winofy-front/.env.example
Afra ‌ bf1dc0b346 feat: dockerize (multi-stage build, standalone output)
Dockerfile: deps -> builder -> runner. NEXT_PUBLIC_* vars are passed as
build args (inlined into the client bundle at build time, per Next.js);
everything else is read at container runtime instead (docker-compose.yml's
env_file / docker run --env-file) and never baked into an image layer.
Runner stage is non-root, ships only server.js + .next/static + public/
via output: "standalone".

Verified by actually running the build twice locally (Docker itself isn't
available in this environment) -- once with the real .env.local, once with
only placeholder values and no .env.local at all, matching the real Docker
build condition. The second run caught a real, pre-existing bug that had
nothing to do with Docker specifically: /login and three other
client-component trees (location/error, location/permission,
CategoryChips and NeighborhoodSearch nested in Server Component pages) all
call useSearchParams() without a Suspense boundary. next dev tolerates
this; next build hard-fails on it ("missing-suspense-with-csr-bailout").
This would have broken any production build -- Vercel, bare metal,
whatever -- not just Docker; fixed all four by wrapping in <Suspense>.

Also added .env.example (committed, no real values -- .env.local itself
stays gitignored) and a docker-compose.yml, with the --env-file .env.local
requirement called out explicitly in README.md since Compose only
auto-reads a file literally named .env, not .env.local.
2026-08-19 11:00:09 +03:30

23 lines
1.4 KiB
Text

# Copy to .env.local and fill in real values. See FRONTEND_GUIDE.md for what
# each of these means; .env.local itself is gitignored, never commit real
# secrets here.
# Winofy backend (this Django/DRF app)
WINOFY_API_BASE_URL=https://winofy-staging.winsoo.ir/api
# Gooyal accounts (OAuth2 resource owner password/OTP grant).
# The browser calls Gooyal directly (its CORS is open), so these are also
# exposed client-side via the NEXT_PUBLIC_ copies below — the client_secret
# is intentionally public here, see .env.local's original comment for why.
GOOYAL_ACCOUNTS_BASE_URL=https://accounts-staging.gooyal.ir
GOOYAL_CLIENT_ID=
GOOYAL_CLIENT_SECRET=
GOOYAL_OAUTH_SCOPE="accounts.account:change_password accounts.account:update accounts.account:retrieve wallet.wallet:get_balance wallet.user:transaction_list data_crud.data:retrieve data_crud.data:update data_crud.data:delete notifications.push:get_client_token accounts.profile:list"
NEXT_PUBLIC_GOOYAL_ACCOUNTS_BASE_URL=https://accounts-staging.gooyal.ir
NEXT_PUBLIC_GOOYAL_CLIENT_ID=
NEXT_PUBLIC_GOOYAL_CLIENT_SECRET=
NEXT_PUBLIC_GOOYAL_OAUTH_SCOPE="accounts.account:change_password accounts.account:update accounts.account:retrieve wallet.wallet:get_balance wallet.user:transaction_list data_crud.data:retrieve data_crud.data:update data_crud.data:delete notifications.push:get_client_token accounts.profile:list"
# Session cookie encryption — generate with: openssl rand -base64 32
SESSION_SECRET=