Removes four unauthenticated dev endpoints that were shipped to production: - pages/api/simple.js (info leak) - pages/api/test-auth.js (auth diagnostic / token-mint side door) - pages/api/test-db.js (DB connection diagnostic) - pages/api/setup-database.js (public POST that ran DDL + seeded admin) setup-database is the highest-impact removal: it was a public endpoint that triggered schema bootstrap and seeded the default admin credentials (admin@tcgvault.com / admin123). AGENTS.md gotcha #5. Also adds a new `forbidden-endpoints` job to .github/workflows/ci.yml that fails the build if any of the four deleted paths re-appear OR if any new pages/api/test-*.js file is added. Cheap insurance against a future agent re-introducing a dev endpoint from an outdated tutorial. README: drops the single `GET /api/test-db` line under "Health Check". Rest of the API list is intentionally left for the doc-writer pass. Verified locally: - npm run build exits 0 (no source callers — confirmed via grep across pages/, components/, lib/) - CI guard local simulation: clean → OK; with test-fake.js → FAIL; OK after cleanup Resolves AGENTS.md gotcha #5. Brief 1/2/4/5 still pending in convoy. Convoy: fix-auth-bypass / Brief 3 Co-authored-by: Cursor <cursoragent@cursor.com>
120 lines
No EOL
2.9 KiB
Markdown
120 lines
No EOL
2.9 KiB
Markdown
# TCG Vault
|
|
|
|
A modern trading card game collection manager built with Next.js and Neon Database.
|
|
|
|
## 🚀 Features
|
|
|
|
- **Card Management**: Track your MTG, Pokémon, and Lorcana cards
|
|
- **Collection Organization**: Create and manage card collections
|
|
- **Deck Building**: Build and share decks
|
|
- **Authentication**: Secure user accounts with JWT
|
|
- **Admin Panel**: Manage cards and users
|
|
- **Real-time Pricing**: Track card values
|
|
|
|
## 🛠️ Tech Stack
|
|
|
|
- **Frontend**: Next.js 15, React 18, TypeScript
|
|
- **Backend**: Next.js API Routes
|
|
- **Database**: Neon PostgreSQL (serverless)
|
|
- **Authentication**: JWT with bcrypt
|
|
- **Styling**: Tailwind CSS
|
|
- **Deployment**: Vercel
|
|
|
|
## 📦 Installation
|
|
|
|
1. **Clone the repository**
|
|
```bash
|
|
git clone <repository-url>
|
|
cd tcg-vault
|
|
```
|
|
|
|
2. **Install dependencies**
|
|
```bash
|
|
npm install
|
|
```
|
|
|
|
3. **Set up environment variables**
|
|
```bash
|
|
cp .env.example .env.local
|
|
```
|
|
|
|
Update `.env.local` with your Neon database URL:
|
|
```env
|
|
POSTGRES_URL="postgresql://your-username:your-password@your-host/your-database"
|
|
JWT_SECRET="your-super-secret-jwt-key"
|
|
```
|
|
|
|
4. **Set up the database**
|
|
```bash
|
|
npm run setup-db
|
|
```
|
|
|
|
5. **Start development server**
|
|
```bash
|
|
npm run dev
|
|
```
|
|
|
|
## 🗄️ Database Schema
|
|
|
|
The application uses the following tables:
|
|
- `users` - User accounts and authentication
|
|
- `cards` - Card information and metadata
|
|
- `user_cards` - User's card collections
|
|
- `collections` - Named card collections
|
|
- `collection_cards` - Cards in collections
|
|
- `decks` - Deck definitions
|
|
- `deck_cards` - Cards in decks
|
|
|
|
## 🔧 API Endpoints
|
|
|
|
### Authentication
|
|
- `POST /api/auth/register` - User registration
|
|
- `POST /api/auth/login` - User login
|
|
|
|
### Admin
|
|
- `GET /api/admin` - Admin panel data
|
|
|
|
### Health Check
|
|
- `GET /api/health` - Application health
|
|
|
|
## 🚀 Deployment
|
|
|
|
This app is configured for deployment on Vercel:
|
|
|
|
1. **Connect your repository** to Vercel
|
|
2. **Set environment variables** in Vercel dashboard
|
|
3. **Deploy automatically** on push to main branch
|
|
|
|
## 📁 Project Structure
|
|
|
|
```
|
|
tcg-vault/
|
|
├── pages/ # Next.js pages and API routes
|
|
│ ├── api/ # API endpoints
|
|
│ │ ├── auth/ # Authentication routes
|
|
│ │ └── admin/ # Admin routes
|
|
│ ├── _app.js # App wrapper
|
|
│ └── index.js # Home page
|
|
├── lib/ # Utility libraries
|
|
│ └── database.js # Database adapter
|
|
├── scripts/ # Database setup scripts
|
|
├── public/ # Static assets
|
|
└── .env.local # Environment variables
|
|
```
|
|
|
|
## 🔐 Default Admin Account
|
|
|
|
After running the database setup:
|
|
- **Email**: admin@tcgvault.com
|
|
- **Password**: admin123
|
|
|
|
## 🤝 Contributing
|
|
|
|
1. Fork the repository
|
|
2. Create a feature branch
|
|
3. Make your changes
|
|
4. Submit a pull request
|
|
|
|
## 📄 License
|
|
|
|
MIT License - see LICENSE file for details |