Goal
Allow users to create an account, sign in, and persist invoices securely so their data is available across devices and sessions.
The current project has no authentication or database dependency, so this issue establishes the account and persistence foundation. Select and document the auth and database providers before implementation.
Product behavior
- Guests may continue creating an invoice locally.
- Signing in enables durable cloud saves and cross-device access.
- Users can only read, update, or delete records that belong to their account.
- Existing public/shared invoice behavior must be explicit rather than exposing account-owned records by default.
Scope
Authentication
- Sign up, sign in, sign out, and session restoration.
- Protected account routes and server-side authorization.
- Clear signed-in and signed-out navigation states.
- Loading, error, and expired-session handling.
Persistence
- Database schema and migrations for users and invoices.
- Account ownership on every invoice.
- Store structured invoice data, not only rendered HTML or PDF.
- Create, read, update, and delete server operations with validation.
- Created/updated timestamps and a stable invoice identifier.
- Safe handling of client/company data and invoice line items.
- Environment-variable and local-development documentation.
Security requirements
- Enforce authorization on the server for every account-owned operation.
- Never trust a user ID supplied by the client.
- Prevent one user from loading or mutating another user's invoice by changing a URL.
- Validate and sanitize persisted invoice data.
- Keep provider and database secrets server-only.
- Define whether shared invoice links use revocable tokens or a separate public identifier.
Goal
Allow users to create an account, sign in, and persist invoices securely so their data is available across devices and sessions.
The current project has no authentication or database dependency, so this issue establishes the account and persistence foundation. Select and document the auth and database providers before implementation.
Product behavior
Scope
Authentication
Persistence
Security requirements