art-bd-ui
v1.0.46
Published
Set of handy components for React like projects
Readme
artbd-ui
React components and utilities used by Gear projects.
Private shadcn registry
This repository exposes every component family and reusable hook through a bearer-token-protected shadcn registry. The source catalog is registry.json and is generated from src/.
Regenerate and verify the catalog after adding or moving source files:
npm run registry:generate
npm run registry:checkGenerate a token and start the registry:
export REGISTRY_TOKEN="$(openssl rand -hex 32)"
npm run registry:startThe server listens on 127.0.0.1:3000 by default. Copy .env.example values into your deployment environment rather than committing a token. The server intentionally does not load .env files itself.
Configure a consumer project's components.json:
{
"registries": {
"@gear": {
"url": "https://registry.example.com/r/{name}.json",
"headers": {
"Authorization": "Bearer ${GEAR_REGISTRY_TOKEN}"
}
}
}
}Then set GEAR_REGISTRY_TOKEN in the consumer environment and use the namespace:
npx shadcn@latest view @gear/kbd
npx shadcn@latest add @gear/kbd
npx shadcn@latest add @gear/use-controllable-stateThe catalog endpoint used by shadcn list, search, and MCP clients is /r/registry.json. Individual items are served from /r/<name>.json.
Deployment notes
- The deployable Next.js service is isolated in
registry/. On Vercel, set the project Root Directory toregistryand enable source access outside that root during the build step. - After linking the Vercel project at the repository root, run
npm --prefix registry run deploy:previewfor a local preview deployment ornpm --prefix registry run deploy:productionto mirror the production GitHub Actions deployment. See the registry README for authentication, verification, and one-time linking instructions. registry/vercel.jsonforcesnpm run build, which stages the root catalog and referencedsrc/files before Next.js builds the authenticated route handlers.- Terminate TLS in front of this HTTP server; never expose tokens over plain HTTP.
- Authenticated success responses are marked
privateand vary onAuthorization; failures areno-store. - The lightweight
registry/server.mjsdevelopment server has a per-process rate limiter. Use Vercel Firewall or another shared limiter for the deployed serverless app. - Rotate tokens through your deployment secret manager. The local server refuses to start without
REGISTRY_TOKEN; the deployed app fails closed with503 Service Unavailableuntil it is configured. - Run
npm run registry:testafter changing the server or catalog. The test loads every generated item through the actual shadcn producer API.
