Some checks are pending
Branch Check / Type Check & Build (push) Waiting to run
- server/utils/jwt.ts: дефолт JWT_ACCESS_EXPIRES 30d → 15m (env сохранено), hashToken() (sha256 hex) - migrations/0082_token_hashes.sql: *_hash колонки в user_sessions/users, DELETE FROM user_sessions (глобальный разлогин), legacy plain-колонки сохранены, но не пишутся - storage: lookup/отзыв сессий и reset-токенов по хэшу; markSessionReplaced по id сессии - auth.service: ротация в rotateFamilySession(), grace-period ротирует активную сессию вместо возврата plain-токена - auth.core.routes: forgot/reset-password пишут/ищут sha256-хэш, plain только в письме - tests/token-security.test.ts: 12 тестов (выпуск по хэшу, ротация, reuse detection, grace, reset) - .env.example, swagger, IMPLEMENTATION_LOG.md обновлены Проверки: npm run check чисто, vitest 118/118, lint 0 errors, build собирается
152 lines
6.5 KiB
Plaintext
152 lines
6.5 KiB
Plaintext
# =============================================
|
||
# Application secrets (required)
|
||
# =============================================
|
||
|
||
# JWT secrets — each token type has its own key (generate with: openssl rand -hex 32)
|
||
# FATAL: app will NOT start if these are missing
|
||
JWT_ACCESS_SECRET=your-access-secret-here
|
||
JWT_REFRESH_SECRET=your-refresh-secret-here
|
||
JWT_SUPERADMIN_SECRET=your-superadmin-secret-here
|
||
# Optional: separate secret for bot service tokens (falls back to JWT_ACCESS_SECRET)
|
||
# JWT_BOT_SECRET=your-bot-secret-here
|
||
|
||
# Token expiry (optional — these are the defaults)
|
||
# Access-токен короткоживущий (15 минут, шаг 0.6): клиент обновляет его через
|
||
# /api/auth/refresh по httpOnly refresh-cookie. Увеличивать только осознанно.
|
||
# JWT_ACCESS_EXPIRES=15m
|
||
# JWT_REFRESH_EXPIRES_REMEMBER=90d
|
||
# JWT_REFRESH_EXPIRES_SESSION=30d
|
||
# JWT_SUPERADMIN_EXPIRES=1h
|
||
# JWT_BOT_EXPIRES=10m
|
||
|
||
# Session secret for express-session (generate with: openssl rand -hex 32)
|
||
SESSION_SECRET=your-session-secret-here
|
||
|
||
# HMAC secret for API key hashing (generate with: openssl rand -hex 32)
|
||
# Required if using MCP/RAG API keys. Without it the server will throw on key creation/lookup.
|
||
API_KEY_HMAC_SECRET=your-api-key-hmac-secret-here
|
||
|
||
# Web Push VAPID keys (generate with: npx web-push generate-vapid-keys)
|
||
VAPID_PUBLIC_KEY=your-vapid-public-key
|
||
VAPID_PRIVATE_KEY=your-vapid-private-key
|
||
|
||
# SendGrid API key for transactional email (optional — app works without it)
|
||
# SENDGRID_API_KEY=SG.xxxxxxxxxxxx
|
||
|
||
# Row Level Security (изоляция tenant'ов на уровне БД).
|
||
# ОБЯЗАТЕЛЬНО для production: без него процесс не стартует (fatal при NODE_ENV=production).
|
||
# В dev можно не задавать (safe default — политики существуют, но не активны).
|
||
# ENABLE_RLS=true
|
||
|
||
# =============================================
|
||
# Database — choose ONE of the two modes below
|
||
# =============================================
|
||
|
||
# --- MODE 1: Neon Cloud (default) ---
|
||
# Run with: docker compose up --build
|
||
# Set DATABASE_URL to your Neon connection string:
|
||
DATABASE_URL=postgresql://user:password@host/dbname?sslmode=require
|
||
|
||
# --- MODE 2: Self-hosted PostgreSQL ---
|
||
# Run with: docker compose --profile with-postgres up --build
|
||
# Set POSTGRES_* variables below AND update DATABASE_URL above to point
|
||
# to the Docker "db" service (e.g. postgresql://appuser:password@db:5432/appdb).
|
||
# DATABASE_URL is NOT auto-constructed — it must be set manually.
|
||
|
||
# POSTGRES_DB=appdb
|
||
# POSTGRES_USER=appuser
|
||
# POSTGRES_PASSWORD=your-strong-db-password
|
||
|
||
# =============================================
|
||
# File storage — choose ONE of the two modes
|
||
# =============================================
|
||
|
||
# --- MODE 1: Local disk (default, Replit/dev) ---
|
||
# Files are stored in the uploads/ folder on disk.
|
||
# No extra variables needed.
|
||
|
||
