SHEET 03 · DRAWING REGISTER
DETAIL SHEET 03.1 — P-01
Jamigos
A deliberately simple app — sign in, see a dashboard for your role, manage your own items — used to practise everything around it: security, testing and delivery.
Browser · Vue 3Pinia · keycloak-js
JWTSpring Boot API3 security filter chains
@PreAuthorize · @RequireOwner
audit-log aspect
@PreAuthorize · @RequireOwner
audit-log aspect
PostgreSQLusers · JPA
MongoDBitems · audit log
KeycloakOAuth2 / OIDC · PKCE · custom login theme
SPECIFICATION
- SECURITY
- Three ordered security chains: public API docs, Actuator behind basic auth, the API behind JWT. Roles read from the token; method security and a custom ownership annotation enforced by an aspect.
- DATA
- PostgreSQL for users (JPA), MongoDB for items and the audit log.
- TESTING
- Unit, slice, security and integration tests on Testcontainers.
- FRONTEND
- Vue 3, Pinia, Vite; Capacitor builds for iOS and Android.
- DELIVERY
- Docker images for backend, frontend and Keycloak; local, dev and prod profiles.
- detect changes
- build & test
- image → GHCR
- deploy
REV. NOTE The jamigos.app domain is retired. The code, tests and pipeline stay public on GitHub.