Imported from zivah-international/website (
AGENTS.md). Install upstream withnpx skills add zivah-international/website. Copyright stays with the author.
Zivah Website — Agent Guide
Purpose and architecture
- This is the full-stack Zivah corporate website: Next.js 16 App Router, React 19, TypeScript, Tailwind CSS 4, and Radix UI primitives.
- It uses a custom session-based authentication system backed by PostgreSQL. Tokens are UUIDs
stored in the
sessionstable and delivered via encryptedHttpOnlycookies. Route Handlers live undersrc/app/api/auth/. There is no external OIDC provider (like Cognito). - Admin dashboard routes live in
src/app/admin, while public pages (Home, Products, Quality, Contact, Quote) are insrc/app. - The database architecture is two-tier:
- Runtime: Direct PostgreSQL queries using the
pgconnection pool (src/lib/db.ts). - Development/Migrations: Prisma is used for schema management and seeding only. Never import
@prisma/clientin application code.
- Runtime: Direct PostgreSQL queries using the
Contracts and implementation rules
- The application is monolithic. Browser code calls the internal Next.js API routes at
/api/*. - Use Zod schemas for strict input validation on all API endpoints.
- Passwords must be hashed using
bcryptjs(12 salt rounds). - Prevent SQL injection by strictly using parameterized queries in all
pgdatabase calls. Never use string concatenation for SQL queries. - Keep user-facing copy in Spanish, with support for English via internationalization (
next-intl). - Reuse existing Radix UI components and design tokens; do not introduce competing UI libraries.
- The system handles quotes and product inquiries. Pay close attention to measurement units and variations in the
quotesandproductstables.
Validation and delivery
-
Use
pnpm. Before handoff run, as applicable:pnpm format:check pnpm type-check pnpm lint pnpm build git diff --check -
Deployment is targeting a cPanel Node.js hosting environment using standalone output. Do not assume Vercel or Amplify-specific build behaviors.
-
Do not commit
.next/,node_modules/,.env*, credentials, tokens, certificates, or unrelated working-tree changes.
