# CLAUDE.md This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. ## Project Overview **QuantEngine v0.1** — A comprehensive quantitative analysis and data collection system for retirement asset portfolio management. - **Architecture**: .NET 9 + C# (web UI + APIs), Python (legacy data collection/analysis) - **Web UI**: Blazor Interactive WebAssembly (MudBlazor) + ASP.NET Core Web API (API-First) - **Database**: PostgreSQL (Npgsql 8.0), single unified database - **Data Source**: KIS Open API (quotations/ranking read-only), with fallbacks - **Key Runtimes**: .NET 9, Python 3.9+, Node.js 16+ ### Migration Phases Status (2026-07-11) **Phase 1: Web UI Migration** ✅ 완료 (2026-07-11) - **새로운 표준**: Razor Pages (Server-Rendered) + Cookie Authentication + Tabler UI - **폐기 대상**: Blazor Interactive WebAssembly, MudBlazor, SmartAdmin - **완료 기준 — Phase 1 Success Criteria**: - ✅ Cookie 인증 구현 (AuthService + IpLockoutService + BCrypt) - ✅ Razor Pages 렌더링 (Admin 레이아웃 + 3개 이상 기본 페이지) - ✅ 공용 UI 컴포넌트 (4개 이상 shared partials) - ✅ 보안: 백도어 제거, 무솔트 해시 마이그레이션, IP 잠금 - ✅ 빌드 성공: 0 errors, 0 warnings - ✅ CLAUDE.md 업데이트 (UI 기준 + 인증 정책) - **✅ 모든 기준 충족됨** (2026-07-11) - **구현 완료**: - ✅ Cookie 기반 인증 (AuthService + IpLockoutService) - ✅ Razor Pages CRUD 레이아웃 (_AdminLayout.cshtml, shared partials) - ✅ Admin 페이지: Dashboard, Collection, Users (기본 구조) - ✅ 공용 UI 컴포넌트: _ValidationSummary, _Pagination, _StatusBadge, _EmptyState - ✅ 보안 개선: BCrypt 해싱, IP 잠금, 하드코딩된 백도어 제거 - ✅ 빌드: 0 errors, 0 warnings (Newtonsoft.Json 보안 경고 제외) - ✅ CLAUDE.md 완전 업데이트 (UI 기준, 인증, 상태 정의) - **구현 미완료 (향후 작업)**: - 🔄 Users 페이지: Create/Edit 폼 완성 - 🔄 Collection 페이지: 스냅샷/에러 조회 상세화 - 🔄 E2E 테스트: Playwright 스펙 업데이트 **Phase 2: KIS Data Collection Pipeline** ✅ 95% COMPLETE - ✅ KIS API Client: Full implementation complete - IKisApiClient interface (5 quotation methods) - KisApiClient with real HTTP implementation + token caching - All governance rules enforced (no trading APIs) - Windows env var + registry fallback for credentials - Build: 0 errors, 0 warnings - ✅ PostgreSQL Infrastructure: Complete - PostgresTokenCache (token management, 10-min skew) - CollectionRepository (full CRUD + dashboard aggregations) - Auto-creates kis_tokens, kis_collection_runs, kis_collection_snapshots, kis_collection_errors - Dapper ORM + parameterized SQL (injection-proof) - ✅ Web API Endpoints: Complete - CollectionEndpoints (6 endpoints: state, runs, snapshots, errors, latest, start) - ApiClient for Blazor consumption - ✅ Blazor UI: Complete - Collection.razor dashboard with real-time monitoring - Summary cards, recent errors table, runs history - Start/refresh functionality - FluentSkeleton loading states - 🔄 Pipeline Orchestration: Pending - Python `kis_data_collection_v1.py` → .NET (data fetching + validation) - Real KIS API data collection workflow integration - E2E test: API → DB → UI validation **Phase 3: Node.js→.NET CLI Tools** 📋 PLANNED - Makefile created (npm → make mappings) - np operations documented **Status Summary**: - Python codebase: Operational (1,140 files) - .NET 9 coverage: Core (✅), Infrastructure (✅), API (✅), Web UI (✅) - Database: PostgreSQL fully migrated - Release gates: Python gates remain authority until Phase 2 integration testing complete ## Deployment & Operations **Production Server**: Hetzner Cloud `178.104.200.7` (kjh2064@178.104.200.7) Projects on server: 1. **TaxBaik** (홈페이지) — Nginx location `/taxbaik` 2. **QuantEngine** (데이터 수집/분석) — Nginx location `/quantengine` See [Temp/DEPLOYMENT_GUIDE.md](Temp/DEPLOYMENT_GUIDE.md) for deployment procedures. ### Quick Deploy (QuantEngine) ```powershell ssh kjh2064@178.104.200.7 systemctl status quantengine-api journalctl -u quantengine-api -f sudo systemctl restart quantengine-api ``` ### Git Repository **Gitea Server** (동일 호스트): - **HTTP**: `http://178.104.200.7/kjh2064/QuantEngineByItz.git` - **SSH**: `git@178.104.200.7:2222/...` ## UI Design Principles (2026-07-11 — Migrated to Razor Pages) ### Framework & Design System (NEW — 2026-07-11) - **Primary Framework**: ASP.NET Core Razor Pages + Bootstrap 5 + Tabler UI - **Design System**: Tabler (Bootstrap 5 기반), 밀집 레이아웃 + 전통 서버 렌더링 - **Render Mode**: **Server-side Razor Pages** — 모든 Admin UI는 서버에서 렌더링, Cookie 기반 인증 (API-First WASM 폐기) - **Authentication**: Cookie Authentication (HttpOnly) + BCrypt password hashing + IP lockout (3 strikes, 15-min) - **Deprecation**: **Blazor Interactive WebAssembly 폐기**, **MudBlazor 컴포넌트 폐기** (2026-07-11), **SmartAdmin 폐기**. 기존 WASM 코드는 `/QuantEngine.Web.Client` 폴더에 참고용으로만 보관 (`.sln`에서 제외) ### Component Development Rules (NEW) 1. **All Admin UI Development** (New + Refactored): - Use **Razor Pages** (.cshtml + .cshtml.cs PageModel) exclusively for admin - UI는 Repository/Service를 생성자 DI로 직접 호출 (API 홉 없음) - Bootstrap 5 + Tabler UI CSS classes for styling - **Form Validation**: DataAnnotations DTO + FluentValidation IValidator 이중 검증 - HTML `
` + tag helpers (`asp-for`, `asp-action`, `asp-page`) 2. **Authentication & Authorization**: - Cookie name: `QuantEngine.Admin.Auth` (HttpOnly, SameSite=Lax) - Session duration: 12 hours (sliding expiration) - Folder-level `[Authorize]` via `AuthorizeFolder("/Admin")` convention (per-page 반복 금지) - Login: `/Account/Login` (Razor Page, NO WASM) - Password: BCrypt-hashed (auto-migrates existing SHA-256 hashes on first login) - IP Lockout: 3 failed attempts → 15-minute lockout 3. **Data & Form Patterns**: - PageModel constructor: `public IndexModel(IWorkspaceRepository repo, ILogger logger)` - Form submission: `OnPostAsync()` / `OnPostDeleteAsync()` (multi-handler pattern) - Validation failures: return `Page()` (re-render with ModelState errors) - Pagination: `PaginationModel` record (Page, TotalPages, Func BuildPageUrl) - Empty states: `` 4. **Component Mapping** (Bootstrap 5 + Tabler): | UI Element | Component | Notes | |-----------|-----------|-------| | Button | `