From 048b46af410e64b45b9d7cdf037d9cfefe8ddefe Mon Sep 17 00:00:00 2001 From: bonamin Date: Mon, 28 Sep 2026 22:17:29 +0300 Subject: [PATCH] docs: CL-6 - the license signing key is permanent (back up, never rotate casually) Co-Authored-By: Claude Opus 5.5 --- docs/README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/README.md b/docs/README.md index 6176cd6..78d2e8d 100644 --- a/docs/README.md +++ b/docs/README.md @@ -50,6 +50,9 @@ If the cloud is down, restaurants must keep taking orders (global Rule 8). Don't **CL-4. Public endpoints are hostile territory.** `menu-app` endpoints are reachable by anyone on the internet. Validate everything, rate-limit where it makes sense, and never return data from another site. Site secrets (`SITE_KEY`) are shown **once**, at registration. +**CL-6. The license signing key is permanent.** +`LICENSE_SIGNING_KEY` (cloud `.env`) signs every site's license. Its public half is built into the site code. Never regenerate or lose it: a new key means every site needs a new image. Keep the backup at `%USERPROFILE%\.xenia\license_signing_key.txt` safe. Never add fields to the token payload that old sites would misread; bump `v` for incompatible changes. + **CL-5. Frontend URLs are baked in at build time.** `VITE_CLOUD_URL` is a build arg, so changing it means rebuilding the image, not restarting it.