docs: CL-6 - the license signing key is permanent (back up, never rotate casually)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 22:17:29 +03:00
co-authored by Claude Opus 5.5
parent 96a014ecbe
commit 048b46af41
+3
View File
@@ -50,6 +50,9 @@ If the cloud is down, restaurants must keep taking orders (global Rule 8). Don't
**CL-4. Public endpoints are hostile territory.** **CL-4. Public endpoints are hostile territory.**
`menu-app` endpoints are reachable by anyone on the internet. Validate everything, rate-limit where it makes sense, and never return data from another site. Site secrets (`SITE_KEY`) are shown **once**, at registration. `menu-app` endpoints are reachable by anyone on the internet. Validate everything, rate-limit where it makes sense, and never return data from another site. Site secrets (`SITE_KEY`) are shown **once**, at registration.
**CL-6. The license signing key is permanent.**
`LICENSE_SIGNING_KEY` (cloud `.env`) signs every site's license. Its public half is built into the site code. Never regenerate or lose it: a new key means every site needs a new image. Keep the backup at `%USERPROFILE%\.xenia\license_signing_key.txt` safe. Never add fields to the token payload that old sites would misread; bump `v` for incompatible changes.
**CL-5. Frontend URLs are baked in at build time.** **CL-5. Frontend URLs are baked in at build time.**
`VITE_CLOUD_URL` is a build arg, so changing it means rebuilding the image, not restarting it. `VITE_CLOUD_URL` is a build arg, so changing it means rebuilding the image, not restarting it.