scan-flow step 9: real SMS via SMSGlobal HTTP API (smshttp sender, proven live OK:0) + docs

This commit is contained in:
2026-08-07 16:10:52 +10:00
parent 453c61b57a
commit d4679068ba
8 changed files with 69 additions and 6 deletions

View File

@@ -38,7 +38,7 @@ Where Woof — a **return-tag platform** (not a tracker): pre-coded QR/NFC tags
## Tools
- `openspec` 1.3.1 (spec-driven dev), `plannotator` (plan + browser review), pi subagents (master/worker), `sqlc` 1.31.1 at `~/go/bin` (not on PATH — `make generate` handles it), `pgx` v5, `gorilla/sessions`, `bcrypt`
- **Secrets are env-only, never committed**: `DATABASE_URL`, `SESSION_SECRET`, `SMS_API_KEY`, `SMS_API_SECRET`, `SMS_FROM` (blank = SMSGlobal pooled number)
- **Secrets are env-only, never committed**: `DATABASE_URL`, `SESSION_SECRET`; SMS via **HTTP API** `SMS_USER`/`SMS_PASSWORD`/`SMS_FROM` (proven live 2026-08-07) with REST key/secret (`SMS_API_KEY`/`SMS_API_SECRET`) as unverified fallback
- SMS is a swappable `internal/sms.Sender` — `LogSender` (default) / `smsglobal.Client` (real)
## Gotchas worth remembering