Repository navigation
votes-api: minimal Vercel entry (hono/vercel) + vercel.json - #1
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Already merged (b8a07ed) before this review. The three new files are a faithful Hono→Vercel adapter of src/index.ts (same createApp wiring, pool max=1, PM2 path untouched, no secrets in git). That is not enough to treat the Vercel host as a working votes API.
What I ran
npm ciinservices/votes-api;npx tsc --noEmit -p tsconfig.jsongreen. Same check withapi/**/*.tsadded toincludeis also green — the committedtsconfig.jsondoes not includeapi/, so the PR claim thattsc --noEmitcovers this entry is vacuously true.npm test: 14 unit tests passed. Both integration files failed at migrate withECONNREFUSED 127.0.0.1:54390(no Postgres in this environment; not introduced here).- Invoked the new
GET/POST/OPTIONShandlers locally viahono/vercelhandle():GET /api/v1/health→ 503{"ok":false,"service":"grokbot-votes-api","db":"down"}(matches the PR write-up; import does not crash).GET /apiandGET /v1/health→ 404not_found. If Vercel applies the rewrite by handing the function the destination URL (/api) instead of the original path, every real route 404s.GET /api/v1/votes/counts?slugs=account-expertandPOST /api/v1/identity→ 500text/plain Internal Server Error(uncaughtpostgresECONNREFUSED), not the health-style JSON. Other DB routes do not fail closed the way health does.OPTIONS /api/v1/health→ 404; noAccess-Control-Allow-Originon a request withOrigin: https://grokbot.dev. The site clients (src/scripts/upvote-button.ts,vote-counts.ts,submit-form.ts) call same-origin/api/v1/*. This host is not a drop-in replacement without a grokbot.dev proxy or CORS + cookie-domain work.
- Live preview
https://votes-api-git-fix-votes-api-vercel-entry-xbookings.vercel.app/api/v1/healthis Vercel Authentication (GET 302 / POST 401). Could not smoke the Ready deploy. - Checks on this SHA: Vercel – votes-api success; Vercel – weeklyplate + Vercel Deployments – xbookings failed (could not read the weeklyplate inspect log).
ci/validate,merge-gate, andDeno/testare red on this SHA and were already red onmain(Create deno.yml) for pre-existing color-literal / community-label / deno-lint reasons — not caused by these three files.
Blocking
vercel.jsonrewrite destination is/apiwith no path capture, and there is noincludeFiles/SLUGS_URL. Locally a request whose URL is/api404s. Slug load defaults to../../content/use-casesthen../../dist/api-meta/use-case-slugs.jsonwith noslugsUrlfallback (submissionsManifestUrlhas a URL; the slug registry does not). File tracing will not pack those trees unless they are imported. Votes/counts will 500 on Vercel even afterDATABASE_URLis set, unless a dashboard toggle actually bundles them — that toggle is not in the repo.- Module-scope
loadConfig()keeps the local-dev fail-opens. UnsetVOTES_HMAC_PEPPER→local-dev-only-replace-me. UnsetTURNSTILE_SECRET_KEY→ Cloudflare always-pass test secret (identity POST with tokenxreached the DB insert locally). Preview is SSO-gated today; a production/public deploy without those env vars is an open signer + open Turnstile. Also missing the Hono-documentedexport const config = { runtime: 'nodejs' }next to the Nodefs/net/cryptoimports.
Residual
- In-memory
MemoryRateLimiter(3 identities / IP / 24h, etc.) is per isolate on serverless; nginxlimit_reqis not in front of this host. installCommand: "npm install"ignores the lockfile (npm ci).- Sibling weeklyplate deploy on this repo connection failed; status context is red even though votes-api is Ready.
- No CORS / cookie
Domainwork, so this cannot servegrokbot.devas a different origin. - Integration tests were not re-run against a real DB here.
Sent by Cursor Automation: Mark’s Automation
| "installCommand": "npm install", | ||
| "buildCommand": "", | ||
| "outputDirectory": "public", | ||
| "rewrites": [{ "source": "/(.*)", "destination": "/api" }] |
There was a problem hiding this comment.
Locally, handle(app) 404s when the request URL is /api or /v1/health and only matches the real routes when the URL is still /api/v1/…. This rewrite sends every path to /api with no $1 capture. If Vercel gives the function the destination URL (not the original path), the Ready deploy is a 404 farm.
This file also never packs the slug sources the registry actually reads. Defaults are ../../content/use-cases and ../../dist/api-meta/use-case-slugs.json; slugsUrl is unset unless SLUGS_URL is in the Vercel project. NFT will not include those trees (they are readdir'd, not imported). The dashboard “include source files outside root” note is not reproducible from git. Add functions["api/index.ts"].includeFiles (or set SLUGS_URL / SLUGS_FILE in committed docs + project env) and use a rewrite that preserves the path, e.g. destination: "/api/$1" or keep this rewrite and prove with an unauthenticated GET /api/v1/health that the function still sees /api/v1/health.
| const cfg = loadConfig(); | ||
| const logger = createLogger(cfg.logLevel); | ||
| // Serverless: keep the pool tiny; each instance handles few concurrent requests. | ||
| const db = connect(cfg.databaseUrl, 1); |
There was a problem hiding this comment.
This is the right factory, and GET /api/v1/health does return 503 db: down without crashing import. Two holes vs src/index.ts + vs a public Vercel host:
loadConfig()still fail-opens toVOTES_HMAC_PEPPER=local-dev-only-replace-meandTURNSTILE_SECRET_KEY=1x0000000000000000000000000000000AA. I posted{"turnstileToken":"x"}to this handler; Turnstile did not 403 (test secret + Cloudflare always-pass) and the handler proceeded toinsert into identities(then 500 onECONNREFUSED). If Vercel Auth is off and those env vars are missing, this is a public signer.- No
export const config = { runtime: 'nodejs' }. This graph usesnode:fs,postgresTCP, andnode:crypto. Hono's Vercel guide sets Node explicitly so the function cannot land on Edge.
src/index.ts also await slugRegistry.load(true) before serve. Lazy has() is fine on serverless, but the first vote/counts call will throw no use-case slugs loaded unless content/dist or SLUGS_URL is actually in the bundle (see vercel.json).


Adds services/votes-api/api/index.ts (exports hono/vercel handle of the existing createApp) and services/votes-api/vercel.json (rewrite all -> /api). src/index.ts / PM2 / nginx self-hosted path untouched. No creds or env values included. Vercel project votes-api (team xbookings) now has rootDirectory=services/votes-api + include source files outside root (needs ../../content, ../../dist). Without DATABASE_URL etc. the function loads but DB routes return errors (health -> db:down); env must be set in Vercel by Mark. tsc --noEmit passes locally.