feat: web push notifications, mobile-ready (PRD §5.6)

ADR 0003: VAPID self-hosted today, DeviceToken model agnostic to
platform so iOS/Android (Expo/APNs/FCM) plug in as new senders later.

Backend (apps/api/src/modules/notifications)
- sender.ts: NotificationSender interface, WebPushSender via VAPID
- notifications.routes.ts: GET /me/notifications/config, POST/DELETE
  /me/device-tokens, PATCH /me/notifications/settings, POST /me/notifications/test
- scheduler.ts: node-cron Mon 09:00 Europe/Rome for weekly weigh-in
  reminder; auto-cleanup of expired tokens on 404/410
- env: VAPID_PUBLIC_KEY/PRIVATE_KEY/SUBJECT (all optional → push gracefully off)

Frontend
- public/sw.js minimal (push + notificationclick)
- lib/notifications/push-client.ts: subscribe / unsubscribe / getCurrentSubscription
- profile/notifications-{actions,panel}.tsx: editorial panel with toggles,
  device list, "send test", per-device removal
- pushReady requires both permission AND active subscription (covers the
  case where the user revoked the SW but kept the browser permission)

Schema
- DeviceToken { userId, platform, endpoint, p256dh, auth, token, userAgent,
  createdAt, lastSeenAt } with unique(userId, endpoint)
- ExtendedPrismaClient type exported from @ketopath/db
- NotificationSettings zod schema in @ketopath/shared

Tooling
- lint-staged: split .js out of eslint glob so service worker is only
  formatted (it lives outside the TS project)

i18n
- Notifications namespace (it) with typed error keys

Smoke tested: POST /me/device-tokens 201, POST /me/notifications/test 200,
real push delivered to a macOS Chrome device.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
lucianoandClaude Opus 4.7 committed 2026-04-29 21:58:35 +02:00
1 parent cdfc685855
commit bb48357179
26 files changed
+1144 -2

No files matched your search

@@ -0,0 +1,24 @@
-- CreateTable
CREATE TABLE "device_tokens" (
"id" TEXT NOT NULL,
"user_id" TEXT NOT NULL,
"platform" TEXT NOT NULL,
"endpoint" TEXT,
"p256dh" TEXT,
"auth" TEXT,
"token" TEXT,
"user_agent" TEXT,
"created_at" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
"last_seen_at" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
CONSTRAINT "device_tokens_pkey" PRIMARY KEY ("id")
);
-- CreateIndex
CREATE INDEX "device_tokens_user_id_idx" ON "device_tokens"("user_id");
-- CreateIndex
CREATE UNIQUE INDEX "device_tokens_user_id_endpoint_key" ON "device_tokens"("user_id", "endpoint");
-- AddForeignKey
ALTER TABLE "device_tokens" ADD CONSTRAINT "device_tokens_user_id_fkey" FOREIGN KEY ("user_id") REFERENCES "users"("id") ON DELETE CASCADE ON UPDATE CASCADE;
+26
View File
@@ -96,6 +96,7 @@ model User {
weightEntries WeightEntry[]
fastEvents FastEvent[]
mealPlans MealPlan[]
deviceTokens DeviceToken[]
@@map("users")
}
@@ -319,6 +320,31 @@ model MealPlan {
@@map("meal_plans")
}
// PRD §5.6 — token di un dispositivo registrato per ricevere push.
// Il modello è agnostico rispetto alla piattaforma per facilitare l'estensione
// a iOS/Android (Expo/APNs/FCM) in futuro: vedi ADR 0003.
//
// `platform` è 'web' | 'ios' | 'android'. Per web valorizziamo endpoint+p256dh+auth;
// per iOS/Android valorizziamo `token` (device token nativo o Expo push token).
model DeviceToken {
id String @id @default(cuid())
userId String @map("user_id")
platform String
endpoint String?
p256dh String?
auth String?
token String?
userAgent String? @map("user_agent")
createdAt DateTime @default(now()) @map("created_at")
lastSeenAt DateTime @default(now()) @map("last_seen_at")
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
@@unique([userId, endpoint])
@@index([userId])
@@map("device_tokens")
}
model MealSlot {
id String @id @default(cuid())
planId String @map("plan_id")
+4
View File
@@ -17,3 +17,7 @@ if (process.env.NODE_ENV !== 'production') {
}
export const prisma = baseClient.$extends(fieldEncryptionExtension());
// Tipo del client esteso (post-$extends), utile per chi consuma `app.prisma`
// fuori dai route handler (es. scheduler).
export type ExtendedPrismaClient = typeof prisma;
+3
View File
@@ -1,4 +1,5 @@
export { prisma } from './client.js';
export type { ExtendedPrismaClient } from './client.js';
export {
ActivityLevel,
CookingTime,
@@ -14,11 +15,13 @@ export {
} from '@prisma/client';
export type {
Account,
DeviceToken,
FastEvent,
Ingredient,
MealPlan,
MealSlot,
Preferences,
PrismaClient,
Profile,
Recipe,
RecipeIngredient,