Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 0 additions & 7 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,3 @@ NEXT_PUBLIC_APP_URL=http://localhost:3000

# Public variables are bundled into browser JavaScript.
# Only use NEXT_PUBLIC_ for values that are safe for every visitor to see.

# Private server-only variables for future integrations.
# These are placeholders only; AckLab does not use them in the local mock MVP.
# AUTH_SECRET=
# DATABASE_URL=
# STRIPE_SECRET_KEY=
# ANALYTICS_WRITE_KEY=
5 changes: 4 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ concurrency:

jobs:
verify:
name: Lint, Typecheck, Build
name: Lint, Typecheck, Test, Build
runs-on: ubuntu-latest
timeout-minutes: 15

Expand Down Expand Up @@ -45,5 +45,8 @@ jobs:
- name: Typecheck
run: pnpm typecheck

- name: Test
run: pnpm test

- name: Build
run: pnpm build
9 changes: 9 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
<!-- BEGIN:nextjs-agent-rules -->

# This is NOT the Next.js you know

This version has breaking changes — APIs, conventions, and file structure may all differ from your training data. Read the relevant guide in `node_modules/next/dist/docs/` (resolved from this file's directory; in monorepos the `next` package may not be visible from the repo root) before writing any code. Heed deprecation notices.

This block is written and re-added by `next dev` — verify at `node_modules/next/dist/server/lib/generate-agent-files.js`. Removing it from a diff only re-creates the uncommitted change; committing it with your work keeps the tree clean.

<!-- END:nextjs-agent-rules -->
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
@AGENTS.md
25 changes: 14 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,16 +28,13 @@ src/components/layout/ shell, nav, command menu, theme provider
src/components/shared/ reusable product UI
src/components/visualizations/
src/features/ domain-owned interactive tools and visualizers
src/services/ future auth/API/payment/progress contracts only
src/data/ local mock data
src/types/ shared TypeScript contracts
src/config/ app and environment configuration
src/constants/ navigation and constants
docs/ architecture and deployment documentation
```

Future infrastructure concerns are represented by interface contracts in `src/services/`, but no network calls or server-side integrations are active.

## Local Setup

Use pnpm through Corepack:
Expand All @@ -60,6 +57,7 @@ pnpm build # create production build
pnpm start # run production server after build
pnpm lint # run ESLint
pnpm typecheck # run TypeScript checks
pnpm test # run Vitest unit tests
pnpm format # write Prettier formatting
pnpm format:check # verify Prettier formatting
pnpm docker:build # build local production Docker image
Expand All @@ -68,6 +66,16 @@ pnpm docker:compose # run Compose-based local container test
pnpm clean # remove generated build artifacts
```

### Next version floor

Stay on Next >= 16.3.0. On 16.2.6 the Turbopack dev server spawned an unbounded
number of `.next/dev/build/postcss.js` child processes when compiling a page
(500+ within 20 seconds), saturating every core and hard-freezing the machine.
`experimental.turbopackPluginRuntimeStrategy: "workerThreads"` was not a
workaround — it throws `ERR_SOCKET_BAD_PORT` in `createIpc` and hangs the
compile. 16.3.0 fixes both that and the workspace-root inference; if you ever
need to downgrade, run `next dev --webpack` instead.

## Environment Variables

Environment validation lives in `src/config/env.ts`.
Expand All @@ -82,13 +90,6 @@ Public variables:

- `NEXT_PUBLIC_APP_URL`: browser-visible app URL.

Private placeholders for future integrations:

- `AUTH_SECRET`
- `DATABASE_URL`
- `STRIPE_SECRET_KEY`
- `ANALYTICS_WRITE_KEY`

Do not expose secrets through `NEXT_PUBLIC_`. Any value with that prefix can be bundled into client-side JavaScript.

## Docker
Expand Down Expand Up @@ -128,6 +129,7 @@ CI runs on `push` and `pull_request`:
- install with frozen lockfile
- lint
- typecheck
- test
- build

## Deployment
Expand All @@ -152,7 +154,8 @@ docker run --rm -p 3000:3000 acklab:local
## Security Defaults

- Security headers are configured in `next.config.ts`.
- A report-only Content Security Policy placeholder is included for tightening before production enforcement.
- An enforced Content Security Policy is configured in `next.config.ts`. `script-src` still allows `'unsafe-inline'` and `'unsafe-eval'` because Next's bootstrap requires them; tightening that needs per-request nonces.
- `upgrade-insecure-requests` is sent in production builds only. The dev server is HTTP, so the directive rewrites every subresource to https and the app renders with no CSS or JS at all. Safari upgrades even on `localhost`; Chrome exempts `localhost` but not a bare LAN IP, so it breaks on the `Network:` URL that `next dev` prints. Chrome on `localhost` is the one combination that hides this — check Safari before assuming a CSP change is dev-safe.
- No secrets are required for the MVP.
- `.env.local` and other local environment files are ignored by Git.
- Runtime Docker container runs as a non-root user.
Expand Down
16 changes: 0 additions & 16 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,19 +17,3 @@ AckLab is organized as a feature-oriented Next.js App Router project. The curren
- `src/components/visualizations/` contains shared visual building blocks.
- `src/data/` contains local mock data.
- `src/lib/` contains shared utilities and networking primitives.
- `src/services/` contains future service contracts only.

## Future Expansion Boundaries

- Auth: `src/services/auth`
- RBAC: `src/services/rbac`
- API client: `src/services/api`
- Database: `src/services/database`
- Payments and subscriptions: `src/services/payments`
- Progress tracking: `src/services/progress`
- Quiz engine: `src/services/quiz`
- Analytics: `src/services/analytics`
- Rate limiting and secure sessions: `src/services/security`
- Audit logging: `src/services/audit`

These placeholders are intentionally minimal. Add real adapters behind these contracts only when the product introduces server-side infrastructure.
7 changes: 0 additions & 7 deletions docs/deployment.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,13 +14,6 @@ Public variables:

- `NEXT_PUBLIC_APP_URL`: safe browser-visible site URL.

Private placeholders:

- `AUTH_SECRET`
- `DATABASE_URL`
- `STRIPE_SECRET_KEY`
- `ANALYTICS_WRITE_KEY`

Do not prefix secrets with `NEXT_PUBLIC_`. Values with that prefix are bundled into browser JavaScript.

## Local Development
Expand Down
Loading