Commit graph

5 commits

Author SHA1 Message Date
9744dc7f24
fix(frontend): add a real robots.txt, cache hashed assets forever
Lighthouse audit findings:
- No robots.txt existed, so nginx's SPA fallback (try_files -> index.html)
  served the React app's HTML at /robots.txt -- crawlers got 44 "syntax
  not understood" lines instead of directives.
- No Cache-Control on /assets/*, so every visit re-fetched a hashed,
  content-addressed bundle that can never actually change under that
  URL. Lighthouse estimated 936 KiB/visit wasted on this alone.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-30 15:40:04 +02:00
e0531eda5e
fix(frontend): session cookie path, browser-language default, avatar crop, EN link previews, topbar logo
- nginx: rewrite the refresh cookie's Path=/auth to /api/auth on the
  production proxy — without this the browser never sent the cookie
  back on POST /api/auth/refresh and the session was lost on reload
- i18n: fallbackLng ru -> en, so only an actual ru browser locale
  defaults to Russian, everything else defaults to English
- index.html: explicit English og:*/twitter:* tags so link previews
  in Discord/etc. don't fall back to the (Russian) meta description
- Avatar upload: pick -> circular crop/reposition/zoom preview ->
  confirm -> upload, instead of uploading the raw file blind
- Topbar: logo pill background removed, pixel-heart mark added next
  to the LoVisual wordmark
- Fixed two tests left stale by the earlier tagline copy change

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 22:23:28 +02:00
1998cdae24
fix(deploy): use bun --frozen-lockfile instead of npm install
npm install with no committed package-lock.json re-resolved semver
ranges fresh on every deploy instead of pinning to bun.lock (the
project's actual lockfile) — a supply-chain integrity gap flagged by
automated commit review. Use bun, the frontend's real package manager,
with --frozen-lockfile so deploys are reproducible.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 15:30:42 +02:00
4c2486d7cd
fix(deploy): use npm install (no committed package-lock.json in frontend)
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 15:27:12 +02:00
2735a1c161
deploy(backend): add prod Dockerfiles, compose stack, nginx configs, deploy scripts
Multi-stage Dockerfiles for accounts-service/configs-service/gateway, a
docker-compose.prod.yml wiring fresh Postgres+MinIO+the three services on a
private network, nginx site templates for visual.loki-code.dev (static SPA +
/api proxy) and bekend.loki-code.dev (full gateway proxy for the mod), and
idempotent setup.sh/deploy.sh scripts for the VDS.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-28 14:47:53 +02:00