Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
212 commits
Select commit Hold shift + click to select a range
c452d73
Add private collection market pipeline documentation
ACoolNerd Jul 10, 2026
c8815f9
Add SportsCardsPro pipeline environment template
ACoolNerd Jul 10, 2026
8730dae
Protect private collection and generated pricing data
ACoolNerd Jul 10, 2026
73e4d87
Implement secure SportsCardsPro collection synchronization
ACoolNerd Jul 10, 2026
654cb0f
Add listing candidate and net proceeds analysis
ACoolNerd Jul 10, 2026
1b949da
Add listing, pricing, earnings, and approval protocol
ACoolNerd Jul 10, 2026
2aadc96
Add private image ingestion utility
ACoolNerd Jul 10, 2026
f7900d6
Add pricing and listing pipeline tests
ACoolNerd Jul 10, 2026
10156dd
Add CI for private collection market pipeline
ACoolNerd Jul 10, 2026
6dcc100
Rewrite README for production collection, pricing, listing, and agent…
ACoolNerd Jul 10, 2026
ea308a8
Expand ACoolOMNI agent instructions and production safeguards
ACoolNerd Jul 10, 2026
8f21327
Remove committed environment secret file
ACoolNerd Jul 10, 2026
4576326
Add repository-wide secret and private evidence exclusions
ACoolNerd Jul 10, 2026
94b9c95
Add safe root environment template
ACoolNerd Jul 10, 2026
0ba5480
Add production architecture and data-boundary specification
ACoolNerd Jul 10, 2026
6b943a6
Document credential rotation and repository history remediation
ACoolNerd Jul 10, 2026
9e5eed1
Add ACoolOMNI private collection market implementation agent
ACoolNerd Jul 10, 2026
e2e92bd
Expand CI to validate repository secret hygiene
ACoolNerd Jul 10, 2026
0f929ce
Document private collection pipeline setup and outputs
ACoolNerd Jul 10, 2026
4e409c4
Fix environment-file safety check in CI
ACoolNerd Jul 10, 2026
817fa0c
Sanitize committed omni-engine environment file
ACoolNerd Jul 10, 2026
2df6c22
Remove tracked omni-engine environment file
ACoolNerd Jul 10, 2026
21137bb
Add safe omni-engine environment template
ACoolNerd Jul 10, 2026
60b9e6a
Add production IAM, referral, audit, and marketplace schema
ACoolNerd Jul 10, 2026
38d105c
Add fail-closed IAM middleware and permission enforcement
ACoolNerd Jul 10, 2026
e84ef06
Replace hard-coded login with Supabase Auth integration
ACoolNerd Jul 10, 2026
88d71e8
Add referral verification and redemption service
ACoolNerd Jul 10, 2026
f3e3e81
Harden SportsCardsPro client and expose full current guide record
ACoolNerd Jul 10, 2026
8e9a754
Replace mock marketplace with private draft and approved public listi…
ACoolNerd Jul 10, 2026
554c1fa
Mount production IAM, referral, pricing search, and safer middleware
ACoolNerd Jul 10, 2026
ada4b08
Add deterministic TypeScript build and test scripts
ACoolNerd Jul 10, 2026
eedac10
Expand safe environment template for IAM and server controls
ACoolNerd Jul 10, 2026
018f95e
Add Gemini prototype-to-production reconciliation record
ACoolNerd Jul 10, 2026
a444f5e
Add full application production matrix and safety boundaries
ACoolNerd Jul 10, 2026
0e98887
Add ACoolOMNI TypeScript build to CI
ACoolNerd Jul 10, 2026
94ad989
Add card show wishlist and vendor intelligence schema
ACoolNerd Jul 10, 2026
65b24bd
Add transparent vendor reputation scoring model
ACoolNerd Jul 10, 2026
67d4684
Add transactional card show capture RPC
ACoolNerd Jul 10, 2026
fb8580b
Add card show wishlist and vendor intelligence API
ACoolNerd Jul 10, 2026
1ab50aa
Mount card show and vendor intelligence API
ACoolNerd Jul 10, 2026
c27ea36
Add card show and vendor intelligence permissions
ACoolNerd Jul 10, 2026
616e48d
Test vendor reputation scoring and evidence thresholds
ACoolNerd Jul 10, 2026
1f3abf7
Run vendor reputation tests with the omni engine test suite
ACoolNerd Jul 10, 2026
e7ead3d
Run card show vendor intelligence tests in CI
ACoolNerd Jul 10, 2026
b63b5b8
Document card show wishlist and vendor intelligence system
ACoolNerd Jul 10, 2026
acca05e
Add card show and vendor intelligence agent prompt
ACoolNerd Jul 10, 2026
e7d63d3
Add card show mode UI and UX screen register
ACoolNerd Jul 10, 2026
f3172b5
Add vendor reputation governance and review policy
ACoolNerd Jul 10, 2026
782a04a
Add card show implementation backlog and release plan
ACoolNerd Jul 10, 2026
ce0dcda
Add discovery, events, promotions, goals, grading, and experiments sc…
ACoolNerd Jul 10, 2026
9817d8d
Add collection, deck, bargain grading, and savings recommendation engine
ACoolNerd Jul 10, 2026
80c497c
Add compliance-first promotions and auditable draw engine
ACoolNerd Jul 10, 2026
f7231d0
Add deterministic privacy-conscious experiment assignment engine
