Progmaweb is the public web and account surface for Progmasoft. The repository intentionally keeps presentation and account policy in one deployable workspace while preserving a strict process boundary between the Next.js frontend and the ASP.NET Core API.
progmasoft.comserves the canonical organization homepage;www.progmasoft.comredirects to it.account.progmasoft.comserves account discovery and authentication.account.progmasoft.com/loginsigns an existing account in.account.progmasoft.com/registercreates a new account after server-side validation.account.progmasoft.com/<Account>/dashboardserves the authenticated account dashboard.viget.progmasoft.comserves the public Visual X# package catalog.viget.progmasoft.com/dslplugins/serves the separate Kotlin DSL plugin catalog.
Account names preserve their original display case but reserve names case-insensitively, preventing visually confusing duplicates. Email uniqueness is also evaluated case-insensitively by the API.
ViGet does not maintain a separate publisher name. A package coordinate's <Publisher> segment is exactly the
canonical Progmasoft <Account> name, with the same spelling and case.
Every page is published in English, German, Russian and Hebrew. A visitor who has not chosen a language gets the language their browser prefers, and English when the browser prefers none of the four. A choice made in the language menu is remembered across the three hosts. Hebrew text runs right to left while the page layout stays as it is. See Localization.
- Architecture: processes, hosts, routing and trust boundaries.
- Account API: endpoints, errors, cookies and limits.
- Localization: language selection, text direction and adding a language.
- Development: local setup, checks and what CI enforces.
- Known limitations: what is missing or temporary. Read this before operating the service; accounts and sessions are kept in PostgreSQL and survive a restart of the API.
- Operations and the mail boundary.
apps/webis a Next.js App Router application. Host-aware routing keeps the public organization, account, and ViGet surfaces in one build without coupling their page hierarchies.apps/apiis an ASP.NET Core minimal API. It owns account-name policy, password hashing, session issuance, secure cookies, rate limiting, and authorization.- The browser never receives password hashes, session digests, deployment secrets, or database credentials.
- Production account maintenance is an explicit operations workflow. The public API does not contain bulk-delete, reset-all, seed-password, or environment-password endpoints.
- Node.js 24 or newer
- pnpm 11 or newer
- .NET SDK 10
The initial Progmaweb release, Git tag, and GitHub Release use version 1.0.0. Visual X# compiler versions belong to
the language repositories and do not determine this website's version.
Install frontend dependencies and start Next.js:
pnpm install --frozen-lockfile
pnpm dev
Start the account API in another terminal:
dotnet run --project apps/api/Progmaweb.Api.csproj --urls http://127.0.0.1:5085
The frontend defaults to http://127.0.0.1:5085 for server-side API requests. Set PROGMAWEB_API_ORIGIN when the API
uses another origin. Browser requests use the same-origin /api boundary so production can proxy them without exposing
an internal address.
Google sign-in uses a server-side authorization-code flow. Configure Authentication__Google__ClientId and
Authentication__Google__ClientSecret only in the process environment or secret manager. The production OAuth client
uses https://account.progmasoft.com as its JavaScript origin and
https://account.progmasoft.com/api/v1/accounts/oauth/google/callback as its exact redirect URI. Never commit the
downloaded Google client JSON.
pnpm check
pnpm test
pnpm test:coverage
pnpm build
dotnet build apps/api/Progmaweb.Api.csproj --configuration Release
dotnet test --project apps/api-tests/Progmaweb.Api.Tests.csproj --configuration Release
dotnet test --project apps/api-tests/Progmaweb.Api.Tests.csproj --configuration Release --coverlet --coverlet-output-format cobertura
dotnet tool restore
dotnet docfx docs/api/docfx.json --warningsAsErrors
dotnet run docs/api/CheckDocumentation.cs -- docs/api
Frontend tests exercise the published locale contract and account/ViGet metadata without starting a production service.
The frontend LCOV and API Cobertura reports are retained as one-day artifacts, then uploaded to Codecov by separate
jobs. Only those upload jobs receive id-token: write; dependency installation, builds, and tests do not receive OIDC
permissions, and fork-originated pull requests skip the upload jobs. CodeQL and Codacy provide static analysis;
Renovate proposes dependency updates without merging them automatically; Dependabot reports vulnerabilities and proposes their fixes. The DocFX command builds the API reference
and fails on a broken link or an unresolved reference; the check after it fails when any item of the reference has no
description. Development explains each check.
Progmaweb project-owned source code is licensed under AGPL-3.0-or-later, matching the Visual X# website, with the
additional Progmasoft Patent Grant, Version 1.1. See LICENSE.txt, PATENTS,
LICENSES/AdditionRef-Progmasoft-Patent-Grant-1.1.txt, and NOTICE.txt. Third-party dependencies remain under their
respective licenses.