feat(web): serve the web app under /app and send every billing link there (WS-B)

apps/web was never deployed, so /billing on the public domain returned the
landing page and d3ro.dev (desktop "upgrade") did not resolve.

- apps/web runs with basePath /app and output standalone; /download and
  /releases redirect to the site's #download. A Dockerfile and a d3ro-web
  compose service (port 3002) deploy it to the NAS with the other images.
- The site bridge worker forwards /app/* to WEB_APP_ORIGIN (the tunnel host)
  and rewrites upstream redirects; everything else still goes to Pages.
  With no origin configured /app answers 503 instead of the landing page.
- Desktop upgrade, desktop Stripe return, mobile subscription management,
  the web checkout/portal returns and the site all use billingUrl(); the
  return query is success=1 / canceled=1, which the billing page reads.
  The billing page highlights ?tier=pro|pro_plus, and signing in from a
  billing link returns to the same plan.
- auth/callback pins the redirect origin in production and rejects
  protocol-relative next= values (open redirect).
- Mobile legal links use SITE_URLS (fixes the missing slash on /terms).
- Compose drops the unused NEXT_PUBLIC_API_URL and the dead wwwroot legal
  mounts; deploy scripts add the web image and the SUPABASE_* values the NAS
  compose already required; .dockerignore keeps app .env files out of images.
- Supabase auth redirects allow /app/** (remote dashboard must match).

Policy: docs/REFACTOR_POLICY.md Wave 3, W3-3 and W3-4.
This commit is contained in:
Yun Chan 2026-09-26 15:48:30 +09:00
parent 88f24d84a1
commit b6fe588a7c
30 changed files with 493 additions and 95 deletions

View file

@ -1,6 +1,7 @@
# ============================================================================
# D3RO Voice — Standalone NAS Docker Compose Specification
# Includes: Core API + Promotional Site + Full Next.js Admin CRM
# Includes: Core API + Next.js Admin CRM + Web App (/app)
# 랜딩·법률 문서는 site/(Cloudflare Pages)가 정본이다. 여기서 서빙하지 않는다.
# ============================================================================
services:
d3ro-api-server:
@ -23,12 +24,6 @@ services:
- TZ=${TZ:-Asia/Seoul}
volumes:
- ${DATA_PATH:-./data}:/app/data
# Play policy/legal endpoints must survive API image recreation without
# replacing unrelated static assets embedded in the running image.
- /volume1/docker/d3ro/wwwroot/privacy:/app/wwwroot/privacy:ro
- /volume1/docker/d3ro/wwwroot/terms:/app/wwwroot/terms:ro
- /volume1/docker/d3ro/wwwroot/delete-account:/app/wwwroot/delete-account:ro
- /volume1/docker/d3ro/wwwroot/legal.css:/app/wwwroot/legal.css:ro
logging:
driver: "json-file"
options:
@ -44,7 +39,6 @@ services:
environment:
- NODE_ENV=production
- PORT=3001
- NEXT_PUBLIC_API_URL=${PUBLIC_URL:-https://d3ro.chanpaca.net}
- API_SERVER_URL=${API_SERVER_URL:?API_SERVER_URL is required}
- ADMIN_SESSION_SECRET=${ADMIN_SESSION_SECRET:?ADMIN_SESSION_SECRET is required}
- ADMIN_COOKIE_SECURE=${ADMIN_COOKIE_SECURE:-true}
@ -57,3 +51,25 @@ services:
options:
max-size: "10m"
max-file: "3"
# ============================================================================
# D3RO Voice — Web App (@d3ro/web), 공개 경로 https://d3ro.chanpaca.net/app
# 사이트 브리지 워커가 /app/* 를 Cloudflare Tunnel 을 거쳐 이 컨테이너로 보낸다.
# ============================================================================
d3ro-web:
image: d3ro-voice-web:latest
container_name: d3ro_voice_web
restart: unless-stopped
ports:
- "${WEB_PORT:-3002}:3002"
# NEXT_PUBLIC_SUPABASE_URL / NEXT_PUBLIC_SUPABASE_ANON_KEY / NEXT_PUBLIC_PAYPLE_CLIENT_KEY 는
# 이미지 빌드 때 번들에 들어간다(build args). 런타임에 넣어도 바뀌지 않으므로 여기 두지 않는다.
environment:
- NODE_ENV=production
- PORT=3002
- TZ=${TZ:-Asia/Seoul}
logging:
driver: "json-file"
options:
max-size: "10m"
max-file: "3"