Email:
- Add nodemailer; rewrite lib/email.ts to send via configured SMTP (Proton
Mail Bridge) first, Resend fallback, then dev simulation.
- Forward SMTP_* env to web and add protonmail-bridge service in compose.
- Document Proton Bridge SMTP vars in .env.example files; add test-smtp.mjs.
Apply:
- OneClickApplyModal now opens the job's real posting URL (company/ATS site)
in a new tab as the primary action when jobUrl is present, and records the
external application so the card shows 'Applied'.
- Internal one-click snapshot flow retained for jobs without an external URL.
- POST /api/applications accepts external:true (skips profile completeness)
and records an external application.
Stop web/scraper containers from using a stray literal DATABASE_URL in the
root .env (which desynced the postgres role password and caused persistent
'password authentication failed' errors). DATABASE_URL is now always computed
from POSTGRES_USER/POSTGRES_PASSWORD.
Also harden postgres-entrypoint.sh: log to stderr, retry on failure, and run
ALTER ROLE unconditionally so the stored password always matches the env.