feat(web): serve the web app under /app and send every billing link there (WS-B)

apps/web was never deployed, so /billing on the public domain returned the
landing page and d3ro.dev (desktop "upgrade") did not resolve.

- apps/web runs with basePath /app and output standalone; /download and
  /releases redirect to the site's #download. A Dockerfile and a d3ro-web
  compose service (port 3002) deploy it to the NAS with the other images.
- The site bridge worker forwards /app/* to WEB_APP_ORIGIN (the tunnel host)
  and rewrites upstream redirects; everything else still goes to Pages.
  With no origin configured /app answers 503 instead of the landing page.
- Desktop upgrade, desktop Stripe return, mobile subscription management,
  the web checkout/portal returns and the site all use billingUrl(); the
  return query is success=1 / canceled=1, which the billing page reads.
  The billing page highlights ?tier=pro|pro_plus, and signing in from a
  billing link returns to the same plan.
- auth/callback pins the redirect origin in production and rejects
  protocol-relative next= values (open redirect).
- Mobile legal links use SITE_URLS (fixes the missing slash on /terms).
- Compose drops the unused NEXT_PUBLIC_API_URL and the dead wwwroot legal
  mounts; deploy scripts add the web image and the SUPABASE_* values the NAS
  compose already required; .dockerignore keeps app .env files out of images.
- Supabase auth redirects allow /app/** (remote dashboard must match).

Policy: docs/REFACTOR_POLICY.md Wave 3, W3-3 and W3-4.
This commit is contained in:
Yun Chan 2026-09-26 15:48:30 +09:00
parent 88f24d84a1
commit b6fe588a7c
30 changed files with 493 additions and 95 deletions

View file

@ -2,18 +2,23 @@
// 공유 레이아웃 — auth 가드 + Sidebar
// route group `(app)`은 URL에 영향을 주지 않고 하위 모든 라우트에 적용.
import { headers } from 'next/headers'
import { redirect } from 'next/navigation'
import { Box } from '@mui/material'
import { Sidebar } from '@/components/layout/sidebar'
import { getSupabaseServerClient, isSupabaseConfiguredServer } from '@/lib/supabase-server'
import { loginPath, RETURN_PATH_HEADER } from '@/lib/web-app-url'
export default async function AppLayout({
children
}: {
children: React.ReactNode
}): Promise<React.ReactElement> {
// 결제 진입(/billing?tier=…)처럼 proxy 가 경로를 넘긴 요청은 로그인 뒤 그 경로로 돌아온다.
const returnPath = (await headers()).get(RETURN_PATH_HEADER)
if (!isSupabaseConfiguredServer()) {
redirect('/login')
redirect(loginPath(returnPath))
}
const supabase = await getSupabaseServerClient()
@ -22,7 +27,7 @@ export default async function AppLayout({
} = await supabase.auth.getUser()
if (!user) {
redirect('/login')
redirect(loginPath(returnPath))
}
return (