Wire prisma-field-encryption AES-256-GCM extension on the shared Prisma client and annotate the four sensitive columns on Profile with @encrypted: - weightStartKg / weightCurrentKg / weightGoalKg (Decimal → String) - targetDate (DateTime @db.Date → String, ISO YYYY-MM-DD) Other Profile fields stay in clear text per ADR 0002 (age, gender, heightCm, activityLevel) — they're needed for plan generation and aggregate analytics, and are not strongly identifying on their own. apps/api profile.routes.ts: - serialize() now reads the columns as strings and parses them back to numbers for BMR/TDEE; targetDate is already an ISO string from the DB - the upsert stringifies numeric inputs and slices the date to YYYY-MM-DD Env wiring: - packages/db, apps/api, apps/web .env.example all document PRISMA_FIELD_ENCRYPTION_KEY (k1.aesgcm256.<base64url>) — must match across every process that hits the DB - key generation snippet documented inline Migration is intentionally NOT in this commit: needs to be created against a live Postgres instance and applied. The fields change Decimal/Date → text so prisma migrate dev will require a USING cast — see the follow-up commit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
29 lines
867 B
Bash
29 lines
867 B
Bash
# Next.js
|
|
NEXT_PUBLIC_APP_URL=http://localhost:3000
|
|
|
|
# API server URL (server-only — non esporre al browser)
|
|
API_URL=http://localhost:4000
|
|
|
|
# Better Auth (deve coincidere con apps/api/.env)
|
|
# Genera un secret a 32+ byte: `openssl rand -base64 32`
|
|
BETTER_AUTH_SECRET=
|
|
BETTER_AUTH_URL=http://localhost:3000
|
|
|
|
# Database (Better Auth usa @ketopath/db, che legge DATABASE_URL)
|
|
DATABASE_URL=postgresql://luciano:luciano%40@localhost:5432/ketopath?schema=public
|
|
|
|
# Cifratura at-rest dei campi sanitari (vedi ADR 0002).
|
|
# DEVE essere identica a apps/api/.env.
|
|
PRISMA_FIELD_ENCRYPTION_KEY=
|
|
|
|
# Google OAuth (configurato a fine progetto)
|
|
# GOOGLE_CLIENT_ID=
|
|
# GOOGLE_CLIENT_SECRET=
|
|
|
|
# Sentry — error tracking (lascia vuoto per disabilitare)
|
|
# NEXT_PUBLIC_SENTRY_DSN=
|
|
# Per il source-map upload in produzione (opzionale):
|
|
# SENTRY_AUTH_TOKEN=
|
|
# SENTRY_ORG=
|
|
# SENTRY_PROJECT=
|