- queryClient: refreshSession возвращает reason (network/unauthorized); при network-ошибке не делаем logout, а бросаем network_error_during_refresh. - useAuth: checkAuth и refreshUser не сбрасывают сессию при network-ошибке во время refresh, переводят в офлайн-режим. - auth.service: remember берётся из сессии, race tolerance 5 минут. - access token lifetime унифицирован до 30 дней по умолчанию, cookie maxAge теперь совпадает с JWT expiry (было 15 минут fallback).
114 lines
4.5 KiB
Plaintext
114 lines
4.5 KiB
Plaintext
# =============================================
|
|
# Application secrets (required)
|
|
# =============================================
|
|
|
|
# JWT secrets — each token type has its own key (generate with: openssl rand -hex 32)
|
|
# FATAL: app will NOT start if these are missing
|
|
JWT_ACCESS_SECRET=your-access-secret-here
|
|
JWT_REFRESH_SECRET=your-refresh-secret-here
|
|
JWT_SUPERADMIN_SECRET=your-superadmin-secret-here
|
|
# Optional: separate secret for bot service tokens (falls back to JWT_ACCESS_SECRET)
|
|
# JWT_BOT_SECRET=your-bot-secret-here
|
|
|
|
# Token expiry (optional — these are the defaults)
|
|
# JWT_ACCESS_EXPIRES=30d
|
|
# JWT_REFRESH_EXPIRES_REMEMBER=90d
|
|
# JWT_REFRESH_EXPIRES_SESSION=30d
|
|
# JWT_SUPERADMIN_EXPIRES=1h
|
|
# JWT_BOT_EXPIRES=10m
|
|
|
|
# Session secret for express-session (generate with: openssl rand -hex 32)
|
|
SESSION_SECRET=your-session-secret-here
|
|
|
|
# HMAC secret for API key hashing (generate with: openssl rand -hex 32)
|
|
# Required if using MCP/RAG API keys. Without it the server will throw on key creation/lookup.
|
|
API_KEY_HMAC_SECRET=your-api-key-hmac-secret-here
|
|
|
|
# Web Push VAPID keys (generate with: npx web-push generate-vapid-keys)
|
|
VAPID_PUBLIC_KEY=your-vapid-public-key
|
|
VAPID_PRIVATE_KEY=your-vapid-private-key
|
|
|
|
# SendGrid API key for transactional email (optional — app works without it)
|
|
# SENDGRID_API_KEY=SG.xxxxxxxxxxxx
|
|
|
|
# =============================================
|
|
# Database — choose ONE of the two modes below
|
|
# =============================================
|
|
|
|
# --- MODE 1: Neon Cloud (default) ---
|
|
# Run with: docker compose up --build
|
|
# Set DATABASE_URL to your Neon connection string:
|
|
DATABASE_URL=postgresql://user:password@host/dbname?sslmode=require
|
|
|
|
# --- MODE 2: Self-hosted PostgreSQL ---
|
|
# Run with: docker compose --profile with-postgres up --build
|
|
# Set POSTGRES_* variables below AND update DATABASE_URL above to point
|
|
# to the Docker "db" service (e.g. postgresql://appuser:password@db:5432/appdb).
|
|
# DATABASE_URL is NOT auto-constructed — it must be set manually.
|
|
|
|
# POSTGRES_DB=appdb
|
|
# POSTGRES_USER=appuser
|
|
# POSTGRES_PASSWORD=your-strong-db-password
|
|
|
|
# =============================================
|
|
# File storage — choose ONE of the two modes
|
|
# =============================================
|
|
|
|
# --- MODE 1: Local disk (default, Replit/dev) ---
|
|
# Files are stored in the uploads/ folder on disk.
|
|
# No extra variables needed.
|
|
|
|
# --- MODE 2: MinIO S3 (recommended for production / "device in a box") ---
|
|
# Run with: docker compose --profile with-minio up --build
|
|
# The app automatically switches to S3 mode when MINIO_ENDPOINT is set.
|
|
|
|
# MINIO_ENDPOINT=http://minio:9000 # use "minio" as hostname inside Docker network
|
|
# MINIO_ACCESS_KEY=minioadmin # same as MINIO_ROOT_USER in docker-compose
|
|
# MINIO_SECRET_KEY=your-strong-minio-password
|
|
# MINIO_BUCKET=files
|
|
|
|
# =============================================
|
|
# WebDAV (optional, only with with-minio profile)
|
|
# =============================================
|
|
# Allows browsing/uploading files via Windows Explorer, Finder, Cyberduck
|
|
# Access: http://device-ip:8080 (user/pass below)
|
|
|
|
# WEBDAV_USER=admin
|
|
# WEBDAV_PASSWORD=your-webdav-password
|
|
|
|
# =============================================
|
|
# Ollama / Local LLM (optional)
|
|
# =============================================
|
|
# Base URL for Ollama server (default: http://localhost:11434)
|
|
# OLLAMA_BASE_URL=http://ollama:11434
|
|
|
|
# Number of CPU threads Ollama should use for inference.
|
|
# Default: (CPU cores - 1), e.g. 3 on a 4-core server.
|
|
# OLLAMA_NUM_THREAD=3
|
|
|
|
# Context window size (default: 2048). Increase only if you have enough RAM.
|
|
# OLLAMA_NUM_CTX=2048
|
|
|
|
# Allow private/loopback URLs for RAG providers (required for local Ollama)
|
|
# ALLOW_PRIVATE_RAG_URLS=true
|
|
|
|
# =============================================
|
|
# MCP API Keys (required for external MCP clients like n8n, Cursor, etc.)
|
|
# =============================================
|
|
# HMAC secret for hashing API keys. Generate with: openssl rand -hex 32
|
|
# FATAL: MCP key creation will fail if this is missing
|
|
# API_KEY_HMAC_SECRET=your-hmac-secret-here
|
|
|
|
# =============================================
|
|
# Public URL of CRM itself — used for presigned document URLs
|
|
# APP_URL=https://iistwin.ru
|
|
|
|
# =============================================
|
|
# Document Worker (optional — for PDF/DOCX generation)
|
|
# =============================================
|
|
# URL of the document-worker microservice (Chromium + LibreOffice).
|
|
# Inside Docker Compose use the service name:
|
|
# DOC_WORKER_URL=http://document-worker:3000
|
|
# For local development without Docker, you can point to an external service:
|
|
# DOC_WORKER_URL=http://localhost:3000
|