Skip to content

About

Official website of Atomic Notes, the local-first Android notes app that syncs to your own Google Drive. Features, FAQ, live updates and blog. Source-available.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Atomic Community Base

The public website for Atomic Notes — features, FAQ, live updates, the blog, and app downloads — plus the secret Atomic-Controller admin panel for managing notifications and user Energy/Coins.

Live site: atomic-notes.devbehindyou.com

Built with Next.js 15 (App Router), React 19, TypeScript, Tailwind CSS, and the Atomic Notes Server (Node.js/MongoDB) as its backend, deployed on Vercel. Brand-matched to the app's Technical Editorial system (ink #15171B, paper #F4F5F1, signal #3A2FF0).

Structure

  • / — public home: hero, features, how sync works, Atomic Energy, roadmap, FAQ, download.
  • /updates — public Notification Center feed (active announcements).
  • /blog, /blog/[slug] — blog index and articles, built from content/blog/*.md.
  • /support-atomic-notes — Patreon / Ko-fi support and early Atomic Coins.
  • /privacy, /terms — legal pages.
  • /controller — secret admin panel (password-gated). CRUD notifications and adjust a user's Atomic Coins / Energy.
  • /api/controller/* — server route handlers. All admin routes check an HMAC-signed httpOnly session cookie, then call the Atomic Notes Server's /api/admin/* endpoints (server-only) to read or write.

Domain, SEO, and AI discovery

The canonical address is https://atomic-notes.devbehindyou.com. It is set once, in SITE_URL (src/lib/site.ts), from NEXT_PUBLIC_SITE_URL with that domain as the default. Every canonical tag, Open Graph URL, JSON-LD @id, the sitemap, robots.txt and the RSS feed derive from it. A configured value on the retired atomic-notes-community.vercel.app host or any *.vercel.app deployment URL is ignored, so a stale environment variable can never leak a preview address into canonical links.

NEXT_PUBLIC_* values are baked in at build time: after changing one in Vercel, redeploy for it to take effect.

Endpoint Source
/sitemap.xml src/app/sitemap.ts (pages + published blog posts, real lastmod dates)
/robots.txt src/app/robots.ts (blocks /api/, points at the sitemap)
/feed.xml src/app/feed.xml/route.ts (RSS 2.0)
/llms.txt public/llms.txt (summary for AI assistants; update with each release)
Page metadata src/lib/seo.ts (pageMetadata: canonical, Open Graph, and X cards per page)

Requests to the old atomic-notes-community.vercel.app host get a permanent redirect to the same path on the new domain (next.config.mjs).

Security model

  • Community holds no database credentials at all — it calls the Atomic Notes Server's admin API instead, authenticated with a static ADMIN_API_KEY shared between the two projects (src/lib/atomicServer.ts, route handlers only). Never NEXT_PUBLIC_, never sent to the browser.
  • The public site reads notifications server-side (server components), via the Server's separate, unauthenticated /api/public/notifications/active endpoint — so no privileged key reaches the client, and the public read path is a different, lower-trust endpoint from the admin one.
  • The Controller is gated by ADMIN_PASSWORD; a successful login sets a time-limited, HMAC-signed httpOnly cookie (SESSION_SECRET). Every admin API re-checks it, then relies on ADMIN_API_KEY to authorize the call to the Server — two separate, deliberately unrelated trust boundaries (see the Server's src/middleware/adminAuth.ts).
  • Notification writes and Energy/Coin adjustments are logged to energy_ledger (adjustments) on the Server, and are only reachable via the admin API — the app itself has no path to them with a user session.

Local development

Use Node.js 22. GitHub Actions runs npm ci, npm audit --audit-level=high, npx tsc --noEmit, npm run build, and npm run test:smoke. The smoke test starts its own localhost production server with test credentials and no backend connection; it checks admin authentication, blog pages, and RSS. Run it after building. Real Server/MongoDB/Google integration needs separate checks.

The security update uses Next.js 15.5.24 and React 19. Next's nested PostCSS is overridden to the patched root PostCSS version because Next still pins an affected version. Keep the override until the upstream dependency is patched.

npm install
cp .env.example .env.local   # fill in real values (never commit .env.local)
npm run dev                  # http://localhost:3000

Environment variables (see .env.example):

Var Where Purpose
ATOMIC_SERVER_URL server base URL of the Atomic Notes Server
ADMIN_API_KEY server must match the Server's own ADMIN_API_KEY
ADMIN_PASSWORD, ADMIN_PASSWORD_2 server the two Controller login keys
SESSION_SECRET server signs the admin session cookie
NEXT_PUBLIC_APK_URL public download link on the home page
NEXT_PUBLIC_SITE_URL public canonical origin, https://atomic-notes.devbehindyou.com

Deploy on Vercel

  1. Import this repo in Vercel (framework auto-detected as Next.js).
  2. Add the environment variables above in Project Settings → Environment Variables (mark the admin key + admin secrets for Production/Preview only).
  3. Under Settings → Domains, add atomic-notes.devbehindyou.com as the production domain.
  4. Deploy. The public site is static/dynamic as needed; the Controller and its APIs run as serverless functions.

Prerequisite

The Atomic Notes Server must be deployed and reachable at ATOMIC_SERVER_URL, with a matching ADMIN_API_KEY on both projects — that server owns the notifications, atomic_users, and energy_ledger MongoDB collections this panel reads and writes.

License

Proprietary and source-available. The code is public to read and verify under the Atomic Notes Source-Available License. All rights reserved. You may not copy, modify, redistribute, host, or reuse it. Versions published before September 28, 2026 were released under the MIT License.

About

Official website of Atomic Notes, the local-first Android notes app that syncs to your own Google Drive. Features, FAQ, live updates and blog. Source-available.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages