deploy/CICD.md documents which git push/tag triggers which pipeline steps; deploy/AUTH.md documents the Authelia OIDC integration contract with a sequence diagram of the login flow. Cross-link from README and INSTALL. The 0.1.0 release also ships the previously-committed security hardening (server-side session expiry + nosniff on served files). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.3 KiB
HSA Receipt Tracker
A small, mobile-first web app for two household users to capture and archive HSA-eligible receipts (photo or PDF) for future reimbursement and tax substantiation, with optional AI auto-fill of the amount/date/category/patient.
- What it does (current behavior): SPEC.md — the source of truth.
- Why it's built this way (history & rationale): DESIGN.md.
- Version log: CHANGELOG.md.
Running
It's a single static Go binary (CGO_ENABLED=0, pure-Go SQLite). Configure via
environment (see .env.example); ./scripts/build.sh builds it and
./scripts/run.sh runs it locally.
Deployment:
- deploy/CICD.md — what each git push/tag triggers (branch =
build+test; release tag
X.Y.Z= build+deploy; pre-release tag = build+stage). - deploy/INSTALL.md — one-time host setup, on-disk layout, manual deploy, and rollback.
- deploy/AUTH.md — the Authelia (OIDC) integration: which config fields must agree with which app env vars, and how access is granted/revoked.
AI classifier correction notes
When an API key is configured, each upload is read by the model to pre-fill the form. You can steer it with correction notes — free-text rules appended to the classifier prompt — managed under the AI tab. When the model misreads a receipt, that upload is recorded; the AI tab lets you review misreads one by one and attribute which note fixed each.
Notes live only in the database (private, never committed, included in /export/db
backups). On first run the table is seeded once with these default notes (no
PII), which you can edit or delete:
- Amounts that use a comma as the decimal separator (e.g. "12,50") mean 12.50, not 1250.
- When both a service/visit date and a separate statement, print, or due date appear, use the service date.
- "Patient Pay", "You Paid", "Amount Due", and "Patient Responsibility" are the amount actually paid — prefer them over subtotals or insurance-covered amounts.
These defaults are defined in code (internal/storage/ai_notes.go); this list is
the human-readable copy. They are only seeded when the notes table is empty, so a
deleted default does not come back on restart.