mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-08-13 14:37:26 +00:00
Adds apps/pwa: an Express + libSQL/Turso app that is now the home of team credential sharing, with the moshcode-style auth stack ported and reskinned to match logicsrc.com (light theme, Inter, green accent). apps/pwa - auth: email/password (scrypt), passkeys (WebAuthn), CoinPay OAuth, cookie sessions, and lsk_ API keys for the CLI via a loopback OAuth-PKCE flow (/cli/authorize + /cli/token). Ported from the moshcode PWA. - credshare API (/api/credshare/*): teams, members, invites, vaults, sealed grants, ciphertext secrets, audit — authed by session OR Bearer lsk_ key. Zero-knowledge: only ciphertext + sealed vault keys + public keys stored. - teams dashboard, accept-invite, and settings (API keys) pages, server-rendered in the LogicSRC brand (lib/html.mjs). - migrations (libSQL) 001_auth + 002_credshare, migrate-on-boot; Turso via TURSO_DATABASE_URL / TURSO_AUTH_TOKEN, or a local file db for dev. - trimmed moshcode-specific approvals/credits/push/deliver. CLI - `logicsrc login` now does browser loopback OAuth-PKCE against the app and stores an lsk_ token (email-OTP removed); --token for CI. Client repointed. Distribution - install.sh (served at logicsrc.com/install.sh) installs the CLI from the GitHub repo: tarball -> npm install -> `npm run build:cli` -> logicsrc wrapper. - root build:cli builds only the CLI's workspace chain (skips web/api/next). Cleanup - removed the commandboard-api credshare backend (superseded by the PWA) and its Supabase/Turso stores + libsql dep; commandboard-api tests green (40). - removed the Next.js /teams page (the PWA is the web UI now). Verified end-to-end: two accounts register on the PWA, mint lsk_ keys, CLI login uploads identity keys, owner pushes an encrypted .env, teammate invited -> accepted -> granted -> pulls the exact file. Server stores ciphertext only. Full workspace build + tests green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
38 lines
1.1 KiB
Text
38 lines
1.1 KiB
Text
# Canonical public site URL (used for CoinPay redirect/webhook URLs and secure cookies)
|
|
PUBLIC_URL=https://logicsrc.com
|
|
COMMANDBOARD_API_URL=http://localhost:4010
|
|
COMMANDBOARD_TOKEN=
|
|
COMMANDBOARD_DID=
|
|
COMMANDBOARD_AGENT_KEY=
|
|
LOGICSRC_SCHEMA_VERSION=0.1
|
|
|
|
COINPAY_API_URL=
|
|
COINPAY_API_KEY=
|
|
COINPAY_MERCHANT_ID=
|
|
COINPAY_BUSINESS_ID=
|
|
COINPAY_ELIGIBILITY_MERCHANT_ID=
|
|
COINPAY_ELIGIBILITY_API_KEY=
|
|
COINPAY_HIRE_US_BLOCKCHAIN=USDC_POL
|
|
COINPAY_WEBHOOK_SECRET=
|
|
COINPAY_OAUTH_ISSUER=https://coinpayportal.com
|
|
COINPAY_OAUTH_CLIENT_ID=
|
|
COINPAY_OAUTH_CLIENT_SECRET=
|
|
COINPAY_OAUTH_REDIRECT_URI=https://logicsrc.com/api/oauth/coinpay/callback
|
|
COINPAY_OAUTH_SCOPES=openid profile email
|
|
LOGICSRC_SESSION_SECRET=
|
|
|
|
UGIG_API_URL=
|
|
UGIG_API_KEY=
|
|
UGIG_WEBHOOK_SECRET=
|
|
|
|
SH1PT_API_URL=
|
|
SH1PT_API_KEY=
|
|
SH1PT_WEBHOOK_SECRET=
|
|
|
|
# Shared secret for the blog-post ingestion webhook (no admin user; the
|
|
# webhook authenticates callers by this secret instead). Generate with:
|
|
# openssl rand -hex 32
|
|
BLOG_WEBHOOK_SECRET=
|
|
|
|
# Team credential sharing lives in its own app — see apps/pwa/.env.example
|
|
# (Express + libSQL/Turso; auth + end-to-end-encrypted team vaults).
|