bilhej/frontend
Hermes Agent 120251867c
Some checks failed
CI / Lint, type check, unit tests, coverage (pull_request) Successful in 3m38s
CI / E2E browser tests (pull_request) Failing after 1m16s
fix(guest): move guest token from URL query to sessionStorage
The guest token (the customer's only credential) was passed as
?token=... in the URL query string on the payment page. Query strings
land in browser history, nginx/reverse-proxy access logs, and can leak
via Referer headers.

The magic-link landing /gast-order/:token is inherently URL-based
(accepted Notion/Stripe pattern), but the payment page does not need to
expose the token in the URL.

Changes:
  - GuestCheckoutPage.vue: store token in sessionStorage before
    navigating to payment page; remove token from query string
  - GuestOrderPage.vue: replace RouterLink with click handler that
    stores token in sessionStorage before navigating to payment;
    add useRouter import
  - GuestPaymentRedirect.vue: read token from sessionStorage with
    fallback to query.token for backward compatibility with existing
    magic links
  - GuestCheckoutPage.spec.ts: assert token is NOT in query, IS in
    sessionStorage after navigation
  - GuestPaymentRedirect.spec.ts: set sessionStorage in mount helper;
    clear sessionStorage in beforeEach

sessionStorage persists across page refreshes within the same tab, so
the payment page still survives refresh. If the user opens the payment
URL in a new tab (from history), sessionStorage is lost — but the
canonical re-entry point is the magic link /gast-order/:token, from
which they can navigate to payment again.

Closes #21
2026-07-18 11:41:58 +00:00
..
e2e fix(e2e): use unique plate in QR code test to avoid admin row collision 2026-06-19 14:04:26 +00:00
public refactor: add design system with CSS tokens, utilities, and app shell 2026-05-16 16:09:35 +02:00
src fix(guest): move guest token from URL query to sessionStorage 2026-07-18 11:41:58 +00:00
.gitignore feat: add login page with Playwright E2E tests 2026-05-13 19:17:29 +02:00
.prettierrc feat: scaffold Vue 3 + Vite frontend with TypeScript, Router, Pinia, Vitest, ESLint, Prettier 2026-05-01 00:52:38 +02:00
eslint.config.ts feat: scaffold Vue 3 + Vite frontend with TypeScript, Router, Pinia, Vitest, ESLint, Prettier 2026-05-01 00:52:38 +02:00
index.html refactor: add design system with CSS tokens, utilities, and app shell 2026-05-16 16:09:35 +02:00
package-lock.json feat(payment): Swish QR code and pre-filled payment link 2026-06-19 12:06:29 +00:00
package.json feat(payment): Swish QR code and pre-filled payment link 2026-06-19 12:06:29 +00:00
playwright.config.ts fix(e2e): retry transient CI failures and fix backend health check 2026-06-22 10:05:36 +00:00
README.md feat: scaffold Vue 3 + Vite frontend with TypeScript, Router, Pinia, Vitest, ESLint, Prettier 2026-05-01 00:52:38 +02:00
tsconfig.app.json fix: E2E pipeline — vite preview instead of nginx, ts build fixes 2026-05-19 18:53:52 +02:00
tsconfig.json feat: scaffold Vue 3 + Vite frontend with TypeScript, Router, Pinia, Vitest, ESLint, Prettier 2026-05-01 00:52:38 +02:00
tsconfig.node.json feat: scaffold Vue 3 + Vite frontend with TypeScript, Router, Pinia, Vitest, ESLint, Prettier 2026-05-01 00:52:38 +02:00
vite.config.ts feat(guest): guest checkout without login (Swish + QR) 2026-06-22 10:35:56 +00:00

Vue 3 + TypeScript + Vite

This template should help get you started developing with Vue 3 and TypeScript in Vite. The template uses Vue 3 <script setup> SFCs, check out the script setup docs to learn more.

Learn more about the recommended Project Setup and IDE Support in the Vue Docs TypeScript Guide.