Files
roast_command_center/AGENTS.md
T

848 B

Development and tests

Run npm test before every commit and whenever changing authentication, API authorization, service-worker behavior, or persistence. Add a regression test under test/ for every new route and for every security/ownership bug. Tests use an in-memory PostgreSQL-compatible database; production migration is run automatically at startup against DATABASE_URL.

For local development, copy .env.example, start docker compose up --build, then visit http://localhost:8090. Production must set APP_ORIGIN=https://roast.srmr.xyz, COOKIE_SECURE=true, a strong POSTGRES_PASSWORD, and a random BOOTSTRAP_SETUP_TOKEN. Bootstrap [email protected] exactly once at POST /api/auth/bootstrap, then remove BOOTSTRAP_SETUP_TOKEN from deployment configuration. Never commit credentials or a bootstrap password/token.