feat(api): wire Novu lifecycle email triggers
Some checks failed
QA Gate (P0/P1) / Test affected app (pull_request) Has been cancelled

Route all lifecycle/transactional emails through Novu
(api.bildirim.semih.ai, delivered via Postal). A framework-agnostic
client is shared by the NestJS API and the standalone BullMQ worker.

- welcome + referral on signup (better-auth user.create.after)
- email-verification + password-reset (auth.ts; token links never
  track-wrapped so the one-time token survives)
- referral-qualified / referral-reward to the referrer on qualification
- payment-success / payment-failed in the Stripe webhook handlers
- trial-ending + win-back via a new daily lifecycle-email cron (worker),
  idempotent via a 1-day endDate window (no sent-flag column)
- signed track.sase.tr CTA links when MAILTRACK_SECRET is set
- NOVU_* / APP_PUBLIC_URL / MAILTRACK_SECRET env added to config,
  validation, .env.example and both compose service blocks

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-27 01:30:39 +03:00
parent d35a009653
commit 1c79c18aff
18 changed files with 665 additions and 8 deletions

View File

@@ -14,3 +14,12 @@ MINIO_PUBLIC_URL=https://storage.sase.tr/sase-schemas
MINIO_USE_SSL=false
CORS_ORIGIN=http://localhost:3000,https://v2.sase.tr
ML_PREDICTION_ENABLED=false
# Novu — lifecycle/transactional email automation (Tailscale-only; sends via Postal).
# Leave NOVU_API_KEY empty in dev → triggers are logged & skipped. Prod key: Bitwarden "Novu admin (bildirim.semih.ai)" → PROD_API_KEY
NOVU_API_URL=https://api.bildirim.semih.ai
NOVU_API_KEY=
# Public marketing-site origin for CTA targets
APP_PUBLIC_URL=https://sase.tr
# HMAC secret for signed track.sase.tr click links (Bitwarden "mailtrack tracking (track.sase.tr)"). Empty → no click tracking.
MAILTRACK_SECRET=