docs: documenta NEXT_PUBLIC_APP_URL e setup Google OAuth nel runbook

Due colpevoli scoperti durante il deploy live:
- `NEXT_PUBLIC_APP_URL` mancava nel runbook ed in .env.example. Il client di Better Auth (lib/auth-client.ts) la usa come baseURL — senza, fallback a localhost:3000 → CORS error sul click di "Continua con Google". Va inlined al build (è NEXT_PUBLIC_*), quindi modificarla richiede rebuild.
- Setup Google OAuth: il bottone è SSG (prerendered al build), quindi aggiungere le env GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET non basta — serve rebuild perché `enabledSocialProviders` è valutato a build-time.

Aggiunta una sezione 4.3.bis dedicata al setup Google con i punti critici evidenziati.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
lucianoandClaude Opus 4.7 committed 2026-05-07 14:52:53 +02:00
1 parent 6a5559fa0a
commit 38f28e015b
2 files changed
+38 -3

No files matched your search

+8 -3
View File
@@ -17,9 +17,14 @@ PRISMA_FIELD_ENCRYPTION_KEY=
BETTER_AUTH_SECRET=
BETTER_AUTH_URL=http://localhost:3000
# Google OAuth (configurato a fine progetto)
# GOOGLE_CLIENT_ID=
# GOOGLE_CLIENT_SECRET=
# Google OAuth — abilita il bottone "Continua con Google" in /sign-in /sign-up.
# Setup: console.cloud.google.com → APIs & Services → Credentials →
# OAuth client ID (Web app) → Authorized redirect URI:
# https://<DOMAIN>/api/auth/callback/google
# Devono essere configurate ANCHE in apps/web/.env (Better Auth le legge da
# entrambi i lati per costruire enabledSocialProviders al boot).
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Sentry — error tracking (lascia vuoto per disabilitare)
# SENTRY_DSN=
+30
View File
@@ -321,9 +321,39 @@ BETTER_AUTH_SECRET=<BETTER_AUTH_SECRET>
BETTER_AUTH_URL=https://lamiadieta.luzaonline.net
API_URL=http://127.0.0.1:4000
NEXT_PUBLIC_VAPID_PUBLIC_KEY=<VAPID_PUBLIC>
# IMPORTANTE: il client di Better Auth (lib/auth-client.ts) usa questa env per
# costruire la baseURL delle fetch OAuth. Se manca → fallback a localhost:3000
# → CORS error sul login Google. È inlined al build, quindi cambiarla richiede
# un nuovo `pnpm --filter web build`.
NEXT_PUBLIC_APP_URL=https://lamiadieta.luzaonline.net
EOF
```
### 4.3.bis Google OAuth (opzionale, per il login con Google)
Se vuoi abilitare "Continua con Google" su `/sign-in` e `/sign-up`:
1. **Google Cloud Console** (https://console.cloud.google.com/) → crea progetto KetoPath.
2. **APIs & Services → OAuth consent screen** → External, scopes `userinfo.email` + `userinfo.profile`, Authorized domain `<DOMAIN>`. Aggiungi te stesso come Test User finché l'app è in modalità Testing.
3. **APIs & Services → Credentials → Create OAuth client ID** (Web application):
- Authorized JavaScript origins: `https://<DOMAIN>`
- Authorized redirect URI: `https://<DOMAIN>/api/auth/callback/google`
4. Aggiungi le credenziali a **entrambi** i `.env` (api e web) — Better Auth le legge da `process.env` al boot:
```bash
# Da fare in apps/api/.env E apps/web/.env
echo "GOOGLE_CLIENT_ID='<client_id>.apps.googleusercontent.com'" >> apps/api/.env
echo "GOOGLE_CLIENT_SECRET='GOCSPX-...'" >> apps/api/.env
# (idem per apps/web/.env)
```
5. **Rebuild + restart**: la pagina `/sign-in` è SSG (prerendered al build). Per renderizzare il bottone Google serve un nuovo build.
```bash
pnpm --filter web build
pm2 restart ketopath-web --update-env
```
### 4.4 Crea `packages/db/.env`
Prisma legge da qui durante le migration.