Skip to content

tt-time-tracker — feature queue ​

Repo: Dr-Wade/tt-time-tracker · Path: /Users/Shared/moltis/repos/tt-time-tracker Audit branch: develop Stack: Vue 3 SPA (PWA) + PrimeVue (mid-migration, see MIGRATION-PRIMEVUE.md), Tailwind, Pinia, NestJS API + BullMQ worker, Prisma/PostgreSQL, Zod schemas. UI language is French throughout — no i18n layer.

✅ Inventory built from develop @ bb3238c on 2026-07-30, after fast-forwarding 132 commits. The checkout was parked on 4458df2 from 10 March — five months stale, and separated from develop by 920 files and +125k lines. The tip commit is "Full rework with NestJS": the pre-pull tree was effectively a different application, so nothing from it survives here.

Derived from services/client/src/router/routes.ts (30 view components). Layout-shell routes are excluded: the unnamed / LayoutApp record and the unnamed /admin AdminWrapper record.

Ordering: the daily-use core (Hours) and the money path (invoices) lead, since time entry is both the product's primary capability and the data that becomes invoices. Auth follows, then admin operations, then configuration.

#FeatureRoutesPatternsStatus
1Hours / time entryhomeforms/time-input, forms/date-picker, forms/form-validation, data-display/tabledrafted
2Invoices (admin)invoices, invoice-detailsdata-display/table, forms/currency-input, content-management/modal, data-display/filter-paneldrafted
3My invoicesuser-invoicesdata-display/table, forms/currency-input, user-feedback/empty-statesdrafted
4Sign inloginauthentication/login, forms/password, forms/form-validationdrafted
5Password resetforgot-password, reset-passwordauthentication/password-reset, forms/passworddrafted
6Accept inviteaccept-inviteauthentication/signup, forms/password, forms/form-validationdrafted
7Email verificationverify-emailauthentication/signup, user-feedback/notificationdrafted
8Onboarding wizardonboardingadvanced/wizard, user-feedback/progress-indicator, forms/form-validationdrafted
9Organization chooserchoose-organizationforms/selection-input, data-display/list-viewdrafted
10User dashboarddashboarddata-display/dashboard, data-display/statistics, data-display/chartdrafted
11Projectsprojects, project-detailsdata-display/table, forms/form-validation, user-feedback/empty-statesdrafted
12Usersusers, user-detailsdata-display/table, authentication/user-profile, forms/multi-select-inputdrafted
13Task liststask-listscontent-management/drag-and-drop, data-display/list-view, forms/form-validationdrafted
14Vehiclesvehiclesdata-display/table, forms/form-validationdrafted
15Admin dashboardadmin-dashboarddata-display/dashboard, data-display/statisticsdrafted
16Overviewoverviewdata-display/table, data-display/filter-panel, data-display/statisticsdrafted
17Settingssettingsauthentication/account-settings, forms/form-validation, forms/toggledrafted
18Integrationsintegrationsdata-display/card-grid, forms/toggle, user-feedback/notificationdrafted
19Syncssyncsdata-display/table, user-feedback/progress-indicator, user-feedback/empty-statesdrafted
20API keysapi-keysdata-display/table, content-management/modal, user-feedback/notificationdrafted
21Organizations (superadmin)organizations, organization-detailsdata-display/table, forms/search-fielddrafted
22Jobs (superadmin)jobsdata-display/table, user-feedback/progress-indicatordrafted
23Profileprofileauthentication/user-profile, authentication/account-settingsdrafted
24Error statesnot-founduser-feedback/empty-states, navigation/linkdrafted
25Component gallerydev— (internal style guide, not a product surface)drafted

25 features to audit. None started.

Inventory-level observations ​

Recorded here rather than as findings — each needs a proper audit run to confirm against the baseline. Flagged so the relevant audits look for them.

  • /dev is publicly reachable. routes.ts:49 declares the route with no requiresAuth meta, and Dev.vue (506 lines) has no import.meta.env build-time gating. It is a component gallery titled « Composants », so this is design-surface exposure rather than a data leak — but it ships to production and is reachable by anyone who guesses the URL. Confirm against the build config in #25 before writing it up; a Vite-level route strip would make it moot.
  • Permission failures redirect silently with no explanation.router/index.ts bounces a non-admin off /admin/* to home, and a non-superadmin off superadmin routes to admin-dashboard. Neither path shows a "you don't have access" surface — the user clicks a link and simply lands somewhere else. Contrast with playout, customer-portal and members, which all have a dedicated forbidden/unauthorized view. Audit under #12 Users or #21; likely a cross-project inconsistency in the opposite direction from the 404 gap below.
  • This project HAS a catch-all 404 (routes.ts:71, /:pathMatch(.*) → NotFound.vue). That settles the cross-project picture: playout and tt-time-tracker have one; customer-portal and members do not. Two-for-two makes it a clear alignment issue for the final consistency pass, with the canonical behaviour already established by two of the four.
  • Two guards busy-wait on async state. router/index.ts awaits isPending and then authStore.role via watch-wrapped promises with no timeout. Same shape as the while (!session.initialized) loop in members — if either never resolves, navigation hangs with no error. Worth checking both projects against the same rule.
  • No i18n layer, French literals in templates — same as members, unlike playout (en/fr/no, CI-enforced). Do not raise hardcoded strings as i18n violations; copy-quality findings remain fair.
  • invoice-details deliberately reuses the Invoices list component (routes.ts:56-58, with a comment) so the review drawer deep-links rather than living on its own page. Audit the drawer as part of #2; do not report the shared component as a routing mistake.
  • PrimeVue migration is in flight (MIGRATION-PRIMEVUE.md). Expect mixed component idioms across views; check that doc before filing consistency findings, or they will duplicate known migration work.
  • AGENTS.md is stale — it documents the client at src/, but the rework moved it to services/client/. Not a UX finding; noted so later runs don't trust its paths.

Suggested next: #1 Hours / time entry — the daily-use core of the product, the screen every user touches most, and the origin of the data that becomes invoices. It also exercises time and date input, which no other project in the programme covers, so it will extend the baseline rather than re-confirm it.