JP 0ead1385f7 Add the owner admin area: invites, people, reset links
Creating an invite previously meant writing SQL by hand, which made the
whole feature unusable in practice. The owner can now create invites
with a use count and expiry, copy the link, show a QR code, and revoke.

QR codes are generated locally by node-qrcode as inline SVG. The CSP
forbids loading from any other origin, so an external generator was not
an option, and img-src 'self' already covers a same-origin SVG.

People lists everyone with what they have added and what their AI use
has cost over 30 days, with suspend, reactivate, per-user AI toggle and
delete. Deleting collects image keys and the minted gateway key id
before the cascade removes the rows, then cleans both up best-effort -
storage or the gateway being unavailable must not leave an account
half-deleted. Guards refuse to suspend or delete yourself or the last
owner.

Password reset links close the gap that came with keeping email and
password sign-in: with no email infrastructure, a member who forgets
their password had no way back in and the owner had no way to help. The
owner generates a single-use 24 hour link and delivers it the same way
as an invite. Issuing one invalidates any earlier unused reset, and the
reset endpoint answers identically for unknown, used and expired tokens
so it cannot be used to probe which exist.

The admin area 404s for members rather than 403ing, so its existence is
not advertised, and every /api/admin handler independently requires the
owner role.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-08 21:26:33 +00:00
2026-08-08 20:42:40 +00:00
2026-08-08 20:42:40 +00:00

This is a Next.js project bootstrapped with create-next-app.

Getting Started

First, run the development server:

npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev

Open http://localhost:3000 with your browser to see the result.

You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.

This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.

AI Gateway (Switchboard)

All AI features — menu scanning, label identification, drink search, the bartender and the recommendation engine — go through Switchboard, an OpenAI-compatible gateway that routes each request to the best available model. The app never pins a model id; it always sends switchboard/auto and lets the gateway choose, then logs which model answered and what it cost.

Setup:

  1. Set SWITCHBOARD_BASE_URL in your env file (defaults to http://192.168.2.11:8787/v1).
  2. Mint an API key in the Switchboard UI under Settings → API keys.
  3. Add that key in the app under Settings → AI Gateway.

Per-feature routing (cost/quality levers, token budgets, timeouts) lives in src/lib/ai/routing.ts. Note that a Switchboard key carries its own routing defaults, so the app sets category and prefer_free explicitly on every request rather than inheriting whatever the key was minted for.

Migrating from the old Claude/OpenAI integration

Earlier versions stored a per-user Anthropic or OpenAI key. Those rows are ignored at runtime and the Settings page offers to remove them, so no migration is required. To clear them in bulk instead:

DELETE FROM "UserApiKey"  WHERE provider IN ('claude','openai');
DELETE FROM "SearchCache" WHERE provider IN ('claude','openai');
UPDATE "UserPreference" SET "defaultProvider" = NULL;

Learn More

To learn more about Next.js, take a look at the following resources:

You can check out the Next.js GitHub repository - your feedback and contributions are welcome!

Deploy on Vercel

The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.

Check out our Next.js deployment documentation for more details.

Description
No description provided
Readme 1.1 MiB
Languages
TypeScript 96.5%
Shell 2.9%
JavaScript 0.3%
CSS 0.2%
Dockerfile 0.1%