ACoolNerd Jul 10, 2026
a1877b0
Add catalog, events, savings, recommendations, promotions, profile, a…
ACoolNerd Jul 10, 2026
f67e124
Mount discovery, events, promotions, goals, and recommendations API
ACoolNerd Jul 10, 2026
a3ef5ee
Add tests for recommendations, promotions, savings, and experiments
ACoolNerd Jul 10, 2026
8ebbb82
Run all ACoolOMNI service tests
ACoolNerd Jul 10, 2026
4c727d7
Add verified 2026 Collect-A-Con schedule and ticket sources
ACoolNerd Jul 10, 2026
57ad318
Add verified upcoming One Piece product schedule
ACoolNerd Jul 10, 2026
7aef3b4
Document releases, events, goals, promotions, grading, and experiment…
ACoolNerd Jul 10, 2026
449c161
Add full mobile UI and UX screen register
ACoolNerd Jul 10, 2026
d9abdf4
Remove invalid draft discovery migration before corrected replacement
ACoolNerd Jul 10, 2026
8df2edc
Add corrected discovery, events, promotions, goals, grading, and expe…
ACoolNerd Jul 10, 2026
9a766bf
Add release date precision and correct month-only product handling
ACoolNerd Jul 10, 2026
1abe351
Add official catalog and event source synchronization backlog
ACoolNerd Jul 10, 2026
29716ba
Add ACoolOMNI discovery and recommendation agent contract
ACoolNerd Jul 10, 2026
c762fe8
Add promotions and raffle compliance release checklist
ACoolNerd Jul 10, 2026
dacc1bf
Add recommendation test plan
ACoolNerd Jul 10, 2026
29859af
Add event ticketing and savings security protocol
ACoolNerd Jul 10, 2026
32d5a9d
Add full user profile and privacy model
ACoolNerd Jul 10, 2026
0016ab6
Add discovery implementation status and external blockers
ACoolNerd Jul 10, 2026
43c2003
Implement schema.org and social metadata builders
ACoolNerd Jul 10, 2026
d6989fb
Test schema.org and social metadata builders
ACoolNerd Jul 10, 2026
4729313
Expose safe metadata and structured-data endpoints
ACoolNerd Jul 10, 2026
eddad6d
Mount metadata API and report Google integration readiness
ACoolNerd Jul 10, 2026
505daa8
Document Google Cloud, metadata, QuickBooks, and affiliate configuration
ACoolNerd Jul 10, 2026
08445c3
Add Google Cloud, SEO, affiliate, and QuickBooks governance schema
ACoolNerd Jul 10, 2026
84d2c7e
Document Google AI Studio and Google Cloud production architecture
ACoolNerd Jul 10, 2026
f8f27ac
Document QuickBooks, partner, affiliate, and disclosure accounting co…
ACoolNerd Jul 10, 2026
cefe59b
Document schema.org, Open Graph, and search metadata implementation
ACoolNerd Jul 10, 2026
4f54e1c
Add Google AI Studio implementation package guide
ACoolNerd Jul 10, 2026
8a94505
Add ACoolCOLLECTOR Google AI Studio system instructions
ACoolNerd Jul 10, 2026
2a4e933
Add Google AI Studio master build prompt
ACoolNerd Jul 10, 2026
a662b33
Add Google AI Studio context manifest
ACoolNerd Jul 10, 2026
d8c58af
Add Gemini function declarations for ACoolCOLLECTOR agents
ACoolNerd Jul 10, 2026
a299534
Add Gemini structured-output schemas
ACoolNerd Jul 10, 2026
a5b6f22
Add ACoolCOLLECTOR Google AI Studio evaluation suite
ACoolNerd Jul 10, 2026
e770d58
Add Google AI Studio and Cloud deployment checklist
ACoolNerd Jul 10, 2026
533f79c
Add affiliation, API, privacy, and claims compliance matrix
ACoolNerd Jul 10, 2026
8fa4130
Add production SEO and social metadata template
ACoolNerd Jul 10, 2026
f05907e
Add production robots baseline
ACoolNerd Jul 10, 2026
aa9ea56
Add sitemap index template
ACoolNerd Jul 10, 2026
bf1164e
Add web app manifest template
ACoolNerd Jul 10, 2026
d2a2941
Implement affiliate destination and disclosure policy
ACoolNerd Jul 10, 2026
a13148b
Test affiliate approval and destination controls
ACoolNerd Jul 10, 2026
fdd65a1
Harden Gemini image analysis as authenticated candidate extraction
ACoolNerd Jul 10, 2026
0c16325
Implement restricted Google Maps Platform clients
ACoolNerd Jul 10, 2026
0b8a021
Expose authenticated Google Maps Platform routes
ACoolNerd Jul 10, 2026
7c88d64
Mount Google Maps Platform API routes
ACoolNerd Jul 10, 2026
3ce2668
Test Google Maps input and field-mask controls
ACoolNerd Jul 10, 2026
f593ca6
Validate AI Studio package, metadata templates, and additional secret…
ACoolNerd Jul 10, 2026
8581368
Add Gemini media-size limit configuration
ACoolNerd Jul 10, 2026
15e709c
Implement QuickBooks OAuth, webhook, and invoice safety utilities
ACoolNerd Jul 10, 2026
9857156
Test QuickBooks OAuth, webhooks, invoices, and idempotency
ACoolNerd Jul 10, 2026
a168b15
Add Google Cloud workload identity access-token helper
ACoolNerd Jul 10, 2026
c911ba3
Add authenticated Google Cloud text-to-speech API
ACoolNerd Jul 10, 2026
596756e
Add authenticated Google Cloud Vision OCR and recognition API