# --- MODE 2: MinIO S3 (recommended for production / "device in a box") ---
|
||
# Run with: docker compose --profile with-minio up --build
|
||
# The app automatically switches to S3 mode when MINIO_ENDPOINT is set.
|
||
|
||
# MINIO_ENDPOINT=http://minio:9000 # use "minio" as hostname inside Docker network
|
||
# MINIO_ACCESS_KEY=minioadmin # пример для dev; в production обязательно сменить дефолтные креды
|
||
# MINIO_SECRET_KEY=your-strong-minio-password
|
||
# MINIO_BUCKET=files
|
||
|
||
# =============================================
|
||
# WebDAV (optional, only with with-minio profile)
|
||
# =============================================
|
||
# Allows browsing/uploading files via Windows Explorer, Finder, Cyberduck
|
||
# Access: http://device-ip:8080 (user/pass below)
|
||
|
||
# WEBDAV_USER=admin
|
||
# WEBDAV_PASSWORD=your-webdav-password
|
||
|
||
# =============================================
|
||
# Ollama / Local LLM (optional)
|
||
# =============================================
|
||
# Base URL for Ollama server (default: http://localhost:11434)
|
||
# OLLAMA_BASE_URL=http://ollama:11434
|
||
|
||
# Number of CPU threads Ollama should use for inference.
|
||
# Default: (CPU cores - 1), e.g. 3 on a 4-core server.
|
||
# OLLAMA_NUM_THREAD=3
|
||
|
||
# Context window size (default: 2048). Increase only if you have enough RAM.
|
||
# OLLAMA_NUM_CTX=2048
|
||
|
||
# Allow private/loopback URLs for RAG providers (required for local Ollama)
|
||
# ALLOW_PRIVATE_RAG_URLS=true
|
||
|
||
# =============================================
|
||
# MCP API Keys (required for external MCP clients like n8n, Cursor, etc.)
|
||
# =============================================
|
||
# HMAC secret for hashing API keys. Generate with: openssl rand -hex 32
|
||
# FATAL: MCP key creation will fail if this is missing
|
||
# API_KEY_HMAC_SECRET=your-hmac-secret-here
|
||
|
||
# =============================================
|
||
# Public URL of CRM itself — used for presigned document URLs
|
||
# APP_URL=https://iistwin.ru
|
||
|
||
# =============================================
|
||
# MedSchedule bot settings (optional)
|
||
# =============================================
|
||
# Telegram bot token for MedSchedule personal/family health assistant
|
||
# TELEGRAM_BOT_TOKEN=your-telegram-bot-token
|
||
# Secret token for validating Telegram webhook requests
|
||
# TELEGRAM_BOT_WEBHOOK_SECRET=your-telegram-webhook-secret
|
||
|
||
# MAX bot token and base URL (optional)
|
||
# MAX_BOT_TOKEN=your-max-bot-token
|
||
# MAX_BOT_API_BASE=https://api.max.ru/bot
|
||
# Secret token for validating MAX webhook requests
|
||
# MAX_BOT_WEBHOOK_SECRET=your-max-webhook-secret
|
||
|
||
# n8n webhook URL for MedSchedule OCR (medical scan analysis)
|
||
# IMPORTANT: iistwin must reach n8n via the internal Docker network URL.
|
||
# External /webhook and /n8n/webhook paths are NOT exposed for webhooks.
|
||
# MED_N8N_OCR_WEBHOOK_URL=http://n8n:5678/webhook/972a1fce-c84c-49f6-bc04-7bd838b61acc/med-ocr
|
||
|
||
# =============================================
|
||
# Document Worker (optional — for PDF/DOCX generation)
|
||
# =============================================
|
||
# URL of the document-worker microservice (Chromium + LibreOffice).
|
||
# Inside Docker Compose use the service name:
|
||
# DOC_WORKER_URL=http://document-worker:3000
|
||
# For local development without Docker, you can point to an external service:
|
||
# DOC_WORKER_URL=http://localhost:3000
|
||
|
||
# =============================================
|
||
# File upload limits (optional, in megabytes)
|
||
# =============================================
|
||
# Per-type limits (extension-based, enforced after upload):
|
||
# UPLOAD_IMAGE_MAX_MB=25
|
||
# UPLOAD_DOC_MAX_MB=100
|
||
# Hard cap for the multipart parser (multer fileSize):
|
||
# UPLOAD_MAX_MB=100
|
||
# Bot login token TTL (access / refresh) — см. этап bot API keys:
|
||
# JWT_BOT_LOGIN_EXPIRES=30d
|
||
# JWT_BOT_LOGIN_REFRESH_EXPIRES=90d
|