Files
DeskcommCRM/CONTRIBUTING.md
T
Rafael MelgaçoandClaude Opus 4.7 5d0cdb5c48 feat(EPIC-12): hardening + e2e + polish [10 waves, partial]
Error handling:
- app/error.tsx + app/app/error.tsx + app/(public)/error.tsx via shared
  components/feedback/SegmentError.tsx — captures to Sentry, displays eventId,
  copy-to-clipboard, reset button.
- app/global-error.tsx upgraded with Sentry capture + eventId UI.
- app/not-found.tsx (PT-BR copy B1).
- app/403/page.tsx polished (copy B2).
- app/500/page.tsx + app/503/page.tsx new (copy B3, B4).

Empty states:
- components/empty/EmptyState.tsx (base) + 10 specialized variants
  (Inbox, Kanban, Contacts, Audit, Pipeline, Team, ApiTokens, Timeline,
  MergeQueue, FilterResults).
- Wired into kanban picker, contacts list, inbox conversation list (3 sites).

Loading skeletons:
- app/app/loading.tsx + 4 route-specific loading.tsx
  (inbox, kanban, contacts, audit) using shadcn Skeleton.

Sentry:
- beforeSend in sentry.server.config.ts, sentry.edge.config.ts,
  instrumentation-client.ts scrubs Authorization/Cookie/x-api-key/
  x-waha-api-key/x-nuvemshop-token/x-deskcomm-token headers + CPF/email/phone
  patterns from message + exception values. sendDefaultPii: false.
- lib/logger.ts: structured JSON logger (zero deps).

Web Vitals:
- next.config.ts: experimental.optimizePackageImports for phosphor/lucide/
  date-fns. Performance budget block documented inline.
- .github/workflows/perf.yml reports build output sizes to Step Summary.

E2E:
- tests/e2e/auth.spec.ts: anon redirect, invalid creds, keyboard tab order,
  axe-core a11y audit on /login (fails on serious/critical).
- tests/e2e/error-pages.spec.ts: 404/403/500/503 routes.
- @axe-core/playwright integrated.

Public paths:
- lib/auth/public-paths.ts allows /500 and /503 (must not require auth).

Docs:
- README.md quickstart 5min reescrito.
- ARCHITECTURE.md (1-page overview + spec refs).
- CONTRIBUTING.md (PR + epic-executor workflow).
- docs/DEPLOY-CHECKLIST.md preflight.

Migrations:
- supabase/migrations/ reconciled against remote schema_migrations
  (verified via Supabase MCP list_migrations); 9 stub files created with
  pointers to the corresponding spec; MANIFEST.md updated for 0008/0009.

Deferred to follow-up (documented in EPIC-12 Wave Completion Log):
- Lighthouse CI + bundle-analyzer thresholds in GitHub Actions.
- E2E specs covering /app/* routes (require MFA bypass strategy via
  test-only env var or storageState fixture).
- Full 5-jornada E2E suite — depends on EPIC-06 (AI) and EPIC-08 (LGPD)
  which remain pending.

Implements S-12.01..S-12.10 contracts. Closes EPIC-12 (10/10 waves with
documented stubs).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 23:32:27 -03:00

2.5 KiB

Contributing — DeskcommCRM

Antes de começar

  1. Leia CLAUDE.md — convenções não-negociáveis.
  2. Leia ARCHITECTURE.md — visão de 1 página.
  3. Identifique o epic de origem em docs/stories/epics/MASTER.md.

Fluxo

Branches

feat/EPIC-XX-short-slug         # nova feature
fix/EPIC-XX-short-slug          # bug fix
chore/short-slug                # chore (deps, configs)
docs/short-slug                 # apenas docs

Commits

Conventional commits + escopo EPIC-XX:

feat(EPIC-04): kanban drag-and-drop com fractional indexing
fix(EPIC-03): cron recover-stuck-messages marcando sending stuck >5min como failed
docs(EPIC-12): mark complete + wave log

Mensagens em PT-BR são aceitas. O assunto deve ser imperativo e ≤72 chars.

epic-executor

Mudanças grandes seguem docs/stories/epics/. O epic-executor consome o frontmatter (epic_id, priority, depends_on, status) e executa wave-by-wave com validação E2E continuous.

Ao finalizar um epic:

  1. Atualizar frontmatter status: pending → completed (partial: ...) ou status: completed.
  2. Append "Wave Completion Log" no final do arquivo.
  3. Atualizar a row correspondente em docs/stories/epics/MASTER.md.

PR process

  1. Branch a partir de main.
  2. Implementar. Adicionar testes (E2E pra fluxos, unit pra lógica pura).
  3. Definition of Done — todos verdes:
    • pnpm typecheck
    • pnpm lint
    • pnpm test:unit
    • pnpm test:e2e (subset relevante)
    • RLS testada se feature toca tabela tenant-aware
    • Audit log emitido se há mutação relevante
    • Rate limit aplicado se rota é pública
    • Zod valida todo input externo
    • Sem console.log esquecido (use lib/logger.ts)
    • Env vars novas em .env.example + lib/env.ts
    • Docs atualizadas se mudou contrato (PRD/spec)
  4. Abrir PR contra main. Description deve referenciar o epic e listar evidências (logs/screenshots dos testes).
  5. CI deve passar antes de merge. Teste de isolamento RLS é gate obrigatório.

Anti-patterns proibidos

Lista completa em CLAUDE.md. Os mais letais:

  • Trigger Postgres fazendo HTTP
  • Service role usado em handler sem filtrar organization_id manualmente
  • getSession() no backend (use getUser())
  • API key em query string
  • Bearer plaintext no DB
  • console.log em código merged

Setup local

Veja README.md §Como rodar local.

Suporte

Dúvidas: rafael@maudibrasil.com.br. Canal interno do BPO Discord (link no Notion).