diff --git a/.gitignore b/.gitignore index 3ce9c40..a78c22c 100644 --- a/.gitignore +++ b/.gitignore @@ -3,4 +3,5 @@ node_modules/ .env .env.local .env.*.local +CLAUDE.local.md .DS_Store diff --git a/AGENTS.md b/AGENTS.md index 2f77d0c..82efce5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -41,7 +41,7 @@ Apps go in `apps/`, shared code in `packages/` — extract a package only when t - Add or update tests for important behavior. - Never weaken tenant isolation, authorization, auditability, or data integrity for convenience. - Never modify an existing applied database migration; add a new one. -- Sign off commits with `git commit -s` (Developer Certificate of Origin); pull requests opened by `quality-runtime[bot]` are exempt. +- Sign off commits with `git commit -s` (Developer Certificate of Origin). Commits authored as `quality-runtime[bot]` are not signed off — a bot cannot make the certification — and pull requests it opens are exempt from the check. ## Licensing diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index 7d5a88b..d24a362 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -198,6 +198,12 @@ Additional services must not become mandatory without strong operational justifi Cloud-provider-specific implementations live in deployment adapters, and the application must remain portable to other environments. +Hostnames are configuration. The runtime assumes no hosted service's domains; custom domains and their certificates belong to the deployment in front of it. + +Public pages, when they exist, are server-rendered routes in `apps/server` answered only on a separate public origin the deployment configures, so nothing served there can use a session: they need no sign-in, set no session cookies, and render structured records, never tenant-supplied HTML or scripts. Printed addresses use immutable identifiers, so they survive a record's rename. + +Anything that needs a sign-in, including an outside reviewer's read access, stays on the application's origin; a public page may link to it. + ## Hosted product boundary The public runtime contains functionality generally useful to anyone operating Quality Runtime themselves. Hosted-service concerns (billing, subscriptions, provisioning, usage metering, entitlements, internal cloud operations) stay outside it. diff --git a/CLAUDE.md b/CLAUDE.md index 43c994c..c8c3431 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -1 +1,2 @@ @AGENTS.md +@CLAUDE.local.md