ACoolNerd Jul 10, 2026
43ff6fa
Mount Cloud Vision and text-to-speech APIs
ACoolNerd Jul 10, 2026
df34b71
Add text-to-speech and Cloud Vision validation tests
ACoolNerd Jul 10, 2026
71c5e98
Add hardened Cloud Run container image
ACoolNerd Jul 10, 2026
14609f6
Add deployable Google Cloud Terraform foundation
ACoolNerd Jul 10, 2026
2ab20ff
Add Google Cloud Terraform variables
ACoolNerd Jul 10, 2026
62357c0
Add Google Cloud Terraform outputs
ACoolNerd Jul 10, 2026
830191f
Add major events, retailers, and grading source registry
ACoolNerd Jul 10, 2026
aa121b4
Add external event, retailer, grader, and partnership schema
ACoolNerd Jul 10, 2026
605a5c1
Add Cloud Vision and text-to-speech configuration
ACoolNerd Jul 10, 2026
2904f4b
Document Google Cloud Terraform deployment
ACoolNerd Jul 10, 2026
c29f8b0
Add AI Studio prompt for speech, vision, events, retailers, graders, …
ACoolNerd Jul 10, 2026
a29820d
Expand AI Studio context for Cloud Vision, speech, events, retailers,…
ACoolNerd Jul 10, 2026
0c0d014
Validate Terraform, Cloud Run container, ecosystem registry, and AI S…
ACoolNerd Jul 10, 2026
c673915
Format Google Cloud Terraform for CI validation
ACoolNerd Jul 10, 2026
b9b4a65
Add officially verified major collectibles events for 2026
ACoolNerd Jul 10, 2026
e2c3fc4
Add timestamped PSA and Beckett service-level source data
ACoolNerd Jul 10, 2026
37dad64
Seed verified major events and current PSA Beckett service levels
ACoolNerd Jul 10, 2026
fa3ecd2
Validate major event and grading source registries
ACoolNerd Jul 10, 2026
890636f
Add verified major events and grading service seeds to AI Studio context
ACoolNerd Jul 10, 2026
32e6179
Correct National general admission price for July 2026
ACoolNerd Jul 10, 2026
b4ad9ec
Implement Issue 8 activation evidence schema
ACoolNerd Jul 10, 2026
4276f04
Add server-side Supabase admin helper
ACoolNerd Jul 10, 2026
8b8037c
Add evidence-backed readiness scoring engine
ACoolNerd Jul 10, 2026
b5a077d
Test evidence-backed readiness scoring
ACoolNerd Jul 10, 2026
9848529
Add official-source monitoring and fingerprint service
ACoolNerd Jul 10, 2026
c924b6d
Test official-source monitoring controls
ACoolNerd Jul 10, 2026
019230d
Expand QuickBooks OAuth, token protection, webhook, and API utilities
ACoolNerd Jul 10, 2026
b9cb912
Add Google Secret Manager payload helper
ACoolNerd Jul 10, 2026
20e69d3
Implement QuickBooks OAuth, refresh, webhook, status, and invoice routes
ACoolNerd Jul 10, 2026
1413a99
Implement integration readiness and source-monitoring API
ACoolNerd Jul 10, 2026
a7966d9
Mount QuickBooks and integration readiness APIs with raw webhook capture
ACoolNerd Jul 10, 2026
c79d068
Expand QuickBooks OAuth, protection, URL, and webhook tests
ACoolNerd Jul 10, 2026
5982b5f
Add OIDC Google Cloud deployment workflow
ACoolNerd Jul 10, 2026
cf65d9b
Expand Google Cloud deployment variables for Issue 8
ACoolNerd Jul 10, 2026
64c35e8
Add protected QuickBooks credential material table
ACoolNerd Jul 10, 2026
f8adf81
Add least-privilege runtime IAM, secrets, and optional GitHub OIDC
ACoolNerd Jul 10, 2026
4296b20
Add Issue 8 activation and score promotion runbook
ACoolNerd Jul 10, 2026
064fbf9
Add event retailer and grading provider outreach kit
ACoolNerd Jul 10, 2026
896b2cd
Implement external source freshness and evidence engine
ACoolNerd Jul 10, 2026
cb955f0
Document QuickBooks callback and protected token configuration
ACoolNerd Jul 10, 2026
5a7a354
Test external source evidence and stale detection
ACoolNerd Jul 10, 2026
e202fa1
Add external ecosystem integration API
ACoolNerd Jul 10, 2026
d7c239d
Add Issue 8 evidence-backed readiness scorecard
ACoolNerd Jul 10, 2026
3acb92b
Add Issue 8 activation evidence and QuickBooks controls
ACoolNerd Jul 10, 2026
ce3cb42
Remove redundant external integration router
ACoolNerd Jul 10, 2026
9fdb2b4
Remove overlapping Issue 8 activation migration
ACoolNerd Jul 10, 2026
8d868d9
Add Cloud Run monitoring and budget controls
ACoolNerd Jul 10, 2026
1a78f47
Add billing budget variables
ACoolNerd Jul 10, 2026
5577525
Enable monitoring, billing, and federation APIs
ACoolNerd Jul 10, 2026
c510885
Add monitoring and budget variables to Cloud deployment workflow
ACoolNerd Jul 10, 2026
2a93332
Add Issue 8 engineering completion manifest
ACoolNerd Jul 10, 2026
93f9dfe
Format observability Terraform
ACoolNerd Jul 10, 2026
c380dea
Align Terraform budget notification fields
ACoolNerd Jul 10, 2026
c9bf1d1
Add 2026 native multidevice and XR architecture
ACoolNerd Jul 10, 2026
c19b11f
Add canonical ACool profile JSON schema
