The console defaulted to a backend on localhost, and features were built against a locally modified server that production never had: Floor, Commerce and their sales/customers routes answered 404 the day they were deployed. The platform API is now https://mcp.loyaly.ai in every environment; LOYALY_API_BASE remains only as an explicit override. Removed what had no server behind it - Floor, Commerce, Lyts, Leaderboard, and the Roles, Notifications, Billing, Integrations, API keys and Preferences settings pages, all of which rendered hard-coded arrays as if they were the merchant's data. Navigation is what the API can honestly back. The removed code is in history if a real backend for any of it is ever built. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
15 lines
757 B
Bash
15 lines
757 B
Bash
# Runtime configuration. Committed on purpose - it carries no secret.
|
|
# Precedence: process.env > .env.production.local > .env.local > .env.production > .env
|
|
#
|
|
# The platform API. https://mcp.loyaly.ai is the default in every environment
|
|
# and the only value production accepts; it is written here so `docker run`
|
|
# is self-describing. NOT platform.loyaly.ai - that host serves this console.
|
|
LOYALY_API_BASE=https://mcp.loyaly.ai
|
|
|
|
# Browser -> this app's own routes, same origin. Empty is correct.
|
|
NEXT_PUBLIC_API_BASE=
|
|
|
|
# AUTH_SECRET is deliberately NOT here: it signs sessions, so a committed value
|
|
# is a session-forging key in git. Set it in the runtime environment (or point
|
|
# AUTH_SECRET_FILE at a mounted secret). Generate with: openssl rand -hex 32
|