Le planning quitte le module de démonstration : la grille lit `WeeklySchedule`
et `Shift`, et les quatre derniers fichiers de `src/lib/demo/` qui portaient des
salariés fictifs disparaissent.
Modèle
- `TeamMember` : rattachement d'un salarié à une équipe, distinct de
`MembershipScope` (qui dit ce qu'un manager a le droit de voir). Sans lui, un
salarié sans créneau n'apparaîtrait pas dans la grille — c'est-à-dire l'état
de départ de toute semaine en construction.
- RLS sur `WeeklySchedule`, `Shift`, `Rest`, `DailyNote` et `TeamMember`.
Temps
- `src/domain/planning/week.ts` : repérage par couple année ISO + semaine ISO,
jamais par date de début. Le lundi 29 décembre 2025 appartient à la semaine 1
de 2026 ; une clé fondée sur la date ferait apparaître deux semaines 1.
- `zonedInstant` / `zonedMidnight` corrigent le décalage mesuré **à l'instant
visé**. Le 29 mars 2026, minuit est en UTC+1 et 09 h en UTC+2 : ajouter neuf
heures à minuit donnerait 10 h locales.
- La semaine du retour à l'heure d'hiver dure 169 h, celle du passage à l'heure
d'été 167 — vérifié par test.
Écritures
- Création, modification, suppression de créneau ; publication et dépublication
**par équipe**, avec verrou optimiste sur `version` : deux managers sur la
même grille est le cas normal, pas l'exception.
- Chevauchement refusé en transaction, pas seulement dans le formulaire.
- Modifier une semaine publiée exige `planning.edit_published`, capacité que le
rôle manager n'a pas : un salarié a organisé sa semaine sur ce qu'il a lu.
- Toute mutation laisse une entrée d'audit ; la suppression écrit sa trace
**avant** l'effacement, sinon l'état supprimé serait perdu.
Lecture
- `planning.view_unpublished` filtre en base : sans cette capacité, les
brouillons ne sont pas chargés du tout. Un test vérifie que les horaires
n'apparaissent pas dans le HTML servi — un masquage CSS les y laisserait.
- Vue jour reconstruite sur les mêmes données, amplitude déduite de la journée
réelle plutôt que figée à 06 h–21 h.
Vérification
- 26 tests unitaires sur le repérage des semaines et la mise en grille.
- Parcours e2e : poser un créneau, refus de chevauchement, publier, dépublier ;
et ce que voient un salarié et un manager sur la même semaine.
- `scripts/dev-db.sh` : la base de développement est éphémère dans cet
environnement, la remonter ne doit pas être une redécouverte.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Adds the referential models, the first database-backed settings
screens, and the register the compliance matrix requires before any
parameter is enforceable.
The register is the point of the lot. The matrix is explicit that
copying another product's configuration is not enough — each parameter
must carry its value, source, effective date, population and an
approver. Approval records the session's actor, never a form field: a
signature you can type yourself is worth nothing. The screen names the
domains that have no approved parameter yet, so the gap is visible
rather than assumed closed.
Two bugs of the same family, both now structurally impossible:
- The Prisma scoping extension read a hand-written list of models
carrying accountId. The four models added here were missing from it,
so writes failed with an opaque Prisma error — and a read would have
silently returned every account's rows. The list is now derived from
the schema itself.
- The RLS policies were likewise per-table. A new integration test
fails if any table with an accountId column lacks forced RLS and both
policies, which is the failure mode that hides best: nobody writes a
wrong rule, someone forgets to write one.
An end-to-end test signs in as a manager and confirms the settings
screens refuse to render — the sidebar hiding them is a convenience,
the server check is the control.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Adds the sign-in screen, sign-out, and a server-side guard on every
application route. The guard lives in the layout rather than the proxy
because the proxy cannot query the database to check whether a session
was revoked — and revocation is the reason sessions are stored there.
Sign-in returns one message for an unknown account and for a wrong
password, and verifies a dummy hash when the account does not exist, so
neither the wording nor the timing enumerates staff addresses. An
end-to-end test compares the two messages rather than trusting the
code to keep them aligned.
The shell now shows the signed-in person and their role from the
database instead of hardcoded initials.
Playwright signs in once in a setup project and shares the cookie;
argon2 is deliberately slow, and logging in per test would also drive
the shared failed-attempt counter toward a lockout. The seed resets
that counter so repeated local runs cannot lock the demo account.
Two test locators had to be scoped to the form: Next's route announcer
carries role="alert" and an empty string, which silently satisfied the
assertion.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Verifying the rendered pages rather than the build turned up real bugs:
- The WP-00 health page still sat at src/app/page.tsx and silently won
the route over the new Aperçu screen, so the home page was a database
status readout. Moved to /api/sante, where a probe belongs, and wired
into the compose healthcheck.
- The unassigned row showed a +14 h delta against a contract of zero,
reading as an overshoot when it is simply the volume left to staff.
It now shows what there is to fill.
- Two sidebar entries lit at once: an anchor link matched its own page,
and /equipe matched an employee record. Highlighting now resolves to
the most specific match, and a test asserts exactly one entry lights
per screen.
- Section tabs with no built screen pointed at the home page, which
reads as a broken tab. They now lead to their first entry's
placeholder.
Also gives truncated compliance alerts a title attribute, so a narrow
cell no longer says there is a problem without saying which.
Playwright can reuse a preinstalled browser through
PLAYWRIGHT_CHROMIUM_PATH when its revision differs from the bundled one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Scaffolds the project: Next.js 16 App Router with strict TypeScript,
Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a
standalone Docker image that applies migrations on boot.
Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than
stated. A per-request nonce-based CSP names no external origin, a unit
test fails if any network directive gains one, and a second test fails
if a tracking package appears in package.json. The end-to-end test
drives the standalone server the Docker image runs, not `next dev`,
so a proxy matcher that stopped matching could not pass unnoticed.
Environment is validated at import, so a missing DATABASE_URL fails at
boot with a readable message instead of surfacing later as a driver
error mid-export. ENCRYPTION_KEY is checked to be 32 bytes.
Three deviations from the plan, recorded in PLAN.md and README:
Next 16 rather than 15, `proxy.ts` rather than the now-deprecated
`middleware.ts`, and database-backed sessions rather than Auth.js v5,
which is still beta and whose JWTs would make the session revocation
required by compliance item 23 awkward.
Verified locally against PostgreSQL 16: migrations apply, extensions
created, typecheck, lint, 9 unit tests and the end-to-end header test
all pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv