Each policy now has exactly one copy: docs/PRIVACY.md in the app's own repository. The pages keep their URLs and chrome and render that file through a content collection, so the published page and the app's own documentation cannot drift. scripts/sync-external.mjs shallow-clones both repos into external/ from prebuild and predev — not from CI: Coolify builds the site from the repo, so a checkout that only ran in a Gitea job would never reach the deploy. It falls back to the raw file if git is unavailable, and takes <APP>_REF or <APP>_LOCAL for work against a branch or an unpushed working copy. A missing, empty or malformed policy fails the build, verified against the real image: the deploy stops rather than publishing an empty privacy page.
12 lines
226 B
Plaintext
12 lines
226 B
Plaintext
node_modules
|
|
dist
|
|
.astro
|
|
.git
|
|
.env
|
|
.env.production
|
|
*.log
|
|
|
|
# Fetched during the build by scripts/sync-external.mjs; never copied in — a
|
|
# local checkout may be a symlink to a working copy on the developer's machine.
|
|
external
|