ACoolNerd Jul 10, 2026
fb712f1
Add native Android profile domain model
ACoolNerd Jul 10, 2026
eae5280
Add adaptive Jetpack Compose profile screen
ACoolNerd Jul 10, 2026
4e7a5f0
Add native Apple profile domain model
ACoolNerd Jul 10, 2026
0e5678f
Add adaptive SwiftUI profile view
ACoolNerd Jul 10, 2026
6217c77
Add Android XR and Meta Quest implementation boundary
ACoolNerd Jul 10, 2026
89fc4e6
Add evidence-backed 90-point activation scorecard
ACoolNerd Jul 10, 2026
1d84fc4
Add native multidevice Google AI Studio build prompt
ACoolNerd Jul 10, 2026
2ca5221
Restrict GitHub OIDC deployment identity to the approved branch
ACoolNerd Jul 10, 2026
2420499
Add native multidevice sources to AI Studio context manifest
ACoolNerd Jul 10, 2026
60a66dd
Add safe Google Cloud activation and Terraform plan script
ACoolNerd Jul 10, 2026
9af3726
Add remote GCS Terraform state backend
ACoolNerd Jul 10, 2026
a643154
Add remote state bootstrap to development activation script
ACoolNerd Jul 10, 2026
b3fcf77
Add guarded Google Cloud bootstrap and development deployment script
ACoolNerd Jul 10, 2026
5ed6301
Harden Google Cloud deployment workflow with remote state and product…
ACoolNerd Jul 10, 2026
85cf5ca
Pass deployment variables explicitly to activation planner
ACoolNerd Jul 10, 2026
29cf965
Add native Android Gradle settings
ACoolNerd Jul 10, 2026
9e3bd50
Add Android native application build
ACoolNerd Jul 10, 2026
8f09112
Add Android Gradle properties
ACoolNerd Jul 10, 2026
147cdbf
Add Android release shrinking rules
ACoolNerd Jul 10, 2026
95e2a70
Add Android native application manifest
ACoolNerd Jul 10, 2026
fda8841
Add Android native app theme resource
ACoolNerd Jul 10, 2026
38b00d2
Add Android native application entry point
ACoolNerd Jul 10, 2026
f89cb3c
Add Android native profile unit tests
ACoolNerd Jul 10, 2026
c1b70eb
Add native Apple Swift package
ACoolNerd Jul 10, 2026
1ffa51c
Add Apple native profile tests
ACoolNerd Jul 10, 2026
3fe2030
Add native Android and Apple build validation
ACoolNerd Jul 10, 2026
e4f5df2
Fix Android SDK license acceptance under pipefail
ACoolNerd Jul 10, 2026
39ed79d
Target stable Android API 36 for native CI
ACoolNerd Jul 10, 2026
43be591
Use stable Android API 36 in native CI
ACoolNerd Jul 10, 2026
2c32653
Add maps, navigation, audio, accessibility, and cost-control architec…
ACoolNerd Jul 10, 2026
1211b0e
Define centralized marketplace, personal storefronts, showcases, coll…
ACoolNerd Jul 10, 2026
333d338
Add storefront, showcase, collaboration, ownership, and fraud-control…
ACoolNerd Jul 10, 2026
2ec5dfd
Add explainable marketplace fraud and counterfeit risk engine
ACoolNerd Jul 10, 2026
09bf3e7
Test marketplace fraud and counterfeit risk decisions
ACoolNerd Jul 10, 2026
de83725
Add storefront, showcase, campaign, audio, and fraud-review API
ACoolNerd Jul 10, 2026
bc89691
Mount community marketplace, showcase, audio, and fraud API
ACoolNerd Jul 10, 2026
cec5fb7
Add route matrix, accessible navigation steps, and Street View metadata
ACoolNerd Jul 10, 2026
93dbbba
Expose route matrix and Street View metadata with consent controls
ACoolNerd Jul 10, 2026
c0bb575
Add context-aware Maps, Street View, navigation, accessibility, and A…
ACoolNerd Jul 10, 2026
2d89aac
Add native Android audio companion rights and safety policy
ACoolNerd Jul 10, 2026
7faf509
Add native Apple audio companion rights and safety policy
ACoolNerd Jul 10, 2026
abb7de2
Add AI Studio prompt for Maps, social marketplace, audio, and fraud p…
ACoolNerd Jul 10, 2026
eb8a572
Add maps, social marketplace, audio, and trust systems to AI Studio c…
ACoolNerd Jul 10, 2026
bc4d99a
Validate cloud activation scripts and new AI Studio expansion prompt
ACoolNerd Jul 10, 2026
819fb2d
Harden Maps API activation against Cloud Shell RAB warnings
ACoolNerd Jul 10, 2026
2d7d791
Harden activation planning against Cloud Shell RAB warnings
ACoolNerd Jul 10, 2026
241ae18
Harden Maps activation token verification in Cloud Shell
ACoolNerd Jul 10, 2026
4beaa14
Harden Terraform activation token retrieval in Cloud Shell
ACoolNerd Jul 10, 2026
c1d07f8
Remove unnecessary Maps access-token gate in Cloud Shell
ACoolNerd Jul 10, 2026
8743dfb
Document Cloud Shell Maps activation recovery
ACoolNerd Jul 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
105 changes: 105 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
# ACoolCOLLECTOR local configuration template
# Copy this file to .env.local and add real values locally.
# Never commit .env.local or paste secrets into issues, pull requests, screenshots, designs, or chat.

