33:53 -07:00
marcuspaico
e0bb888115 fix(labs): remove BUN aliases from urea, correct DHEA-S molar mass 2026-08-17 15:28:13 -07:00
marcuspaico
a08544db7d feat(labs): unit conversion, analyte registry, marker normalization 2026-08-17 15:23:34 -07:00
marcuspaico
bd4817cb77 feat(db): lab_drafts, lab_draws, biomarkers tables
Refs PAI-91.
2026-08-17 15:17:37 -07:00
marcuspaico
0b0f81b7bb fix(auth): global login rate limit — XFF was spoofable and Map unbounded
The login rate limiter keyed on the client-controlled x-forwarded-for
header, letting an attacker rotate XFF for unlimited password guesses
while also growing the failures Map unboundedly (memory DoS). Since
this is a single-password instance, replace with one global
{count, resetAt} tracker per app instance: check the 15-min window and
reject at >=10 failures before verifying the password, increment on
failure, reset on success.
2026-08-17 14:34:08 -07:00
marcuspaico
0ac233945c fix: 404 unknown API routes, add .dockerignore
- Add catch-all 404 handler for unknown /api/* routes after API mounts
- Unauthed requests to unknown API paths now return 401, authed return 404
- Add .dockerignore to prevent leaking data/ (DB, secret.key), .git/, node_modules/
- Add test in auth.test.ts verifying unknown /api/nope returns 401 unauthed, 404 authed

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 14:27:15 -07:00
marcuspaico
f33d395b71 feat(settings): LLM config API with AES-GCM sealed key, masked reads
- Add GET/PUT /api/settings for encrypted LLM configuration
- SettingsResponse with masked key display
- SettingsUpdate validation with optional fields
- Defaults: llmBaseUrl "https://openrouter.ai/api/v1", llmModel "anthropic/claude-sonnet-4.5"
- Encrypted storage with AES-256-GCM for llm_key
- getSetting() export for future route groups
- Comprehensive test coverage: defaults, updates, masking, encryption at rest, validation

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 14:14:53 -07:00
marcuspaico
0b8e897e31 feat(auth): setup/login/logout, argon2id, sessions, login rate limit 2026-08-17 14:11:00 -07:00
marcuspaico
3c796da649 feat(crypto): boot-generated key + AES-256-GCM sealed values 2026-08-17 14:07:50 -07:00
marcuspaico
0f96d5e3b8 feat(db): drizzle schema (settings, sessions) + boot migrations 2026-08-17 14:04:56 -07:00
marcuspaico
caa9af2f40 fix: typecheck without emit, placeholder test, drop build artifacts
Removes composite project references in favor of simpler -p checking.
Adds noEmit to tsconfig so tsc is typecheck-only.
Adds smoke test to unblock CI test gate.
Ignores tsbuildinfo artifacts from git.
2026-08-17 14:02:12 -07:00