Files
accounted/.env.example
T
Jakob WennbergandClaude Opus 5 d4f82cafc4 feat(analytics): add PostHog (EU) behind a same-origin proxy (#1237)
Recapt shuts down in four days, taking product analytics and session
replay with it. This adds PostHog Cloud EU alongside it; the Recapt
removal follows separately so events can be confirmed landing first.

Wiring choices that are not the tutorial defaults:

- Same-origin reverse proxy (/rl -> eu.i.posthog.com) instead of adding
  PostHog hosts to the CSP. connect-src 'self' and script-src 'self'
  already cover it, tracking blockers have no third-party host to match,
  and the Recapt allowlist entries in next.config.ts get replaced by
  nothing at all when they go. Needs skipTrailingSlashRedirect, since
  PostHog sends trailing-slash API requests; verified that trailing-slash
  URLs on normal routes still resolve 200 rather than 404.

- /rl is excluded from the proxy.ts matcher. Middleware runs BEFORE
  next.config rewrites, so without this updateSession() treats an
  ingestion POST as an unknown protected path and 307s it to /login.
  Verified with a control: /zz/flags/ -> 307 /login, /rl/flags/ -> 200
  from PostHog. This fails silently otherwise, because asset loads keep
  working through the rewrite while no events arrive.

- persistence: 'memory' so nothing is written to the device and no
  cookie-consent banner is required. Everything post-login is unaffected:
  AnalyticsIdentify re-identifies on each dashboard load.

- session_recording.maskTextSelector: '*'. PostHog masks inputs but not
  text by default, and this app renders org numbers (which for an
  enskild firma ARE the owner's personnummer), customer names and
  balances as ordinary text. Replays show where a user gets stuck, never
  what their books say. buildGroupProperties() also refuses to send
  org_number at all, with a test pinning it.

- Error tracking registers through the existing lib/observability sink
  rather than bypassing it, so every error-level createLogger() line is
  captured already redacted. instrumentation.ts onRequestError covers
  what escapes uncaught.

Analytics is hosted-only: isAnalyticsEnabled() short-circuits on
NEXT_PUBLIC_SELF_HOSTED and no Docker sentinel is added, so self-hosted
runs with zero third-party runtime code. Recapt got that outcome only by
accident, via a missing sentinel; here it is explicit and tested.

vitest.config.ts aliases 'server-only' to a stub: it is a build-time
guard whose real entry point always throws, which broke 48 test files the
moment a server-only module entered the graph. request-context.ts was
already carrying the same latent trap.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-27 14:30:49 +02:00

91 lines
4.6 KiB
Bash

# Local development environment variables.
# Copy to .env and fill in the values: cp .env.example .env
# ── Required ──────────────────────────────────────────────
# Supabase project credentials (Dashboard -> Settings -> API)
NEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co
NEXT_PUBLIC_SUPABASE_ANON_KEY=your-anon-or-publishable-key
SUPABASE_SERVICE_ROLE_KEY=your-service-role-or-secret-key
# App base URL (local dev)
NEXT_PUBLIC_APP_URL=http://localhost:3000
# Secret for authenticating cron/scheduled requests.
# Any non-empty random string for local dev: openssl rand -hex 16
CRON_SECRET=generate-a-random-secret
# ── Optional: extension features (core runs without these) ─
# AI features
# ANTHROPIC_API_KEY=
# OPENAI_API_KEY=
# Bank connections (Enable Banking)
# ENABLE_BANKING_APP_ID=
# ENABLE_BANKING_PRIVATE_KEY=
# Accounting integrations
# FORTNOX_CLIENT_ID=
# FORTNOX_CLIENT_SECRET=
# FORTNOX_REDIRECT_URI=
# Björn Lundén app credentials (OAuth2 client credentials; per-company
# User-Key is entered by the user in the migration wizard)
# BJORN_LUNDEN_CLIENT_ID=
# BJORN_LUNDEN_CLIENT_SECRET=
# Bolagsverket: digital inlämning av årsredovisning (bolagsverket extension).
# BOLAGSVERKET_ENV is test | accept | prod (default test) and also caps which
# environment a company may select in settings (test < accept < prod).
# Certificate material is read from env ONLY (PEM or base64-wrapped PEM):
# never from extension settings or the database.
#
# SECRET CUSTODY (prod): never keep the real mTLS private key in a plaintext
# .env file. Inject these at runtime from a secrets manager (Vercel encrypted
# env vars, AWS Secrets Manager, Vault, Doppler, …), restrict read access to
# the deploy pipeline, and rotate the client certificate/key on the cadence
# agreed with Bolagsverket (and immediately on suspected exposure). Outbound
# hosts are pinned per environment in extensions/general/bolagsverket/lib/
# client.ts (HOSTS): the endpoint is not configurable via env.
# BOLAGSVERKET_ENV=
# BOLAGSVERKET_CLIENT_CERT=
# BOLAGSVERKET_CLIENT_KEY=
# BOLAGSVERKET_CA=
# Safety gate: enable only after agreement, certificate, test-bank fixtures,
# acceptance testing, and production runbook approval are complete.
# BOLAGSVERKET_FILING_ENABLED=false
# NEXT_PUBLIC_BOLAGSVERKET_FILING_ENABLED=false
# BOLAGSVERKET_ARELLE_VALIDATOR_URL=
# BOLAGSVERKET_ARELLE_VALIDATOR_TOKEN=
# ── Optional: product analytics + error tracking (PostHog) ─
# Hosted only. Self-hosted deployments never load PostHog: isAnalyticsEnabled()
# (lib/analytics/enabled.ts) short-circuits on NEXT_PUBLIC_SELF_HOSTED=true, and
# no __NEXT_PUBLIC_POSTHOG_*__ sentinel is baked into the Docker image, so an
# operator cannot accidentally ship their users' behaviour to our project.
#
# The token is the PUBLIC project token (phc_...). It is embedded in the client
# bundle by design and is not a secret. Leave unset to run with analytics off.
# Browser traffic goes through the same-origin /rl rewrite in next.config.ts;
# NEXT_PUBLIC_POSTHOG_HOST is only used by the server-side SDK.
# NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN=
# NEXT_PUBLIC_POSTHOG_HOST=https://eu.i.posthog.com
# ── Optional: error tracking / observability ──────────────
# The app routes every error-level log line, and anything flagged
# `alert: true`, to a provider-agnostic sink (lib/observability). When the
# PostHog token above is set, lib/init.ts registers the PostHog adapter
# (lib/analytics/posthog-observability.ts) as that sink; otherwise the sink
# stays a NO-OP, the PostHog client is never constructed and nothing is ever
# sent. (The SDK is still bundled in those builds, since the imports are
# static; it simply never initialises.) The variables below are for a
# DIFFERENT vendor adapter and still change nothing on their own.
#
# Names are generic placeholders. When a provider is picked, either keep these
# and read them in the adapter, or replace them with the vendor's own names.
# OBSERVABILITY_DSN= # server-side ingest endpoint / key
# NEXT_PUBLIC_OBSERVABILITY_DSN= # browser ingest endpoint / key, if used
# Any adapter reading these MUST forward only post-redaction payloads
# (lib/observability/redact.ts): see docs/security/logging-and-observability.md
# Optional overrides. Both have sensible defaults: the environment falls back
# to VERCEL_ENV then NODE_ENV, and the release falls back to
# NEXT_PUBLIC_BUILD_ID (the commit sha next.config.ts inlines at build time)
# then VERCEL_GIT_COMMIT_SHA. Set them only when tagging must differ.
# OBSERVABILITY_ENVIRONMENT=
# OBSERVABILITY_RELEASE=