Milestone 2: module/model docs (MD, Sphinx RST, PDF) and work log

74 source modules documented with extracted signatures, JSDoc params,
imports, and call graphs. 10 first-class models (PriceRule through
StatusResponse) have their own MD/RST/PDF. Sphinx HTML builds from
docs/sphinx. Per-module PDFs in docs/modules-pdf and docs/models-pdf.

Middleware gates 2–6 and 10 pass on MOCK_VERAE without NATS.

Learned: RST includes are relative to the RST file; keep one PDF per
module; Add Numbers remains the only push required tomorrow.
This commit is contained in:
George Lambert 2026-09-09 02:44:51 -04:00
parent b814501441
commit 10c663cc0c
347 changed files with 17200 additions and 14 deletions

View file

@ -0,0 +1,71 @@
# `zappier/accounts`
**Package:** `zappier`
**Source:** `packages/zappier/src/accounts.ts`
**Lines:** 166
## What this module is
Implementation module in `zappier`. The tables below are extracted from the source (signatures + JSDoc).
## Exports
`hashPassword`, `verifyPassword`, `base32Encode`, `base32Decode`, `hotp`, `totp`, `verifyTotp`, `generateTotpSecret`, `totpUri`, `PortalSession`, `SessionRepo`, `newSessionToken`, `InMemorySessionRepo`
## Types / interfaces / classes
| Kind | Name |
|------|------|
| interface | `PortalSession` |
| interface | `SessionRepo` |
| class | `InMemorySessionRepo` |
## Functions
| Name | Parameters | Param types (JSDoc) | Returns | Calls (same file / helpers) |
|------|------------|---------------------|---------|-----------------------------|
| `hashPassword` | `password: string` | — | `unknown` | see Call graph |
| | _Format: scrypt:N:r:p:<salt b64>:<hash b64>_ | | | |
| `verifyPassword` | `password: string, stored: string` | — | `unknown` | see Call graph |
| `base32Encode` | `buf: Buffer` | — | `unknown` | see Call graph |
| `base32Decode` | `s: string` | — | `unknown` | see Call graph |
| `hotp` | `secret: string, counter: number, digits = 6` | — | `unknown` | see Call graph |
| `totp` | `secret: string, atMs: number, stepSec = 30, digits = 6` | — | `unknown` | see Call graph |
| `verifyTotp` | `secret: string,
code: string,
atMs: number,
window = 1,` | — | `unknown` | see Call graph |
| `generateTotpSecret` | `(none)` | — | `unknown` | see Call graph |
| | _160-bit secret, base32 without padding (authenticator-app standard)._ | | | |
| `totpUri` | `secret: string, email: string, issuer = 'Zappier'` | — | `unknown` | see Call graph |
| | _160-bit secret, base32 without padding (authenticator-app standard)._ | | | |
| `newSessionToken` | `(none)` | — | `unknown` | see Call graph |
| | _Returns the session, or undefined when unknown or expired at nowMs._ | | | |
## Methods (class / object)
| Name | Parameters |
|------|------------|
| `create` | `customerId: string, ttlMs: number` |
| `get` | `token: string, nowMs?: number` |
| `delete` | `token: string` |
| `create` | `customerId: string, ttlMs: number` |
| `get` | `token: string, nowMs = Date.now(` |
| `delete` | `token: string` |
## What it imports / requires
- `crypto`
## Call graph (identifiers invoked)
`hashing`, `secrets`, `hashPassword`, `randomBytes`, `scryptSync`, `toString`, `verifyPassword`, `split`, `from`, `timingSafeEqual`, `base32`, `base32Encode`, `base32Decode`, `toUpperCase`, `replace`, `indexOf`, `push`, `hotp`, `alloc`, `writeBigUInt64BE`, `createHmac`, `update`, `digest`, `padStart`, `totp`, `floor`, `verifyTotp`, `test`, `padding`, `generateTotpSecret`, `totpUri`, `encodeURIComponent`, `create`, `get`, `delete`, `newSessionToken`, `now`, `set`
Each identifier is a call site in this file. Follow the import list to see the defining module; open that modules MD for parameter and return types.
## Return values (how to read this)
- HTTP route handlers return Express `res.json(...)` bodies (see route docs).
- Zapier `perform` functions return a **single object** (creates) or an **array** (triggers/searches).
- Pricing functions return integer **cents** on `Quote.totalCents`.