Deploy on DigitalOcean App Platform (GitHub-source build) + consolidate audit-fixes

Deploy config:
- .do/app.yaml: build the Dockerfile directly from GitHub (deploy_on_push) instead
  of a pre-built DOCR image; NEXT_PUBLIC_* set RUN_AND_BUILD_TIME with the
  propertymanagement.network domain so they bake into the client bundle; add
  custom domains block (apex + www); wire Sentry DSN (server + browser).

Included pending work from the audit-fixes branch:
- AI provider abstraction (OpenAI/Anthropic, admin-selectable; Anthropic default)
- Per-landlord e-signature (DocuSign OAuth + Dropbox Sign) + migration 0010
- Outbound webhooks / Zapier integration
- PayPal removal (Stripe-only billing)
- Storage hardening (fail-loud when Spaces unconfigured), security fixes

Verified: full production Docker build (same build-args as DO) passes clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-03 04:45:24 -04:00
co-authored by Claude Opus 4.8
parent 917a06ee85
commit 5495b94924
86 changed files with 7647 additions and 1182 deletions
+13 -19
View File
@@ -4,13 +4,16 @@ import { db } from "@/lib/db"
import { leases as leasesTable } from "@/lib/db/schema"
import { getSessionUser } from "@/lib/session"
import { getAccountContext } from "@/lib/account"
import { listAdapters, listRequestsForLease } from "@/lib/esign"
import { listEsignConnections, listRequestsForLease } from "@/lib/esign"
import Link from "next/link"
import { FileText, ExternalLink } from "lucide-react"
import { FileText } from "lucide-react"
import { formatCurrency, formatDate, daysUntil } from "@/lib/utils"
import { cn } from "@/lib/utils"
import { LeaseActions } from "@/components/forms/lease-actions"
import { EsignLease } from "@/components/forms/esign-lease"
import { LeaseDocument } from "@/components/forms/lease-document"
const ESIGN_LABEL: Record<string, string> = { docusign: "DocuSign", dropbox_sign: "Dropbox Sign" }
export const metadata = { title: "Lease" }
@@ -56,8 +59,12 @@ export default async function LeaseDetailPage({ params }: { params: Promise<{ le
if (!lease) notFound()
const esignRequests = await listRequestsForLease(ownerId, leaseId)
const esignProviders = listAdapters()
const canSendEsign = ctx.canWrite && !!lease.document_url && !!lease.tenant?.email
const esignConnections = await listEsignConnections(ownerId)
const connectedProviders = esignConnections
.filter((c) => c.status !== "revoked")
.map((c) => ({ id: c.provider, label: ESIGN_LABEL[c.provider] ?? c.provider }))
const canSendEsign =
ctx.canWrite && !!lease.document_url && !!lease.tenant?.email && connectedProviders.length > 0
const esignDisabledReason = !ctx.canWrite
? "You have read-only access."
: !lease.document_url
@@ -196,24 +203,11 @@ export default async function LeaseDetailPage({ params }: { params: Promise<{ le
</div>
</div>
{lease.document_url && (
<a
href={lease.document_url}
target="_blank"
rel="noopener noreferrer"
className="flex items-center justify-between rounded-xl border border-white/[0.06] bg-[#16161f] p-5 transition hover:border-white/15"
>
<div className="flex items-center gap-2 text-sm font-medium text-white">
<FileText className="h-4 w-4 text-indigo-400" />
Lease document
</div>
<ExternalLink className="h-4 w-4 text-white/40" />
</a>
)}
<LeaseDocument leaseId={leaseId} documentUrl={lease.document_url} canWrite={ctx.canWrite} />
<EsignLease
leaseId={leaseId}
providers={esignProviders}
connected={connectedProviders}
requests={esignRequests}
canSend={canSendEsign}
disabledReason={esignDisabledReason}
+4 -20
View File
@@ -5,9 +5,7 @@ import { profiles, properties, tenants } from "@/lib/db/schema"
import { getSessionUser } from "@/lib/session"
import { CheckoutButton } from "@/components/forms/checkout-button"
import { PortalButton } from "@/components/forms/portal-button"
import { PaypalCancelButton } from "@/components/forms/paypal-cancel-button"
import { getPlanLabel, PLAN_LIMITS, annualEnabled } from "@/lib/stripe/plans"
import { paypalConfigured } from "@/lib/paypal/client"
import { Check } from "lucide-react"
import type { Plan } from "@/types"
@@ -59,7 +57,7 @@ const PLANS = [
export default async function BillingPage({
searchParams,
}: {
searchParams: Promise<{ success?: string; canceled?: string; error?: string }>
