docs+comment: pin account.json untrack-after-redeploy TODO

추적 해제는 코드 작업이 아니라 사용자의 1회 재배포에 게이트된 운영 절차이므로,
잊히지 않도록 명시적 TODO 를 코드(paths.ts) + 운영 문서(admin-site.md)에 고정.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
2026-07-11 13:31:50 +09:00
parent face70b3e9
commit 662c3c7b23
2 changed files with 17 additions and 0 deletions

View File

@@ -8,6 +8,13 @@ export const manifestDirPath = path.join(projectRoot, 'manifest')
export const manifestTermsDirPath = path.join(manifestDirPath, 'terms')
// 추적되는 account.json(과거 평문 노출)을 대체할, gitignore 된 운영 계정 파일.
// readAccounts 는 이 파일을 우선 사용하고, 없을 때만 account.json 을 시드로 읽는다.
//
// TODO(untrack-after-redeploy): account.json 은 아직 git 추적 상태다. 절대 지금
// 같은 커밋에서 `git rm --cached account.json` 하지 말 것 — 서버에 account.local.json
// 이 아직 없을 때 시드 소스가 사라져 로그인이 막힌다(chicken-and-egg).
// 안전한 순서: (1) 이 커밋 배포 → 서버가 account.local.json(0o600) 자동 생성 확인 →
// (2) 그 다음 후속 커밋에서 account.json 추적 해제.
// 주의: 추적 해제는 위생일 뿐, 히스토리의 평문 비밀번호는 지워지지 않는다 → 비밀번호 로테이션이 실질 조치.
export const accountFilePath = path.join(projectRoot, 'account.json')
export const accountLocalFilePath = path.join(projectRoot, 'account.local.json')
export const fileDirPath = path.join(projectRoot, 'file')