feat: add authenticated share publishing APIs

This commit is contained in:
2026-08-16 00:50:55 +07:00 Unverified
parent b8e6389ac3
commit 5bf5d2a2c0
8 changed files with 407 additions and 0 deletions
+3
View File
@@ -38,6 +38,7 @@ Create `.env.local` for local development. The application uses these groups of
- `NEXTAUTH_URL`, `NEXTAUTH_SECRET` — authentication configuration
- `DISCORD_CLIENT_ID`, `DISCORD_CLIENT_SECRET` — Discord OAuth
- `DISCORD_BOT_TOKEN`, `DISCORD_GUILD_ID` — Discord role and profile lookups
- `SHARE_BOT_SECRET` — bearer secret for private Discord bot share uploads
- `ADMIN_DISCORD_IDS` — comma-separated Discord IDs allowed into admin tools
- `BASE_URL` — canonical public URL used in links and OAuth callbacks
- platform credentials used by follower-count integrations
@@ -57,6 +58,8 @@ bun run secrets:scan
- `/leaderboard/vc` — voice activity leaderboard
- `/sse/[topic]` — authenticated realtime updates
- `/api/upload` — authenticated image uploads stored in PostgreSQL
- `/share` — Discord-authenticated text publishing with public share pages
- `/api/share` — private bearer-authenticated Discord bot publishing endpoint
- `/admin/upload` — admin video publishing workspace for YouTube and TikTok
Forms use server actions for authorization, persistence, validation, Discord webhooks, and cache invalidation. Public form drafts are stored locally in the browser.