The public website for Atomic Notes — features, FAQ, live updates, the blog, and app downloads — plus the secret Atomic-Controller admin panel for managing notifications and user Energy/Coins.
Live site: atomic-notes.devbehindyou.com
Built with Next.js 15 (App Router), React 19, TypeScript, Tailwind CSS, and
the Atomic Notes Server (Node.js/MongoDB) as its backend, deployed on
Vercel. Brand-matched to the app's Technical Editorial system (ink
#15171B, paper #F4F5F1, signal #3A2FF0).
/— public home: hero, features, how sync works, Atomic Energy, roadmap, FAQ, download./updates— public Notification Center feed (active announcements)./blog,/blog/[slug]— blog index and articles, built fromcontent/blog/*.md./support-atomic-notes— Patreon / Ko-fi support and early Atomic Coins./privacy,/terms— legal pages./controller— secret admin panel (password-gated). CRUD notifications and adjust a user's Atomic Coins / Energy./api/controller/*— server route handlers. All admin routes check an HMAC-signed httpOnly session cookie, then call the Atomic Notes Server's/api/admin/*endpoints (server-only) to read or write.
The canonical address is https://atomic-notes.devbehindyou.com. It is set once, in
SITE_URL (src/lib/site.ts), from NEXT_PUBLIC_SITE_URL with that domain as the
default. Every canonical tag, Open Graph URL, JSON-LD @id, the sitemap, robots.txt
and the RSS feed derive from it. A configured value on the retired
atomic-notes-community.vercel.app host or any *.vercel.app deployment URL is
ignored, so a stale environment variable can never leak a preview address into
canonical links.
NEXT_PUBLIC_* values are baked in at build time: after changing one in Vercel,
redeploy for it to take effect.
| Endpoint | Source |
|---|---|
/sitemap.xml |
src/app/sitemap.ts (pages + published blog posts, real lastmod dates) |
/robots.txt |
src/app/robots.ts (blocks /api/, points at the sitemap) |
/feed.xml |
src/app/feed.xml/route.ts (RSS 2.0) |
/llms.txt |
public/llms.txt (summary for AI assistants; update with each release) |
| Page metadata | src/lib/seo.ts (pageMetadata: canonical, Open Graph, and X cards per page) |
Requests to the old atomic-notes-community.vercel.app host get a permanent redirect
to the same path on the new domain (next.config.mjs).
- Community holds no database credentials at all — it calls the Atomic
Notes Server's admin API instead, authenticated with a static
ADMIN_API_KEYshared between the two projects (src/lib/atomicServer.ts, route handlers only). NeverNEXT_PUBLIC_, never sent to the browser. - The public site reads notifications server-side (server components),
via the Server's separate, unauthenticated
/api/public/notifications/activeendpoint — so no privileged key reaches the client, and the public read path is a different, lower-trust endpoint from the admin one. - The Controller is gated by
ADMIN_PASSWORD; a successful login sets a time-limited, HMAC-signed httpOnly cookie (SESSION_SECRET). Every admin API re-checks it, then relies onADMIN_API_KEYto authorize the call to the Server — two separate, deliberately unrelated trust boundaries (see the Server'ssrc/middleware/adminAuth.ts). - Notification writes and Energy/Coin adjustments are logged to
energy_ledger(adjustments) on the Server, and are only reachable via the admin API — the app itself has no path to them with a user session.
Use Node.js 22. GitHub Actions runs npm ci, npm audit --audit-level=high,
npx tsc --noEmit, npm run build, and npm run test:smoke.
The smoke test starts its own localhost production server with test credentials
and no backend connection; it checks admin authentication, blog pages, and RSS.
Run it after building. Real Server/MongoDB/Google integration needs separate checks.
The security update uses Next.js 15.5.24 and React 19. Next's nested PostCSS is overridden to the patched root PostCSS version because Next still pins an affected version. Keep the override until the upstream dependency is patched.
npm install
cp .env.example .env.local # fill in real values (never commit .env.local)
npm run dev # http://localhost:3000Environment variables (see .env.example):
| Var | Where | Purpose |
|---|---|---|
ATOMIC_SERVER_URL |
server | base URL of the Atomic Notes Server |
ADMIN_API_KEY |
server | must match the Server's own ADMIN_API_KEY |
ADMIN_PASSWORD, ADMIN_PASSWORD_2 |
server | the two Controller login keys |
SESSION_SECRET |
server | signs the admin session cookie |
NEXT_PUBLIC_APK_URL |
public | download link on the home page |
NEXT_PUBLIC_SITE_URL |
public | canonical origin, https://atomic-notes.devbehindyou.com |
- Import this repo in Vercel (framework auto-detected as Next.js).
- Add the environment variables above in Project Settings → Environment Variables (mark the admin key + admin secrets for Production/Preview only).
- Under Settings → Domains, add
atomic-notes.devbehindyou.comas the production domain. - Deploy. The public site is static/dynamic as needed; the Controller and its APIs run as serverless functions.
The Atomic Notes Server must be deployed and reachable at ATOMIC_SERVER_URL,
with a matching ADMIN_API_KEY on both projects — that server owns the
notifications, atomic_users, and energy_ledger MongoDB collections this
panel reads and writes.
Proprietary and source-available. The code is public to read and verify under the Atomic Notes Source-Available License. All rights reserved. You may not copy, modify, redistribute, host, or reuse it. Versions published before September 28, 2026 were released under the MIT License.