app/__pycache__/app.cpython-313.pyc was committed and went stale the moment
app.py changed. It was inert because the image runs 3.12 and the bytecode was
3.13, but a stale .pyc that happened to match the interpreter would be a very
quiet way to run the wrong code.
Also ignores service_account.json, which is bind-mounted in at runtime and has
no business being committable.
Form submissions now land in /data/scout73.db before anything leaves the
box. The Google Sheet and the ntfy push become mirrors whose per-record
outcome is recorded, so a failed sheet write is replayable instead of
surviving only as a push telling you to retype it.
The table is a generic record store keyed by 'kind', with workflow columns
and an audit trail, so RSVPs and other forms can land in the same place
later without a migration. Admin panel talks to /api/admin over HTTP and
never opens the DB file.
- app/store.py schema, writes, reads, one-time leads.jsonl backfill
- app/admin_api.py token-gated API; fails closed when ADMIN_TOKEN is unset
- app/app.py three hunks: imports, boot init, join_post
- compose ADMIN_TOKEN passed through from the Portainer stack env