Everything now renders inside a phone illustration on the entry screen, with a five-tab bar. The frame lives in the root layout rather than one page, so sign-in, onboarding and the job form are inside it too. - Entry screen is the product running, not a marketing page: a live swipeable deck of real verified pros with a trade-filter strip above the card. deck.showcase is the only public procedure in that router and writes nothing, so an anonymous right swipe reaches no one. - Settings: notification preferences (new table, defaults returned when no row exists), signed-in devices, GDPR export, deletion request. Closes the setEmail finding: an unverified address is no longer written to users.email, which is UNIQUE -- claiming a stranger's address used to block them from ever signing up with Google, and the uniqueness error leaked whether an address was registered. Now parked in email_change_requests until a token proves ownership. - Profile: for a pro it leads with their REAL deck card, rendered by the same exported <Card> clients swipe, so the two cannot drift. Adds pro.previewCard (works at draft/pending, where publicProfile 404s) and pro.reorderMedia (photo position 0 is the deck card). Warns before an edit that would send a verified pro back for review, rather than after it silently drops them off the deck. Clients get a thin profile plus a route into pro onboarding -- supply is the launch blocker. - Dev login: +34600000000 / 000000, behind THREE guards (NODE_ENV, an explicit ALLOW_DEV_LOGIN flag, and an exact number match). It overwrites the stored code rather than skipping verification, so the real expiry, attempt cap and single-use consumption still apply. - Seed uses portrait photos. The cards previously showed picsum stock scenery -- a locksmith standing on a railway track. Fixes found along the way: the card's name rendered ink-950 navy on a dark photo because globals.css sets h1..h6 colour in @layer base, which beat the inherited text-white; and the card referenced --color-go-500, --border and --card, none of which exist, so the SEND JOB stamp had no colour. Also adds public/sw.js as a kill-switch: a service worker left registered on localhost:3000 by a different project was intercepting this app's chunks. typecheck, lint clean; 186 tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
57 lines
1.5 KiB
Bash
57 lines
1.5 KiB
Bash
# ---- Core ----
|
|
NODE_ENV=development
|
|
NEXT_PUBLIC_APP_URL=http://localhost:3000
|
|
|
|
# ---- Database (Postgres 16 + PostGIS) ----
|
|
DATABASE_URL=postgresql://linkder:linkder@localhost:5442/linkder
|
|
|
|
# ---- Redis (pub/sub for SSE chat + BullMQ queues) ----
|
|
REDIS_URL=redis://localhost:6389
|
|
|
|
# ---- Auth.js v5 ----
|
|
# generate with: openssl rand -base64 32
|
|
AUTH_SECRET=
|
|
AUTH_URL=http://localhost:3000
|
|
# Optional. Leave blank and phone OTP is the only route: the "Continue with
|
|
# Google" button still renders, and tells the user it is not set up.
|
|
# Authorised redirect URI: {NEXT_PUBLIC_APP_URL}/api/auth/callback/google
|
|
AUTH_GOOGLE_ID=
|
|
AUTH_GOOGLE_SECRET=
|
|
|
|
# ---- Phone OTP (Twilio Verify) ----
|
|
TWILIO_ACCOUNT_SID=
|
|
TWILIO_AUTH_TOKEN=
|
|
TWILIO_VERIFY_SERVICE_SID=
|
|
|
|
# ---- Stripe Connect ----
|
|
STRIPE_SECRET_KEY=
|
|
STRIPE_WEBHOOK_SECRET=
|
|
NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY=
|
|
# Platform commission in basis points (1500 = 15%)
|
|
PLATFORM_FEE_BPS=1500
|
|
|
|
# ---- Didit (ID verification) ----
|
|
DIDIT_API_KEY=
|
|
DIDIT_WORKFLOW_ID=
|
|
DIDIT_WEBHOOK_SECRET=
|
|
|
|
# ---- Cloudflare R2 (S3-compatible object storage) ----
|
|
R2_ACCOUNT_ID=
|
|
R2_ACCESS_KEY_ID=
|
|
R2_SECRET_ACCESS_KEY=
|
|
R2_BUCKET=linkder-uploads
|
|
R2_PUBLIC_URL=
|
|
|
|
# ---- Resend (transactional email) ----
|
|
RESEND_API_KEY=
|
|
EMAIL_FROM=noreply@linkder.app
|
|
|
|
# ---- Launch market (city-scoped MVP) ----
|
|
NEXT_PUBLIC_CITY_NAME=Barcelona
|
|
NEXT_PUBLIC_CITY_LAT=41.3874
|
|
NEXT_PUBLIC_CITY_LNG=2.1686
|
|
TWILIO_FROM_NUMBER=
|
|
|
|
# Dev-only fixed login (+34600000000 / code 000000). MUST stay false/unset in production.
|
|
ALLOW_DEV_LOGIN=false
|