Backend - Routes moved under /api/, JWT bearer auth via @before_request - DEV_AUTH_BYPASS escape hatch for local dev - In-memory chat history and report state replaced with Postgres tables (preferences, chat_messages, reports, feedback_events) keyed on user - SQLAlchemy 2.x + Alembic migrations run on container start - Graceful Airtable failure handling — bad creds no longer 500 the API - Per-user data isolation via g.user_email from validated token Frontend - React + Vite + TypeScript SPA at /programme-pulse/ - MSAL.js (PKCE, sessionStorage, ID token to backend) - VITE_DEV_AUTH_BYPASS mirrors backend bypass for local dev - Streaming chat via fetch ReadableStream + SSE parsing - Charts via chart.js, markdown via react-markdown + remark-gfm - Full UI parity with the original templates/index.html Deploy (optical-dev split-build pattern) - Dockerfile + docker-compose.yml (name: programme-pulse pinned; app + Postgres; 127.0.0.1 binding only) - deploy/apache-programme-pulse.conf.tmpl with flushpackets=on for SSE - deploy/deploy.sh mirrors OSOP — port auto-pick (5051..5099), apache conf render, frontend build in throwaway node container, rsync to /var/www/html/programme-pulse, /api/health poll Tests - 49 passing; new tests for DB-backed preferences and JWT auth helpers - SQLite-backed test fixture in tests/conftest.py Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
15 lines
711 B
Text
15 lines
711 B
Text
# Azure AD app registration (Single-page application platform).
|
|
# Add these as redirect URIs in the registration:
|
|
# https://optical-dev.oliver.solutions/programme-pulse/
|
|
# http://localhost:5173/programme-pulse/
|
|
VITE_AZURE_TENANT_ID=
|
|
VITE_AZURE_CLIENT_ID=
|
|
|
|
# API base. Production: same-origin via Apache proxy → /programme-pulse/api.
|
|
# Dev: Vite proxy forwards /programme-pulse/api → http://localhost:5051/api.
|
|
VITE_API_BASE=/programme-pulse/api
|
|
|
|
# Set to "true" to skip the MSAL sign-in gate locally. Must be paired with
|
|
# DEV_AUTH_BYPASS=true on the backend. The SPA will render straight to the
|
|
# signed-in UI and apiFetch will send requests without an Authorization header.
|
|
VITE_DEV_AUTH_BYPASS=false
|