Unit 1 of the slpsoftware-api feature (FR-1/FR-2/FR-3): adds a new SlpModularCms.Api.SlpSoftware Client project, intended to eventually become the deployed API for est.slpsoftware.nl/slpsoftware.nl
Extracts the hosting-pipeline composition from SlpModularCms.Api/Program.cs into shared SlpModularCms.Core.Hosting.CmsHost (ConfigureServices/ConfigurePipeline), so both Client projects call the same code instead of duplicating it
Moves StaticContentExtensions.cs + WebsitePlaceholder.html from Api into Core (required since Core cannot depend on Api)
Adds SlpModularCms.Api.Tests with WebApplicationFactory-based pipeline regression tests (security headers, health check, SPA fallback, rate limiting)
Adds a dev:slpsoftware frontend pnpm script mirroring the existing dev:slave
Fixes GlobalExceptionHandler logging routine 401s (e.g. an expired/missing refresh token) as unhandled errors -- pre-existing, unrelated to this feature, found while testing the new instance
Test plan
Full solution build succeeds
SlpModularCms.Core.Tests: 196/196 passed (no regression from the file move)
SlpModularCms.Api.Tests (new): 4/4 passed
Manual smoke test of SlpModularCms.Api.SlpSoftware locally (setup flow, login)
Full traceability (requirements, decisions, design, per-stage Q&A) is documented under idlc-docs/features/slpsoftware-api/.
## Summary
- Unit 1 of the slpsoftware-api feature (FR-1/FR-2/FR-3): adds a new SlpModularCms.Api.SlpSoftware Client project, intended to eventually become the deployed API for est.slpsoftware.nl/slpsoftware.nl
- Extracts the hosting-pipeline composition from SlpModularCms.Api/Program.cs into shared SlpModularCms.Core.Hosting.CmsHost (ConfigureServices/ConfigurePipeline), so both Client projects call the same code instead of duplicating it
- Moves StaticContentExtensions.cs + WebsitePlaceholder.html from Api into Core (required since Core cannot depend on Api)
- Adds SlpModularCms.Api.Tests with WebApplicationFactory-based pipeline regression tests (security headers, health check, SPA fallback, rate limiting)
- Adds a dev:slpsoftware frontend pnpm script mirroring the existing dev:slave
- Fixes GlobalExceptionHandler logging routine 401s (e.g. an expired/missing refresh token) as unhandled errors -- pre-existing, unrelated to this feature, found while testing the new instance
## Test plan
- [x] Full solution build succeeds
- [x] SlpModularCms.Core.Tests: 196/196 passed (no regression from the file move)
- [x] SlpModularCms.Api.Tests (new): 4/4 passed
- [x] Manual smoke test of SlpModularCms.Api.SlpSoftware locally (setup flow, login)
Full traceability (requirements, decisions, design, per-stage Q&A) is documented under idlc-docs/features/slpsoftware-api/.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Unit 1 of the slpsoftware-api feature (FR-1/FR-2/FR-3): a new Client project
in the Clients solution folder, intended to eventually become the deployed
API for test.slpsoftware.nl/slpsoftware.nl, hosting the same four modules as
SlpModularCms.Api plus a future Offerings module.
- Extracts SlpModularCms.Api/Program.cs's hosting-pipeline composition into
SlpModularCms.Core.Hosting.CmsHost (ConfigureServices/ConfigurePipeline),
shared by both Client projects so they cannot drift apart
- Moves StaticContentExtensions.cs + WebsitePlaceholder.html from Api into
Core, since CmsHost cannot live in Api but Core cannot depend on Api
- Adds SlpModularCms.Api.SlpSoftware with its own isolated local dev database
and dev ports (5286/7223, distinct from Api's and Api.Slave's)
- Adds SlpModularCms.Api.Tests with WebApplicationFactory-based pipeline
regression tests (security headers, health check, SPA fallback, rate
limiting), scoped to Api per NFR Design
- Adds a frontend dev:slpsoftware pnpm script mirroring dev:slave
- Fixes GlobalExceptionHandler logging routine 401s (e.g. an expired/missing
refresh token) as unhandled errors -- pre-existing, unrelated to this
feature's own scope, found while testing the new instance
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
The new pipeline regression tests boot the real Api host via
WebApplicationFactory, which unconditionally runs the startup database
migration -- unlike every other test project here, which mocks or uses EF
Core InMemory. CI had no MariaDB service at all, so those tests failed on
the connection itself. Adds a mariadb service container to the backend-test
job plus a ConnectionStrings__DefaultConnection override for that step,
which overrides the appsettings.Development.json placeholder via standard
config layering without touching any committed appsettings file or
affecting local test runs.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
The services: block was silently broken on this runner: job and service
containers both use host networking here, so the ports: mapping was
ignored and the mariadb:11 service ended up sharing the host's own port
3306 -- which something else on this runner already answers on (root auth
was rejected with a password nothing but this job ever set). Replaced with
an explicit `docker run` on host port 3307, bypassing that collision, plus
a readiness loop. Also fixes the readiness command itself: mariadb:11 does
not provide a `mysqladmin` alias, the correct binary is `mariadb-admin`
(verified locally against the exact image before pushing this).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
Implements Unit 2 "Offerings" (backend module, admin CRUD UI with
drag-and-drop reordering, public GET /api/v1/offerings endpoint) and
executes the feature's D-15 CI/CD cutover, switching the deploy
pipeline's build/publish target from SlpModularCms.Api to
SlpModularCms.Api.SlpSoftware.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
Confirms existing tag-based Sentry alerting and domain-based UptimeRobot/
Umami monitoring already cover the Offerings module and the Api.SlpSoftware
cutover with no new configuration. Closes the SECURITY-13 audit-trail open
item and records the final production-readiness traceability, completing
the slpsoftware-api feature's AI-DLC lifecycle.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
A new push to a PR previously left the prior CI attempt running
independently instead of superseding it. Scoped strictly to
pull_request events, since deploy-test/deploy-production only ever
run on a push to master or a manual workflow_dispatch.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FWyStNL2ZsjrS7FLd7xvvN
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Test plan
Full traceability (requirements, decisions, design, per-stage Q&A) is documented under idlc-docs/features/slpsoftware-api/.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com