-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
206 lines (182 loc) · 9 KB
/
Copy path.env.example
File metadata and controls
206 lines (182 loc) · 9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
# SignUpFlow Environment Configuration Template
# Copy this file to .env and fill in your actual values
# DO NOT COMMIT .env TO VERSION CONTROL!
# ==============================================================================
# Local test configuration
# ==============================================================================
# Supported test commands sanitize their own environment. Keep bypasses off in
# ordinary development, and never enable them in production.
DISABLE_RATE_LIMITS=false
DISABLE_USAGE_LIMITS=false
# ==============================================================================
# Database Configuration
# ==============================================================================
# For local development with SQLite:
DATABASE_URL=sqlite:///./roster.db
# For production with PostgreSQL (used by docker-compose):
POSTGRES_DB=signupflow
POSTGRES_USER=signupflow
POSTGRES_PASSWORD=
POSTGRES_PORT=5432
# The host "db" below is the compose service name. It resolves ONLY inside the
# compose network, so uncommenting this line breaks host-side `make setup` and
# `make run` with a name-resolution error. Uncomment it only for containers
# started by docker-compose, which already set DATABASE_URL for you.
# From the host, reach the same database through its published port instead:
# DATABASE_URL=postgresql://signupflow:<password>@localhost:5432/signupflow
# DATABASE_URL=postgresql://signupflow:<password>@db:5432/signupflow
# ==============================================================================
# CORS Configuration
# ==============================================================================
# Comma-separated list of allowed origins for cross-origin requests.
# Leave empty to use local-dev defaults (localhost:8000, :8080, :3000, plus 127.0.0.1).
# In production, set to your mobile app's web origin(s) and any admin web client.
# Example: CORS_ALLOWED_ORIGINS=https://app.signupflow.example.com,https://admin.signupflow.example.com
CORS_ALLOWED_ORIGINS=
# ==============================================================================
# Rate Limiting Configuration
# ==============================================================================
RATE_LIMIT_SIGNUP_MAX=3
RATE_LIMIT_SIGNUP_WINDOW=3600
RATE_LIMIT_LOGIN_MAX=5
RATE_LIMIT_LOGIN_WINDOW=300
RATE_LIMIT_CREATE_ORG_MAX=2
RATE_LIMIT_CREATE_ORG_WINDOW=3600
RATE_LIMIT_CREATE_INVITATION_MAX=10
RATE_LIMIT_CREATE_INVITATION_WINDOW=300
RATE_LIMIT_VERIFY_INVITATION_MAX=10
RATE_LIMIT_VERIFY_INVITATION_WINDOW=60
RATE_LIMIT_PASSWORD_RESET_MAX=3
RATE_LIMIT_PASSWORD_RESET_WINDOW=3600
RATE_LIMIT_PASSWORD_RESET_CONFIRM_MAX=5
RATE_LIMIT_PASSWORD_RESET_CONFIRM_WINDOW=300
# Comma-separated direct proxy IPs or CIDRs allowed to supply X-Forwarded-For.
# Leave empty when clients connect directly. Never use 0.0.0.0/0 or ::/0.
TRUSTED_PROXY_IPS=
# ==============================================================================
# Mailtrap Email Testing Configuration
# ==============================================================================
# Mailtrap SMTP Credentials (for sending emails in development)
# Get from: https://mailtrap.io/ → Inbox → SMTP Settings
MAILTRAP_SMTP_HOST=sandbox.smtp.mailtrap.io
MAILTRAP_SMTP_PORT=2525
MAILTRAP_SMTP_USER=your_mailtrap_smtp_username
MAILTRAP_SMTP_PASSWORD=your_mailtrap_smtp_password
# Mailtrap Inbox API (OPTIONAL - for automated email verification in tests)
# Leave provider credentials blank for the core scheduling workflow.
# Get from: https://mailtrap.io/
# 1. API Token: Settings → API Tokens → Create Token
# 2. Account ID & Inbox ID: From inbox URL
# https://mailtrap.io/accounts/{ACCOUNT_ID}/inboxes/{INBOX_ID}
MAILTRAP_API_TOKEN=
MAILTRAP_ACCOUNT_ID=
MAILTRAP_INBOX_ID=
# Email Service Configuration
EMAIL_FROM=noreply@signupflow.io
EMAIL_FROM_NAME=SignUpFlow
# ==============================================================================
# Twilio SMS Configuration
# ==============================================================================
# Get credentials from: https://console.twilio.com/
# For testing: Use Twilio Test Credentials (free, no charges)
# Test Account SID format: ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
# Test Auth Token format: your_auth_token_here
# Test Phone Number format: +15005550006 (Twilio magic number for testing)
TWILIO_ACCOUNT_SID=your_twilio_account_sid_here
TWILIO_AUTH_TOKEN=your_twilio_auth_token_here
TWILIO_PHONE_NUMBER=+15005550006
