TCG Vault - Trading Card Game Collection Management with OCR Scanning
Find a file
Randall Stillwell 50ce9ab43a architect: pick-a-name (queued → in-progress; 2 briefs, D1-D5 routed back for operator gate-1)
Five decisions routed back for operator gate-1 ratification — none
architect-self-ratifiable, since all five are naming choices rather than
architectural ones. Gate-0 brand winner (Deck Hearth) is captured;
architect's job was to scope and minimize the cost of the rename, not to
re-litigate the brand. No blocking findings surfaced: no npm-package
collision (we don't publish), domain ownership is already a known queued
follow-up, Redis counter reset is the explicitly-accepted trade.

Architecture: 2 file-disjoint briefs that can run in parallel via
/multitask once gate-1 lands. ~75-110 lines net diff across 16 source
files + 1 new migration script (excluding the opaque package-lock.json
regen). Brief 1 is the mechanical display/comment sweep (7 files, ~7
lines) — branding notes, rule descriptions, three User-Agent product
tokens. Brief 2 owns the infrastructure + email-rename blast (10 files
+ 1 new migration script, ~30 edits) — Redis prefix rename in
lib/rate-limit.js (5 lines), package.json + lockfile regen, admin/alice/
bob email rename across seed/reset/test-user scripts + login.js
fixtures + README + TESTING_GUIDE + the test-file regression-lock, plus
the new scripts/migrations/2026-05-24-rename-admin-email.js (idempotent
REPLACE() UPDATE with UNIQUE-constraint fail-loud semantics).

D1-D5 recommendations all biased toward existing-string consistency:
D1 "Deck Hearth" (matches all 7 already-correct user-facing surfaces;
choosing "Deckhearth" would re-sweep them — net-negative cost), D2
`deck-hearth` (matches the existing `deck-hearth-logo-container` CSS
class), D3 `deckhearth` (single token for ID use), D4
`admin@deckhearth.com` (placeholder .com pending point-domain convoy),
D5 full `deckhearth` Redis prefix (the 8-byte/key savings of `dh` are
negligible vs. self-documenting debuggability).

Boot-the-brief findings preempted: lockfile regen is architect-verified
to touch only the 2 `name` field lines (lines 2 + 8 of package-lock.json);
the test-file negative regression assertion's email literal recommendation
is PRESERVE the historical `admin@tcgvault.com` (the literal is a
documented pre-fix-auth-bypass bug shape, not an arbitrary email value);
scripts/reset-db.js line 142's CJS-in-ESM bug is OUT OF SCOPE and queued
as convert-reset-db-to-esm; the in-DB migration's UNIQUE-constraint fail-
loud is the intentional safety behavior. AGENTS.md Gotcha #4 / #12
updates are reserved for the doc-writer pass at convoy close (not
preempted by Brief 1).