# Server and public metadata
PORT=3000
APP_BASE_URL=http://localhost:3000
PUBLIC_SITE_URL=https://acoolcollector.com
ALLOWED_ORIGINS=http://localhost:3000
JSON_BODY_LIMIT=12mb
ACOOL_INVENTORY_PATH=data/processed/ACoolINVENTORY_Master.csv

# SportsCardsPro current-value provider
SPORTSCARDSPRO_API_TOKEN=
SPORTSCARDSPRO_BASE_URL=https://www.sportscardspro.com
ACOOL_API_DELAY_SECONDS=1.1
ACOOL_PRICE_CACHE_HOURS=24

# Private collection source and generated outputs
ACoolCOLLECTION_MANIFEST_PATH=
ACOOL_PRIVATE_OUTPUT_DIR=integrations/sportscardspro_pipeline/private

# Earnings scenario defaults — planning assumptions only
ACOOL_MARKETPLACE_FEE_RATE=0.13
ACOOL_PAYMENT_FEE_RATE=0.029
ACOOL_PAYMENT_FIXED_FEE_CENTS=30
ACOOL_DEFAULT_SHIPPING_CENTS=500
ACOOL_DEFAULT_INSURANCE_CENTS=0
ACOOL_RETURN_RESERVE_RATE=0.05

