phase-7: motion, an installable app, and a capture that survives no signal
GSAP carries the counter roll-ups, the bandeja card physics, the dialog transitions and the three success moments FLOWS.md allows. Every one of them checks prefers-reduced-motion first and does nothing when it is set. boneyard and canvas-ui are not what SPEC.md's stack table says they are: on npm the names belong to two abandoned projects that do neither job. The skeletons were already ours; the two canvas spots are now sixty lines each with no dependency. DECISIONS.md records the substitution. The app installs, keeps a scan taken with no network in IndexedDB and sends it when there is one, falls back to a page that explains itself, and can push a deadline notice. Reading the log of what is queued is the source of truth, so the notice clears when the capture actually lands. The CSP now allows scripts by per-request nonce rather than by 'unsafe-inline'. That forced /offline to render per request: a prerendered page carries a build-time nonce no live policy matches, so its scripts were blocked and it never hydrated. Two crashes fixed on the way. web-push throws on a VAPID subject that is not https: or mailto:, and the code handed it APP_PUBLIC_URL, so any machine with push keys died at boot; a misconfigured optional channel now switches itself off and says why. And a subscription the push service answers 410 for is deleted rather than retried forever. Lighthouse on the production build: accessibility 100, best practices 96, SEO 100, performance 73. The performance number is not trustworthy on this machine and DECISIONS.md says why; total blocking time did fall from 17.6s to 1.7s once the hero canvas stopped drawing at full resolution every frame and the landing page stopped importing GSAP. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
4c39926483
commit
e4eb1617d1
@@ -8,6 +8,25 @@ const nextConfig: NextConfig = {
|
||||
output: 'standalone',
|
||||
// /api is proxied at runtime by app/api/[...path]/route.ts rather than by a rewrite,
|
||||
// so API_INTERNAL_URL stays a runtime setting. See the comment in that file.
|
||||
async headers() {
|
||||
return [
|
||||
{
|
||||
// The bundler emits the service worker under /_next/static, and a worker may only
|
||||
// claim a scope at or below its own path unless the response says otherwise.
|
||||
// Security headers for everything else are set in proxy.ts, which does not run for
|
||||
// /_next.
|
||||
source: '/_next/static/service-worker/:path*',
|
||||
headers: [
|
||||
{ key: 'Service-Worker-Allowed', value: '/' },
|
||||
// Production only: Next warns that a custom Cache-Control here interferes with
|
||||
// how the dev server serves its own assets, and it does.
|
||||
...(process.env.NODE_ENV === 'production'
|
||||
? [{ key: 'Cache-Control', value: 'no-cache, no-store, must-revalidate' }]
|
||||
: []),
|
||||
],
|
||||
},
|
||||
];
|
||||
},
|
||||
};
|
||||
|
||||
export default createNextIntlPlugin('./src/i18n/request.ts')(nextConfig);
|
||||
|
||||
Reference in New Issue
Block a user