Ersetzt das message-only-submit durch FeedbackSubmission (kind/title/ description/contactEmail/guestName/images/context/appVersion), exakt wie Web (@mana/shared-feedback) und iOS. Fixt den 400-Bug: der alte Client schickte nur `message`, ein Feld das das wunsch-Backend nie kannte (es verlangt `title`) -> jeder Android-Submit lief in 400. v0.8.0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
65 lines
3.2 KiB
Markdown
65 lines
3.2 KiB
Markdown
# Changelog
|
||
|
||
## 0.8.0 — 2026-06-12
|
||
|
||
- **`FeedbackClient` auf den vollen Wunsch-Backend-Vertrag gehoben**
|
||
(Breaking für Direkt-Aufrufer; einziger Konsument ist `mana-kotlin-ui`,
|
||
das mitzieht). Neu: `FeedbackKind`-Enum, `FeedbackImage`,
|
||
`FeedbackSubmission`-Datenklasse, `FeedbackResult`.
|
||
- `submit(message: String)` → `submit(submission: FeedbackSubmission,
|
||
context: Map<String,String>)`. Sendet jetzt `title`/`description`/
|
||
`kind`/`contactEmail`/`guestName`/`images`/`context`/`appVersion`/`_hp`
|
||
— exakt wie Web-`SubmitFeedbackInput` und iOS-`FeedbackClient`.
|
||
- **Bugfix:** der alte Client schickte nur `message` — ein Feld, das das
|
||
Backend **nie** kannte (es verlangt `title`, 3–140). Jeder Android-
|
||
Submit lief damit in `400 "title muss 3–140 Zeichen lang sein"` und kam
|
||
nie am Board an. Behoben.
|
||
- `images` = base64-Anhänge (ohne `data:`-Präfix), 1:1 zum Web-Vertrag.
|
||
- Konstruktor nimmt optional `appVersion` (Bug-Kontext).
|
||
|
||
## 0.4.0 — 2026-06-08
|
||
|
||
- **`AuthClient`: voller Auth-Lebenszyklus** (additiv, kein Breaking) —
|
||
portiert aus dem Swift-`ManaCore` als native Parität für die Android-Flotte:
|
||
- `register(email, password, name?, sourceAppUrl?)` → `RegisterOutcome`
|
||
(`AwaitingVerification` bei Server-Default `requireEmailVerification`,
|
||
`SignedIn` wenn der Server direkt Tokens liefert, `Failed`).
|
||
- `requestPasswordReset(email, redirectTo)` — Server antwortet
|
||
datenschutzbedingt immer 200 (kein User-Enumeration-Leak).
|
||
- `confirmPasswordReset(token, newPassword)`.
|
||
- `verifyTwoFactor(code, method = Totp|BackupCode, trustDevice)` schließt
|
||
den `signIn`-2FA-Challenge ab (`twoFactorToken` aus dem Status gelesen).
|
||
- Neuer `RegisterOutcome`-Typ + `TwoFactorMethod`-Enum (eigener Ergebnistyp
|
||
statt neuer `AuthStatus`-Variante → bestehende exhaustive `when` brechen nicht).
|
||
- 8 neue Tests (MockEngine). Endpoint-SOT: `mana/services/mana-auth/src/routes/auth.ts`.
|
||
|
||
## 0.3.0 — 2026-06-05
|
||
|
||
- **`ManaMeClient`** (`ev.mana.core.me`) — löst das Ökosystem-Profilbild
|
||
des angemeldeten Nutzers auf: fragt mana-me
|
||
`GET /api/v1/me/images/primary/avatar` (über `AuthenticatedApi`) ab und
|
||
baut die öffentliche mana-media-Thumb-URL. `avatarThumbUrl()` gibt `null`
|
||
zurück (ausgeloggt / kein Bild / Fehler) statt zu werfen. Reines Kotlin —
|
||
die Bild-Anzeige (Coil) bleibt App-Sache. Byte-/Pfad-gleich zur Web-BFF
|
||
und zum nativen Swift `ManaAvatarImageStore`. 3 Tests (MockEngine).
|
||
|
||
## 0.2.0 — 2026-06-04
|
||
|
||
- `AuthClient`: Identitäts-Methoden für Consumer (Event-Sync-Client) —
|
||
`currentAccessToken()`, `currentSubject()` (JWT-`sub`), `currentGuestId()`,
|
||
`ensureGuestId()`. 14 Tests.
|
||
|
||
## 0.1.0 — 2026-06-04
|
||
|
||
Erstes Skelett. Phase 1 des Android-Plans
|
||
([`WORDECK_ANDROID_GREENFIELD.md`](../mana/docs/playbooks/WORDECK_ANDROID_GREENFIELD.md)).
|
||
|
||
- `AuthClient` (login/refresh/logout) mit Single-Flight-Refresh,
|
||
proaktivem Refresh und Soft-Fail-Policy — portiert aus `ManaCore`
|
||
(Swift, v1.16.0).
|
||
- `TokenStore`-Interface + `InMemoryTokenStore`.
|
||
- `Jwt`-Claim-Reader (exp/sub/tier, ohne Signatur-Prüfung).
|
||
- `AuthenticatedApi` (Bearer + 401-Refresh-Retry).
|
||
- `manaHttpClient` / `ManaJson`.
|
||
- Domain-Models `Deck`, `Card` (5 text-only Typen), `Tier`.
|
||
- 12 Tests (Jwt, AuthClient, AuthenticatedApi).
|