srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/crates
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-12-18 19:21:00 +0200
committersrdusr <[email protected]>2025-12-18 19:21:00 +0200
commitb371f21989bfca13fe8cc9bd59e95f5614f63b0d (patch)
tree4244c0d4a7000aa12cfee4e86f3ffcc6476bc4ec /crates
parent1740327557074df0c8b99635ee949e2540ac94d0 (diff)
downloadtyperpunk-b371f21989bfca13fe8cc9bd59e95f5614f63b0d.tar.gz
typerpunk-b371f21989bfca13fe8cc9bd59e95f5614f63b0d.zip
Fix the end screen layout, make the app responsive, document secrets
End screen - There was an auto-fit routine that forced this screen into one viewport: it shrank the graph to a 120px floor, trimmed the Play Again margin, then capped the passage box at 80px with its own scrollbar. On a 650px window that left the passage 80px tall and clipped, and the graph 120px, which are the two things the screen exists to show. Removed. The page scrolls instead, which is the right trade for a screen that is read rather than acted on under time pressure. - The screen is a flex column, so its children also shrank by default once the content was taller than the viewport. The passage, graph, stat row and standings no longer shrink, and the chart has a floor below which it stops carrying information. Bottom chrome - The keyboard hint and the footer links were both fixed at bottom centre and overlapped at every window size. The hint now sits above the footer. - Normal-flow content could end up underneath the fixed footer and the corner rails. One --bottom-chrome variable reserves that space on every screen. - On a narrow screen the footer grows to the full width once its links wrap, so at 375px it ran through both corner rails and covered Play Again, which made the button unclickable. The chrome stacks there instead: rails on the bottom line, footer above them, hint above that. Mode picker - It ran to the last pixel of the window at every size. It now keeps clear of the bottom edge, and opens upward when a short window leaves more room above than below. Responsive - Checked at nine viewports from 1920x1080 down to 375x667: no horizontal overflow and nothing off-screen on the menu, the typing screen or the end screen. Configuration - dotenvy searches upward from the working directory, so crates/server/.env was only found when starting the server from that directory. The repository root is tried as well, which is where it is usually started from. - .env.example and the README explain where secrets belong: the environment, a gitignored .env for local work, and EnvironmentFile or a platform secret store in production. Also what to do if one is exposed. - TYPERPUNK_ADMIN_USERNAME and TYPERPUNK_ENV are documented rather than left to be discovered in the source.
Diffstat (limited to 'crates')
-rw-r--r--crates/server/.env.example18
-rw-r--r--crates/server/src/main.rs9
2 files changed, 26 insertions, 1 deletions
diff --git a/crates/server/.env.example b/crates/server/.env.example
index 8485826..b7501a1 100644
--- a/crates/server/.env.example
+++ b/crates/server/.env.example
@@ -1,3 +1,11 @@
+# Copy this file to .env and fill it in. .env is gitignored and must never be
+# committed: it is the only place a password or a client secret belongs.
+#
+# In production, prefer real environment variables over a file. systemd units
+# take EnvironmentFile= with the file owned by root and mode 600; container
+# runtimes and hosting platforms have their own secret stores. The server reads
+# plain environment variables either way, so nothing here has to change.
+
# Postgres. Create the database and role first:
# sudo -u postgres createuser --pwprompt typerpunk
# sudo -u postgres createdb -O typerpunk typerpunk
@@ -13,6 +21,16 @@ FRONTEND_ORIGIN=http://localhost:4173
# texts.json in the process's working directory (the repo root, normally).
TEXTS_JSON_PATH=texts.json
+# The account promoted to administrator at startup. That account can appoint
+# moderators from the Contribute screen. Leave it unset once the roles are
+# assigned; it is only needed to create the first administrator, or to recover
+# if the last one is removed.
+TYPERPUNK_ADMIN_USERNAME=
+
+# Set to production to make the server refuse to start on an unsafe
+# configuration rather than warn about it.
+TYPERPUNK_ENV=
+
# Set to 1 behind TLS in production. Left off for local HTTP dev, where a
# Secure cookie would silently never be set by the browser.
COOKIE_SECURE=0
diff --git a/crates/server/src/main.rs b/crates/server/src/main.rs
index 22cd9cd..b291e64 100644
--- a/crates/server/src/main.rs
+++ b/crates/server/src/main.rs
@@ -102,7 +102,14 @@ fn build_app(app_state: Arc<AppState>) -> Router {
async fn main() -> anyhow::Result<()> {
// Ignored if absent - production deployments are expected to set real
// env vars directly rather than ship a .env file.
- let _ = dotenvy::dotenv();
+ // dotenvy searches upward from the working directory, so a plain call
+ // finds .env only when the server is started from crates/server. The
+ // usual thing is to run it from the repository root, so that location is
+ // tried too. Neither is required: every setting has a default or is read
+ // straight from the environment.
+ if dotenvy::dotenv().is_err() {
+ let _ = dotenvy::from_filename("crates/server/.env");
+ }
tracing_subscriber::fmt()
.with_env_filter(tracing_subscriber::EnvFilter::try_from_default_env().unwrap_or_else(|_| "info".into()))