Some checks are pending
CI / Lint, Typecheck, Test, Build (push) Waiting to run
CI-Pipeline (Forgejo Actions): - .forgejo/workflows/ci.yml: lint + typecheck + test + admin build - typecheck-Scripts in packages/api, packages/db, apps/admin ergaenzt - ESLint FlatConfig (eslint-config-next 16) in apps/admin angelegt - React-19-Hook-Findings im bestehenden Code als Warnings markiert (set-state-in-effect, preserve-manual-memoization, no-unused-vars) DB-Schema-Split: - packages/db/src/schema/health.ts (636 Zeilen, Monolith) entfernt und auf 7 Domain-Module aufgeteilt: profiles, foods, stores, recipes, tracking, shopping, community. index.ts re-exportiert alles. API-Refactoring: - 2FA-Middleware: 2 DB-Queries pro Admin-Call sind jetzt lazy + per-Request gecached. Bei tRPC-Batch-Requests mit mehreren protected Procedures wird der 2FA-State nur einmal geladen (siehe context.ts getTwoFactorState). - any-Typen in trpc/init.ts und trpc/routers/health.ts entfernt; Drizzle inferiert Closure-Typen automatisch. - packages/api/src/trpc/routers/health/_shared.ts: alle Helper-Funktionen und Zod-Input-Schemas aus health.ts extrahiert. health.ts: 2419 -> 2061 Zeilen. Vorbereitung fuer Procedure-Split in Folge-Session. Konfiguration: - .env.example um alle in turbo.json deklarierten Env-Vars erweitert, jeweils mit Kontext-Kommentar. - turbo.json um real genutzte Env-Vars erweitert: NEXT_PUBLIC_HELP_URL, ENABLE_DB_MIGRATIONS, ADMIN_INITIAL_PASSWORD, DEMO_RECIPE_OWNER_EMAIL. - .gitignore: *.tsbuildinfo (TypeScript-Build-Cache). - apps/admin/lib/hellth-data.test.ts: fehlendes Recipe.minutes Feld in Mocks. Offene Folge-Sessions: - Vollstaendiger Procedure-Split von routers/health.ts in Sub-Files - Aufteilung von apps/admin/lib/hellth-data.ts (1149 Zeilen) in Domain-Module Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
80 lines
4 KiB
Text
80 lines
4 KiB
Text
# =============================================================================
|
|
# Hellth Hub - Beispiel-Umgebungsvariablen
|
|
# Kopiere diese Datei nach `.env` und ersetze alle Secrets durch echte Werte.
|
|
# Verwendung der Variablen ist in turbo.json deklariert; alle hier gelisteten
|
|
# Werte werden von packages/api, packages/db oder apps/admin gelesen.
|
|
# =============================================================================
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Datenbank
|
|
# -----------------------------------------------------------------------------
|
|
DATABASE_URL=postgresql://hellth:hellth_dev@localhost:5432/hellth_hub
|
|
# `true` erzwingt SSL gegenueber Postgres. In Produktion empfohlen.
|
|
DATABASE_REQUIRE_SSL=false
|
|
# Wenn `true`, fuehrt die API beim Start automatisch ausstehende Migrationen aus.
|
|
ENABLE_DB_MIGRATIONS=false
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Better Auth (Login, Session-Cookies, 2FA)
|
|
# -----------------------------------------------------------------------------
|
|
# In Produktion durch starkes Secret ersetzen, z. B. `openssl rand -base64 32`.
|
|
BETTER_AUTH_SECRET=change-me-in-production-use-openssl-rand-base64-32
|
|
# Basis-URL fuer Auth-Endpoints und Passkey-Origins. In Produktion zwingend https://.
|
|
BETTER_AUTH_BASE_URL=http://localhost:3002
|
|
# Wenn `true`, oeffnet sich Self-Service-SignUp (nur fuer Seed-Skripte aktivieren).
|
|
ALLOW_SEED_SIGNUP=false
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Passkeys (WebAuthn)
|
|
# -----------------------------------------------------------------------------
|
|
PASSKEY_RP_ID=localhost
|
|
PASSKEY_RP_NAME=Hellth Hub
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# API-Server
|
|
# -----------------------------------------------------------------------------
|
|
API_PORT=3002
|
|
# Kommaseparierte Origin-Liste, die CORS akzeptieren soll.
|
|
TRUSTED_ORIGINS=http://localhost:3001
|
|
# Hinter Reverse-Proxy: `true`, damit X-Forwarded-Proto fuer HTTPS-Pruefung gelesen wird.
|
|
TRUST_PROXY_FORWARD_HEADERS=false
|
|
# Optional: Basis-URL fuer hochgeladene Assets (Fallback: BETTER_AUTH_BASE_URL).
|
|
PUBLIC_ASSETS_BASE_URL=
|
|
# Wenn `true`, schreibt der Health-Router Audit-Eintraege ins Konsolen-Log.
|
|
HEALTH_AUDIT_LOGS=false
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Admin-App (Next.js)
|
|
# -----------------------------------------------------------------------------
|
|
NEXT_PUBLIC_API_URL=http://localhost:3002
|
|
# Optional: URL fuer den Hilfe-Link in der UI.
|
|
NEXT_PUBLIC_HELP_URL=
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Plattform-Admin-Zugriff
|
|
# -----------------------------------------------------------------------------
|
|
# Server-Seite: berechtigt zusaetzlich zu role=admin in der DB.
|
|
PLATFORM_ADMIN_EMAILS=admin@domain.tld
|
|
# Frontend-Seite: gleiche Liste, fuer UI-Sichtbarkeit von Admin-Bereichen.
|
|
NEXT_PUBLIC_PLATFORM_ADMIN_EMAILS=admin@domain.tld
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Initialer Admin-User (vom seed:admin-Script verwendet)
|
|
# -----------------------------------------------------------------------------
|
|
ADMIN_EMAIL=admin@domain.tld
|
|
ADMIN_INITIAL_PASSWORD=please-set-a-strong-password-with-16-plus-chars
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Demo-Daten (optional, vom seed:demo-recipes-Script verwendet)
|
|
# -----------------------------------------------------------------------------
|
|
# Wenn gesetzt, werden Demo-Rezepte diesem Benutzer zugeordnet.
|
|
DEMO_RECIPE_OWNER_EMAIL=
|
|
|
|
# -----------------------------------------------------------------------------
|
|
# Wearables: Fitbit OAuth (optional, derzeit vorbereitet)
|
|
# -----------------------------------------------------------------------------
|
|
FITBIT_CLIENT_ID=
|
|
FITBIT_CLIENT_SECRET=
|
|
FITBIT_REDIRECT_URI=http://localhost:3002/api/wearables/fitbit/callback
|
|
# 32-Byte Base64-Key zur Verschluesselung von Wearable-Access-Tokens in der DB.
|
|
WEARABLE_TOKEN_ENCRYPTION_KEY=change-me-32-byte-base64-key
|