Skip to content

feat(pcb-portal): QodeX PCB website, customer portal and 3D Studio (USD, Stripe + PayPal) - #108

Closed
QodeXcli wants to merge 2 commits into
mainfrom
claude/qodex-pcb-comprehensive-spec-5emn57
Closed

QodeXcli wants to merge 2 commits into
mainfrom
claude/qodex-pcb-comprehensive-spec-5emn57

Conversation

@QodeXcli

@QodeXcli QodeXcli commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds pcb-portal/: the public website, customer ordering portal and admin panel for the QodeX PCB routing service. It is English-only and international, and all prices are in US dollars. Routing itself is not done on the site: it runs offline on the operator's workstation. The site handles orders, payment, file exchange and 3D review.

Public site (rendered on the server, SEO-ready)

  • Pages: home, how it works, 3D Studio, use cases plus six domain pages (RF, high-speed digital, power, mixed-signal, flex, HDI), KiCad integration, pricing estimator, evidence library, docs & DFM academy, trust & security, about, careers, contact, legal.
  • The home page has a live 3D hero, board telemetry and a before/after slider showing the DFM polish.
  • Every page gets canonical, Open Graph and JSON-LD metadata. sitemap.xml, robots.txt and llms.txt are generated.

Ordering and payments

  • The customer drops a .kicad_pcb and gets a 3D preview and quote straight away in the browser. The server parses the board again, and its numbers win for pricing.
  • Payment is in USD through Stripe Checkout (cards, Apple Pay, Google Pay, Link), with a signed webhook, or PayPal Orders v2. The customer chooses the method at checkout.
  • Payments are verified server-to-server, and recording a payment is idempotent and safe under concurrent callbacks. If the admin changes the price, any open checkout is cancelled. Customers get printable receipts.

3D viewer

  • Formats: .kicad_pcb (KiCad 5 to 9), .glb, .gltf, .stl, .obj, .wrl.
  • Layer toggles, solder-mask transparency and an exploded-stack view.
  • Inspect: hover to identify parts and copper, click to highlight a whole net and show its routed length.
  • Measure: distance, ΔX/ΔY and mils. Also auto-rotate, PNG screenshot and fullscreen.

Portal and admin

  • Customer portal: dashboard, new order, order detail (status steps, deliverables, engineer message thread, activity log), billing & receipts, account settings.
  • Admin: order queue with stats, price/status/internal notes (internal notes are never sent to customers), deliverable upload with an optional "mark delivered", customers, contact-form inbox, and a tariff editor.

Security

  • Files are stored privately and only served after an ownership check.
  • scrypt password hashing, HttpOnly/SameSite sessions and a CSRF guard based on a custom header.
  • Rate limits on auth and on the contact form.
  • A strict CSP with no third-party scripts, plus an upload file-type allow-list and size cap.

Stack: Express 5 + better-sqlite3 + three.js. There is no build step. It is self-contained in pcb-portal/, and the root CLI build and tests are unaffected.

Testing

  • cd pcb-portal && npm test: 38 node:test tests pass. They cover:
    • the KiCad parser, including net resolution, and pricing;
    • every public page renders with no unfilled placeholders and no non-English script;
    • the full order, payment and delivery API, including access control and admin-note privacy;
    • the contact inbox, including the honeypot;
    • PayPal (create, forged-token rejection, capture) and Stripe (bad-signature rejection, signed webhook) against stubbed providers.
  • Ran the whole flow end to end in headless Chromium: register → upload → preview/quote → mock payment → admin delivers GLB and KiCad files → customer views them in 3D → receipt. No browser errors. Also verified inspect, measure, net highlighting and the mobile navigation.

🤖 Generated with Claude Code

https://claude.ai/code/session_017BQf54SD6EFwPyF5xPtqv8

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@QodeXcli QodeXcli changed the title feat(pcb-portal): customer ordering, payment and 3D board viewer site feat(pcb-portal): QodeX PCB website, customer portal and 3D Studio (USD, Stripe + PayPal) Sep 30, 2026
Add pcb-portal/, an English-only international website and ordering portal
for the QodeX PCB routing service. Routing runs offline on the operator's
workstation; the site handles order intake, USD payments, file exchange
and in-browser 3D review.

- Server-rendered public site with SEO metadata, sitemap, robots and
  llms.txt: home, how it works, 3D Studio, use cases (six domains), KiCad
  integration, pricing estimator, evidence library, docs, trust &
  security, about, careers, contact, legal.
- Ordering: .kicad_pcb parsed in the browser for preview and quote, and on
  the server (authoritative for pricing).
- Payments in USD: Stripe Checkout with signed webhook, PayPal Orders v2;
  server-to-server verification, idempotent finalisation, receipts.
- 3D viewer for .kicad_pcb (KiCad 5-9), glb, gltf, stl, obj, wrl: layers,
  mask transparency, exploded stack, inspect with net highlighting,
  measuring tool.
- Customer portal and admin panel (queue, pricing, deliverables,
  customers, inquiries, tariffs).
- 38 node:test tests; CI job added.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017BQf54SD6EFwPyF5xPtqv8
@QodeXcli
QodeXcli force-pushed the claude/qodex-pcb-comprehensive-spec-5emn57 branch from ace730f to d03adfe Compare September 30, 2026 13:52
- Rate limiting: use express-rate-limit on the customer and admin API
  routers (plus stricter limits on auth, contact and the Stripe webhook).
- Cookies: read the session cookie by name instead of building an object
  keyed by header input (remote property injection).
- Login redirect: follow `next` only when it resolves to this origin and
  prefix it with location.origin (a `/\evil.com` value previously passed).
- Password change moved to POST /api/auth/password, which always verifies
  the current password; PATCH /api/auth/me only updates the profile.
- Package description updated for Stripe / PayPal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017BQf54SD6EFwPyF5xPtqv8
assert.equal(bad.status, 400);

// the customer comes back before Stripe reports the session as paid
stripeSession.payment_status = 'unpaid';
@QodeXcli QodeXcli closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants