- Split database.py into a runtime engine (scoped `kds` DB role, used for
all request handling) and a migration engine (privileged `kitchen` role,
used only at startup to create KDS's own tables and ALTER kitchen_settings)
— KDS previously shared kitchen's full-access DB credential wholesale
- Dispose both engines on shutdown (main.py)
- Fix theme colour clash: KDS was accidentally seeded with kitchen's teal
(#0d9488) instead of its own colour — now #ea580c (orange), regenerated
PWA icons to match
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
iOS Safari has no beforeinstallprompt API, so the portal's Install
button (?install=1) silently did nothing there. IosInstallHint now
shows Share -> Add to Home Screen steps on Safari, or a prompt to
switch to Safari first if opened in another iOS browser/in-app
webview (those can't install PWAs on iOS at all).
Also added apple-mobile-web-app-title + apple-touch-icon so the
home screen icon isn't a page screenshot, and added the
beforeinstallprompt handler that was missing entirely (Android
Install button did nothing either).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
index.html linked /kds/manifest.json, which never existed (404).
Replaced with vite-plugin-pwa, matching the pattern used by every
other app, plus icons that were entirely missing before.
Same fix as kitchen: AuthGate unconditionally hard-navigated
window.top to the central /login on session expiry, even when not
embedded in the portal iframe — dropping an installed/directly-opened
kds session into the portal's framed browser view instead of staying
in its own window.
Now only bounces to central login when actually embedded (passing
?from= so it returns here afterwards); standalone or directly-opened
tabs get an in-app login form and never navigate away. Also wired up
the inactivity auto-logout timer. The legacy token/restrictedPages/
login/logout compat shim is unchanged.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
KDS uses a minimal Kitchen stub (no resos_* relationship properties) so
back_populates="resos_bookings" etc. caused mapper init to fail on every
request. Changed all four Resos.kitchen relationships to viewonly=True
with no back reference — KDS only reads these, not writes.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
kds_course_bumps.bumped_by_user_id references users.id — SQLAlchemy needs
the User model in Base.metadata to resolve this at startup. Route handlers
still receive a SimpleNamespace from auth.py at runtime.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
settings.py imports Kitchen for the back-reference relationship on
KitchenSettings.kitchen. KDS uses kitchen_db directly so the table exists;
this minimal model satisfies the import without pulling in kitchen-only models.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>