diff --git a/apps/api/.env.example b/apps/api/.env.example index be17bb4..d0273ab 100644 --- a/apps/api/.env.example +++ b/apps/api/.env.example @@ -17,9 +17,14 @@ PRISMA_FIELD_ENCRYPTION_KEY= BETTER_AUTH_SECRET= BETTER_AUTH_URL=http://localhost:3000 -# Google OAuth (configurato a fine progetto) -# GOOGLE_CLIENT_ID= -# GOOGLE_CLIENT_SECRET= +# Google OAuth — abilita il bottone "Continua con Google" in /sign-in /sign-up. +# Setup: console.cloud.google.com → APIs & Services → Credentials → +# OAuth client ID (Web app) → Authorized redirect URI: +# https:///api/auth/callback/google +# Devono essere configurate ANCHE in apps/web/.env (Better Auth le legge da +# entrambi i lati per costruire enabledSocialProviders al boot). +GOOGLE_CLIENT_ID= +GOOGLE_CLIENT_SECRET= # Sentry — error tracking (lascia vuoto per disabilitare) # SENTRY_DSN= diff --git a/docs/deployment.md b/docs/deployment.md index b1d47ad..ba7c808 100644 --- a/docs/deployment.md +++ b/docs/deployment.md @@ -321,9 +321,39 @@ BETTER_AUTH_SECRET= BETTER_AUTH_URL=https://lamiadieta.luzaonline.net API_URL=http://127.0.0.1:4000 NEXT_PUBLIC_VAPID_PUBLIC_KEY= +# IMPORTANTE: il client di Better Auth (lib/auth-client.ts) usa questa env per +# costruire la baseURL delle fetch OAuth. Se manca → fallback a localhost:3000 +# → CORS error sul login Google. È inlined al build, quindi cambiarla richiede +# un nuovo `pnpm --filter web build`. +NEXT_PUBLIC_APP_URL=https://lamiadieta.luzaonline.net EOF ``` +### 4.3.bis Google OAuth (opzionale, per il login con Google) + +Se vuoi abilitare "Continua con Google" su `/sign-in` e `/sign-up`: + +1. **Google Cloud Console** (https://console.cloud.google.com/) → crea progetto KetoPath. +2. **APIs & Services → OAuth consent screen** → External, scopes `userinfo.email` + `userinfo.profile`, Authorized domain ``. Aggiungi te stesso come Test User finché l'app è in modalità Testing. +3. **APIs & Services → Credentials → Create OAuth client ID** (Web application): + - Authorized JavaScript origins: `https://` + - Authorized redirect URI: `https:///api/auth/callback/google` +4. Aggiungi le credenziali a **entrambi** i `.env` (api e web) — Better Auth le legge da `process.env` al boot: + +```bash +# Da fare in apps/api/.env E apps/web/.env +echo "GOOGLE_CLIENT_ID='.apps.googleusercontent.com'" >> apps/api/.env +echo "GOOGLE_CLIENT_SECRET='GOCSPX-...'" >> apps/api/.env +# (idem per apps/web/.env) +``` + +5. **Rebuild + restart**: la pagina `/sign-in` è SSG (prerendered al build). Per renderizzare il bottone Google serve un nuovo build. + +```bash +pnpm --filter web build +pm2 restart ketopath-web --update-env +``` + ### 4.4 Crea `packages/db/.env` Prisma legge da qui durante le migration.