# Configure Twilio to sign these exact externally visible URLs. Production requires HTTPS.
TWILIO_STATUS_CALLBACK_URL=http://localhost:8000/api/sms/webhook/delivery-status
TWILIO_INCOMING_SMS_URL=http://localhost:8000/api/sms/webhook/incoming-sms
# Redis Configuration (for Celery and rate limiting)
# For local development:
# REDIS_URL=redis://localhost:6379/0
# For docker-compose (with password):
REDIS_PASSWORD=
REDIS_PORT=6379
REDIS_URL=redis://localhost:6379/0
RATE_LIMIT_STORAGE=memory
EVENT_BUS_STORAGE=memory
CELERY_BROKER_URL=redis://localhost:6379/0
CELERY_RESULT_BACKEND=redis://localhost:6379/0
# ==============================================================================
# Stripe Billing Configuration
# ==============================================================================
# Get keys from: https://dashboard.stripe.com/test/apikeys
# Use test mode keys for development (pk_test_..., sk_test_...)
# For production, use live mode keys (pk_live_..., sk_live_...)
STRIPE_SECRET_KEY=
STRIPE_PUBLIC_KEY=
STRIPE_WEBHOOK_SECRET=
# Stripe Price IDs (create these in Stripe Dashboard → Products)
# Format: price_xxxxxxxxxxxxxxxxxxxxx
STRIPE_PRICE_STARTER_MONTHLY=price_starter_monthly_placeholder
STRIPE_PRICE_STARTER_ANNUAL=price_starter_annual_placeholder
STRIPE_PRICE_PRO_MONTHLY=price_pro_monthly_placeholder
STRIPE_PRICE_PRO_ANNUAL=price_pro_annual_placeholder
STRIPE_PRICE_ENTERPRISE_MONTHLY=price_enterprise_monthly_placeholder
STRIPE_PRICE_ENTERPRISE_ANNUAL=price_enterprise_annual_placeholder
# ==============================================================================
# JWT Authentication Configuration
# ==============================================================================
SECRET_KEY=change-this-to-a-random-secret-key-in-production
ALGORITHM=HS256
ACCESS_TOKEN_EXPIRE_HOURS=24
# ==============================================================================
# Application Configuration
# ==============================================================================
APP_URL=http://localhost:8000
API_BASE_URL=http://localhost:8000
# Exact public browser origin used for unsafe form and HTMX origin checks.
FRONTEND_URL=http://localhost:8000
# Server Configuration (for docker-compose)
PORT=8000
HOST=0.0.0.0
# Increase only after the owned Redis and multi-replica acceptance drills pass.
WORKERS=1
# Environment
ENVIRONMENT=development # Options: development, staging, production
# Production requires the exact 40-character lowercase Git commit SHA.
RELEASE_SHA=
DEBUG=false
LOG_LEVEL=INFO # Options: DEBUG, INFO, WARNING, ERROR, CRITICAL
# Test/debug controls. Production startup requires all of these to be false.
TESTING=false
DEBUG_RETURN_RESET_TOKEN=false
SIGNUPFLOW_ALLOW_TEST_CLOCK=false
SECURITY_HSTS_ENABLED=true
SECURITY_HSTS_MAX_AGE=31536000
SECURITY_CSP_ENABLED=true
# Feature Flags
# Email is disabled by default. Flip to true (and configure SendGrid or SMTP
# credentials) to opt into real transactional sends — leaving this at "false"
# keeps password-reset and other email-bearing endpoints from queuing real
# SMTP requests against deployments that lack credentials.
EMAIL_ENABLED=false
# Optional provider-free development sink. When set, this takes precedence over
# SMTP/SendGrid and writes one RFC 822 .eml file per message. Never configure it
# in production or commit its contents; links can contain single-use tokens.
# LOCAL_EMAIL_CAPTURE_DIR=.local/email-capture
# SendGrid HTTP API key — production email backend.
# Read by EmailService at api/services/email_service.py:97; if set, the
# service auto-selects the SendGrid backend (use_sendgrid=True). Leave
# blank for provider-free local development. Use LOCAL_EMAIL_CAPTURE_DIR above,
# or configure an explicitly authorized SMTP sandbox (see MAILTRAP_* vars). See
# docs/saas/SMOKE_TESTING_EMAIL.md for the end-to-end smoke runbook.
SENDGRID_API_KEY=
# Base64 DER ECDSA public key from SendGrid Event Webhook signature verification.
# Required with EMAIL_ENABLED=true in production. This is a public verification key.
SENDGRID_WEBHOOK_PUBLIC_KEY=
# Paid integrations are deferred and remain unavailable unless explicitly enabled
# for an authorized sandbox validation.
SMS_ENABLED=false
BILLING_ENABLED=false
SESSION_TTL_HOURS=24
# ==============================================================================
# Monitoring & Error Tracking
# ==============================================================================
# Local structured signal threshold; this does not configure an alert recipient.
READINESS_FAILURE_ALERT_THRESHOLD=3
# Optional Sentry error reporting. Leave empty to keep reporting disabled.
# A configured client sends no default PII and has performance tracing disabled.
SENTRY_DSN=