trails/openspec/changes/archive/2026-05-23-komoot-import/proposal.md
Ullrich Schäfer ae23d31a5f
Wire INTEGRATION_SECRET into docker-compose and CI; archive komoot-import
- Add INTEGRATION_SECRET to journal service in docker-compose.yml with
  :? guard so a missing value fails loudly at compose-up time
- Add INTEGRATION_SECRET to E2E test step in ci.yml via GitHub secret
  (unit tests already set their own value in the test file)
- Archive openspec/changes/komoot-import → archive/2026-05-23-komoot-import
- Sync delta specs: new openspec/specs/komoot-import/spec.md,
  updated openspec/specs/route-management/spec.md

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 21:10:08 +02:00

1.8 KiB

Why

Users switching to trails.cool have years of tours on Komoot. Without import, they start with an empty Journal — no history, no motivation to switch. A Komoot import lets users bring their existing tours and start using trails.cool immediately.

What Changes

  • Public import (no credentials): user proves ownership of their Komoot profile by placing their trails.cool profile URL in their Komoot bio field. trails.cool verifies via the public Komoot API, then imports all public tours.
  • Authenticated import (email + password): imports all tours including private ones. Credentials stored encrypted.
  • Both modes share the same batch import engine, progress tracking, and deduplication logic.

Capabilities

New Capabilities

  • komoot-import: Two-mode Komoot import — public (bio verification, no credential storage) and authenticated (email + password, all tours including private). Both track batch progress and deduplicate on re-import.

Modified Capabilities

  • route-management: Routes can now be created via import (not just manual creation), with an external source tracking field.

Impact

  • Database: New tables for integration connections and import batches in journal schema. Connections can be credential-free (public mode).
  • Files: New routes (/integrations, /api/integrations/*), new server utilities for Komoot API, new DB schema tables
  • Dependencies: No new packages — uses fetch for Komoot API, existing Drizzle for DB
  • Privacy: Only authenticated mode stores credentials (encrypted). Public mode stores only the Komoot username. Both documented in privacy manifest.
  • External: Komoot public API (api.komoot.de) — unauthenticated for public tours and profile lookup; basic auth for authenticated mode