feat: GDPR (export+delete) + catalogo ricette 46→96

GDPR (PRD §14, art. 17 + 20)
- GET /me/export.json: dump completo dei dati personali
  (User, Profile, Preferences, WeightEntry, FastEvent, MealPlan+slots,
  DailyCheckIn, DeviceToken). I campi @encrypted vengono decifrati a runtime
  dall'extension Prisma. Risposta con Content-Disposition attachment.
- DELETE /me: cancellazione account con cascade automatico. Per gli
  account email/password richiede conferma password (verifica via
  auth.api.signInEmail). Account OAuth-only: solo sessione attiva.
- Proxy Next /api/gdpr-export per same-origin + cookie sessione.
- /profile: nuova sezione "I tuoi dati (GDPR)" in fondo con due azioni
  (esporta + elimina) e modale di conferma password per la cancellazione.

Catalogo ricette 46 → 96 (target 100)
- 50 ricette nuove italiane keto/low-carb bilanciate per categoria:
  12 colazioni, 14 pranzi, 12 spuntini, 12 cene
- Macros realistici, ingredienti dal seed esistente (no nuovi ingredienti
  necessari)
- Run db:seed: ingredients +0 (catalog 55), recipes +49 (catalog 96),
  recipe-ingredient links: 323

i18n: namespace Profile esteso con dataEyebrow/Title/Subtitle, dataExport*,
dataDelete* (incluso typed errors map), working.

81/81 unit test verdi. Lint, typecheck verdi.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
lucianoandClaude Opus 4.7 committed 2026-04-30 00:24:53 +02:00
1 parent d8f2a17888
commit 60a3d072f6
8 files changed
+1206