# Supabase Auth, PostgreSQL REST, RLS, IAM and referrals
SUPABASE_URL=
SUPABASE_ANON_KEY=
SUPABASE_SERVICE_ROLE_KEY=

# Gemini API / Google AI Studio prototype integration
GEMINI_API_KEY=
GEMINI_VISION_MODEL=
GEMINI_AGENT_MODEL=
GEMINI_MAX_IMAGE_BYTES=8388608
GOOGLE_GENAI_ENVIRONMENT=developer_api
GOOGLE_CLOUD_PROJECT_ID=
GOOGLE_CLOUD_REGION=us-central1

# Google Cloud workload authentication
# Cloud Run should use its service account. GOOGLE_CLOUD_ACCESS_TOKEN is local-test-only and short-lived.
GOOGLE_CLOUD_ACCESS_TOKEN=

# Google Cloud Vision and Text-to-Speech
GOOGLE_CLOUD_VISION_ENABLED=false
GOOGLE_CLOUD_TTS_ENABLED=false
GOOGLE_CLOUD_TTS_DEFAULT_LANGUAGE=en-US
GOOGLE_CLOUD_TTS_DEFAULT_ENCODING=MP3

# Google Maps Platform
GOOGLE_MAPS_BROWSER_API_KEY=
GOOGLE_MAPS_SERVER_API_KEY=
GOOGLE_MAPS_MAP_ID=
GOOGLE_MAPS_ALLOWED_COUNTRIES=US,CA
GOOGLE_PLACES_FIELD_MASK=id,displayName,formattedAddress,location,websiteUri,nationalPhoneNumber

# Google OAuth / People and Calendar APIs — user consent required
GOOGLE_OAUTH_CLIENT_ID=
GOOGLE_OAUTH_CLIENT_SECRET=
GOOGLE_OAUTH_REDIRECT_URI=
GOOGLE_PEOPLE_SYNC_ENABLED=false
GOOGLE_CALENDAR_SYNC_ENABLED=false

# Google Cloud managed services
GOOGLE_CLOUD_STORAGE_BUCKET_PRIVATE=
GOOGLE_CLOUD_STORAGE_BUCKET_PUBLIC=
GOOGLE_CLOUD_TASKS_QUEUE=
GOOGLE_CLOUD_PUBSUB_TOPIC=
GOOGLE_CLOUD_KMS_KEY_NAME=
GOOGLE_CLOUD_RECAPTCHA_SITE_KEY=
GOOGLE_CLOUD_RECAPTCHA_PROJECT_ID=
BIGQUERY_DATASET_ID=
GA4_MEASUREMENT_ID=
GOOGLE_SEARCH_CONSOLE_SITE_URL=https://acoolcollector.com/

# QuickBooks Online integration
INTUIT_CLIENT_ID=
INTUIT_CLIENT_SECRET=
INTUIT_REDIRECT_URI=https://api.acoolcollector.com/api/v1/quickbooks/oauth/callback
INTUIT_ENVIRONMENT=sandbox
INTUIT_WEBHOOK_VERIFIER_TOKEN=
QBO_POST_CONNECT_REDIRECT_URI=https://acoolcollector.com/settings/integrations/quickbooks
# Base64-encoded 32-byte key. Generate outside chat and store through the approved secret manager.
QBO_TOKEN_ENCRYPTION_KEY=
QBO_DEFAULT_CLASS_NAME=ACoolCOLLECTOR
QBO_DEFAULT_LOCATION_NAME=Online
QBO_AFFILIATE_INCOME_ACCOUNT_NAME=Affiliate and Partner Revenue
QBO_AFFILIATE_PAYABLE_ACCOUNT_NAME=Affiliate Commissions Payable
QBO_MERCHANT_FEES_ACCOUNT_NAME=Merchant Processing Fees

# Affiliate and partnership governance
AFFILIATE_DISCLOSURE_DEFAULT=ACoolCOLLECTOR may earn a commission from qualifying purchases made through clearly labeled links.
AFFILIATE_REDIRECT_ALLOWLIST=
AFFILIATE_CLICK_RETENTION_DAYS=90
AFFILIATE_CONSENT_REQUIRED=true

# Future payment providers — not active until provider onboarding and server integration pass review
STRIPE_SECRET_KEY=
STRIPE_WEBHOOK_SECRET=
STRIPE_PUBLISHABLE_KEY=
2 changes: 0 additions & 2 deletions .env.local

This file was deleted.