Two NEW out-of-scope follow-ups surfaced beyond the convoy seed's four:
convert-reset-db-to-esm (CJS-in-ESM bug in reset-db.js, may fold into
purge-weak-creds-from-helpers) and update-seed-visual-baselines-on-linux-
ordering (the queued seed-visual-baselines convoy MUST run AFTER
pick-a-name so the first Linux baseline captures Deck Hearth strings,
not TCG Vault).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 00:04:07 -05:00
.convoys architect: pick-a-name (queued → in-progress; 2 briefs, D1-D5 routed back for operator gate-1) 2026-05-25 00:04:07 -05:00
.cursor docs: post-convoy cleanup for add-rate-limiting — MILESTONE, last P0 closed 2026-05-24 23:09:07 -05:00
.github fix(security): drop wildcard CORS + redundant OPTIONS from 24 API routes (P0 #5) 2026-05-24 20:41:38 -05:00
components fix(layout+pages): default user=null + page audit sweep (P0 #7) (#15) 2026-05-24 14:31:37 -05:00
docs bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00
lib feat(security): rate-limit search/upload/import + gate import routes (P0 #6 - closes last P0) 2026-05-24 22:59:59 -05:00
pages feat(security): rate-limit search/upload/import + gate import routes (P0 #6 - closes last P0) 2026-05-24 22:59:59 -05:00
public Major redesign: Enhanced card display with particle effects, improved filters, and search functionality 2025-07-23 21:26:54 -05:00
scripts fix(seed): convert scripts/setup-neon-db.js from CJS to ESM (Node 22.x compat) 2026-05-23 17:02:44 -05:00
styles 🚀 Implement Mobile-First Navigation System 2025-08-01 18:18:21 -05:00
test fix(layout+pages): default user=null + page audit sweep (P0 #7) (#15) 2026-05-24 14:31:37 -05:00
tests feat(test): adopt @playwright/test + ship playwright.config.js + visual scaffold (P1 #10 step 2) 2026-05-24 19:25:18 -05:00
.agent-context-manifest.yml bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00
.gitignore feat(test): adopt @playwright/test + ship playwright.config.js + visual scaffold (P1 #10 step 2) 2026-05-24 19:25:18 -05:00
.npmrc Fix build compatibility issues 2025-07-22 10:32:15 -05:00
AGENTS.md docs: post-convoy cleanup for add-rate-limiting — MILESTONE, last P0 closed 2026-05-24 23:09:07 -05:00
eslint.config.mjs bump: next 15.4.3 -> 16.2.6, ESLint flat config (v9 fallback), typescript devDep 2026-05-23 02:31:26 -05:00
next.config.js bump: next 15.4.3 -> 16.2.6, ESLint flat config (v9 fallback), typescript devDep 2026-05-23 02:31:26 -05:00
package-lock.json feat(test): adopt @playwright/test + ship playwright.config.js + visual scaffold (P1 #10 step 2) 2026-05-24 19:25:18 -05:00
package.json feat(test): adopt @playwright/test + ship playwright.config.js + visual scaffold (P1 #10 step 2) 2026-05-24 19:25:18 -05:00
playwright.config.js feat(test): adopt @playwright/test + ship playwright.config.js + visual scaffold (P1 #10 step 2) 2026-05-24 19:25:18 -05:00
postcss.config.js Major redesign: Enhanced card display with particle effects, improved filters, and search functionality 2025-07-23 21:26:54 -05:00
README.md feat(seed): require ADMIN_INITIAL_PASSWORD env var; strip admin123 from README 2026-05-23 17:02:44 -05:00
tailwind.config.js Ultra-Smooth Hover System with Expanding Actions 2025-07-26 09:00:26 -05:00
TESTING_GUIDE.md 🎨 Restructured Layout System 2025-07-25 11:28:04 -05:00
vercel.json Simplify Vercel config to resolve API routing issues 2025-07-23 09:22:14 -05:00
vitest.config.js fix(layout+pages): default user=null + page audit sweep (P0 #7) (#15) 2026-05-24 14:31:37 -05:00

TCG Vault

A modern trading card game collection manager built with Next.js and Neon Database.

🚀 Features

  • Card Management: Track your MTG, Pokémon, and Lorcana cards
  • Collection Organization: Create and manage card collections
  • Deck Building: Build and share decks
  • Authentication: Secure user accounts with JWT
  • Admin Panel: Manage cards and users
  • Real-time Pricing: Track card values

🛠️ Tech Stack

  • Frontend: Next.js 16 (Pages router), React 18, JavaScript (TypeScript is a devDep only — see AGENTS.md Gotcha #9)
  • Backend: Next.js API Routes
  • Database: Neon PostgreSQL (serverless)
  • Authentication: JWT with bcrypt (24-hour expiry; lib/auth-secret.js is the single source of truth for JWT_SECRET)
  • Rate limiting: @upstash/ratelimit on /api/auth/login + /api/auth/register (5 attempts / 15 min per IP)
  • Testing: Vitest (unit); Playwright queued
  • Styling: Tailwind CSS
  • Deployment: Vercel