searchParams: Promise<{ success?: string; canceled?: string }>
}) {
const user = await getSessionUser()
if (!user) redirect("/login")
@@ -72,16 +70,12 @@ export default async function BillingPage({
plan_expires_at: true,
stripe_customer_id: true,
stripe_subscription_id: true,
paypal_subscription_id: true,
billing_provider: true,
},
})
const params = await searchParams
const currentPlan = (profile?.plan ?? "starter") as Plan
const hasStripeAccount = !!profile?.stripe_customer_id
const isPaypal = profile?.billing_provider === "paypal" || !!profile?.paypal_subscription_id
const paypalEnabled = paypalConfigured()
const limits = PLAN_LIMITS[currentPlan]
const canBillAnnually = annualEnabled()
@@ -113,12 +107,6 @@ export default async function BillingPage({
Checkout canceled no charge was made.
</div>
)}
{params.error === "paypal" && (
<div className="rounded-xl border border-red-500/20 bg-red-500/10 px-5 py-4 text-sm text-red-400">
We couldn&apos;t complete your PayPal payment. No charge was made please try again.
</div>
)}
{/* Current plan */}
<div className="rounded-xl border border-white/[0.06] bg-[#16161f] p-5">
<div className="flex items-center justify-between">
@@ -129,12 +117,9 @@ export default async function BillingPage({
<p className="mt-0.5 text-xs text-white/40 capitalize">Status: {profile.subscription_status}</p>
)}
</div>
{currentPlan !== "starter" && currentPlan !== "lifetime" &&
(isPaypal ? (
<PaypalCancelButton />
) : hasStripeAccount ? (
<PortalButton />
) : null)}
{hasStripeAccount && currentPlan !== "starter" && currentPlan !== "lifetime" && (
<PortalButton />
)}
</div>
</div>
@@ -197,7 +182,6 @@ export default async function BillingPage({
label={plan.cta}
highlight={plan.highlight}
annualAvailable={canBillAnnually && plan.key !== "lifetime"}
paypalEnabled={paypalEnabled}
/>
)}
</div>
+39 -12
View File
@@ -2,7 +2,9 @@ import { redirect } from "next/navigation"
import { getSessionUser } from "@/lib/session"
import { getAccountContext } from "@/lib/account"
import { listProviders, listConnections } from "@/lib/accounting"
import { listEsignAdapters, listEsignConnections } from "@/lib/esign"
import { AccountingIntegrations } from "@/components/dashboard/accounting-integrations"
import { EsignIntegrations } from "@/components/dashboard/esign-integrations"
export const metadata = { title: "Integrations" }
export const dynamic = "force-dynamic"
@@ -20,20 +22,45 @@ export default async function IntegrationsPage({
const providers = listProviders()
const connections = ctx.isOwner ? await listConnections(ctx.ownerId) : []
const esignAdapters = listEsignAdapters()
const esignConnections = ctx.isOwner ? await listEsignConnections(ctx.ownerId) : []
const appUrl = (process.env.NEXT_PUBLIC_APP_URL ?? "http://localhost:3000").replace(/\/+$/, "")
// DocuSign vs Dropbox Sign flash messages are keyed by provider id, so a single
// connected/error param drives whichever card the user just acted on.
const esignFlash = { connected: sp.connected, error: sp.error }
return (
<div className="max-w-3xl mx-auto space-y-6">
<div>
<h2 className="text-lg font-bold text-white">Integrations</h2>
<p className="text-sm text-white/40 mt-0.5">
Connect your accounting software to automatically push rent income and expenses into your books.
</p>
<div className="max-w-3xl mx-auto space-y-8">
<div className="space-y-4">
<div>
<h2 className="text-lg font-bold text-white">E-signature</h2>
<p className="text-sm text-white/40 mt-0.5">
Connect your own DocuSign or Dropbox Sign account to send leases for signature.
</p>
</div>
<EsignIntegrations
adapters={esignAdapters}
connections={esignConnections}
isOwner={ctx.isOwner}
flash={esignFlash}
webhookUrl={`${appUrl}/api/esign/dropbox_sign/webhook`}
/>
</div>
<div className="space-y-4">
<div>
<h2 className="text-lg font-bold text-white">Accounting</h2>
<p className="text-sm text-white/40 mt-0.5">
Connect your accounting software to automatically push rent income and expenses into your books.
</p>
</div>
<AccountingIntegrations
providers={providers}
connections={connections}
isOwner={ctx.isOwner}
flash={{ connected: sp.connected, error: sp.error }}
/>
</div>
<AccountingIntegrations
providers={providers}
connections={connections}
isOwner={ctx.isOwner}
flash={{ connected: sp.connected, error: sp.error }}
/>
</div>
)
}