Resolve the operational/config sprawl (#10-#14 from the review): the app read NORMOGEN_*/MONGODB_* env vars but every env/compose file set SERVER_*/DATABASE_*, the ports were all over the place (8080/8000/6500/6800), there were 5 inconsistent Dockerfiles (rust:1.82 vs rust:1.93, missing curl), and an 18 MB binary was committed. Env-var names — standardize on what the code reads: * config/mod.rs: NORMOGEN_PORT default 8080 -> 6500 (avoid the over-common 8000/8080). * db/mod.rs: create_database() now reads MONGODB_DATABASE (was DATABASE_NAME). * .env.example, defaults.env, docker-compose.yml, docker-compose.dev.yml, DEPLOYMENT_GUIDE.md, deployment/README.md, deploy-and-test-solaria.sh, deploy-local-build.sh: use NORMOGEN_HOST/NORMOGEN_PORT/MONGODB_URI/ MONGODB_DATABASE/APP_ENVIRONMENT; drop the dead SERVER_*/DATABASE_URI/ DATABASE_NAME names. Ports — canonical container port 6500 everywhere: * Both Dockerfiles EXPOSE 6500; prod compose maps 6500:6500, dev 6501:6500. * Bulk-replaced the long tail of solaria:8000/localhost:8000/localhost:8080 in docs and test scripts -> 6500. Dockerfiles — 2 canonical, rust:latest, curl + healthcheck: * backend/Dockerfile (prod): rust:latest builder, debian runtime now installs curl (so the compose HEALTHCHECK actually works), EXPOSE 6500. * backend/docker/Dockerfile.dev (dev): rust:latest both stages, EXPOSE 6500. * Deleted 3 redundant Dockerfiles (Dockerfile.improved x2, docker/Dockerfile). * Deleted the committed 18 MB binary backend/docker/normogen-backend. * Deleted 2 stray fix-notes in backend/docker/. Compose: * docker-compose.yml: correct env names, 6500:6500, APP_ENVIRONMENT=production, JWT_SECRET/ENCRYPTION_KEY required via compose interpolation, dropped the obsolete top-level version: key. * docker-compose.dev.yml: correct env names, 6501:6500, mongo:7 (was 6.0), added a working backend healthcheck. * Deleted docker/docker-compose.improved.yml + backend/deploy-to-solaria-improved.sh (built around the now-deleted 'improved' Docker files). Verified: cargo fmt --check clean, build + clippy --all-targets clean, 18 unit tests pass; grep confirms no SERVER_*/DATABASE_* env names and no rust:1.x tags remain outside docs/archive and docs/adr (historical). |
||
|---|---|---|
| .. | ||
| FRONTEND_STATUS.md | ||
| MEDICATION_MANAGEMENT_IMPLEMENTATION_SUMMARY.md | ||
| MVP_PHASE_2.7_SUMMARY.md | ||
| PHASE-2-3-COMPLETION-REPORT.md | ||
| PHASE-2-4-COMPLETE.md | ||
| PHASE-2-5-COMPLETE.md | ||
| PHASE27_COMPLETION_REPORT.md | ||
| PHASE28_FINAL_STATUS.md | ||
| PHASE_2.6_COMPLETION.md | ||
| README.md | ||
Implementation Documentation
Phase-by-phase implementation completion records. Each phase that's been built has a canonical completion note here; original plans and specs are in ../archive/.
By Phase
Phase 2.3 — JWT Authentication ✅
Phase 2.4 — User Management ✅
- (completion notes folded into ../product/STATUS.md)
Phase 2.5 — Access Control ✅
Phase 2.6 — Security Hardening ✅
Phase 2.7 — Health Data Features ✅
- PHASE27_COMPLETION_REPORT.md - Completion report
- MVP_PHASE_2.7_SUMMARY.md - MVP prioritization
- MEDICATION_MANAGEMENT_IMPLEMENTATION_SUMMARY.md - Medication CRUD
- Original plans: ../archive/
Phase 2.8 — Drug Interactions ✅
- PHASE28_FINAL_STATUS.md - Completion (interactions live)
- Original plan + specs: ../archive/
Frontend 🚧
- FRONTEND_STATUS.md - Current frontend status
Implementation Progress
| Phase | Status |
|---|---|
| 2.3 | ✅ Implemented |
| 2.4 | ✅ Implemented |
| 2.5 | ✅ Implemented |
| 2.6 | ✅ Implemented |
| 2.7 | ✅ Implemented |
| 2.8 | ✅ Implemented (drug interactions) |
| P0/P1 Security + Tests | ✅ Implemented |
| Frontend (Phase 3) | 🚧 Early |
Key Features Implemented
- JWT authentication with token rotation +
token_versioninvalidation - User management (profiles, settings, password change/recovery)
- Permission-based access control + share management
- Security hardening (audit logging, account lockout, session management)
- Medication management (CRUD, dose logging, adherence)
- Health statistics tracking + trends
- Drug interaction checking (OpenFDA-based ingredient mapping)
- Refresh-token persistence (hashed, revocable) +
/refreshand/logout - Fail-fast production config + real client-IP audit logging
Last Updated: 2026-06-27