Verifying the rendered pages rather than the build turned up real bugs:
- The WP-00 health page still sat at src/app/page.tsx and silently won
the route over the new Aperçu screen, so the home page was a database
status readout. Moved to /api/sante, where a probe belongs, and wired
into the compose healthcheck.
- The unassigned row showed a +14 h delta against a contract of zero,
reading as an overshoot when it is simply the volume left to staff.
It now shows what there is to fill.
- Two sidebar entries lit at once: an anchor link matched its own page,
and /equipe matched an employee record. Highlighting now resolves to
the most specific match, and a test asserts exactly one entry lights
per screen.
- Section tabs with no built screen pointed at the home page, which
reads as a broken tab. They now lead to their first entry's
placeholder.
Also gives truncated compliance alerts a title attribute, so a narrow
cell no longer says there is a problem without saying which.
Playwright can reuse a preinstalled browser through
PLAYWRIGHT_CHROMIUM_PATH when its revision differs from the bundled one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Scaffolds the project: Next.js 16 App Router with strict TypeScript,
Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a
standalone Docker image that applies migrations on boot.
Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than
stated. A per-request nonce-based CSP names no external origin, a unit
test fails if any network directive gains one, and a second test fails
if a tracking package appears in package.json. The end-to-end test
drives the standalone server the Docker image runs, not `next dev`,
so a proxy matcher that stopped matching could not pass unnoticed.
Environment is validated at import, so a missing DATABASE_URL fails at
boot with a readable message instead of surfacing later as a driver
error mid-export. ENCRYPTION_KEY is checked to be 32 bytes.
Three deviations from the plan, recorded in PLAN.md and README:
Next 16 rather than 15, `proxy.ts` rather than the now-deprecated
`middleware.ts`, and database-backed sessions rather than Auth.js v5,
which is still beta and whose JWTs would make the session revocation
required by compliance item 23 awkward.
Verified locally against PostgreSQL 16: migrations apply, extensions
created, typecheck, lint, 9 unit tests and the end-to-end header test
all pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv