-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
112 lines (88 loc) · 4.2 KB
/
Copy path.env.example
File metadata and controls
112 lines (88 loc) · 4.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
# ---- Backend ----
# Copy to .env and adjust. Running the backend WITHOUT Docker reads all of these.
# With `docker compose`, the compose file hardcodes DATABASE_URL / CORS_ORIGINS /
# PUBLIC_SITE_URL for local dev; the remaining backend vars below (ADMIN_TOKEN,
# MAX_UPLOAD_MB, AUTO_HIDE_THRESHOLD, STALE_AFTER_DAYS, RATE_LIMIT_*,
# CAT_DETECTION_*) are read from this .env if set.
# In docker-compose the DB host is "db"; outside Docker use localhost.
DATABASE_URL=postgresql+psycopg://catmap:catmap@localhost:5432/catmap
# Comma-separated allowed origins, or "*" for any (dev only).
# Set explicit origins before a public launch (the server logs a warning on "*").
CORS_ORIGINS=*
# Optional extra CORS origin regex. Leave empty in production (do not use
# https://[\w-]+\.onrender\.com — that allows any Render app).
CORS_ORIGIN_REGEX_PATTERN=
# Public site URL for share-page Open Graph tags (no trailing slash).
PUBLIC_SITE_URL=https://catmap.drytrix.com
# Max accepted upload size in MB.
MAX_UPLOAD_MB=10
# Moderation: hide a sighting once this many distinct devices report it.
AUTO_HIDE_THRESHOLD=3
# Sightings not confirmed within this many days are flagged "stale" (dimmed).
STALE_AFTER_DAYS=30
# Token protecting /api/admin moderation endpoints + the /admin web UI.
# Empty = admin disabled.
ADMIN_TOKEN=
# Rate limits (slowapi syntax), keyed on device token then client IP.
RATE_LIMIT_CREATE=20/hour
RATE_LIMIT_CONFIRM=120/hour
RATE_LIMIT_REPORT=40/hour
RATE_LIMIT_ISSUE=5/hour
RATE_LIMIT_ADD_PHOTO=30/hour
RATE_LIMIT_MUTATE=60/hour
# Cat detection (YOLOv10 COCO detector on upload).
CAT_DETECTION_ENABLED=true
CAT_DETECTION_THRESHOLD=0.20
CAT_DETECTION_ANIMAL_THRESHOLD=0.30
CAT_DETECTION_STRICT=true
# Error tracking (Sentry). Leave empty to disable. https://sentry.io
SENTRY_DSN=
SENTRY_TRACES_SAMPLE_RATE=0.0
SENTRY_ENVIRONMENT=production
# Log level for the JSON request/application logger.
LOG_LEVEL=INFO
# Telegram admin notifications (optional). Create a bot via @BotFather, send it a
# message, then read your chat id from getUpdates. Both must be set to enable.
# Used for new/pending sightings, content reports, and user bug/issue reports.
TELEGRAM_BOT_TOKEN=
TELEGRAM_CHAT_ID=
# Web Push (VAPID). Empty keys disable browser push.
# Generate with: python backend/scripts/generate_vapid.py
# On Render: set these in the catmap-backend Environment dashboard (sync: false).
VAPID_PUBLIC_KEY=
VAPID_PRIVATE_KEY=
VAPID_SUBJECT=mailto:admin@catmap.drytrix.com
# FCM HTTP v1 for native Android (Capacitor). Empty disables mobile push.
# Firebase Console → Project Settings → Service accounts → Generate new private key.
# Paste the JSON as a single line. Also place google-services.json at
# frontend/android/app/google-services.json (gitignored).
FCM_SERVICE_ACCOUNT_JSON=
# Comma-separated Google OAuth client IDs (web + Android + iOS). Empty disables
# Google sign-in. Create OAuth clients in Google Cloud Console for the same
# Firebase/Google project used for FCM.
GOOGLE_CLIENT_IDS=
# Resend email API (https://resend.com). Empty disables outbound email
# (verification / password reset / notification emails become no-ops).
RESEND_API_KEY=
EMAIL_FROM=CatMap <noreply@catmap.drytrix.com>
EMAIL_REPLY_TO=
# Opaque account session lifetime (days).
SESSION_TTL_DAYS=90
# Auth endpoint rate limit (signup / login / forgot-password).
RATE_LIMIT_AUTH=20/hour
# ---- Frontend (build-time) ----
# Base URL of the backend API as seen by the browser.
# Leave empty to use same-origin /api (Vite dev proxy + production nginx proxy).
VITE_API_BASE=
# Native/Capacitor builds talk to this host when VITE_API_BASE is unset.
# Override for staging or a custom domain so CORS matches the proxy.
VITE_API_BASE_NATIVE=https://catmap-backend.onrender.com
# Google Identity Services web client ID (must also appear in GOOGLE_CLIENT_IDS).
VITE_GOOGLE_CLIENT_ID=
# Google Analytics 4 measurement ID (G-XXXXXXXXXX). Leave empty to disable analytics.
# On Render: set on catmap-frontend and redeploy (written to /env-config.js at startup).
VITE_GA_MEASUREMENT_ID=
# Sentry DSN for frontend error tracking. Leave empty to disable (also skipped
# in dev builds). On Render: set on catmap-frontend and redeploy (written to
# /env-config.js at startup).
VITE_SENTRY_DSN=