Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -190,6 +190,27 @@ LTI_PUBLIC_KEY_PATH=/app/keys/lti_public.pem
# Canvas API URL (for file downloads, optional)
CANVAS_API_URL=

# Canvas API token used by the watcher and bridge workers
# Create via Admin → Settings → New Access Token, scope to the institution's
# accessibility service account. Stored as a SecretStr by the config layer.
CANVAS_API_TOKEN=

# Comma-separated list of Canvas course IDs the watcher should poll.
# Leave empty to idle (useful while testing LTI plumbing). Replace with
# Canvas Live Events in Phase 5.
CANVAS_WATCHED_COURSES=

# Canvas Live Events / DOM-overlay allow-list (used by the panorama.js
# script to know which Canvas origins may call our score endpoints).
CANVAS_ALLOWED_ORIGINS=https://canvas.instructure.com

# Polling intervals (seconds) for the two Canvas-side workers
CANVAS_POLL_SECONDS=60
REFLOW_POLL_SECONDS=30

# Public URL of this tool (used when composing review-link emails)
LTI_PUBLIC_URL=

# LTI state TTL in seconds (default: 600 = 10 minutes)
LTI_STATE_TTL_SECONDS=600

Expand Down
1 change: 0 additions & 1 deletion CLAUDE.md

This file was deleted.

1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
AGENTS.md
9 changes: 9 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,15 @@ FROM base AS dependencies
# conversion are handled by the docling-serve sidecar container.
RUN apt-get update && apt-get install -y --no-install-recommends \
poppler-utils \
tesseract-ocr \
tesseract-ocr-eng \
ghostscript \
qpdf \
pngquant \
unpaper \
liblouis-data \
liblouis20 \
liblouis-bin \
&& rm -rf /var/lib/apt/lists/*

# Copy dependency files
Expand Down
19 changes: 17 additions & 2 deletions docker-compose.dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,8 @@ services:
volumes:
# Mount source code for hot-reload (read-only to prevent accidental writes)
- ./src:/app/src:ro
# Ops CLIs (list_platforms, test_service_token) run via `python -m scripts.<name>`
- ./scripts:/app/scripts:ro
# Mount agent prompt configurations
- ./config:/app/config:ro
# Mount tests for containerized test runs
Expand All @@ -108,15 +110,28 @@ services:
- AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID:-test}
- AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY:-test}
- AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN:-}
# Clear AWS_PROFILE to prevent boto3 from looking for profile config in container
- AWS_PROFILE=
# AWS_PROFILE intentionally unset (do not even define it). boto3 treats
# an empty string as "use the profile named 'default'", which then
# makes it look for ~/.aws/credentials inside the container - which
# doesn't exist, raising ProfileNotFound. With AWS_PROFILE absent,
# boto3 picks up AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY from the
# env above and the credential chain succeeds. Restore by uncommenting
# if you ever mount a credentials file into the container.
# - AWS_PROFILE=
- AWS_DEFAULT_REGION=us-east-1
# Disable AWS Instance Metadata Service (IMDS) to prevent boto3 hang in Docker
- AWS_EC2_METADATA_DISABLED=true
# S3 Configuration
- S3_TEMP_BUCKET=equalify-pdf-temp
- S3_RESULTS_BUCKET=equalify-pdf-results
- S3_PUBLIC_URL=http://localhost:4566
# Internal hostname for server-side fetches of presigned URLs.
# Floci returns URLs with the public host (localhost:4566) but the
# api-gateway container can't reach itself there; ``floci:4566`` is
# the Docker-network address. The reflow_client rewrites the host
# portion of any presigned URL before fetching. Leave unset in prod
# — real AWS S3 needs no rewrite.
- S3_INTERNAL_URL=http://floci:4566
# Redis: use explicit container name to avoid DNS collision with Canvas Redis
# when api-gateway is on both equalify-network and canvas-lms_default network
- REDIS_URL=redis://equalify-reflow-redis:6379
Expand Down
312 changes: 312 additions & 0 deletions docs/explanation/canvas-lti-integration.md

Large diffs are not rendered by default.

409 changes: 409 additions & 0 deletions docs/explanation/iso-security-brief.md

Large diffs are not rendered by default.

Loading
Loading