Appearance
tt-time-tracker — feature queue
Repo: Dr-Wade/tt-time-tracker · Path: /Users/Shared/moltis/repos/tt-time-tracker Audit branch: develop Stack: Vue 3 SPA (PWA) + PrimeVue (mid-migration, see MIGRATION-PRIMEVUE.md), Tailwind, Pinia, NestJS API + BullMQ worker, Prisma/PostgreSQL, Zod schemas. UI language is French throughout — no i18n layer.
✅ Inventory built from
develop@bb3238con 2026-07-30, after fast-forwarding 132 commits. The checkout was parked on4458df2from 10 March — five months stale, and separated fromdevelopby 920 files and +125k lines. The tip commit is "Full rework with NestJS": the pre-pull tree was effectively a different application, so nothing from it survives here.
Derived from services/client/src/router/routes.ts (30 view components). Layout-shell routes are excluded: the unnamed / LayoutApp record and the unnamed /admin AdminWrapper record.
Ordering: the daily-use core (Hours) and the money path (invoices) lead, since time entry is both the product's primary capability and the data that becomes invoices. Auth follows, then admin operations, then configuration.
| # | Feature | Routes | Patterns | Status |
|---|---|---|---|---|
| 1 | Hours / time entry | home | forms/time-input, forms/date-picker, forms/form-validation, data-display/table | drafted |
| 2 | Invoices (admin) | invoices, invoice-details | data-display/table, forms/currency-input, content-management/modal, data-display/filter-panel | drafted |
| 3 | My invoices | user-invoices | data-display/table, forms/currency-input, user-feedback/empty-states | drafted |
| 4 | Sign in | login | authentication/login, forms/password, forms/form-validation | drafted |
| 5 | Password reset | forgot-password, reset-password | authentication/password-reset, forms/password | drafted |
| 6 | Accept invite | accept-invite | authentication/signup, forms/password, forms/form-validation | drafted |
| 7 | Email verification | verify-email | authentication/signup, user-feedback/notification | drafted |
| 8 | Onboarding wizard | onboarding | advanced/wizard, user-feedback/progress-indicator, forms/form-validation | drafted |
| 9 | Organization chooser | choose-organization | forms/selection-input, data-display/list-view | drafted |
| 10 | User dashboard | dashboard | data-display/dashboard, data-display/statistics, data-display/chart | drafted |
| 11 | Projects | projects, project-details | data-display/table, forms/form-validation, user-feedback/empty-states | drafted |
| 12 | Users | users, user-details | data-display/table, authentication/user-profile, forms/multi-select-input | drafted |
| 13 | Task lists | task-lists | content-management/drag-and-drop, data-display/list-view, forms/form-validation | drafted |
| 14 | Vehicles | vehicles | data-display/table, forms/form-validation | drafted |
| 15 | Admin dashboard | admin-dashboard | data-display/dashboard, data-display/statistics | drafted |
| 16 | Overview | overview | data-display/table, data-display/filter-panel, data-display/statistics | drafted |
| 17 | Settings | settings | authentication/account-settings, forms/form-validation, forms/toggle | drafted |
| 18 | Integrations | integrations | data-display/card-grid, forms/toggle, user-feedback/notification | drafted |
| 19 | Syncs | syncs | data-display/table, user-feedback/progress-indicator, user-feedback/empty-states | drafted |
| 20 | API keys | api-keys | data-display/table, content-management/modal, user-feedback/notification | drafted |
| 21 | Organizations (superadmin) | organizations, organization-details | data-display/table, forms/search-field | drafted |
| 22 | Jobs (superadmin) | jobs | data-display/table, user-feedback/progress-indicator | drafted |
| 23 | Profile | profile | authentication/user-profile, authentication/account-settings | drafted |
| 24 | Error states | not-found | user-feedback/empty-states, navigation/link | drafted |
| 25 | Component gallery | dev | — (internal style guide, not a product surface) | drafted |
25 features to audit. None started.
Inventory-level observations
Recorded here rather than as findings — each needs a proper audit run to confirm against the baseline. Flagged so the relevant audits look for them.
/devis publicly reachable.routes.ts:49declares the route with norequiresAuthmeta, andDev.vue(506 lines) has noimport.meta.envbuild-time gating. It is a component gallery titled « Composants », so this is design-surface exposure rather than a data leak — but it ships to production and is reachable by anyone who guesses the URL. Confirm against the build config in #25 before writing it up; a Vite-level route strip would make it moot.- Permission failures redirect silently with no explanation.
router/index.tsbounces a non-admin off/admin/*tohome, and a non-superadmin off superadmin routes toadmin-dashboard. Neither path shows a "you don't have access" surface — the user clicks a link and simply lands somewhere else. Contrast with playout, customer-portal and members, which all have a dedicated forbidden/unauthorized view. Audit under #12 Users or #21; likely a cross-project inconsistency in the opposite direction from the 404 gap below. - This project HAS a catch-all 404 (
routes.ts:71,/:pathMatch(.*)→NotFound.vue). That settles the cross-project picture: playout and tt-time-tracker have one; customer-portal and members do not. Two-for-two makes it a clear alignment issue for the final consistency pass, with the canonical behaviour already established by two of the four. - Two guards busy-wait on async state.
router/index.tsawaitsisPendingand thenauthStore.roleviawatch-wrapped promises with no timeout. Same shape as thewhile (!session.initialized)loop in members — if either never resolves, navigation hangs with no error. Worth checking both projects against the same rule. - No i18n layer, French literals in templates — same as members, unlike playout (en/fr/no, CI-enforced). Do not raise hardcoded strings as i18n violations; copy-quality findings remain fair.
invoice-detailsdeliberately reuses theInvoiceslist component (routes.ts:56-58, with a comment) so the review drawer deep-links rather than living on its own page. Audit the drawer as part of #2; do not report the shared component as a routing mistake.- PrimeVue migration is in flight (
MIGRATION-PRIMEVUE.md). Expect mixed component idioms across views; check that doc before filing consistency findings, or they will duplicate known migration work. AGENTS.mdis stale — it documents the client atsrc/, but the rework moved it toservices/client/. Not a UX finding; noted so later runs don't trust its paths.
Suggested next: #1 Hours / time entry — the daily-use core of the product, the screen every user touches most, and the origin of the data that becomes invoices. It also exercises time and date input, which no other project in the programme covers, so it will extend the baseline rather than re-confirm it.