201 changes: 201 additions & 0 deletions .github/workflows/deploy-google-cloud.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,201 @@
name: Deploy ACoolCOLLECTOR to Google Cloud

on:
workflow_dispatch:
inputs:
environment:
description: GitHub environment and Google Cloud target
required: true
type: choice
options:
- development
- production
default: development
apply:
description: Apply the reviewed Terraform plan
required: true
type: boolean
default: false
production_confirmation:
description: Type DEPLOY PRODUCTION only for a production apply
required: false
type: string
default: ""

permissions:
contents: read
id-token: write

concurrency:
group: acoolcollector-${{ inputs.environment }}
cancel-in-progress: false

jobs:
deploy:
runs-on: ubuntu-latest
environment: ${{ inputs.environment }}
env:
GCP_PROJECT_ID: ${{ vars.GCP_PROJECT_ID }}
GCP_REGION: ${{ vars.GCP_REGION || 'us-central1' }}
GCP_TERRAFORM_STATE_BUCKET: ${{ vars.GCP_TERRAFORM_STATE_BUCKET }}
PUBLIC_SITE_URL: ${{ vars.PUBLIC_SITE_URL }}
TERRAFORM_DIR: infra/google-cloud/terraform
TF_STATE_PREFIX: acoolcollector/${{ inputs.environment }}
IMAGE_NAME: acoolcollector-api
TF_VAR_environment: ${{ inputs.environment }}
TF_VAR_allowed_origins: ${{ vars.ALLOWED_ORIGINS_JSON || '[]' }}
TF_VAR_alert_email: ${{ vars.ALERT_EMAIL }}
TF_VAR_billing_account_id: ${{ vars.GCP_BILLING_ACCOUNT_ID }}
TF_VAR_monthly_budget_usd: ${{ vars.MONTHLY_BUDGET_USD || '250' }}
TF_VAR_enable_github_oidc: true
TF_VAR_github_repository: ACoolNerd/ACoolCOLLECTOR
TF_VAR_github_branch: main
PRODUCTION_CONFIRMATION: ${{ inputs.production_confirmation }}
steps:
- uses: actions/checkout@v4

- name: Authenticate to Google Cloud with OIDC
uses: google-github-actions/auth@v2
with:
workload_identity_provider: ${{ vars.GCP_WORKLOAD_IDENTITY_PROVIDER }}
service_account: ${{ vars.GCP_DEPLOY_SERVICE_ACCOUNT }}
create_credentials_file: true

- uses: google-github-actions/setup-gcloud@v2

- uses: hashicorp/setup-terraform@v3

- name: Validate deployment configuration
shell: bash
run: |
set -euo pipefail
test -n "$GCP_PROJECT_ID"
test -n "$GCP_TERRAFORM_STATE_BUCKET"
test -n "$PUBLIC_SITE_URL"
test -n "${{ vars.GCP_WORKLOAD_IDENTITY_PROVIDER }}"
test -n "${{ vars.GCP_DEPLOY_SERVICE_ACCOUNT }}"
[[ "$PUBLIC_SITE_URL" == https://* ]]

if [[ "${{ inputs.environment }}" == "production" && "${{ inputs.apply }}" == "true" ]]; then
[[ "$PRODUCTION_CONFIRMATION" == "DEPLOY PRODUCTION" ]]
fi

python - <<'PY'
import json, os
value = json.loads(os.environ['TF_VAR_allowed_origins'])
assert isinstance(value, list)
assert all(isinstance(item, str) and item.startswith('https://') for item in value)
PY

- name: Configure Artifact Registry authentication
run: gcloud auth configure-docker "${GCP_REGION}-docker.pkg.dev" --quiet

- name: Build immutable container
id: image
shell: bash
run: |
set -euo pipefail
image="${GCP_REGION}-docker.pkg.dev/${GCP_PROJECT_ID}/acoolcollector/${IMAGE_NAME}:${GITHUB_SHA}"
docker build --pull --label "org.opencontainers.image.revision=${GITHUB_SHA}" -t "$image" src/omni-engine
docker push "$image"
digest="$(gcloud artifacts docker images describe "$image" --format='value(image_summary.digest)')"
test -n "$digest"
echo "image=$image" >> "$GITHUB_OUTPUT"
echo "digest=$digest" >> "$GITHUB_OUTPUT"
echo "immutable_image=${image}@${digest}" >> "$GITHUB_OUTPUT"

- name: Terraform init and validate
working-directory: ${{ env.TERRAFORM_DIR }}
shell: bash
run: |
set -euo pipefail
terraform fmt -check -recursive
terraform init \
-reconfigure \
-backend-config="bucket=${GCP_TERRAFORM_STATE_BUCKET}" \
-backend-config="prefix=${TF_STATE_PREFIX}"
terraform validate

- name: Build Terraform plan
id: plan
working-directory: ${{ env.TERRAFORM_DIR }}
shell: bash
run: |
set -euo pipefail
terraform plan \
-out=tfplan \
-var="project_id=${GCP_PROJECT_ID}" \
-var="region=${GCP_REGION}" \
-var="container_image=${{ steps.image.outputs.immutable_image }}" \
-var="public_site_url=${PUBLIC_SITE_URL}"
terraform show -json tfplan > tfplan.json
terraform show -no-color tfplan > tfplan.txt
digest="$(sha256sum tfplan.json | awk '{print $1}')"
echo "terraform_plan_digest=$digest" >> "$GITHUB_OUTPUT"

