52ec3ce497
Enables PostHog Support through the Direct API (posthog.conversations), restoring the second channel Recapt used to provide, but as a real ticket linked to the person and their session replay instead of a black hole. The in-app WIDGET stays off on purpose. It is a third-party floating chat bubble, which is exactly what Recapt was: it would sit next to the Assistenten FAB (which already has a hide_assistant_fab preference because users wanted it gone), cannot follow the locked design system, and its copy is not ours to keep Swedish. The conversations API gives the same tickets from components/ui/support-link.tsx, which is already on-design, Swedish and reachable from 8 surfaces. A ticket is explicitly NOT treated as delivery. submitFeedback returns ok only when the Resend email actually went out, even if the ticket opened. Recapt's precise failure mode was reporting success on its own channel while /api/support/contact was dead, and nobody is watching PostHog at 02:00. Tests pin that: ticket-only is ok:false. Identity verification uses posthog.setIdentity(distinctId, hash) at runtime rather than the identity_distinct_id/identity_hash init options PostHog's settings page documents. init runs from instrumentation-client.ts app-wide, before the user is known and including logged-out pages, and PostHog fixes init values for the session. setIdentity is a real method on the SDK (verified typed in posthog-js 1.407.3), so the hash applies from AnalyticsIdentify once the dashboard layout knows who the user is. Without the key it is skipped and tickets fall back to browser-scoped with email recovery, which is the normal state off hosted. POSTHOG_SECRET_API_KEY is server-only, no NEXT_PUBLIC_ prefix: it signs identity hashes AND authenticates external API requests, so unlike the phc_ project token it is a real credential. Only the derived per-user HMAC crosses to the browser. Compliance: support free text is declared as its own data category (user.content.support) in .compliance/ropa.yaml and named on the privacy page. Analytics events still carry no message body (the breadcrumb sends only the subject); a ticket carries what the user wrote, because that is the point. Keeping the purposes separate is what stops the privacy page drifting the way the Recapt row did. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
