GSAP carries the counter roll-ups, the bandeja card physics, the dialog transitions and the three success moments FLOWS.md allows. Every one of them checks prefers-reduced-motion first and does nothing when it is set. boneyard and canvas-ui are not what SPEC.md's stack table says they are: on npm the names belong to two abandoned projects that do neither job. The skeletons were already ours; the two canvas spots are now sixty lines each with no dependency. DECISIONS.md records the substitution. The app installs, keeps a scan taken with no network in IndexedDB and sends it when there is one, falls back to a page that explains itself, and can push a deadline notice. Reading the log of what is queued is the source of truth, so the notice clears when the capture actually lands. The CSP now allows scripts by per-request nonce rather than by 'unsafe-inline'. That forced /offline to render per request: a prerendered page carries a build-time nonce no live policy matches, so its scripts were blocked and it never hydrated. Two crashes fixed on the way. web-push throws on a VAPID subject that is not https: or mailto:, and the code handed it APP_PUBLIC_URL, so any machine with push keys died at boot; a misconfigured optional channel now switches itself off and says why. And a subscription the push service answers 410 for is deleted rather than retried forever. Lighthouse on the production build: accessibility 100, best practices 96, SEO 100, performance 73. The performance number is not trustworthy on this machine and DECISIONS.md says why; total blocking time did fall from 17.6s to 1.7s once the hero canvas stopped drawing at full resolution every frame and the landing page stopped importing GSAP. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
68 lines
2.6 KiB
Bash
68 lines
2.6 KiB
Bash
# apps/api environment. Copy to .env and adjust. Every variable is validated at boot
|
|
# by src/lib/env.ts, which fails fast with the exact problem.
|
|
|
|
# development | test | production
|
|
NODE_ENV=development
|
|
# Port the Hono server listens on. The web app proxies /api here.
|
|
PORT=4000
|
|
# User facing origin. Used for links in emails, push payloads and Telegram messages.
|
|
# Must name the same port as apps/web/.env PORT, or better-auth rejects the sign in
|
|
# request as a foreign origin.
|
|
APP_PUBLIC_URL=http://localhost:3005
|
|
|
|
# server = serves HTTP. worker = runs the job poller and sweeps, serves only /healthz.
|
|
ROLE=server
|
|
# Run the job poller inside the server process. Set false only when a dedicated
|
|
# worker exists, which requires Postgres (SQLite is single writer).
|
|
JOBS_INLINE=true
|
|
JOBS_POLL_INTERVAL_MS=2000
|
|
# A running job whose lock is older than this returns to pending, for crash recovery.
|
|
JOBS_STALE_MINUTES=10
|
|
|
|
# sqlite:./data/app.db, sqlite::memory: or postgres://user:pass@host:5432/db
|
|
# The dialect is chosen from this scheme. Nothing else selects it.
|
|
DATABASE_URL=sqlite:./data/app.db
|
|
|
|
# Signing key for sessions. At least 32 characters. Generate: openssl rand -base64 32
|
|
BETTER_AUTH_SECRET=change-me-to-at-least-32-characters-long
|
|
# Public origin cookies are issued for. Auth routes are proxied, so this is the web origin.
|
|
# Keep in step with APP_PUBLIC_URL and apps/web/.env PORT.
|
|
BETTER_AUTH_URL=http://localhost:3005
|
|
|
|
# local | s3. local needs one shared volume across replicas; s3 is required to scale out.
|
|
STORAGE_DRIVER=local
|
|
STORAGE_LOCAL_PATH=./data/files
|
|
# Only read when STORAGE_DRIVER=s3. Bucket, region and both keys are then required.
|
|
S3_ENDPOINT=
|
|
S3_REGION=
|
|
S3_BUCKET=
|
|
S3_ACCESS_KEY_ID=
|
|
S3_SECRET_ACCESS_KEY=
|
|
# Needed by MinIO and most non AWS S3 implementations.
|
|
S3_FORCE_PATH_STYLE=true
|
|
|
|
# Optional. Without it, scans with no QR go straight to the manual form instead of OCR.
|
|
ANTHROPIC_API_KEY=
|
|
OCR_MODEL=claude-sonnet-4-6
|
|
|
|
# Optional. Web push is hidden in the UI when unset. Generate: npx web-push generate-vapid-keys
|
|
PUSH_VAPID_PUBLIC_KEY=
|
|
PUSH_VAPID_PRIVATE_KEY=
|
|
# Who the push service can contact about this deployment. An https: or mailto: URL, which
|
|
# is what RFC 8292 allows. Defaults to APP_PUBLIC_URL when that is https, then to
|
|
# mailto:SMTP_FROM. With none of the three, push stays off and says so at boot.
|
|
PUSH_VAPID_SUBJECT=
|
|
|
|
# Optional. Without SMTP_HOST, verification codes and emails are logged to stdout.
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_USER=
|
|
SMTP_PASS=
|
|
SMTP_FROM=
|
|
|
|
# Optional. Telegram is hidden as a notification channel when unset.
|
|
TELEGRAM_BOT_TOKEN=
|
|
|
|
# Locale for anonymous requests. Signed in users are served their profiles.locale.
|
|
DEFAULT_LOCALE=es
|