- nginx: rewrite the refresh cookie's Path=/auth to /api/auth on the
production proxy — without this the browser never sent the cookie
back on POST /api/auth/refresh and the session was lost on reload
- i18n: fallbackLng ru -> en, so only an actual ru browser locale
defaults to Russian, everything else defaults to English
- index.html: explicit English og:*/twitter:* tags so link previews
in Discord/etc. don't fall back to the (Russian) meta description
- Avatar upload: pick -> circular crop/reposition/zoom preview ->
confirm -> upload, instead of uploading the raw file blind
- Topbar: logo pill background removed, pixel-heart mark added next
to the LoVisual wordmark
- Fixed two tests left stale by the earlier tagline copy change
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
npm install with no committed package-lock.json re-resolved semver
ranges fresh on every deploy instead of pinning to bun.lock (the
project's actual lockfile) — a supply-chain integrity gap flagged by
automated commit review. Use bun, the frontend's real package manager,
with --frozen-lockfile so deploys are reproducible.
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
Multi-stage Dockerfiles for accounts-service/configs-service/gateway, a
docker-compose.prod.yml wiring fresh Postgres+MinIO+the three services on a
private network, nginx site templates for visual.loki-code.dev (static SPA +
/api proxy) and bekend.loki-code.dev (full gateway proxy for the mod), and
idempotent setup.sh/deploy.sh scripts for the VDS.
Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