99 lines
5.1 KiB
Bash
99 lines
5.1 KiB
Bash
# Local development environment variables.
|
|
# Copy to .env and fill in the values: cp .env.example .env
|
|
|
|
# ── Required ──────────────────────────────────────────────
|
|
# Supabase project credentials (Dashboard -> Settings -> API)
|
|
NEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co
|
|
NEXT_PUBLIC_SUPABASE_ANON_KEY=your-anon-or-publishable-key
|
|
SUPABASE_SERVICE_ROLE_KEY=your-service-role-or-secret-key
|
|
|
|
# App base URL (local dev)
|
|
NEXT_PUBLIC_APP_URL=http://localhost:3000
|
|
|
|
# Secret for authenticating cron/scheduled requests.
|
|
# Any non-empty random string for local dev: openssl rand -hex 16
|
|
CRON_SECRET=generate-a-random-secret
|
|
|
|
# ── Optional: extension features (core runs without these) ─
|
|
# AI features
|
|
# ANTHROPIC_API_KEY=
|
|
# OPENAI_API_KEY=
|
|
# Bank connections (Enable Banking)
|
|
# ENABLE_BANKING_APP_ID=
|
|
# ENABLE_BANKING_PRIVATE_KEY=
|
|
# Accounting integrations
|
|
# FORTNOX_CLIENT_ID=
|
|
# FORTNOX_CLIENT_SECRET=
|
|
# FORTNOX_REDIRECT_URI=
|
|
# Björn Lundén app credentials (OAuth2 client credentials; per-company
|
|
# User-Key is entered by the user in the migration wizard)
|
|
# BJORN_LUNDEN_CLIENT_ID=
|
|
# BJORN_LUNDEN_CLIENT_SECRET=
|
|
# Bolagsverket: digital inlämning av årsredovisning (bolagsverket extension).
|
|
# BOLAGSVERKET_ENV is test | accept | prod (default test) and also caps which
|
|
# environment a company may select in settings (test < accept < prod).
|
|
# Certificate material is read from env ONLY (PEM or base64-wrapped PEM):
|
|
# never from extension settings or the database.
|
|
#
|
|
# SECRET CUSTODY (prod): never keep the real mTLS private key in a plaintext
|
|
# .env file. Inject these at runtime from a secrets manager (Vercel encrypted
|
|
# env vars, AWS Secrets Manager, Vault, Doppler, …), restrict read access to
|
|
# the deploy pipeline, and rotate the client certificate/key on the cadence
|
|
# agreed with Bolagsverket (and immediately on suspected exposure). Outbound
|
|
# hosts are pinned per environment in extensions/general/bolagsverket/lib/
|
|
# client.ts (HOSTS): the endpoint is not configurable via env.
|
|
# BOLAGSVERKET_ENV=
|
|
# BOLAGSVERKET_CLIENT_CERT=
|
|
# BOLAGSVERKET_CLIENT_KEY=
|
|
# BOLAGSVERKET_CA=
|
|
# Safety gate: enable only after agreement, certificate, test-bank fixtures,
|
|
# acceptance testing, and production runbook approval are complete.
|
|
# BOLAGSVERKET_FILING_ENABLED=false
|
|
# NEXT_PUBLIC_BOLAGSVERKET_FILING_ENABLED=false
|
|
# BOLAGSVERKET_ARELLE_VALIDATOR_URL=
|
|
# BOLAGSVERKET_ARELLE_VALIDATOR_TOKEN=
|
|
|
|
# ── Optional: product analytics + error tracking (PostHog) ─
|
|
# Hosted only. Self-hosted deployments never load PostHog: isAnalyticsEnabled()
|
|
# (lib/analytics/enabled.ts) short-circuits on NEXT_PUBLIC_SELF_HOSTED=true, and
|
|
# no __NEXT_PUBLIC_POSTHOG_*__ sentinel is baked into the Docker image, so an
|
|
# operator cannot accidentally ship their users' behaviour to our project.
|
|
#
|
|
# The token is the PUBLIC project token (phc_...). It is embedded in the client
|
|
# bundle by design and is not a secret. Leave unset to run with analytics off.
|
|
# Browser traffic goes through the same-origin /rl rewrite in next.config.ts;
|
|
# NEXT_PUBLIC_POSTHOG_HOST is only used by the server-side SDK.
|
|
# NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN=
|
|
# NEXT_PUBLIC_POSTHOG_HOST=https://eu.i.posthog.com
|
|
#
|
|
# PostHog Support identity verification. A REAL SECRET (it also authenticates
|
|
# external API requests), so no NEXT_PUBLIC_ prefix: it must never reach the
|
|
# client bundle. Only the derived per-user HMAC crosses to the browser
|
|
# (lib/analytics/identity-hash.ts). Unset means support tickets are scoped to
|
|
# one browser session and users recover them by email link, which is the
|
|
# normal state for local dev, CI and self-hosted.
|
|
# POSTHOG_SECRET_API_KEY=
|
|
|
|
# ── Optional: error tracking / observability ──────────────
|
|
# The app routes every error-level log line, and anything flagged
|
|
# `alert: true`, to a provider-agnostic sink (lib/observability). When the
|
|
# PostHog token above is set, lib/init.ts registers the PostHog adapter
|
|
# (lib/analytics/posthog-observability.ts) as that sink; otherwise the sink
|
|
# stays a NO-OP, the PostHog client is never constructed and nothing is ever
|
|
# sent. (The SDK is still bundled in those builds, since the imports are
|
|
# static; it simply never initialises.) The variables below are for a
|
|
# DIFFERENT vendor adapter and still change nothing on their own.
|
|
#
|
|
# Names are generic placeholders. When a provider is picked, either keep these
|
|
# and read them in the adapter, or replace them with the vendor's own names.
|
|
# OBSERVABILITY_DSN= # server-side ingest endpoint / key
|
|
# NEXT_PUBLIC_OBSERVABILITY_DSN= # browser ingest endpoint / key, if used
|
|
# Any adapter reading these MUST forward only post-redaction payloads
|
|
# (lib/observability/redact.ts): see docs/security/logging-and-observability.md
|
|
# Optional overrides. Both have sensible defaults: the environment falls back
|
|
# to VERCEL_ENV then NODE_ENV, and the release falls back to
|
|
# NEXT_PUBLIC_BUILD_ID (the commit sha next.config.ts inlines at build time)
|
|
# then VERCEL_GIT_COMMIT_SHA. Set them only when tagging must differ.
|
|
# OBSERVABILITY_ENVIRONMENT=
|
|
# OBSERVABILITY_RELEASE=
|