- Auth: middleware.ts guards /protected via better-auth session cookie; protected page reads session server-side (auth.api.getSession) - Demo wiring (app/demo + components/demo): react-markdown + remark-gfm + shiki CodeBlock, RHF+zod form with react-query mutation + sonner toast, react-table items list (legacy API, table v9), /api/items GET+POST (zod v4 coercion, schema in lib/items.ts shared with unit tests) - Error UX: app/error.tsx (retry + digest), not-found.tsx (404), loading.tsx - Env: lib/env.ts zod-validated (no import-time throw), .env.example sync (NEXT_PUBLIC_BETTER_AUTH_URL), auth-client uses env - Tooling: @vitest/coverage-v8 (test:coverage works), tsconfig cleanup (drop .next/dev/dev/types artifact), README rewrite, demo e2e specs
- CI: GitHub Actions (bun 1.3.14, lint/typecheck/test/build/format gates) - Docker: multi-stage standalone build + .dockerignore (next.config output=standalone) - Auth: better-auth server (memory adapter, drizzle-swap-ready) + react client + /api/auth/[...all] route handler - API: /api/health + /api/openapi routes, openapi-typescript codegen to types/api.ts, typed openapi-fetch client (lib/api, lib/http) - Shiki: server-side CodeBlock component (escaped HTML) - E2E: playwright home + health specs on dedicated :3100 (chromium 1243 installed from GCS after CDN timeout) - Dev: allow 127.0.0.1/localhost dev origins (HMR for local tooling)