ADR 0003: VAPID self-hosted today, DeviceToken model agnostic to
platform so iOS/Android (Expo/APNs/FCM) plug in as new senders later.
Backend (apps/api/src/modules/notifications)
- sender.ts: NotificationSender interface, WebPushSender via VAPID
- notifications.routes.ts: GET /me/notifications/config, POST/DELETE
/me/device-tokens, PATCH /me/notifications/settings, POST /me/notifications/test
- scheduler.ts: node-cron Mon 09:00 Europe/Rome for weekly weigh-in
reminder; auto-cleanup of expired tokens on 404/410
- env: VAPID_PUBLIC_KEY/PRIVATE_KEY/SUBJECT (all optional → push gracefully off)
Frontend
- public/sw.js minimal (push + notificationclick)
- lib/notifications/push-client.ts: subscribe / unsubscribe / getCurrentSubscription
- profile/notifications-{actions,panel}.tsx: editorial panel with toggles,
device list, "send test", per-device removal
- pushReady requires both permission AND active subscription (covers the
case where the user revoked the SW but kept the browser permission)
Schema
- DeviceToken { userId, platform, endpoint, p256dh, auth, token, userAgent,
createdAt, lastSeenAt } with unique(userId, endpoint)
- ExtendedPrismaClient type exported from @ketopath/db
- NotificationSettings zod schema in @ketopath/shared
Tooling
- lint-staged: split .js out of eslint glob so service worker is only
formatted (it lives outside the TS project)
i18n
- Notifications namespace (it) with typed error keys
Smoke tested: POST /me/device-tokens 201, POST /me/notifications/test 200,
real push delivered to a macOS Chrome device.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
34 lines
1.1 KiB
Bash
34 lines
1.1 KiB
Bash
# Next.js
|
|
NEXT_PUBLIC_APP_URL=http://localhost:3000
|
|
|
|
# API server URL (server-only — non esporre al browser)
|
|
API_URL=http://localhost:4000
|
|
|
|
# Better Auth (deve coincidere con apps/api/.env)
|
|
# Genera un secret a 32+ byte: `openssl rand -base64 32`
|
|
BETTER_AUTH_SECRET=
|
|
BETTER_AUTH_URL=http://localhost:3000
|
|
|
|
# Database (Better Auth usa @ketopath/db, che legge DATABASE_URL)
|
|
DATABASE_URL=postgresql://luciano:luciano%40@localhost:5432/ketopath?schema=public
|
|
|
|
# Cifratura at-rest dei campi sanitari (vedi ADR 0002).
|
|
# DEVE essere identica a apps/api/.env.
|
|
PRISMA_FIELD_ENCRYPTION_KEY=
|
|
|
|
# Google OAuth (configurato a fine progetto)
|
|
# GOOGLE_CLIENT_ID=
|
|
# GOOGLE_CLIENT_SECRET=
|
|
|
|
# Sentry — error tracking (lascia vuoto per disabilitare)
|
|
# NEXT_PUBLIC_SENTRY_DSN=
|
|
# Per il source-map upload in produzione (opzionale):
|
|
# SENTRY_AUTH_TOKEN=
|
|
# SENTRY_ORG=
|
|
# SENTRY_PROJECT=
|
|
|
|
# Web Push — chiave pubblica VAPID (vedi ADR 0003).
|
|
# Stessa chiave pubblica configurata in apps/api/.env come VAPID_PUBLIC_KEY.
|
|
# Lascia vuoto per disattivare il flusso di iscrizione lato client.
|
|
NEXT_PUBLIC_VAPID_PUBLIC_KEY=
|