One backend, and only the screens it can stand behind
The console defaulted to a backend on localhost, and features were built against a locally modified server that production never had: Floor, Commerce and their sales/customers routes answered 404 the day they were deployed. The platform API is now https://mcp.loyaly.ai in every environment; LOYALY_API_BASE remains only as an explicit override. Removed what had no server behind it - Floor, Commerce, Lyts, Leaderboard, and the Roles, Notifications, Billing, Integrations, API keys and Preferences settings pages, all of which rendered hard-coded arrays as if they were the merchant's data. Navigation is what the API can honestly back. The removed code is in history if a real backend for any of it is ever built. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
This commit is contained in:
46
.env.example
46
.env.example
@@ -1,42 +1,12 @@
|
||||
# ---------------------------------------------------------------------------
|
||||
# Template for `.env.local` — your LOCAL overrides. Copy it:
|
||||
#
|
||||
# cp .env.example .env.local
|
||||
#
|
||||
# Do not copy it to `.env`. `.env` is committed and already holds the
|
||||
# production values; `.env.local` is loaded ahead of it and is gitignored.
|
||||
# ---------------------------------------------------------------------------
|
||||
# Copy to .env.local for development. Only AUTH_SECRET is required.
|
||||
|
||||
# The one shared Loyaly platform API (Behavision). Server-side only and
|
||||
# deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass
|
||||
# the BFF, which is what keeps the access token out of JavaScript.
|
||||
#
|
||||
# local dev http://127.0.0.1:8088 ← what belongs in .env.local
|
||||
# production https://mcp.loyaly.ai ← already set in the committed .env
|
||||
#
|
||||
# NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing
|
||||
# the variable there makes the BFF call its own origin, which fails in a way
|
||||
# that looks like a broken login form rather than a misconfiguration.
|
||||
#
|
||||
# Production no longer requires this: it accepts exactly one origin, so an unset
|
||||
# value can only have meant that one, and platformApi resolves it. Any OTHER
|
||||
# host set explicitly is still rejected. Locally it is worth setting, because a
|
||||
# dev machine legitimately means a different address.
|
||||
LOYALY_API_BASE=http://127.0.0.1:8088
|
||||
|
||||
# Signs the session cookie and encrypts the platform token bundle.
|
||||
#
|
||||
# The ONLY variable production requires, the only real secret, and the only one
|
||||
# taken solely from the environment — it is in no committed file, by design.
|
||||
# Set it as a Dokploy environment variable in the RUNTIME panel (a build
|
||||
# argument is not present at runtime), or mount it and set AUTH_SECRET_FILE to
|
||||
# its path. Locally, any string works; leave it blank and a development key is
|
||||
# used.
|
||||
#
|
||||
# Generate with: openssl rand -hex 32 (hex, not base64 — a trailing '=' can be
|
||||
# mangled by a dashboard env editor that splits on the first '=')
|
||||
# Signs the session cookie and encrypts the platform tokens inside it.
|
||||
# Generate with: openssl rand -hex 32
|
||||
AUTH_SECRET=
|
||||
|
||||
# Browser → this app's own BFF routes. Same origin, so leave it empty. Inlined
|
||||
# at BUILD time (NEXT_PUBLIC), so changing it at runtime does nothing.
|
||||
# The platform API. Defaults to https://mcp.loyaly.ai in EVERY environment;
|
||||
# set this only if you are deliberately developing against another backend.
|
||||
# LOYALY_API_BASE=
|
||||
|
||||
# Browser -> this app's own routes. Empty is correct.
|
||||
NEXT_PUBLIC_API_BASE=
|
||||
|
||||
Reference in New Issue
Block a user