The showcase was a Barcelona market: Catalan names, +34 numbers, euro rates and "Carrer Example 12" on every job. Presented to a Mexican client, all of that reads as somebody else's product. City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at 19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were Barcelona literals, so an unset env quietly seeded a different city than the app rendered — they now agree. Two db tests pinned the Barcelona centre as a hardcoded constant, which is why the deck returned zero cards on the first run here: every pro was a continent outside the radius. They read the same env as the seed now, so the trap cannot recur. Money: formatCents defaults to USD/en-US, and the nine hardcoded euro signs across the card, search rows, quote strip and forms are dollars. The rate NUMBERS are unchanged and still read high for CDMX — that is a pricing decision, not a currency one, and is left alone deliberately. Seed people are Mexican, addressed on real Roma/Condesa streets rotated by index rather than one placeholder repeated. Phones moved to +52 55, which moves the demo login to +525500000000 / 000000. Also in here, from the same session: - Sending a job now confirms. The mutation always succeeded; the sheet just closed with no receipt, which from the customer's side is indistinguishable from a dead button. Dismissing that receipt resolves as 'sent', so the card does not return to the deck. - Media moves to DigitalOcean Spaces, with the public origin derived from bucket and region instead of a second env var to keep in sync. - Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM. - The client-facing project panel beside the running app. - Two profiles removed and four renamed to match their photos. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
20 lines
767 B
TypeScript
20 lines
767 B
TypeScript
import { sendSms } from '@linkdr/notify';
|
|
|
|
/**
|
|
* SMS delivery for one-time codes.
|
|
*
|
|
* The transport itself now lives in @linkdr/notify, so the API package can
|
|
* reach it too — a tRPC procedure cannot import from `apps/web`, and the sign-in
|
|
* code and a "somebody wants to hire you" text have no business going out
|
|
* through two different Twilio clients with two different failure policies.
|
|
*
|
|
* The copy stays here. This is the one message that is part of the auth flow
|
|
* rather than part of the product, and it says things the others must not.
|
|
*/
|
|
export async function sendVerificationSms(to: string, code: string): Promise<void> {
|
|
await sendSms(
|
|
to,
|
|
`${code} is your Linkdr code. It expires in 5 minutes. We will never ask you for it.`,
|
|
);
|
|
}
|