1. Architecture in One Screen
The app is a React 19 + TypeScript single-page client (built with Vite) plus a small Express server (server.ts) that serves static/precompressed assets, handles GitHub OAuth, and provides the SSRF-hardened API proxy. A build step (prerender.js) pre-renders marketing/blog/docs pages for performance and SEO.
vite build → client bundle (code-split vendors)
tsx prerender.js → static HTML for /docs, /blog, tools…
esbuild server.ts → server.cjs (beside dist/)
precompress.js → .br / .gz siblings for assets
2. Deployment ownership and source permissions
The production workflow publishes the publisher's built static site to its configured host; optional API and OAuth endpoints run in the publisher's server environment. This page documents that architecture for transparency. Access to the hosted site or this reference does not grant permission to copy, locally execute, or redistribute the application source. See the Terms and LICENSE for current permissions.
3. Environment Variables
| Variable | Purpose |
|---|---|
| GITHUB_CLIENT_ID | OAuth App client id. A legacy in-repo id is used with a loud warning if unset; set it for rotation without redeploy. |
| GITHUB_CLIENT_SECRET | OAuth App secret. Required for the token exchange; never commit it. |
| APP_URL | Canonical https origin advertised to clients and used as the OAuth redirect target (resolves apex/www and proxy mismatches). |
| TRUST_PROXY | Set true behind a reverse proxy so req.protocol honours X-Forwarded-Proto (auto-on in Cloud Run via K_SERVICE). |
| OAUTH_ALLOWED_ORIGINS | Comma-separated extra origins (e.g. a static hosting mirror) allowed to participate in the OAuth relay. |
| FRAME_ANCESTORS | Comma-separated extra https origins allowed to embed the app in a frame; each is validated and malformed entries are dropped. |
| EXTRA_PROXY_DOMAINS | Comma-separated additional hostnames the API proxy may forward to (your own gateways). |
| NODE_ENV / DISABLE_HMR | production tightens CSP; DISABLE_HMR=true turns off Vite HMR. |
4. Server Endpoints (Overview)
POST /api/proxy — SSRF-allowlisted relay to AI/search providers (rate limited).
/api/gemini/* — Gemini generate/countTokens/image helpers.
/api/anthropic/* — Anthropic relay used when direct browser access is blocked.
/api/auth/github/* — OAuth config, session init/status/relay, callback, and token refresh (origin-checked).
/api/enhance-prompt & similar — server-side prompt utilities (rate limited, errors sanitized).
Static — precompressed brotli/gzip assets, prerendered pages, and an SPA fallback for app routes.
5. Publisher deployment safeguards
- Set
GITHUB_CLIENT_SECRETandAPP_URL; confirm the redirect URI matches in the GitHub App. - Enable
TRUST_PROXY=trueif behind a load balancer (or rely onK_SERVICEon Cloud Run). - Terminate TLS at the proxy; the server sends HSTS in production.
- Only add
FRAME_ANCESTORSorigins you actually want framing the app — a wildcard (especially for shared hosts) reopens clickjacking. - Keep the dependency tree patched;
npm auditshould show no high/critical issues in shipped packages. - Verify
npm testandnpm run buildpass after configuring.
6. Data and privacy boundaries
The application does not use a central account database to persist chat history. Server routes can relay provider requests and handle short-lived OAuth state; origin checks can also write warning logs that include request metadata. The hosting provider controls its own access-log retention. Avoid logging Authorization headers or request bodies, which may contain prompts or credentials.