Add admin identity module: better-auth, per-app permissions, invitations (#12)
Jenkins Production Deployment
Jenkins Production Deployment
Reviewed-on: #12 Co-authored-by: Patrick Müller <mail@pmueller.me> Co-committed-by: Patrick Müller <mail@pmueller.me>
This commit was merged in pull request #12.
This commit is contained in:
@@ -1,5 +1,11 @@
|
||||
# Values containing #, ", \ or surrounding spaces must be single-quoted
|
||||
# (dotenv 16 treats an unquoted # as a comment): DB_PASSWORD='abc#def'
|
||||
# REQUIRED. The admin module treats anything other than "development" or "test"
|
||||
# as production: strict secrets, cross-subdomain cookies, no relaxed CORS.
|
||||
# Leaving it unset is therefore safe-by-default but will refuse to boot without
|
||||
# the admin secrets below. Set it to development for local work.
|
||||
NODE_ENV=development
|
||||
|
||||
PORT=3000
|
||||
|
||||
DB_HOST=
|
||||
@@ -25,6 +31,41 @@ TICKETS_DB=
|
||||
TICKETS_RATE_LIMIT_MAX=10
|
||||
TICKETS_RATE_LIMIT_WINDOW_MIN=10
|
||||
|
||||
ADMIN_DB=
|
||||
# 32+ random bytes, e.g. `openssl rand -base64 48`. Mandatory outside
|
||||
# development/test - there is deliberately no fallback, since a hardcoded one
|
||||
# would be a published signing key. Rotating it signs everyone out and
|
||||
# invalidates outstanding password-reset links.
|
||||
BETTER_AUTH_SECRET=
|
||||
API_BASE_URL=http://localhost:3000
|
||||
ADMIN_APP_URL=http://localhost:3002
|
||||
# Comma-separated origins of the apps that may call /admin/* with credentials.
|
||||
APP_ORIGINS=http://localhost:3001
|
||||
# nachklang.art in production; passkeys are bound to this value.
|
||||
PASSKEY_RP_ID=localhost
|
||||
# On start-up, makes sure this address can get in (invite, or grant admin if the
|
||||
# user already exists). Idempotent, safe to leave set.
|
||||
ADMIN_BOOTSTRAP_EMAIL=
|
||||
|
||||
# The header the reverse proxy puts the real client IP in, and the proxy hops to
|
||||
# trust. Get these right or better-auth cannot resolve a client IP and every
|
||||
# request shares ONE rate-limit bucket (/sign-in/* allows 3 per 10 seconds, so
|
||||
# one noisy client locks everyone out). Check with:
|
||||
# SELECT `key` FROM rateLimit; -- a "no-trusted-ip" row means it is happening.
|
||||
# The header the reverse proxy puts the real client IP in. Must be one the proxy
|
||||
# actually overwrites - trusting a header it does not set lets any client send its
|
||||
# own value and bypass the sign-in rate limit entirely.
|
||||
# Set to "none" to trust no header at all: every request then shares one rate-limit
|
||||
# bucket, which is the safe fallback if the check below fails. Verify after deploy
|
||||
# with: SELECT ipAddress FROM session ORDER BY createdAt DESC LIMIT 3;
|
||||
CLIENT_IP_HEADERS=x-real-ip
|
||||
TRUSTED_PROXY_IPS=
|
||||
|
||||
# Writes invitation links to the log. That link is a live account-creation
|
||||
# credential, so this is refused outside development. Needed locally, where the
|
||||
# mail relay is off and only the token's hash is stored.
|
||||
ADMIN_LOG_INVITE_LINKS=true
|
||||
|
||||
MEMBER_CREDENTIAL=123
|
||||
CHOIR_CREDENTIAL=123
|
||||
MANAGEMENT_CREDENTIAL=123
|
||||
|
||||
Reference in New Issue
Block a user