Deploy on DigitalOcean App Platform (GitHub-source build) + consolidate audit-fixes

Deploy config:
- .do/app.yaml: build the Dockerfile directly from GitHub (deploy_on_push) instead
  of a pre-built DOCR image; NEXT_PUBLIC_* set RUN_AND_BUILD_TIME with the
  propertymanagement.network domain so they bake into the client bundle; add
  custom domains block (apex + www); wire Sentry DSN (server + browser).

Included pending work from the audit-fixes branch:
- AI provider abstraction (OpenAI/Anthropic, admin-selectable; Anthropic default)
- Per-landlord e-signature (DocuSign OAuth + Dropbox Sign) + migration 0010
- Outbound webhooks / Zapier integration
- PayPal removal (Stripe-only billing)
- Storage hardening (fail-loud when Spaces unconfigured), security fixes

Verified: full production Docker build (same build-args as DO) passes clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-03 04:45:24 -04:00
co-authored by Claude Opus 4.8
parent 917a06ee85
commit 5495b94924
86 changed files with 7647 additions and 1182 deletions
+20
View File
@@ -8,6 +8,7 @@ import { z } from "zod"
import { getAdminSession } from "@/lib/session"
import { logAdminAction } from "@/lib/admin/audit"
import { setMaintenanceMode } from "@/lib/settings"
import { setAiProvider, type AiProvider } from "@/lib/ai/provider"
import { auth } from "@/lib/auth"
import { db } from "@/lib/db"
import { profiles, user as userTable } from "@/lib/db/schema"
@@ -158,3 +159,22 @@ export async function setSiteMaintenance(enabled: boolean, message?: string) {
revalidatePath("/", "layout")
return { ok: true }
}
// ── AI provider ───────────────────────────────────────────────────────────────
// Chooses which LLM provider powers all AI features (OpenAI or Anthropic/Claude),
// persisted in app_settings. Applies immediately to every AI route.
export async function setAiProviderAction(provider: string) {
const a = await guard()
if (provider !== "openai" && provider !== "anthropic") throw new Error("Invalid AI provider")
await setAiProvider(provider as AiProvider)
await logAdminAction({
adminId: a.user.id,
action: "ai_provider",
metadata: { provider },
})
revalidatePath("/admin/system")
return { ok: true }
}
+6 -1
View File
@@ -36,7 +36,12 @@ export async function signUp(formData: FormData) {
headers: h,
})
} catch (e) {
const msg = e instanceof APIError ? e.message : "Sign up failed"
const raw = e instanceof APIError ? e.message : "Sign up failed"
// Don't reveal that an email is already registered (user enumeration) — the
// "already exists" path must not be distinguishable from other failures.
const msg = /exist|registered|already|taken/i.test(raw)
? "We couldn't complete your sign-up. Please try a different email or sign in."
: raw
redirect(`/signup?error=${encodeURIComponent(msg)}`)
}
+63 -1
View File
@@ -1,9 +1,27 @@
"use server"
import { revalidatePath } from "next/cache"
import { and, eq } from "drizzle-orm"
import { db } from "@/lib/db"
import { leases } from "@/lib/db/schema"
import { getSessionUser } from "@/lib/session"
import { getAccountContext } from "@/lib/account"
import { sendLeaseForSignature, getAdapter, type ESignProvider } from "@/lib/esign"
import { keyBelongsToOwner } from "@/lib/storage"
import {
sendLeaseForSignature,
getAdapter,
saveEsignConnection,
disconnectEsign,
type ESignProvider,
} from "@/lib/esign"
async function ownerGuard() {
const user = await getSessionUser()
if (!user) throw new Error("Unauthorized")
const ctx = await getAccountContext(user.id)
if (!ctx.isOwner) throw new Error("Only the account owner can manage integrations")
return ctx
}
export async function sendLeaseForSignatureAction(leaseId: string, provider: string) {
const user = await getSessionUser()
@@ -15,3 +33,47 @@ export async function sendLeaseForSignatureAction(leaseId: string, provider: str
revalidatePath(`/leases/${leaseId}`)
return { ok: true }
}
/** Connect Dropbox Sign by validating and storing the landlord's API key. */
export async function connectDropboxSign(apiKey: string) {
const ctx = await ownerGuard()
const adapter = getAdapter("dropbox_sign")
if (!adapter) throw new Error("Unknown provider")
const tokens = await adapter.connectApiKey(typeof apiKey === "string" ? apiKey : "")
await saveEsignConnection(ctx.ownerId, "dropbox_sign", tokens)
revalidatePath("/settings/integrations")
return { ok: true, accountName: tokens.accountName }
}
export async function disconnectEsignAction(provider: string) {
const ctx = await ownerGuard()
if (!getAdapter(provider)) throw new Error("Unknown provider")
await disconnectEsign(ctx.ownerId, provider as ESignProvider)
revalidatePath("/settings/integrations")
return { ok: true }
}
/**
* Attach an already-uploaded document (via /api/upload) to a lease. Validates
* the file belongs to the caller's namespace to prevent cross-tenant refs.
*/
export async function setLeaseDocument(leaseId: string, fileUrl: string) {
const user = await getSessionUser()
if (!user) throw new Error("Unauthorized")
const ctx = await getAccountContext(user.id)
if (!ctx.canWrite) throw new Error("You don't have permission to do that")
const prefix = "/api/files/"
if (typeof fileUrl !== "string" || !fileUrl.startsWith(prefix)) throw new Error("Invalid document reference")
if (!keyBelongsToOwner(fileUrl.slice(prefix.length), ctx.ownerId)) throw new Error("Invalid document reference")
const [row] = await db
.update(leases)
.set({ document_url: fileUrl })
.where(and(eq(leases.id, leaseId), eq(leases.user_id, ctx.ownerId)))
.returning({ id: leases.id })
if (!row) throw new Error("Lease not found")
revalidatePath(`/leases/${leaseId}`)
return { ok: true, url: fileUrl }
}