Files
impuestospy/apps/api/.env.example
T
MichilisandClaude Opus 5 e4eb1617d1 phase-7: motion, an installable app, and a capture that survives no signal
GSAP carries the counter roll-ups, the bandeja card physics, the dialog
transitions and the three success moments FLOWS.md allows. Every one of
them checks prefers-reduced-motion first and does nothing when it is set.

boneyard and canvas-ui are not what SPEC.md's stack table says they are:
on npm the names belong to two abandoned projects that do neither job.
The skeletons were already ours; the two canvas spots are now sixty lines
each with no dependency. DECISIONS.md records the substitution.

The app installs, keeps a scan taken with no network in IndexedDB and
sends it when there is one, falls back to a page that explains itself,
and can push a deadline notice. Reading the log of what is queued is the
source of truth, so the notice clears when the capture actually lands.

The CSP now allows scripts by per-request nonce rather than by
'unsafe-inline'. That forced /offline to render per request: a
prerendered page carries a build-time nonce no live policy matches, so
its scripts were blocked and it never hydrated.

Two crashes fixed on the way. web-push throws on a VAPID subject that is
not https: or mailto:, and the code handed it APP_PUBLIC_URL, so any
machine with push keys died at boot; a misconfigured optional channel now
switches itself off and says why. And a subscription the push service
answers 410 for is deleted rather than retried forever.

Lighthouse on the production build: accessibility 100, best practices 96,
SEO 100, performance 73. The performance number is not trustworthy on
this machine and DECISIONS.md says why; total blocking time did fall from
17.6s to 1.7s once the hero canvas stopped drawing at full resolution
every frame and the landing page stopped importing GSAP.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 20:48:48 +00:00

68 lines
2.6 KiB
Bash

# apps/api environment. Copy to .env and adjust. Every variable is validated at boot
# by src/lib/env.ts, which fails fast with the exact problem.
# development | test | production
NODE_ENV=development
# Port the Hono server listens on. The web app proxies /api here.
PORT=4000
# User facing origin. Used for links in emails, push payloads and Telegram messages.
# Must name the same port as apps/web/.env PORT, or better-auth rejects the sign in
# request as a foreign origin.
APP_PUBLIC_URL=http://localhost:3005
# server = serves HTTP. worker = runs the job poller and sweeps, serves only /healthz.
ROLE=server
# Run the job poller inside the server process. Set false only when a dedicated
# worker exists, which requires Postgres (SQLite is single writer).
JOBS_INLINE=true
JOBS_POLL_INTERVAL_MS=2000
# A running job whose lock is older than this returns to pending, for crash recovery.
JOBS_STALE_MINUTES=10
# sqlite:./data/app.db, sqlite::memory: or postgres://user:pass@host:5432/db
# The dialect is chosen from this scheme. Nothing else selects it.
DATABASE_URL=sqlite:./data/app.db
# Signing key for sessions. At least 32 characters. Generate: openssl rand -base64 32
BETTER_AUTH_SECRET=change-me-to-at-least-32-characters-long
# Public origin cookies are issued for. Auth routes are proxied, so this is the web origin.
# Keep in step with APP_PUBLIC_URL and apps/web/.env PORT.
BETTER_AUTH_URL=http://localhost:3005
# local | s3. local needs one shared volume across replicas; s3 is required to scale out.
STORAGE_DRIVER=local
STORAGE_LOCAL_PATH=./data/files
# Only read when STORAGE_DRIVER=s3. Bucket, region and both keys are then required.
S3_ENDPOINT=
S3_REGION=
S3_BUCKET=
S3_ACCESS_KEY_ID=
S3_SECRET_ACCESS_KEY=
# Needed by MinIO and most non AWS S3 implementations.
S3_FORCE_PATH_STYLE=true
# Optional. Without it, scans with no QR go straight to the manual form instead of OCR.
ANTHROPIC_API_KEY=
OCR_MODEL=claude-sonnet-4-6
# Optional. Web push is hidden in the UI when unset. Generate: npx web-push generate-vapid-keys
PUSH_VAPID_PUBLIC_KEY=
PUSH_VAPID_PRIVATE_KEY=
# Who the push service can contact about this deployment. An https: or mailto: URL, which
# is what RFC 8292 allows. Defaults to APP_PUBLIC_URL when that is https, then to
# mailto:SMTP_FROM. With none of the three, push stays off and says so at boot.
PUSH_VAPID_SUBJECT=
# Optional. Without SMTP_HOST, verification codes and emails are logged to stdout.
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASS=
SMTP_FROM=
# Optional. Telegram is hidden as a notification channel when unset.
TELEGRAM_BOT_TOKEN=
# Locale for anonymous requests. Signed in users are served their profiles.locale.
DEFAULT_LOCALE=es