Adds SlpModularCms.Api.SlpSoftware and extracts shared CmsHost composition
Continuous Integration / config (pull_request) Successful in 11s
Continuous Integration / changes (pull_request) Successful in 21s
Continuous Integration / backend-build (pull_request) Successful in 6m10s
Continuous Integration / vulnerability-scan (pull_request) Successful in 4m59s
Continuous Integration / frontend-prepare (pull_request) Successful in 1m27s
Continuous Integration / backend-test (pull_request) Failing after 7m48s
Continuous Integration / frontend-build (pull_request) Successful in 2m5s
Continuous Integration / frontend-test (pull_request) Successful in 4m24s
Continuous Integration / frontend-lint (pull_request) Successful in 2m0s
Continuous Integration / publish-test (pull_request) Skipped
Continuous Integration / publish-production (pull_request) Skipped
Continuous Integration / deploy-test (pull_request) Skipped
Continuous Integration / deploy-production (pull_request) Skipped

Unit 1 of the slpsoftware-api feature (FR-1/FR-2/FR-3): a new Client project
in the Clients solution folder, intended to eventually become the deployed
API for test.slpsoftware.nl/slpsoftware.nl, hosting the same four modules as
SlpModularCms.Api plus a future Offerings module.

- Extracts SlpModularCms.Api/Program.cs's hosting-pipeline composition into
  SlpModularCms.Core.Hosting.CmsHost (ConfigureServices/ConfigurePipeline),
  shared by both Client projects so they cannot drift apart
- Moves StaticContentExtensions.cs + WebsitePlaceholder.html from Api into
  Core, since CmsHost cannot live in Api but Core cannot depend on Api
- Adds SlpModularCms.Api.SlpSoftware with its own isolated local dev database
  and dev ports (5286/7223, distinct from Api's and Api.Slave's)
- Adds SlpModularCms.Api.Tests with WebApplicationFactory-based pipeline
  regression tests (security headers, health check, SPA fallback, rate
  limiting), scoped to Api per NFR Design
- Adds a frontend dev:slpsoftware pnpm script mirroring dev:slave
- Fixes GlobalExceptionHandler logging routine 401s (e.g. an expired/missing
  refresh token) as unhandled errors -- pre-existing, unrelated to this
  feature's own scope, found while testing the new instance

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
This commit is contained in:
2026-08-02 01:28:39 +02:00
co-authored by Claude Sonnet 5
parent dcc82cdf62
commit fa389e42ee
51 changed files with 3119 additions and 127 deletions
@@ -0,0 +1,55 @@
{
"Logging": {
"LogLevel": {
"Default": "Information",
"Microsoft.AspNetCore": "Warning"
}
},
"ConnectionStrings": {
// Own, isolated local dev database (Infrastructure Design decision Q1 = B) — deliberately
// separate from SlpModularCms.Api's local database, so developing/testing this project
// (and the future Offerings module) never touches Api's local data, or vice versa.
"DefaultConnection": "Server=127.0.0.1;Port=3306;Database=SlpModularCmsSlpSoftwareDev;Uid=root;Pwd=<your-local-mariadb-password>"
},
"JwtSettings": {
"Secret": "SuperSecretKeyForDevelopmentOnly_MustBeLongerThan32Bytes!",
"Issuer": "SlpModularCms",
"Audience": "SlpModularCmsPortal",
"ExpiryMinutes": 60,
"RefreshTokenExpiryDays": 7,
"CookieSameSite": "None"
},
"Availability": {
"CircuitBreakerSeconds": 30,
"StatusCacheSeconds": 1
},
"MasterPolling": {
"PollIntervalSeconds": 15,
"FailOpenAfterMinutes": 2,
"HttpTimeoutSeconds": 5
},
"MasterModule": {
"IntegrityCheckIntervalMinutes": 60,
"HttpTimeoutSeconds": 10,
"MasterUrl": "https://localhost:7223"
},
"Cors": {
// Port 5175, not 5173: that's Api's own frontend dev port (see frontend/package.json's
// plain `pnpm dev`). This project is reached via `pnpm dev:slpsoftware`, which runs the
// frontend dev server on 5175 (see .env.slpsoftware.local / package.json).
"AllowedOrigins": [
"http://localhost:5175",
"https://localhost:5175"
]
},
"RateLimiting": {
"Login": {
"PermitLimit": 100,
"WindowSeconds": 60
},
"Refresh": {
"PermitLimit": 500,
"WindowSeconds": 60
}
}
}