# GuestOps Web A Linux-hosted hotel email workspace, developed separately from the Windows GuestOps application. **This migration now includes AI draft generation, staff-approved Gmail sending, reviewed OHIP reservation updates, NMI hosted invoices, controlled FAQ auto-replies and team onboarding. It is not yet a production-complete replacement.** Current release-candidate version: **0.2.0** Project progress is tracked in the [milestone report](MILESTONES.md). User-visible changes and release limitations are recorded in the [release notes](RELEASE_NOTES.md). ## Implemented so far - Responsive React inbox, message search and status filters, editable saved drafts, approved hotel answers, activity history and hotel settings. - ASP.NET Core authentication using protected HttpOnly cookies, password hashing, CSRF validation, login rate limiting and server-derived hotel membership. Owner-only settings and knowledge editing. - MongoDB storage with tenant-scoped operations, unique mailbox/message indexes, optimistic concurrency, single-use OAuth state and expiring worker leases. - Optional OpenAI drafts based on approved hotel answers, with source references and staff escalation. - Staff-approved Gmail replies with immutable approval snapshots, duplicate prevention and uncertain-delivery verification. Both AI and sending are off by default per hotel. - Google OAuth connection and a separate Gmail import/delivery worker. The first import covers seven days of inbox messages; paginated checkpoints and duplicate suppression survive restarts. - Windows-independent booking model, validation, email cleaning, JSON extraction and secret redaction migrated from the hardened desktop code. OHIP exact reservation lookup, internal notes and owner-approved stay-date changes are implemented with durable review and read-only reconciliation; writes are off by default. - Owner-reviewed NMI invoice creation, tenant-specific merchant configuration and read-only status/recovery checks. Creation may email the customer a hosted payment link through NMI; it is off by default. - Controlled FAQ auto-replies: exact plain-text questions, owner-reviewed answers, test mode, daily quotas and thread/knowledge rechecks. Live mode defaults off. - Owner-issued staff invitations, assisted password recovery, session invalidation, disabled-account restoration and a hotel setup checklist. See [team access](docs/accounts.md). - Google mailbox health, owner-only disconnect/reconnect and import restart, revoked-consent handling, retry delays and connection-bound delivery approvals. See [mailbox management](docs/mailboxes.md). - Docker image builds, private MongoDB configuration and an Nginx HTTPS example for the Debian sandbox. ## Explicit limits Staff replies require server configuration, Google send consent, hotel-owner opt-in and explicit approval of a saved reply. Controlled FAQ auto-replies additionally require reviewed rules and live-mode enablement. Broad natural-language automatic sending, wider PMS workflows, direct payment URLs in replies, self-service recovery emails, granular roles, attachments and complete Gmail-thread aggregation are follow-on work. There is no public registration endpoint. Initial hotel owners are provisioned by the server administrator. The Google integration needs OAuth credentials and a sandbox mailbox before its live behaviour can be accepted. Automated tests do not access Gmail or a hotel system. An integration being implemented is not a claim of Google verification or production readiness. ## Local development Requires .NET 10 SDK and Node.js 22. In the repository root: ```sh dotnet build src/GuestOps.Worker/GuestOps.Worker.csproj cd web npm ci npm run dev ``` In a second terminal, start the isolated preview API: ```sh # Linux/macOS shell ASPNETCORE_ENVIRONMENT=Development Preview=true dotnet run --project src/GuestOps.Api --urls http://127.0.0.1:5180 ``` PowerShell equivalent: ```powershell $env:ASPNETCORE_ENVIRONMENT='Development' $env:Preview='true' dotnet run --project src/GuestOps.Api --urls http://127.0.0.1:5180 ``` Open http://127.0.0.1:5173 and select **Open preview workspace**. Each preview login creates its own sample hotel. This mode uses temporary memory storage, does not connect real mailboxes, and cannot start in Production. Do not use the development server as a public deployment. For MongoDB-backed operation, disable Preview and set `Mongo__ConnectionString`, `Mongo__Database`, and a persistent private `Keys__Path`. See [deployment](docs/deployment.md). Operational tooling includes an owner-only Workspace health page and Linux deployment preflight, encrypted backup and isolated restore drill. See [operations and recovery](docs/operations.md) before the hotel pilot. ## Verification ```sh dotnet run --project tests/GuestOps.Tests cd web && npm ci && npm run build ``` Set `MONGO_TEST_URI` to an isolated MongoDB server and `TEST_API_URL=http://127.0.0.1:5180` with a preview API running to enable database and HTTP integration checks. The suite creates and drops only its own randomly named `guestops_test_*` database. CI runs both integrations and builds both Linux images. See [controlled FAQ automation](docs/auto-replies.md), [NMI payment setup and recovery](docs/payments.md), [OHIP reservation setup and recovery](docs/pms.md), [AI drafts and reply delivery setup](docs/replies.md), [migration status](docs/migration.md) and [deployment guide](docs/deployment.md).