- name: Enforce Terraform plan safety gates
working-directory: ${{ env.TERRAFORM_DIR }}
shell: bash
run: |
set -euo pipefail
if grep -Eq 'roles/(owner|editor)' tfplan.txt; then
echo "Blocked: Terraform plan contains project Owner or Editor role."
exit 1
fi
if grep -q 'allAuthenticatedUsers' tfplan.txt; then
echo "Blocked: Terraform plan contains allAuthenticatedUsers."
exit 1
fi
if grep -q 'public_access_prevention = "inherited"' tfplan.txt; then
echo "Blocked: a storage bucket does not enforce public access prevention."
exit 1
fi

- name: Upload deployment evidence
uses: actions/upload-artifact@v4
with:
name: acoolcollector-${{ inputs.environment }}-${{ github.sha }}-deployment-evidence
path: |
${{ env.TERRAFORM_DIR }}/tfplan
${{ env.TERRAFORM_DIR }}/tfplan.json
${{ env.TERRAFORM_DIR }}/tfplan.txt
retention-days: 30

- name: Apply reviewed Terraform plan
if: ${{ inputs.apply }}
working-directory: ${{ env.TERRAFORM_DIR }}
run: terraform apply -auto-approve tfplan

- name: Verify Cloud Run health
if: ${{ inputs.apply }}
id: health
shell: bash
run: |
set -euo pipefail
url="$(gcloud run services describe acoolcollector-api --project "$GCP_PROJECT_ID" --region "$GCP_REGION" --format='value(status.url)')"
test -n "$url"
for attempt in $(seq 1 12); do
if curl --fail --silent --show-error --max-time 10 "${url}/health" > health.json; then
break
fi
sleep 10
done
test -s health.json
grep -q '"status":"ok"' health.json
echo "service_url=$url" >> "$GITHUB_OUTPUT"

- name: Deployment summary
shell: bash
run: |
{
echo "## ACoolCOLLECTOR deployment evidence"
echo "- Environment: ${{ inputs.environment }}"
echo "- Commit: ${GITHUB_SHA}"
echo "- Image: ${{ steps.image.outputs.immutable_image }}"
echo "- Terraform state: gs://${GCP_TERRAFORM_STATE_BUCKET}/${TF_STATE_PREFIX}"
echo "- Terraform plan digest: ${{ steps.plan.outputs.terraform_plan_digest }}"
echo "- Applied: ${{ inputs.apply }}"
echo "- Service URL: ${{ steps.health.outputs.service_url }}"
echo "- Monitoring notification configured: ${{ vars.ALERT_EMAIL != '' }}"
echo "- Budget configured: ${{ vars.GCP_BILLING_ACCOUNT_ID != '' }}"
} >> "$GITHUB_STEP_SUMMARY"
79 changes: 79 additions & 0 deletions .github/workflows/native-app-foundations.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
name: Native App Foundations

on:
pull_request:
paths:
- "apps/android-native/**"
- "apps/apple-native/**"
- "schemas/acool-profile.schema.json"
- ".github/workflows/native-app-foundations.yml"
workflow_dispatch:

permissions:
contents: read

concurrency:
group: native-app-foundations-${{ github.ref }}
cancel-in-progress: true

jobs:
android-native:
name: Android native build and tests
runs-on: ubuntu-latest
timeout-minutes: 35
steps:
- uses: actions/checkout@v4

- uses: actions/setup-java@v4
with:
distribution: temurin
java-version: "17"

- uses: android-actions/setup-android@v3

- name: Install stable Android API 36
shell: bash
run: |
set -euo pipefail
yes | sdkmanager --licenses >/dev/null || true
sdkmanager "platforms;android-36" "build-tools;36.0.0" "platform-tools"

- uses: gradle/actions/setup-gradle@v4
with:
gradle-version: "9.4.1"

- name: Build and test Android app
shell: bash
run: |
set -euo pipefail
gradle \
-p apps/android-native \
testDebugUnitTest \
assembleDebug \
--stacktrace

- name: Upload Android debug artifact
uses: actions/upload-artifact@v4
with:
name: acoolcollector-android-debug-${{ github.sha }}
path: apps/android-native/build/outputs/apk/debug/*.apk
retention-days: 7
if-no-files-found: error

apple-native:
name: Apple native package build and tests
runs-on: macos-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4

- name: Record Apple toolchain
run: |
xcodebuild -version
swift --version

- name: Build Apple native package
run: swift build --package-path apps/apple-native

- name: Test Apple native package
run: swift test --package-path apps/apple-native
Loading
Loading