persistence
This commit introduces a major architectural change by replacing the
previous hardcoded user and data system with a robust, database-driven
approach. It lays the foundation for persistent data storage for all
application models.
Key Changes:
- **Database Integration:** - Added `GORM` and `SQLite` for the database
layer. - The database is now initialized and migrated on application
startup. - Configuration is managed through environment variables
(`DATABASE`, `USERS_FILE`).
- **User Authentication & Management:** - The login endpoint
(`/api/token`) now authenticates users against the database. - JWT
claims are now populated with real user data (`id`, `username`,
`is_superuser`). - Implemented a system to seed the database with
initial users from a `users.json` file.
- **New User API Endpoints:** - `GET /api/users`: Retrieves a list of
all users (superuser access required). - `GET /api/users/user`: Fetches
the data for the currently authenticated user based on their JWT.
- **Data Model Overhaul:** - Refactored all data models (`User`,
`Category`, `Operation`, `Subcategory`) to include GORM tags,
relationships, and a `BaseModel` with auto-generated UUIDs for primary
keys. - Separated user-related structs into `User` (database model),
`AuthRequest` (login payload), and `UserResponse` (safe API response).
- **Middleware & Routing:** - Improved JWT error handling for clearer
client-side messages. - Added a new middleware to allow passing the JWT
in the request body for more flexible client integration.
This commit implements a full-stack authentication system using JWT.
On the backend, a new login endpoint `/api/token` is created. It
validates credentials and issues a signed JWT. A JWT middleware is added
to the server configuration to protect sensitive API endpoints like
`/api/category` and `/api/operation`. Configuration is now managed via a
`wallet.conf` file, loaded at startup.
On the frontend, this enables a complete authentication lifecycle: - A
new `/login` page allows users to enter their credentials. - A
`PrivateRoute` component wraps protected pages, redirecting
unauthenticated users to the login page. - API calls to protected
resources now include the `Authorization: Bearer <token>` header. - A
logout function is added to clear user session data.
refactor(ui): enhance history and category views
This commit also introduces major UI improvements.
The History modal has been completely redesigned. Operations are no
longer displayed as a flat list but are now grouped into tabs for Daily,
Weekly, Monthly, and Yearly views, providing a much clearer overview of
transactions.
The Categories modal now separates categories into "Incomes" and
"Expenses" tabs, reflecting the changes in the backend data model.