ac617f4fe5
- MailModule with SMTP transport configured from ENV variables - MailService for password reset and welcome emails (plain text, i18n) - Password reset flow: request-reset (public), reset-password (token-based) - Change password for logged-in users with current password verification - Admin reset password endpoint (ADMIN/SUPER_ADMIN only, D-03) - ForcePasswordChangeInterceptor blocks all routes except change-password, logout, me when mustChangePassword=true (D-06, Pitfall 5) - Frontend: reset-password request page, token reset page, change-password page - Forgot password link added to login page - MailHog service added to docker-compose.dev.yml for dev email testing - SMTP env vars added to docker-compose.yml (defaults to MailHog) - Complete DE/EN i18n coverage for reset and change password flows - SUS packages installed: @nestjs-modules/mailer, nodemailer, ldapts Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
78 lines
2.1 KiB
YAML
78 lines
2.1 KiB
YAML
services:
|
|
web:
|
|
build:
|
|
context: .
|
|
dockerfile: apps/web/Dockerfile
|
|
ports:
|
|
- "3000:3000"
|
|
environment:
|
|
HOSTNAME: "0.0.0.0"
|
|
NEXT_PUBLIC_API_URL: "http://localhost:3001"
|
|
networks:
|
|
- frontend-net
|
|
- backend-net
|
|
depends_on:
|
|
api:
|
|
condition: service_healthy
|
|
|
|
api:
|
|
build:
|
|
context: .
|
|
dockerfile: apps/api/Dockerfile
|
|
ports:
|
|
- "3001:3001"
|
|
networks:
|
|
- backend-net
|
|
- data-net
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
environment:
|
|
DATABASE_URL: ${DATABASE_URL:-postgresql://tessera:tessera_dev@db:5432/tessera}
|
|
JWT_SECRET: ${JWT_SECRET:-tessera-dev-jwt-secret-change-in-production}
|
|
TESSERA_ADMIN_USER: ${TESSERA_ADMIN_USER:-admin}
|
|
TESSERA_ADMIN_EMAIL: ${TESSERA_ADMIN_EMAIL:-admin@tessera.local}
|
|
TESSERA_ADMIN_PASSWORD: ${TESSERA_ADMIN_PASSWORD:-admin123}
|
|
TESSERA_FORCE_CHANGE: ${TESSERA_FORCE_CHANGE:-false}
|
|
TESSERA_SMTP_HOST: ${TESSERA_SMTP_HOST:-mailhog}
|
|
TESSERA_SMTP_PORT: ${TESSERA_SMTP_PORT:-1025}
|
|
TESSERA_SMTP_SECURE: ${TESSERA_SMTP_SECURE:-false}
|
|
TESSERA_SMTP_USER: ${TESSERA_SMTP_USER:-}
|
|
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
|
|
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <tessera@tessera.local>}
|
|
TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000}
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 10s
|
|
|
|
db:
|
|
image: postgres:16-alpine
|
|
networks:
|
|
- data-net
|
|
volumes:
|
|
- pgdata:/var/lib/postgresql/data
|
|
environment:
|
|
POSTGRES_USER: tessera
|
|
POSTGRES_PASSWORD: ${DB_PASSWORD:-tessera_dev}
|
|
POSTGRES_DB: tessera
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U tessera"]
|
|
interval: 5s
|
|
timeout: 3s
|
|
retries: 5
|
|
|
|
networks:
|
|
frontend-net:
|
|
driver: bridge
|
|
backend-net:
|
|
driver: bridge
|
|
data-net:
|
|
driver: bridge
|
|
internal: true
|
|
|
|
volumes:
|
|
pgdata:
|