Strip out the web UI (login + subscription filter management) #1
Loading…
Reference in a new issue
No description provided.
Delete branch "mailship-d5i-strip-out-the-web-ui-login-subscription--1d8"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
mailship-d5i
Fully remove the browser admin SPA under
web/that let users log in via a Nostr signer and manage subscription filters, keeping the server as a headless API only. Also includes improvements to the email templates, database layer, and notification flow that were developed alongside the removal.Changes:
Web UI removed — Deleted the entire
web/directory (SPA built with Vite + Mithril + Tailwind). Removedexpress.static('web/dist')middleware and the fallback HTML render onGET /. The root endpoint now always returns a JSON server description. Removedbuild:webfrompackage.json, Dockerfile web build steps, andbuild-in-production.shreferences. Cleaned up the orphanedweb/dist/entry in.dockerignore.Subscription API upgraded — Changed
POST /subscription/emailtoPUTfor idempotent upserts. AddedGET /subscription/email?pubkey=...so clients can check existing subscriptions before re-registering. Added CORSPUTto the allowed methods.Event verification added — The
/notify/:idendpoint now accepts an optionaleventbody field (include_event). When provided, the event is signature-verified withnostr-tools/purebefore storing, defending against relay tampering. Falls back to relay fetch when omitted.Email branding + templates — Confirmation and digest emails now render with configurable brand name, accent color, and logo (from
BRAND_NAME,BRAND_ACCENT,BRAND_LOGOenv vars). Confirmation and error pages (undersrc/pages/) redesigned with branded layout and settings links. Digest template updated with modern MJML styling. Confirmation email sends via a styled HTML table with branded button.SMTP reliability — Auto-detects port 465 for SSL vs STARTTLS (
secure+requireTLS). Added error logging with SMTP host/port on send failures.Database layer — Refactored subscription write paths to deduplicate and serialize writes. Added
insertSubscription(upsert),confirmSubscription,getSubscriptionByPubkeyhelpers. Events are now stored withid, sub_id, event JSON, relay, created_atand periodically purged (7-day retention).Lint fixes — Removed 20 pre-existing
no-unused-varsviolations acrosssrc/actions.ts,src/alert.ts,src/digest.ts,src/env.ts,src/worker/email.tssoscript/checks(tsc + eslint) passes clean.How to test:
script/checks— tsc --noEmit, eslint, and full build all pass.node test/web-ui.test.js— 3/3 test confirming the guardednormalizeRelayUrlpattern.BRAND_NAME,BRAND_ACCENT,BRAND_LOGOenv vars and verify confirmation/digest emails render with branding.pnpm run preview:digestrendersdigest-preview.htmlfor template iteration.Remove the browser admin SPA under web/ that let users log in via a Nostr signer and manage subscription filters. The server is now a headless API only. Changes: - Delete web/ directory entirely (SPA source, config, deps) - Remove express.static('web/dist') serving from server.ts - Simplify GET / handler to always return JSON (no fallback) - Remove build:web from package.json build pipeline - Remove web build steps from Dockerfile - Remove web references from build-in-production.sh Kept: core subscription/unsubscribe/confirm/notify backend and transactional src/pages/*.html (part of email flow, not the UI).