Deploy on DigitalOcean App Platform (GitHub-source build) + consolidate audit-fixes

Deploy config:
- .do/app.yaml: build the Dockerfile directly from GitHub (deploy_on_push) instead
  of a pre-built DOCR image; NEXT_PUBLIC_* set RUN_AND_BUILD_TIME with the
  propertymanagement.network domain so they bake into the client bundle; add
  custom domains block (apex + www); wire Sentry DSN (server + browser).

Included pending work from the audit-fixes branch:
- AI provider abstraction (OpenAI/Anthropic, admin-selectable; Anthropic default)
- Per-landlord e-signature (DocuSign OAuth + Dropbox Sign) + migration 0010
- Outbound webhooks / Zapier integration
- PayPal removal (Stripe-only billing)
- Storage hardening (fail-loud when Spaces unconfigured), security fixes

Verified: full production Docker build (same build-args as DO) passes clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-03 04:45:24 -04:00
co-authored by Claude Opus 4.8
parent 917a06ee85
commit 5495b94924
86 changed files with 7647 additions and 1182 deletions
+11
View File
@@ -1,5 +1,16 @@
import OpenAI from "openai"
// True when the server has an AI provider key (OpenAI OR Anthropic). AI routes
// check this up front and return a friendly 503 instead of throwing, matching
// how the other optional integrations (Stripe / SMTP / Turnstile) degrade when
// unconfigured. The active provider is chosen by an admin (see lib/ai/provider).
export function aiConfigured(): boolean {
return Boolean(process.env.OPENAI_API_KEY || process.env.ANTHROPIC_API_KEY)
}
export const AI_UNCONFIGURED_ERROR =
"AI features aren't configured on this server (no OpenAI or Anthropic API key). Ask your administrator to enable them."
// Lazily construct the OpenAI client so `next build` does NOT require
// OPENAI_API_KEY — it's only needed at runtime. Call sites keep using
// `openai.xxx` unchanged; the Proxy builds the real client on first access.