CarterPerez-dev
|
98c006897d
|
fix(canary-phase0): address audit findings before phase rollup
Phase 0 audit (superpowers:code-reviewer + general-purpose) returned FAIL
on shared findings. This commit resolves the blockers + important items.
Blockers:
- infra/docker/vite.prod: replace 'react-scss/' COPY paths with 'frontend/'
(would have broken 'docker compose build nginx')
- Delete backend/Dockerfile (broken template debris referencing deleted
cmd/api, missing migrations/, deleted keys/)
- Delete backend/Justfile (docker compose recipes pointed at deleted
backend/compose.yml + backend/dev.compose.yml; project-root justfile
[backend] group covers everything operationally)
- backend/internal/admin/handler.go: strip the residual JWT/auth scaffolding
(AuthService interface, authSvc field, authenticator+adminOnly mw params).
Phase 12 will gate /admin under OperatorBearer; for now RegisterRoutes
takes only chi.Router.
- Delete backend/.env + backend/.env.example: stale template duplicates
containing only template keys; project-root .env.example is the source
of truth per spec §12.4.
Important:
- Add © glyph to file headers in cloudflared.compose.yml, infra/docker/
vite.{dev,prod}, backend/.gitignore (operator's standing rule:
'©AngelaMos | 2026', not 'AngelaMos | 2026')
- backend/.gitignore: drop stale 'keys/*.pem' / 'keys/*.key' entries
(backend/keys/ no longer exists)
- scripts/init.sh: rename 'local_tmp' variable to 'tmp_dir' to remove
visual ambiguity with the 'local' bash keyword (both audit agents
briefly misread it as 'local local_tmp=...')
- .env.example: add inline comment explaining the dual NGINX_HOST_PORT
defaults (22784 prod compose, 58495 dev compose; do not override in
shared .env)
Deferred (logged but not blocking Phase 0):
- Pre-existing template Go files (internal/{config,core,server,health,
middleware/{request_id,logging,headers,ratelimit},admin}/*.go) carry
'// AngelaMos | 2026' without ©. Bulk-fixing these belongs to a
hygiene pass; not Phase 0 scope.
- frontend/vite.config.ts and frontend/stylelint.config.js reference
'2025'; operator-imported template files, separate concern.
- APP_ENVIRONMENT vs ENVIRONMENT spec/impl mismatch: spec §12.1 sample
uses APP_ENVIRONMENT; envKeyMap in config.go uses ENVIRONMENT (template
default). Implementation is internally consistent. Logged in plan
Appendix C as a non-blocking spec amendment candidate.
Verification: go build ./... + go vet ./... clean. grep returns no
hits for react-scss / carterperez-dev/templates / JWTConfig /
InvalidateAllSessions across backend/, infra/, scripts/, compose files.
|
2026-05-10 05:37:32 -04:00 |
CarterPerez-dev
|
382890cb56
|
chore(canary): rebrand from no-auth-template to canary-token-generator
- compose.yml: APP_NAME default → canary-token-generator
- dev.compose.yml: APP_NAME default → canary-token-generator
./react-scss bind paths → ./frontend (template flatten)
- cloudflared.compose.yml: APP_NAME default → canary-token-generator
- VITE_APP_TITLE default in both compose files → "Canary Token Generator"
Frontend package.json and index.html were already rebranded by operator
between sessions. All three compose stacks now validate via docker compose
config (prod, dev, prod+tunnel overlay).
|
2026-05-10 05:15:09 -04:00 |