FitnessApp/README.md

49 lines
3.9 KiB
Markdown

# Fitness App
A Next.js proof of concept for a multi-tenant fitness and yoga platform with live Jitsi classrooms.
## Current work
- Milestone 1: schema, migrations, dashboard probes, and basic tenant-scoped Prisma queries are implemented. PostgreSQL, Redis, and MinIO connections were confirmed on the Windows development PC.
- Milestone 2: class schedules, instructor scheduling, join APIs, and Jitsi classrooms are implemented. Instructor and student viewport sizing were confirmed in live sessions; simulated API/fallback layout checks passed at seven screen sizes.
- Milestone 3: video uploads, MinIO buckets/CORS, BullMQ processing, and playback UI remain to be built.
- Milestone 4: recurring scheduling, payments, waivers, authentication, and administration remain to be completed. Add a system-admin-only settings area for service endpoints, validated updates, health checks, and protected credentials.
## Local development
Keep the existing Windows project and its `.env`/`.env.local` files. This checkpoint does not include those files or change installed dependency versions.
For a fresh checkout:
1. Copy `.env.example` to `.env.local` and fill the blank connection strings and credentials locally. Jitsi's signing key must match the Jitsi server. Do not use a generated replacement key without configuring both sides.
2. Run `npm ci` and `npx prisma generate`.
3. For a new database, apply the included migrations with `npx prisma migrate deploy`.
4. Run `npm run dev` and open the local address printed in the terminal.
Environment files belong at the project root, not under `src`. The dashboard displays only endpoint hosts/ports, without URL usernames, passwords, or queries.
The current verified service addresses are PostgreSQL `192.168.16.90:5432`, Redis `192.168.16.3:6379`, and MinIO `192.168.16.6:9000`. These are configuration values, not fixed service-discovery guarantees.
## Project layout
`app/`, `components/`, and `lib/` are the active source roots because the TypeScript `@/*` alias points to the repository root. Existing duplicate classroom/Jitsi files under `src/` are retained and synchronized for compatibility. Do not create a second `src/app/` router alongside the root `app/` tree.
Prisma schema and migrations are under `prisma/`. Connection and Jitsi integration scripts are under `scripts/`.
## Validation
- `npm run build`: passes and includes TypeScript checking.
- `npm run lint`: existing lint issues remain; this checkpoint does not declare a clean lint result.
- `npm run test:connections`: requires your configured services and performs a temporary Redis key write/read/delete.
- `npm run test:jitsi`: requires configured services and creates test tenant/users/classes/bookings. Run against a development database; it is not a read-only health check.
Offline token, service-address, Redis socket/error, and responsive layout checks were run while preparing the checkpoint. Cloud checks do not replace real Windows camera/microphone and service tests.
## Known limitations
This is a development proof of concept, not a production-ready access-control system. Login/session enforcement is absent; request-supplied user IDs/roles and demo users are not trusted authentication. Instructor actions and demo data actions need permissions. The Clear Data action currently deletes all tenants' records. Booking capacity checks are not concurrency-safe, and joins can mark a waiver timestamp without a real waiver signature. Tenant extensions still require a broader isolation review, including related/nested writes.
Hardcoded Jitsi and Redis credential fallbacks have been removed. Real credentials stay outside Git; `.env.example` contains blank credential fields. Protect the local environment files and do not force-add them to Git.
The original Windows project can be reopened in Antigravity. Follow `AGENTS.md` and the installed Next.js guides before further changes. Generated `.next/`, `next-env.d.ts`, and dependency directories are excluded from Git.