📦 Installation

  1. Clone the repository

    git clone <repository-url>
    cd tcg-vault
    
  2. Install dependencies

    npm install
    
  3. Set up environment variables

    cp .env.example .env.local
    

    Update .env.local with your Neon database URL and a real JWT secret:

    POSTGRES_URL="postgresql://your-username:your-password@your-host/your-database"
    JWT_SECRET="<generate with: openssl rand -hex 32>"
    # Required for `npm run setup-db` — used once to hash the initial admin password.
    # Set in .env.local for local dev, or as a CI secret if you run setup from CI.
    ADMIN_INITIAL_PASSWORD="<generate with: openssl rand -base64 24>"
    # Optional — exercise the rate limiter locally. Without them, `lib/rate-limit.js`
    # warn-and-no-ops in dev. In production these are auto-provisioned by the
    # Vercel Upstash Marketplace integration.
    KV_REST_API_URL="https://<your-upstash-host>.upstash.io"
    KV_REST_API_TOKEN="<your-upstash-rest-token>"
    

    JWT_SECRET is requiredlib/auth-secret.js throws at import time if it's unset. ADMIN_INITIAL_PASSWORD is required for npm run setup-db — the script exits with code 1 if it's unset.

  4. Set up the database

    npm run setup-db
    
  5. Start development server

    npm run dev
    

🗄️ Database Schema

The application uses the following tables:

  • users - User accounts and authentication
  • cards - Card information and metadata
  • user_cards - User's card collections
  • collections - Named card collections
  • collection_cards - Cards in collections
  • decks - Deck definitions
  • deck_cards - Cards in decks

🔧 API Endpoints

Authentication

  • POST /api/auth/register - User registration
  • POST /api/auth/login - User login

Admin

  • GET /api/admin - Admin panel data

Health Check

  • GET /api/health - Application health

Note: Earlier revisions of this README also listed GET /api/test-db (and three other unauthenticated dev endpoints: /api/simple, /api/test-auth, /api/setup-database). All four were deleted in fix-auth-bypass Brief 3 (commit fc0dd73) and CI now blocks their reintroduction. Don't recreate them.

🚀 Deployment

This app is configured for deployment on Vercel:

  1. Connect your repository to Vercel
  2. Set environment variables in Vercel dashboard
  3. Deploy automatically on push to main branch

📁 Project Structure

tcg-vault/
├── pages/                 # Next.js pages and API routes
│   ├── api/              # API endpoints
│   │   ├── auth/         # Authentication routes
│   │   └── admin/        # Admin routes
│   ├── _app.js           # App wrapper
│   └── index.js          # Home page
├── lib/                  # Utility libraries
│   └── database.js       # Database adapter
├── scripts/              # Database setup scripts
├── public/               # Static assets
└── .env.local           # Environment variables

🔐 First-time admin setup

npm run setup-db creates a single admin user the first time it runs. The password is read from the ADMIN_INITIAL_PASSWORD environment variable; the script exits with code 1 (and does not open a database connection) if the variable is unset or empty.

  • Local dev: set ADMIN_INITIAL_PASSWORD in .env.local before running npm run setup-db. Use openssl rand -base64 24 (or any other strong source) to generate the value.
  • CI / Vercel: set ADMIN_INITIAL_PASSWORD as a project secret if setup ever runs from CI. The env var is only read by the seed script; runtime auth uses the per-user password stored in the database.
  • Admin email: the seed creates admin@tcgvault.com. Change the password immediately after first login via the app's profile settings.

Operators of envs that pre-date this change: npm run setup-db is idempotent (ON CONFLICT (email) DO NOTHING) — re-running it with ADMIN_INITIAL_PASSWORD set will not rotate an existing admin row's password. If your environment was set up before this change and still has the prior weak default, rotate the password manually via the app after logging in, or wait for the queued rotate-default-admin follow-up convoy.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Make your changes
  4. Submit a pull request

📄 License

MIT License - see LICENSE file for details