The previous setup packaged the development `.env` into the installer
resources, mixing local server settings (PORT/HOST/SESSION_SECRET) with
the build-time site domain. Introduce a dedicated `.env.build`:
- electron-builder configs now copy `.env.build` (gitignored) into
`resources/`, no longer touching the dev `.env`.
- `loadEnv()` prefers `resources/.env.build` first, falling back to
`resources/.env` (for operators who hand-edit the packaged file),
then `<root>/.env.build`, then `<root>/.env`.
- `.env.build.example` documents the build-only keys (SITE_BASE_URL,
MANIFEST_URL, MUSIC_CONCURRENCY); server-side keys stay in `.env`.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>