53 lines
1.5 KiB
Markdown
53 lines
1.5 KiB
Markdown
# Mixmaker backend
|
|
|
|
Go/PostgreSQL API organized as domain, application, and inbound/outbound adapters.
|
|
|
|
## Run
|
|
|
|
Required environment:
|
|
|
|
- `DATABASE_URL`
|
|
- `DISCORD_CLIENT_ID`
|
|
- `DISCORD_CLIENT_SECRET`
|
|
- `DISCORD_REDIRECT_URL`
|
|
- `ADMIN_DISCORD_IDS` (comma-separated Discord IDs)
|
|
|
|
Optional environment:
|
|
|
|
- `HTTP_ADDR=:8080`
|
|
- `FRONTEND_URL=/`
|
|
- `SESSION_COOKIE_NAME=mixmaker_session`
|
|
- `SESSION_TTL=168h`
|
|
- `COOKIE_SECURE=true` (set `false` only for local HTTP)
|
|
- `MIGRATIONS_DIR=migrations`
|
|
|
|
Apply migrations and run:
|
|
|
|
```sh
|
|
go run ./cmd/api migrate
|
|
go run ./cmd/api
|
|
```
|
|
|
|
The same commands work with the container image:
|
|
|
|
```sh
|
|
docker run --rm ... mixmaker-api migrate
|
|
docker run --rm ... mixmaker-api
|
|
```
|
|
|
|
`GET /healthz` is a process health check and `GET /readyz` checks PostgreSQL.
|
|
Authenticated realtime updates are available from
|
|
`GET /api/events/stream?topic=event:<event-id>` as Server-Sent Events.
|
|
|
|
## Security and behavior
|
|
|
|
Discord access tokens are used only during callback and are not stored. The API
|
|
creates opaque server-side sessions and sends an HttpOnly, SameSite=Lax cookie.
|
|
Initial administrators are promoted only when their Discord ID is present in
|
|
`ADMIN_DISCORD_IDS`; existing administrators are never demoted by login.
|
|
|
|
Draft and series writes use persisted versions to reject stale repeated
|
|
commands. RSVP overrides, captain assignments, balancing selections, tosses,
|
|
draft actions, and results retain actor information in domain state or the
|
|
append-only audit log.
|