d3ro-voice/server/supabase/config.toml
Yun Chan b6fe588a7c feat(web): serve the web app under /app and send every billing link there (WS-B)
apps/web was never deployed, so /billing on the public domain returned the
landing page and d3ro.dev (desktop "upgrade") did not resolve.

- apps/web runs with basePath /app and output standalone; /download and
  /releases redirect to the site's #download. A Dockerfile and a d3ro-web
  compose service (port 3002) deploy it to the NAS with the other images.
- The site bridge worker forwards /app/* to WEB_APP_ORIGIN (the tunnel host)
  and rewrites upstream redirects; everything else still goes to Pages.
  With no origin configured /app answers 503 instead of the landing page.
- Desktop upgrade, desktop Stripe return, mobile subscription management,
  the web checkout/portal returns and the site all use billingUrl(); the
  return query is success=1 / canceled=1, which the billing page reads.
  The billing page highlights ?tier=pro|pro_plus, and signing in from a
  billing link returns to the same plan.
- auth/callback pins the redirect origin in production and rejects
  protocol-relative next= values (open redirect).
- Mobile legal links use SITE_URLS (fixes the missing slash on /terms).
- Compose drops the unused NEXT_PUBLIC_API_URL and the dead wwwroot legal
  mounts; deploy scripts add the web image and the SUPABASE_* values the NAS
  compose already required; .dockerignore keeps app .env files out of images.
- Supabase auth redirects allow /app/** (remote dashboard must match).

Policy: docs/REFACTOR_POLICY.md Wave 3, W3-3 and W3-4.
2026-09-26 15:48:30 +09:00

178 lines
3.8 KiB
TOML

# Supabase 프로젝트 설정 (로컬 개발 + CLI 기준)
# 공식 문서: https://supabase.com/docs/guides/cli/config
project_id = "d3ro-voice"
[api]
enabled = true
port = 55321
schemas = ["public", "storage"]
extra_search_path = ["public", "extensions"]
max_rows = 1000
[db]
port = 55322
shadow_port = 55320
major_version = 17
[db.pooler]
enabled = false
[db.seed]
enabled = true
sql_paths = ["./seed.sql"]
[realtime]
enabled = true
[studio]
enabled = true
port = 55323
[inbucket]
enabled = true
port = 55324
[storage]
enabled = true
file_size_limit = "50MiB"
[auth]
enabled = true
site_url = "http://localhost:5173"
additional_redirect_urls = [
"http://localhost:5173",
"http://localhost:3000",
"http://localhost:3001",
"https://d3ro.chanpaca.net",
"https://d3ro.chanpaca.net/app/**",
"http://localhost:3000/app/**",
"d3ro-voice://auth-callback"
]
jwt_expiry = 3600
enable_signup = true
enable_anonymous_sign_ins = false
enable_manual_linking = false
[auth.email]
enable_signup = true
double_confirm_changes = true
enable_confirmations = false
[auth.external.google]
enabled = true
client_id = "env(GOOGLE_OAUTH_CLIENT_ID)"
secret = "env(GOOGLE_OAUTH_SECRET)"
redirect_uri = ""
[auth.external.github]
enabled = true
client_id = "env(GITHUB_OAUTH_CLIENT_ID)"
secret = "env(GITHUB_OAUTH_SECRET)"
redirect_uri = ""
[auth.external.apple]
enabled = true
client_id = "env(APPLE_OAUTH_CLIENT_ID)"
secret = "env(APPLE_OAUTH_SECRET)"
redirect_uri = ""
[edge_runtime]
enabled = true
policy = "per_worker"
inspector_port = 55383
[functions.stt-proxy]
# requireUser()에서 직접 인증 처리
verify_jwt = false
[functions.llm-proxy]
# 2026 sb_publishable_ 키와 Gateway JWT 검증 비호환 — requireUser()에서 직접 인증
verify_jwt = false
[functions.content-report]
# requireUser() verifies the caller before the service-only reporting RPC.
verify_jwt = false
[functions.generate-meeting-document]
# requireUser() authenticates the caller before the service-role atomic RPCs.
verify_jwt = false
[functions.realtime-token]
# 2026 sb_publishable_ 키와 Gateway JWT 검증 비호환 — requireUser()에서 직접 인증
verify_jwt = false
[functions.stripe-checkout]
verify_jwt = true
[functions.billing-catalog]
# requireUser supports modern publishable keys and validates the access token.
verify_jwt = false
[functions.stripe-portal]
verify_jwt = true
[functions.stripe-webhook]
verify_jwt = false
[functions.payple-checkout]
verify_jwt = false
[functions.payple-webhook]
verify_jwt = false
[functions.payple-manage]
verify_jwt = false
[functions.payple-renew]
verify_jwt = false
[functions.team-invite]
verify_jwt = true
[functions.team-accept]
verify_jwt = true
[functions.send-push]
# Mixed user-JWT and service-key endpoint. The handler verifies either the
# current user session or an exact server secret; platform JWT verification
# would reject modern sb_secret_ service calls before code can authorize them.
verify_jwt = false
[functions.embed-chunks]
verify_jwt = true
[functions.search-knowledge]
verify_jwt = true
[functions.admin-users]
verify_jwt = true
[functions.admin-subscriptions]
verify_jwt = true
[functions.admin-payments]
verify_jwt = true
[functions.admin-audit-log]
verify_jwt = true
[functions.account-delete]
# requireUser() verifies the current access token and the function additionally
# requires a recently issued session before destructive deletion.
verify_jwt = false
[functions.iap-verify]
# Store verification occurs only after requireUser() validates the caller.
verify_jwt = false
[functions.admob-ssv]
# AdMob calls this endpoint without a Supabase JWT; ECDSA SSV validation is mandatory.
verify_jwt = false
[functions.google-play-rtdn]
# Pub/Sub calls this endpoint with a Google-issued OIDC token validated in the function.
verify_jwt = false
[analytics]
enabled = false