Scaffolds the project: Next.js 16 App Router with strict TypeScript, Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a standalone Docker image that applies migrations on boot. Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than stated. A per-request nonce-based CSP names no external origin, a unit test fails if any network directive gains one, and a second test fails if a tracking package appears in package.json. The end-to-end test drives the standalone server the Docker image runs, not `next dev`, so a proxy matcher that stopped matching could not pass unnoticed. Environment is validated at import, so a missing DATABASE_URL fails at boot with a readable message instead of surfacing later as a driver error mid-export. ENCRYPTION_KEY is checked to be 32 bytes. Three deviations from the plan, recorded in PLAN.md and README: Next 16 rather than 15, `proxy.ts` rather than the now-deprecated `middleware.ts`, and database-backed sessions rather than Auth.js v5, which is still beta and whose JWTs would make the session revocation required by compliance item 23 awkward. Verified locally against PostgreSQL 16: migrations apply, extensions created, typecheck, lint, 9 unit tests and the end-to-end header test all pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
26 lines
985 B
Bash
26 lines
985 B
Bash
# Copier vers .env et renseigner. Ne jamais committer .env.
|
|
|
|
# --- Base de données --------------------------------------------------------
|
|
POSTGRES_USER=planflow
|
|
POSTGRES_PASSWORD=change-me
|
|
POSTGRES_DB=planflow
|
|
|
|
# Utilisée par l'application et par Prisma.
|
|
# En docker-compose l'hôte est `db` ; en développement local, `localhost`.
|
|
DATABASE_URL=postgresql://planflow:change-me@localhost:5432/planflow
|
|
|
|
# --- Chiffrement ------------------------------------------------------------
|
|
# Chiffre au repos les colonnes sensibles exigées par PLAN.md §3.6 :
|
|
# NIR, IBAN, BIC. 32 octets en base64.
|
|
#
|
|
# openssl rand -base64 32
|
|
#
|
|
# Cette clé vit hors de la base : une sauvegarde volée ne doit pas suffire à
|
|
# lire ces colonnes. La perdre rend les données chiffrées irrécupérables —
|
|
# la sauvegarder séparément et documenter sa rotation.
|
|
ENCRYPTION_KEY=
|
|
|
|
# --- Application ------------------------------------------------------------
|
|
APP_URL=http://localhost:3000
|
|
APP_PORT=3000
|