add photos, an immich-backed library behind its own sidecar
officer-photos owns the whole Immich contract: the instance URL and the API key live there and nowhere else, and the platform side is an auth-gated forwarder holding no credentials. The route surface is an allow-list keyed on the first path segment, so admin, auth, api-keys, sessions, jobs, system-config and libraries are unreachable by construction rather than by enumeration. The UI mirrors Immich's own sidebar — timeline, explore, map, search, albums, people, favorites, sharing, archive, trash — because the point of a sidecar screen is to reproduce what the upstream already ships, then extend it. The timeline reads Immich's columnar time-bucket format directly; selection lives in the URL per docs/navigation-audit.md. Two things worth knowing for anyone touching this later: - `duration` is an integer count of milliseconds in Immich 3.0. It was an HH:MM:SS.mmm string before, and every stale example still shows that form. - the map container is sized with h-full/w-full, never `absolute inset-0`. maplibre's stylesheet sets `position: relative; overflow: hidden` on the element it is given, and an unlayered vendor rule beats Tailwind 4's layered `.absolute` regardless of source order — so the div collapses to height 0 and clips its own canvas away. Nothing errors: the GL context is healthy, tiles download and pixels are drawn into a buffer nobody ever composites. maplibre-gl is pinned to 5.x deliberately; 6.0 resolves a separate worker file from import.meta.url, which Officer's index.html fallback answers with HTML. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -77,3 +77,10 @@ VAULT_STORE_KEY="<generate with: openssl rand -base64 32>"
|
||||
# NOTE: seed material is encrypted with VAULT_STORE_KEY (above) on top of the owner passphrase that
|
||||
# seals it. Both are required to spend. If you lose VAULT_STORE_KEY, every stored seed is
|
||||
# unrecoverable — back up the mnemonics separately, offline.
|
||||
|
||||
# Immich (officer-photos). The key is injected as x-api-key on every forwarded request; the platform never
|
||||
# sees it. Create it in Immich: Account Settings → API Keys → New API Key. Immich keys are SCOPED — grant
|
||||
# all permissions unless you want a read-only library, because a missing permission answers 403 on that one
|
||||
# route and looks like a broken feature rather than a bad credential.
|
||||
IMMICH_URL=http://127.0.0.1:2283
|
||||
IMMICH_API_KEY="<immich api key>"
|
||||
|
||||
Reference in New Issue
Block a user