diff --git a/apps/api/src/index.ts b/apps/api/src/index.ts index 1715708..0423f0b 100644 --- a/apps/api/src/index.ts +++ b/apps/api/src/index.ts @@ -12,7 +12,9 @@ import { qrRoutes } from "./routes/qr.js"; import { restaurantsRoutes } from "./routes/restaurants.js"; import { subscriptionRoutes } from "./routes/subscription.js"; -const app = Fastify({ logger: true }); +// Default Fastify bodyLimit is 1 MiB — a base64-encoded menu photo from a +// phone camera routinely exceeds that, so AI import uploads need real headroom. +const app = Fastify({ logger: true, bodyLimit: 20 * 1024 * 1024 }); await app.register(cors); diff --git a/supabase/migrations/20260820000000_public_domain_resolution.sql b/supabase/migrations/20260820000000_public_domain_resolution.sql new file mode 100644 index 0000000..75357bd --- /dev/null +++ b/supabase/migrations/20260820000000_public_domain_resolution.sql @@ -0,0 +1,16 @@ +-- Custom domain resolution needs to be readable by anon so the public web +-- app (apps/web/src/app/menu/[slug]/page.tsx) can map an arbitrary incoming +-- hostname -> restaurant without going through the API. Scoped to verified +-- domains on restaurants that actually have a published menu, matching the +-- same pattern as the restaurants/locations public policies. + +create policy "anyone can resolve verified custom domains" on domains + for select using ( + status = 'verified' + and exists ( + select 1 + from locations l + join menus m on m.location_id = l.id + where l.restaurant_id = domains.restaurant_id and m.is_published = true + ) + );