diff options
| author | srdusr <[email protected]> | 2025-12-18 19:21:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-12-18 19:21:00 +0200 |
| commit | b371f21989bfca13fe8cc9bd59e95f5614f63b0d (patch) | |
| tree | 4244c0d4a7000aa12cfee4e86f3ffcc6476bc4ec /crates | |
| parent | 1740327557074df0c8b99635ee949e2540ac94d0 (diff) | |
| download | typerpunk-b371f21989bfca13fe8cc9bd59e95f5614f63b0d.tar.gz typerpunk-b371f21989bfca13fe8cc9bd59e95f5614f63b0d.zip | |
Fix the end screen layout, make the app responsive, document secrets
End screen
- There was an auto-fit routine that forced this screen into one viewport: it
shrank the graph to a 120px floor, trimmed the Play Again margin, then
capped the passage box at 80px with its own scrollbar. On a 650px window
that left the passage 80px tall and clipped, and the graph 120px, which are
the two things the screen exists to show. Removed. The page scrolls
instead, which is the right trade for a screen that is read rather than
acted on under time pressure.
- The screen is a flex column, so its children also shrank by default once
the content was taller than the viewport. The passage, graph, stat row and
standings no longer shrink, and the chart has a floor below which it stops
carrying information.
Bottom chrome
- The keyboard hint and the footer links were both fixed at bottom centre and
overlapped at every window size. The hint now sits above the footer.
- Normal-flow content could end up underneath the fixed footer and the corner
rails. One --bottom-chrome variable reserves that space on every screen.
- On a narrow screen the footer grows to the full width once its links wrap,
so at 375px it ran through both corner rails and covered Play Again, which
made the button unclickable. The chrome stacks there instead: rails on the
bottom line, footer above them, hint above that.
Mode picker
- It ran to the last pixel of the window at every size. It now keeps clear of
the bottom edge, and opens upward when a short window leaves more room
above than below.
Responsive
- Checked at nine viewports from 1920x1080 down to 375x667: no horizontal
overflow and nothing off-screen on the menu, the typing screen or the end
screen.
Configuration
- dotenvy searches upward from the working directory, so crates/server/.env
was only found when starting the server from that directory. The repository
root is tried as well, which is where it is usually started from.
- .env.example and the README explain where secrets belong: the environment,
a gitignored .env for local work, and EnvironmentFile or a platform secret
store in production. Also what to do if one is exposed.
- TYPERPUNK_ADMIN_USERNAME and TYPERPUNK_ENV are documented rather than left
to be discovered in the source.
Diffstat (limited to 'crates')
| -rw-r--r-- | crates/server/.env.example | 18 | ||||
| -rw-r--r-- | crates/server/src/main.rs | 9 |
2 files changed, 26 insertions, 1 deletions
diff --git a/crates/server/.env.example b/crates/server/.env.example index 8485826..b7501a1 100644 --- a/crates/server/.env.example +++ b/crates/server/.env.example @@ -1,3 +1,11 @@ +# Copy this file to .env and fill it in. .env is gitignored and must never be +# committed: it is the only place a password or a client secret belongs. +# +# In production, prefer real environment variables over a file. systemd units +# take EnvironmentFile= with the file owned by root and mode 600; container +# runtimes and hosting platforms have their own secret stores. The server reads +# plain environment variables either way, so nothing here has to change. + # Postgres. Create the database and role first: # sudo -u postgres createuser --pwprompt typerpunk # sudo -u postgres createdb -O typerpunk typerpunk @@ -13,6 +21,16 @@ FRONTEND_ORIGIN=http://localhost:4173 # texts.json in the process's working directory (the repo root, normally). TEXTS_JSON_PATH=texts.json +# The account promoted to administrator at startup. That account can appoint +# moderators from the Contribute screen. Leave it unset once the roles are +# assigned; it is only needed to create the first administrator, or to recover +# if the last one is removed. +TYPERPUNK_ADMIN_USERNAME= + +# Set to production to make the server refuse to start on an unsafe +# configuration rather than warn about it. +TYPERPUNK_ENV= + # Set to 1 behind TLS in production. Left off for local HTTP dev, where a # Secure cookie would silently never be set by the browser. COOKIE_SECURE=0 diff --git a/crates/server/src/main.rs b/crates/server/src/main.rs index 22cd9cd..b291e64 100644 --- a/crates/server/src/main.rs +++ b/crates/server/src/main.rs @@ -102,7 +102,14 @@ fn build_app(app_state: Arc<AppState>) -> Router { async fn main() -> anyhow::Result<()> { // Ignored if absent - production deployments are expected to set real // env vars directly rather than ship a .env file. - let _ = dotenvy::dotenv(); + // dotenvy searches upward from the working directory, so a plain call + // finds .env only when the server is started from crates/server. The + // usual thing is to run it from the repository root, so that location is + // tried too. Neither is required: every setting has a default or is read + // straight from the environment. + if dotenvy::dotenv().is_err() { + let _ = dotenvy::from_filename("crates/server/.env"); + } tracing_subscriber::fmt() .with_env_filter(tracing_subscriber::EnvFilter::try_from_default_env().unwrap_or_else(|_| "info".into())) |