62 lines
3.7 KiB
Markdown
62 lines
3.7 KiB
Markdown
# GuestOps Web
|
|
|
|
A Linux-hosted hotel email workspace, developed separately from the Windows GuestOps application. **This migration now includes AI draft generation and staff-approved Gmail sending. It is not yet a production-complete replacement.**
|
|
|
|
## Implemented so far
|
|
|
|
- Responsive React inbox, message search and status filters, editable saved drafts, approved hotel answers, activity history and hotel settings.
|
|
- ASP.NET Core authentication using protected HttpOnly cookies, password hashing, CSRF validation, login rate limiting and server-derived hotel membership. Owner-only settings and knowledge editing.
|
|
- MongoDB storage with tenant-scoped operations, unique mailbox/message indexes, optimistic concurrency, single-use OAuth state and expiring worker leases.
|
|
- Optional OpenAI drafts based on approved hotel answers, with source references and staff escalation.
|
|
- Staff-approved Gmail replies with immutable approval snapshots, duplicate prevention and uncertain-delivery verification. Both AI and sending are off by default per hotel.
|
|
- Google OAuth connection and a separate Gmail import/delivery worker. The first import covers seven days of inbox messages; paginated checkpoints and duplicate suppression survive restarts.
|
|
- Windows-independent booking model, validation, email cleaning, JSON extraction and secret redaction migrated from the hardened desktop code. Live PMS writes have not been ported or enabled.
|
|
- Docker image builds, private MongoDB configuration and an Nginx HTTPS example for the Debian sandbox.
|
|
|
|
## Explicit limits
|
|
|
|
Real email is sent only after server configuration, Google send consent, hotel-owner opt-in and explicit staff approval of a saved reply. Automatic sending, PMS/payment workflows, staff invitation/password-reset UI, attachments and complete Gmail-thread aggregation are follow-on work. There is no public registration endpoint. Initial hotel owners are provisioned by the server administrator.
|
|
|
|
The Google integration needs OAuth credentials and a sandbox mailbox before its live behaviour can be accepted. Automated tests do not access Gmail or a hotel system. An integration being implemented is not a claim of Google verification or production readiness.
|
|
|
|
## Local development
|
|
|
|
Requires .NET 10 SDK and Node.js 22. In the repository root:
|
|
|
|
```sh
|
|
dotnet build src/GuestOps.Worker/GuestOps.Worker.csproj
|
|
cd web
|
|
npm ci
|
|
npm run dev
|
|
```
|
|
|
|
In a second terminal, start the isolated preview API:
|
|
|
|
```sh
|
|
# Linux/macOS shell
|
|
ASPNETCORE_ENVIRONMENT=Development Preview=true dotnet run --project src/GuestOps.Api --urls http://127.0.0.1:5180
|
|
```
|
|
|
|
PowerShell equivalent:
|
|
|
|
```powershell
|
|
$env:ASPNETCORE_ENVIRONMENT='Development'
|
|
$env:Preview='true'
|
|
dotnet run --project src/GuestOps.Api --urls http://127.0.0.1:5180
|
|
```
|
|
|
|
Open http://127.0.0.1:5173 and select **Open preview workspace**. Each preview login creates its own sample hotel. This mode uses temporary memory storage, does not connect real mailboxes, and cannot start in Production. Do not use the development server as a public deployment.
|
|
|
|
For MongoDB-backed operation, disable Preview and set `Mongo__ConnectionString`, `Mongo__Database`, and a persistent private `Keys__Path`. See [deployment](docs/deployment.md).
|
|
|
|
## Verification
|
|
|
|
```sh
|
|
dotnet run --project tests/GuestOps.Tests
|
|
cd web && npm ci && npm run build
|
|
```
|
|
|
|
Set `MONGO_TEST_URI` to an isolated MongoDB server and `TEST_API_URL=http://127.0.0.1:5180` with a preview API running to enable database and HTTP integration checks. The suite creates and drops only its own randomly named `guestops_test_*` database. CI runs both integrations and builds both Linux images.
|
|
|
|
See [AI drafts and reply delivery setup](docs/replies.md), [migration status](docs/migration.md) and [deployment guide](docs/deployment.md).
|