Repository-specific risks, ownership boundaries, and verification hints for deciding where a change belongs.
Read these before changing the paths they reference.
app/root.tsx serialises getEnv() into window.ENV on every page, so adding a secret there to reach it from a component publishes it to every visitor, and source maps make hard-coded secrets public too.
The LiteFS proxy forwards POST-style requests to the primary, but a GET loader that creates or updates rows — like the OAuth callback that links connections and creates sessions — would run on a read-only replica for users routed to another region, a failure that never appears locally.
litefs.yml applies `prisma migrate deploy` when the new primary boots and deploys are zero-downtime, so a migration that drops or renames a column breaks instances still running the old code until they are replaced.
app/entry.server.tsx sends the CSP with `reportOnly: true` (ADR 022), so the browser logs violations instead of blocking them; an adopter who assumes the nonce setup protects against injected scripts is running without an enforced policy.
Only non-GET paths containing an entry in `strongPaths` get the 10-per-minute limit. /forgot-password, which sends an email per valid request, and the /webauthn endpoints fall into the 100-per-minute tier, and limits use in-memory stores per instance.
`shouldRequestTwoFA` computes `const twoHours = 1000 * 60 * 2` under a comment saying two hours, so users with 2FA are asked for a fresh code on change-email and two-factor/disable far more often than the comment suggests.
server/index.ts registers its `/img` and `/favicons` 404 handler before `express.static`, although its comment assumes the opposite order, so the Android icons public/site.webmanifest references are never served.
Start at the primary boundary, then follow the related paths and checks.
Start here
The route manifest is generated from file and folder names, so a file's location is its URL; the route module owns its data and guards, and UI inherits the shell and user from root.tsx.
Verify before you finish
Start here
Prisma generates both the client and the migration from the schema, the seed and test factories construct rows directly, and production applies migrations at boot on the LiteFS primary.
Verify before you finish
Start here
Primitives are shadcn/ui sources owned by the repository and styled with semantic Tailwind tokens, so a new one arrives through the CLI into this folder and takes its colours from tailwind.css.
Verify before you finish
Start here
Offline development is a guiding principle: every outbound service has an MSW handler, a fake value in .env.example and, if required at boot, an entry in the env.server.ts schema.
Verify before you finish
Start here
The Vite spritesheet plugin compiles this folder into app/components/ui/icons/sprite.svg with generated types, so Icon only accepts names of files that exist here.
Verify before you finish
Start here
Server checks and client affordances use the same permission strings, and a new permission only exists in every environment if a migration inserts it and assigns it to roles.
Verify before you finish