logicsrc/apps/pwa
Anthony Ettinger 20797a98f1
Some checks are pending
CI / build (push) Waiting to run
Deploy to dev2 / deploy (push) Waiting to run
test / test (push) Waiting to run
Run on Bun: bun install, bun --bun next, both dev2 sites on Bun (#222)
* Run on Bun: bun install, bun --bun next, both dev2 sites on Bun

Moves logicsrc.com and app.logicsrc.com (one image) off Node + npm onto Bun,
following the fleet recipe (phonenumbers.bot pilot).

- Package manager: bun.lock migrated from package-lock.json, so every resolved
  version is unchanged; packageManager bun@1.4.2. Root scripts run each
  workspace with `bun run --cwd <dir>` instead of `npm --workspace`.
- Bun 1.4.2, not the fleet's 1.4.0: 1.4.0 re-resolves this workspace's `file:`
  cross-references differently on every install, so its own lockfile never
  passes --frozen-lockfile. 1.4.2 is stable on it.
- Runtime: logicsrc-web runs `bun --bun next build/start`; apps/pwa (Express,
  app.logicsrc.com) runs `bun src/server.mjs`.
- Image: .nixpacks/Dockerfile (the path both dev2 compose stacks build) is now
  a hand-written oven/bun image carrying the whole workspace, run as the
  non-root bun user. ENTRYPOINT stays `bash -l -c` so a compose `command:` is
  one string, as before; app.logicsrc.com's compose starts it with
  "npm --workspace @logicsrc/pwa run start", which .nixpacks/npm (the image's
  only `npm`) turns into `bun run start` in apps/pwa. Port 3000, the PUBLIC_URL
  build arg and the / health path are unchanged. The nixpacks .nix and
  build.sh are gone.
- CI: both workflows install with bun and run every script through bun (Node
  stays only as the interpreter for vitest/tsc/node --test/Playwright, as
  before), and CI now boots the site under Bun.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci: boot check on port 3100 and stop it before Playwright needs 3000

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): keep next dev on port 5174, which Playwright waits on

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 08:14:40 -07:00
..
public feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare 2026-07-13 14:29:29 +00:00
src feat(pwa): move app.logicsrc.com from Turso/libSQL to Postgres via @profullstack/libsql-pg (#218) 2026-09-25 09:28:40 -07:00
test feat(pwa): move app.logicsrc.com from Turso/libSQL to Postgres via @profullstack/libsql-pg (#218) 2026-09-25 09:28:40 -07:00
.env.example feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare 2026-07-13 14:29:29 +00:00
.gitignore feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare 2026-07-13 14:29:29 +00:00
package.json Run on Bun: bun install, bun --bun next, both dev2 sites on Bun (#222) 2026-10-01 08:14:40 -07:00
Procfile feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare 2026-07-13 14:29:29 +00:00
railway.json feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare 2026-07-13 14:29:29 +00:00
README.md feat(pwa): move app.logicsrc.com from Turso/libSQL to Postgres via @profullstack/libsql-pg (#218) 2026-09-25 09:28:40 -07:00

@logicsrc/pwa — LogicSRC credentials

Express app on Postgres for team credential sharing: auth (email/password, passkeys, CoinPay OAuth, sessions, lsk_ CLI API keys) + end-to-end-encrypted team vaults. Zero-knowledge — the server only stores ciphertext, per-member sealed vault keys, and identity public keys. Decryption happens in the logicsrc CLI.

cp .env.example .env      # set SESSION_SECRET; DATABASE_URL=postgres://… for prod (else a local libSQL file db)
npm install
npm start                 # migrates on boot, serves on :8080

Database

Production runs on Postgres: DATABASE_URL must be a postgres:// URL and the app refuses to start on anything else there (a leftover libsql:// value is called out by name). The client is @profullstack/libsql-pg, which keeps the @libsql/client surface the code was written against and rewrites the remaining SQLite idioms per statement. Development and the tests use libSQL itself (file:./data/local.db by default, :memory: in tests).

Migrations run at boot and live in two dialect copies with the same file names: src/migrations/ (SQLite) and src/migrations-pg/ (Postgres, generated with npx libsql-pg convert-schema and reviewed). npm run migrate applies the copy matching DATABASE_URL. To move an existing Turso database:

DATABASE_URL=postgres://… npm run migrate                                   # schema
npx libsql-pg copy --from "$TURSO_DATABASE_URL" --token "$TURSO_AUTH_TOKEN" \
  --to "$DATABASE_URL" --verify                                             # rows

Set PWA_TEST_DATABASE_URL=postgres://… to run the test suite against a real Postgres (it drops and recreates the public schema of that database).

The CLI connects with LOGICSRC_API=<origin> logicsrc login (browser OAuth-PKCE loopback → an lsk_ key). See docs/credential-sharing.md in the repo root.