No files matched your search

@@ -42,6 +42,21 @@ export async function fetchProfile(): Promise<unknown | null> {
return data.profile;
}
export async function deleteAccount(
password: string,
): Promise<{ ok: true } | { ok: false; error: string }> {
const cookie = headers().get('cookie') ?? '';
const res = await fetch(`${API_URL}/me`, {
method: 'DELETE',
headers: { 'Content-Type': 'application/json', cookie },
body: JSON.stringify({ password }),
cache: 'no-store',
});
if (res.status === 204) return { ok: true };
const body = (await res.json().catch(() => ({}))) as { error?: string };
return { ok: false, error: body.error ?? `api_error_${res.status}` };
}
export type SaveConditionsResult = { ok: true } | { ok: false; error: string };
export async function saveConditions(conditions: readonly string[]): Promise<SaveConditionsResult> {
@@ -0,0 +1,119 @@
'use client';
import { useRouter } from 'next/navigation';
import { useTranslations } from 'next-intl';
import { useState, useTransition } from 'react';
import { Button } from '@/components/ui/button';
import { Input } from '@/components/ui/input';
import { deleteAccount } from './actions';
export function DataPanel() {
const t = useTranslations('Profile');
const router = useRouter();
const [confirmOpen, setConfirmOpen] = useState(false);
const [password, setPassword] = useState('');
const [error, setError] = useState<string | null>(null);
const [pending, startTransition] = useTransition();
function handleDelete(): void {
setError(null);
startTransition(async () => {
const result = await deleteAccount(password);
if (!result.ok) {
setError(t(`dataDeleteErrors.${result.error}` as never) ?? t('dataDeleteErrors.api_error'));
return;
}
// Account cancellato: vai alla home pubblica.
router.replace('/');
});
}
return (
<section className="space-y-8">
<header className="space-y-3">
<p className="editorial-eyebrow">{t('dataEyebrow')}</p>
<h2 className="font-display text-ink text-3xl font-medium leading-tight tracking-tight">
{t('dataTitle')}
</h2>
<p className="font-display text-ink-soft max-w-xl text-base italic leading-snug">
{t('dataSubtitle')}
</p>
</header>
<div className="border-ink/15 border-t" />
<div className="grid gap-8 md:grid-cols-2">
<article className="space-y-3">
<p className="editorial-eyebrow">{t('dataExportEyebrow')}</p>
<p className="font-display text-ink text-base leading-snug">
{t('dataExportDescription')}
</p>
<a
href="/api/gdpr-export"
target="_blank"
rel="noopener noreferrer"
className="text-ink hover:text-pomodoro decoration-pomodoro inline-block font-mono text-[11px] uppercase tracking-widest underline decoration-[1.5px] underline-offset-[5px] transition-colors"
>
{t('dataExportAction')} ↗
</a>
</article>
<article className="border-pomodoro/40 space-y-3 border-l pl-6">
<p className="editorial-eyebrow text-pomodoro">{t('dataDeleteEyebrow')}</p>
<p className="font-display text-ink text-base leading-snug">
{t('dataDeleteDescription')}
</p>
{!confirmOpen ? (
<Button
type="button"
variant="outline"
onClick={() => setConfirmOpen(true)}
className="border-pomodoro text-pomodoro hover:bg-pomodoro hover:text-carta-light"
>
{t('dataDeleteAction')}
</Button>
) : (
<div className="space-y-3">
<p className="font-display text-pomodoro text-sm italic">{t('dataDeleteWarning')}</p>
<Input
type="password"
value={password}
onChange={(e) => setPassword(e.target.value)}
placeholder={t('dataDeletePasswordPlaceholder')}
autoComplete="current-password"
/>
{error ? (
<p className="font-display text-pomodoro text-sm italic" role="alert">
{error}
</p>
) : null}
<div className="flex flex-wrap gap-3">
<Button
type="button"
onClick={handleDelete}
disabled={pending || password.length === 0}
className="bg-pomodoro text-carta-light hover:bg-ink"
>
{pending ? t('working') : t('dataDeleteConfirm')}
</Button>
<button
type="button"
onClick={() => {
setConfirmOpen(false);
setPassword('');
setError(null);
}}
className="text-ink-soft hover:text-ink font-mono text-[11px] uppercase tracking-widest"
>
{t('dataDeleteCancel')}
</button>
</div>
</div>
)}
</article>
</div>
</section>
);
}
@@ -7,6 +7,7 @@ import { Masthead } from '@/components/masthead';
import { getServerSession } from '@/lib/auth';
import { fetchProfile } from './actions';
import { DataPanel } from './data-panel';
import { fetchNotificationConfig } from './notifications-actions';
import { NotificationsPanel } from './notifications-panel';
import { fetchPreferences } from './preferences-actions';
@@ -74,6 +75,12 @@ function ProfilePageContent({
<div className="animate-fade-up [animation-delay:660ms]">
<NotificationsPanel initial={notifications} />
</div>
<div className="rule animate-rule-in my-16 [animation-delay:780ms]" />
<div className="animate-fade-up [animation-delay:840ms]">
<DataPanel />
</div>
</main>
</div>
);
+33
View File
@@ -0,0 +1,33 @@
// Proxy verso /me/export.json (GDPR art. 20).
import { headers } from 'next/headers';
import { NextResponse } from 'next/server';
export const dynamic = 'force-dynamic';
const API_URL = process.env.API_URL ?? 'http://localhost:4000';
export async function GET(): Promise<Response> {
const cookie = headers().get('cookie') ?? '';
const upstream = await fetch(`${API_URL}/me/export.json`, {
headers: { cookie },
cache: 'no-store',
});
if (!upstream.ok) {
return NextResponse.json(
{ error: `api_error_${upstream.status}` },
{ status: upstream.status },
);
}
const body = await upstream.text();
return new NextResponse(body, {
status: 200,
headers: {
'Content-Type': 'application/json; charset=utf-8',
'Content-Disposition':
upstream.headers.get('content-disposition') ??
'attachment; filename="ketopath-export.json"',
'Cache-Control': 'no-store',
},
});
}