feat(variants): wire energy.worldmonitor.app subdomain (gaps #9-11)#3394
Conversation
DNS (Cloudflare) and the Vercel domain are already provisioned by the operator; this lands the matching code-side wiring so the variant actually resolves and renders correctly. Changes: middleware.ts - Add `'energy.worldmonitor.app': 'energy'` to VARIANT_HOST_MAP. This also auto-includes the host in ALLOWED_HOSTS via the spread on line 87. - Add `energy` entry to VARIANT_OG with the Energy-Atlas-specific title + description from `src/config/variant-meta.ts:130-152`. OG image points at `https://energy.worldmonitor.app/favico/energy/og-image.png`, matching the per-variant convention used by tech / finance / commodity / happy. vercel.json - Add `https://energy.worldmonitor.app` to BOTH `frame-src` and `frame-ancestors` in the global Content-Security-Policy header. Without this, the variant subdomain would render but be blocked from being framed back into worldmonitor.app for any embedded flow (Slack/LinkedIn previews, future iframe widgets, etc.). This supersedes the CSP-only portion of PR #3359 (which mixed CSP with unrelated relay/military changes). convex/payments/checkout.ts:108-117 - Add `https://energy.worldmonitor.app` to the checkout returnUrl allowlist. Without this, a PRO upgrade flow initiated from the energy subdomain would fail with "Invalid returnUrl" on Convex. src-tauri/tauri.conf.json:32 - Add `https://energy.worldmonitor.app` to the Tauri desktop CSP frame-src so the desktop app can embed the variant the same way it embeds the other 4. public/favico/energy/* (NEW, 7 files) - Stub the per-variant favicon directory by copying the root-level WorldMonitor brand assets (android-chrome 192/512, apple-touch, favicon 16/32/ico, og-image). This keeps the launch unblocked on design assets — every referenced URL resolves with valid bytes from day one. Replace with energy-themed designs in a follow-up PR; the file paths are stable. Other variant subdomains already on main (tech / finance / commodity / happy) are unchanged. APP_HOSTS in src/services/runtime.ts already admits any `*.worldmonitor.app` via `host.endsWith('.worldmonitor.app')` on line 226, so no edit needed there. Closes gaps §L #9, #10, #11 in docs/internal/energy-atlas-registry-expansion.md.
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
Greptile SummaryThis PR wires Confidence Score: 4/5Safe to merge; the only finding is a minor documentation gap in AGENTS.md. All code changes follow the established variant-wiring pattern exactly, with no logic changes. The single P2 finding (AGENTS.md missing the energy variant) doesn't affect runtime behaviour. P2-only → 4/5. AGENTS.md — Variant System list should include Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Request to energy.worldmonitor.app] --> B{middleware.ts\nVARIANT_HOST_MAP}
B -- energy variant --> C{Social bot UA?}
C -- yes --> D[Return OG HTML\nfrom VARIANT_OG]
C -- no --> E{/api/* or /favico/*?}
E -- no --> F[Pass through\nto Next.js / Vercel]
E -- yes --> G{Bot UA check}
G -- blocked --> H[403 Forbidden]
G -- allowed --> F
F --> I[energy.worldmonitor.app\nUI Rendered]
I --> J{PRO upgrade flow}
J --> K[convex/payments/checkout.ts\nallowedOrigins includes energy]
K --> L[Dodo Payments checkout\nreturn_url validated]
|
Summary
DNS (Cloudflare) and Vercel domain are already provisioned by the operator. This lands the matching code-side wiring so `energy.worldmonitor.app` actually resolves and renders the Energy Atlas variant correctly.
Changes
What's NOT touched
Closes
Gaps §L #9, #10, #11 from `docs/internal/energy-atlas-registry-expansion.md`.
Test plan