generate-secrets.mjs was importing from ../apps/api/node_modules/web-push/src/index.js
(a private source path) which breaks if web-push restructures internally or
workspace hoisting moves the package. Replace with Node.js built-in createECDH
('prime256v1') which produces identical base64url-encoded keys, including the
same defensive padding logic as web-push for short key buffers.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add scripts/generate-secrets.mjs: plain ESM script that prints
SESSION_SECRET + APP_PASSWORD_ENCRYPTION_KEY (32 random bytes each,
hex-encoded) and VAPID_PUBLIC_KEY + VAPID_PRIVATE_KEY from web-push
generateVAPIDKeys() — all to stdout only (SC-3: nothing written to disk)
- Resolve web-push as CommonJS default import from apps/api/node_modules
(avoids a root-level dependency; named-export ESM form not supported)
- Wire root package.json "generate-secrets" script: node scripts/generate-secrets.mjs