Since 2026-09-19 the site bridge worker served every path from Pages, so the
API server on the NAS had no public route: admin login (API_SERVER_URL)
and stt-proxy (D3RO_API_URL) called https://d3ro.chanpaca.net/api/... and
got the landing page's 405.
- The worker passes /app, /api and /health through to the domain origin
(the kd-nas tunnel) and serves everything else from Pages.
- The kd-nas tunnel sends path ^/app on d3ro.chanpaca.net to the web app
(NAS 3002); other paths keep going to the API (NAS 5050). No extra
hostname or DNS record is needed, so WEB_APP_ORIGIN is removed.
- API_PATH_PREFIXES joins WEB_APP_BASE_PATH in packages/core/src/web-urls.ts
(contract regenerated).
Verified live: /app/login 200, /health and /api/health 200, API login 401 for
an unknown account (was 405), landing/legal/404 unchanged, git/sso/admin
hosts unaffected.
Prices, quotas and site URLs were copied by hand into the edge functions,
admin, desktop and the landing site, and the copies disagreed (Payple billed
9,900/29,900 KRW, admin labels said 12,900/24,900 KRW and $9.9/$19.9, the
site said 2,900/8,900 KRW).
- packages/core/src/plan-catalog.ts is the single source for PLAN_PRICE_KRW
(Free 0 / Pro 2,900 / Pro+ 8,900 a month) and PLAN_QUOTA.
- packages/core/src/web-urls.ts is the single source for the public origin,
the /app web-app base path, SITE_URLS and billingUrl().
- Deno cannot bundle packages/core, so scripts/ci/sync-core-contract.mjs
generates _shared/core-contract.generated.ts; `npm run contract:check`
fails on drift (same pattern as version:sync).
- Payple checkout, renewal and webhook amount checks now bill the catalog
price, so existing subscribers move to the new price at their next renewal.
quota.ts, team-contract.ts and the tests read the generated values.
- Admin MRR/ARR is computed in KRW from the catalog; license labels, the
release link and desktop PREMIUM_LLM limits derive from core; the site
imports prices and quotas directly.
Policy: docs/REFACTOR_POLICY.md Wave 3, W3-1 and W3-2.