FROM node:22-alpine

RUN apk add --no-cache curl

WORKDIR /app

# Copy package descriptors
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./

# Install pnpm and dependencies
RUN npm install -g pnpm && pnpm install --frozen-lockfile

# Copy application source
COPY . .

ARG VITE_SUPABASE_URL
ARG VITE_SUPABASE_ANON_KEY
ENV VITE_SUPABASE_URL=$VITE_SUPABASE_URL
ENV VITE_SUPABASE_ANON_KEY=$VITE_SUPABASE_ANON_KEY

# Fail the build if the Supabase keys did not arrive.
#
# Vite inlines import.meta.env at BUILD time, so an empty ARG bakes empty strings
# into the bundle. That does not crash anything: the app still builds, still
# returns 200, and still renders a normal-looking SPA shell -- it just silently
# shows zero products because every query has no destination. That happened in
# production on 2026-09-29 and was invisible from the outside. Refuse to ship it.
RUN test -n "$VITE_SUPABASE_URL" \
    && test -n "$VITE_SUPABASE_ANON_KEY" \
    || (echo "FATAL: VITE_SUPABASE_URL / VITE_SUPABASE_ANON_KEY are empty." \
        && echo "This build would ship a storefront with zero products." \
        && echo "Pass them as build args (Openship: envVars in the build trigger body)." \
        && exit 1)

# Build production Vite assets
RUN pnpm build

# Second gate, on the artifact itself: the keys must actually be present in the
# built bundle. Guards against the ARG being passed but dropped somewhere.
RUN grep -rqF "$VITE_SUPABASE_URL" dist/assets \
    || (echo "FATAL: supabase URL not found in dist/assets -- keys did not bake in." && exit 1)

EXPOSE 3000

ENV PORT=3000
ENV NODE_ENV=production

CMD ["node", "server.js"]
