All four services now share one builder stage (dependencies compile once per
deploy, not once per service). BuildKit cache mounts keep the cargo registry
and target/ between deploys: a one-line change rebuilds in ~16 s instead of
recompiling the whole dependency tree.
- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL
- migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified
- reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503
- forgot-password and resend-verification do their work in a background task (no timing oracle)
- device linking requires a verified email; email_verified exposed via /me and gRPC
- gateway rate limits, SMTP_* in compose and .env.example
- frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
accounts-service returned avatar_url built from the internal S3_ENDPOINT
(http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never
rendered and the re-crop fetch failed. MinIO is intentionally not exposed.
Add a public GET /media/{key} read route in accounts-service (behind the
gateway internal-key guard, no identity required so anonymous profile pages
work) that streams the object out of private MinIO. Introduce
AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the
internal endpoint; prod sets it to the same-origin /api/media, gateway routes
the media segment to accounts.
minio/minio and minio/mc are no longer pullable from Docker Hub; use
quay.io/minio/minio for both the server and the one-shot bucket-init step
(mc ships bundled inside the minio image).
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
Multi-stage Dockerfiles for accounts-service/configs-service/gateway, a
docker-compose.prod.yml wiring fresh Postgres+MinIO+the three services on a
private network, nginx site templates for visual.loki-code.dev (static SPA +
/api proxy) and bekend.loki-code.dev (full gateway proxy for the mod), and
idempotent setup.sh/deploy.sh scripts for the VDS.
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