Files
linkder/.env.example
T
serfaandClaude Opus 5 1808ad4cba Move the demo market to Mexico City, priced in US dollars
The showcase was a Barcelona market: Catalan names, +34 numbers, euro
rates and "Carrer Example 12" on every job. Presented to a Mexican
client, all of that reads as somebody else's product.

City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at
19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were
Barcelona literals, so an unset env quietly seeded a different city
than the app rendered — they now agree.

Two db tests pinned the Barcelona centre as a hardcoded constant, which
is why the deck returned zero cards on the first run here: every pro was
a continent outside the radius. They read the same env as the seed now,
so the trap cannot recur.

Money: formatCents defaults to USD/en-US, and the nine hardcoded euro
signs across the card, search rows, quote strip and forms are dollars.
The rate NUMBERS are unchanged and still read high for CDMX — that is a
pricing decision, not a currency one, and is left alone deliberately.

Seed people are Mexican, addressed on real Roma/Condesa streets rotated
by index rather than one placeholder repeated. Phones moved to +52 55,
which moves the demo login to +525500000000 / 000000.

Also in here, from the same session:
- Sending a job now confirms. The mutation always succeeded; the sheet
  just closed with no receipt, which from the customer's side is
  indistinguishable from a dead button. Dismissing that receipt resolves
  as 'sent', so the card does not return to the deck.
- Media moves to DigitalOcean Spaces, with the public origin derived
  from bucket and region instead of a second env var to keep in sync.
- Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM.
- The client-facing project panel beside the running app.
- Two profiles removed and four renamed to match their photos.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-23 10:56:31 -04:00

113 lines
4.2 KiB
Bash

# ---- Core ----
NODE_ENV=development
NEXT_PUBLIC_APP_URL=http://localhost:3000
# ---- Database (Postgres 16 + PostGIS) ----
DATABASE_URL=postgresql://linkder:linkder@localhost:5442/linkder
# Managed Postgres only. Verifies the server's IDENTITY, not merely that the
# link is encrypted — sslmode=require alone leaves you open to anything that can
# answer for the hostname. Takes a path to the provider's .crt, or the PEM
# inline for a platform whose secrets are environment variables.
DATABASE_CA_CERT=
# ---- Redis (pub/sub for SSE chat + BullMQ queues) ----
REDIS_URL=redis://localhost:6389
# ---- Auth.js v5 ----
# generate with: openssl rand -base64 32
AUTH_SECRET=
AUTH_URL=http://localhost:3000
# Social sign-in. Each provider is optional and independent — leave a pair
# blank and phone OTP still works. The buttons render either way and tell the
# user when a provider is not set up, so the screen never changes shape between
# environments. Set BOTH values of a pair or neither: a half-set pair is treated
# as unset (see lib/auth.ts).
#
# Authorised redirect URI: {NEXT_PUBLIC_APP_URL}/api/auth/callback/google
AUTH_GOOGLE_ID=
AUTH_GOOGLE_SECRET=
# Microsoft Entra ID (Azure AD). Register an app at
# https://entra.microsoft.com > App registrations, add a Web platform with
# redirect URI {NEXT_PUBLIC_APP_URL}/api/auth/callback/microsoft, then create a
# client secret under Certificates & secrets.
#
# TENANT_ID decides WHO may sign in and defaults to `common`:
# common work, school and personal Microsoft accounts
# organizations work and school only
# consumers personal only
# <tenant guid> one organisation only
# For a consumer marketplace `common` is almost always what you want — set the
# app registration's supported account types to match, or sign-in fails at
# Microsoft's end with AADSTS50194 no matter what is set here.
AUTH_MICROSOFT_ID=
AUTH_MICROSOFT_SECRET=
AUTH_MICROSOFT_TENANT_ID=common
# GitHub. Create an OAuth app at
# https://github.com/settings/developers > New OAuth App, with
# Authorization callback URL {NEXT_PUBLIC_APP_URL}/api/auth/callback/github.
#
# GitHub only returns a primary email if the OAuth app requests `user:email`
# AND the account has a verified one; a user whose email is private signs up
# with no address, so never assume `users.email` is reachable mail — gate
# outbound on isSyntheticEmail() from @linkdr/shared, same as phone signups.
AUTH_GITHUB_ID=
AUTH_GITHUB_SECRET=
# ---- Geocoding (Mapbox) ----
# Turns a typed address into the coordinates the deck matches on. Without it,
# every job and every pro base falls back to the city centre and is stored with
# location_precision='city' — honest, but unmatched: ST_Distance measures a
# constant and ST_DWithin passes everyone.
#
# The token MUST be entitled for PERMANENT geocoding. We store the coordinates
# indefinitely because they are the matching primitive, and Mapbox's temporary
# endpoint forbids persistence — every request sets permanent=true, so a token
# without that entitlement returns 401/403 rather than silently working.
MAPBOX_TOKEN=
# ISO 3166-1 alpha-2. Bounds results to one country: "Carrer de Sants" matches
# in several places and the wrong continent is a worse answer than none.
MAPBOX_COUNTRY=mx
# ---- Phone OTP (Twilio Verify) ----
TWILIO_ACCOUNT_SID=
TWILIO_AUTH_TOKEN=
TWILIO_VERIFY_SERVICE_SID=
# ---- Stripe Connect ----
STRIPE_SECRET_KEY=
STRIPE_WEBHOOK_SECRET=
NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY=
# Platform commission in basis points (1500 = 15%)
PLATFORM_FEE_BPS=1500
# ---- Didit (ID verification) ----
DIDIT_API_KEY=
DIDIT_WORKFLOW_ID=
DIDIT_WEBHOOK_SECRET=
# ---- Resend (transactional email) ----
RESEND_API_KEY=
EMAIL_FROM=noreply@linkdr.app
# ---- Launch market (city-scoped MVP) ----
NEXT_PUBLIC_CITY_NAME=Ciudad de México
NEXT_PUBLIC_CITY_LAT=19.4326
NEXT_PUBLIC_CITY_LNG=-99.1332
TWILIO_FROM_NUMBER=
# Dev-only fixed login (+34600000000 / code 000000). MUST stay false/unset in production.
ALLOW_DEV_LOGIN=false
# Bugsink (Sentry-compatible error tracking). Write-only ingest key, safe in the
# client bundle. Leave blank to disable reporting entirely.
NEXT_PUBLIC_SENTRY_DSN=
# ---- Object storage (DigitalOcean Spaces) ----
SPACES_REGION=nyc3
SPACES_BUCKET=
SPACES_KEY=
SPACES_SECRET=
SPACES_CDN_URL=