Files
iistwin/.env.example
Ильяс Султанов 06bfd2aa75
Some checks are pending
Branch Check / Type Check & Build (push) Waiting to run
feat(auth): шаг 0.6 — TTL access 15 минут + хэширование refresh/reset-токенов в БД
- server/utils/jwt.ts: дефолт JWT_ACCESS_EXPIRES 30d → 15m (env сохранено), hashToken() (sha256 hex)
- migrations/0082_token_hashes.sql: *_hash колонки в user_sessions/users, DELETE FROM user_sessions (глобальный разлогин), legacy plain-колонки сохранены, но не пишутся
- storage: lookup/отзыв сессий и reset-токенов по хэшу; markSessionReplaced по id сессии
- auth.service: ротация в rotateFamilySession(), grace-period ротирует активную сессию вместо возврата plain-токена
- auth.core.routes: forgot/reset-password пишут/ищут sha256-хэш, plain только в письме
- tests/token-security.test.ts: 12 тестов (выпуск по хэшу, ротация, reuse detection, grace, reset)
- .env.example, swagger, IMPLEMENTATION_LOG.md обновлены

Проверки: npm run check чисто, vitest 118/118, lint 0 errors, build собирается
2026-09-08 11:35:32 +03:00

152 lines
6.5 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# =============================================
# Application secrets (required)
# =============================================
# JWT secrets — each token type has its own key (generate with: openssl rand -hex 32)
# FATAL: app will NOT start if these are missing
JWT_ACCESS_SECRET=your-access-secret-here
JWT_REFRESH_SECRET=your-refresh-secret-here
JWT_SUPERADMIN_SECRET=your-superadmin-secret-here
# Optional: separate secret for bot service tokens (falls back to JWT_ACCESS_SECRET)
# JWT_BOT_SECRET=your-bot-secret-here
# Token expiry (optional — these are the defaults)
# Access-токен короткоживущий (15 минут, шаг 0.6): клиент обновляет его через
# /api/auth/refresh по httpOnly refresh-cookie. Увеличивать только осознанно.
# JWT_ACCESS_EXPIRES=15m
# JWT_REFRESH_EXPIRES_REMEMBER=90d
# JWT_REFRESH_EXPIRES_SESSION=30d
# JWT_SUPERADMIN_EXPIRES=1h
# JWT_BOT_EXPIRES=10m
# Session secret for express-session (generate with: openssl rand -hex 32)
SESSION_SECRET=your-session-secret-here
# HMAC secret for API key hashing (generate with: openssl rand -hex 32)
# Required if using MCP/RAG API keys. Without it the server will throw on key creation/lookup.
API_KEY_HMAC_SECRET=your-api-key-hmac-secret-here
# Web Push VAPID keys (generate with: npx web-push generate-vapid-keys)
VAPID_PUBLIC_KEY=your-vapid-public-key
VAPID_PRIVATE_KEY=your-vapid-private-key
# SendGrid API key for transactional email (optional — app works without it)
# SENDGRID_API_KEY=SG.xxxxxxxxxxxx
# Row Level Security (изоляция tenant'ов на уровне БД).
# ОБЯЗАТЕЛЬНО для production: без него процесс не стартует (fatal при NODE_ENV=production).
# В dev можно не задавать (safe default — политики существуют, но не активны).
# ENABLE_RLS=true
# =============================================
# Database — choose ONE of the two modes below
# =============================================
# --- MODE 1: Neon Cloud (default) ---
# Run with: docker compose up --build
# Set DATABASE_URL to your Neon connection string:
DATABASE_URL=postgresql://user:password@host/dbname?sslmode=require
# --- MODE 2: Self-hosted PostgreSQL ---
# Run with: docker compose --profile with-postgres up --build
# Set POSTGRES_* variables below AND update DATABASE_URL above to point
# to the Docker "db" service (e.g. postgresql://appuser:password@db:5432/appdb).
# DATABASE_URL is NOT auto-constructed — it must be set manually.
# POSTGRES_DB=appdb
# POSTGRES_USER=appuser
# POSTGRES_PASSWORD=your-strong-db-password
# =============================================
# File storage — choose ONE of the two modes
# =============================================
# --- MODE 1: Local disk (default, Replit/dev) ---
# Files are stored in the uploads/ folder on disk.
# No extra variables needed.
# --- MODE 2: MinIO S3 (recommended for production / "device in a box") ---
# Run with: docker compose --profile with-minio up --build
# The app automatically switches to S3 mode when MINIO_ENDPOINT is set.
# MINIO_ENDPOINT=http://minio:9000 # use "minio" as hostname inside Docker network
# MINIO_ACCESS_KEY=minioadmin # пример для dev; в production обязательно сменить дефолтные креды
# MINIO_SECRET_KEY=your-strong-minio-password
# MINIO_BUCKET=files
# =============================================
# WebDAV (optional, only with with-minio profile)
# =============================================
# Allows browsing/uploading files via Windows Explorer, Finder, Cyberduck
# Access: http://device-ip:8080 (user/pass below)
# WEBDAV_USER=admin
# WEBDAV_PASSWORD=your-webdav-password
# =============================================
# Ollama / Local LLM (optional)
# =============================================
# Base URL for Ollama server (default: http://localhost:11434)
# OLLAMA_BASE_URL=http://ollama:11434
# Number of CPU threads Ollama should use for inference.
# Default: (CPU cores - 1), e.g. 3 on a 4-core server.
# OLLAMA_NUM_THREAD=3
# Context window size (default: 2048). Increase only if you have enough RAM.
# OLLAMA_NUM_CTX=2048
# Allow private/loopback URLs for RAG providers (required for local Ollama)
# ALLOW_PRIVATE_RAG_URLS=true
# =============================================
# MCP API Keys (required for external MCP clients like n8n, Cursor, etc.)
# =============================================
# HMAC secret for hashing API keys. Generate with: openssl rand -hex 32
# FATAL: MCP key creation will fail if this is missing
# API_KEY_HMAC_SECRET=your-hmac-secret-here
# =============================================
# Public URL of CRM itself — used for presigned document URLs
# APP_URL=https://iistwin.ru
# =============================================
# MedSchedule bot settings (optional)
# =============================================
# Telegram bot token for MedSchedule personal/family health assistant
# TELEGRAM_BOT_TOKEN=your-telegram-bot-token
# Secret token for validating Telegram webhook requests
# TELEGRAM_BOT_WEBHOOK_SECRET=your-telegram-webhook-secret
# MAX bot token and base URL (optional)
# MAX_BOT_TOKEN=your-max-bot-token
# MAX_BOT_API_BASE=https://api.max.ru/bot
# Secret token for validating MAX webhook requests
# MAX_BOT_WEBHOOK_SECRET=your-max-webhook-secret
# n8n webhook URL for MedSchedule OCR (medical scan analysis)
# IMPORTANT: iistwin must reach n8n via the internal Docker network URL.
# External /webhook and /n8n/webhook paths are NOT exposed for webhooks.
# MED_N8N_OCR_WEBHOOK_URL=http://n8n:5678/webhook/972a1fce-c84c-49f6-bc04-7bd838b61acc/med-ocr
# =============================================
# Document Worker (optional — for PDF/DOCX generation)
# =============================================
# URL of the document-worker microservice (Chromium + LibreOffice).
# Inside Docker Compose use the service name:
# DOC_WORKER_URL=http://document-worker:3000
# For local development without Docker, you can point to an external service:
# DOC_WORKER_URL=http://localhost:3000
# =============================================
# File upload limits (optional, in megabytes)
# =============================================
# Per-type limits (extension-based, enforced after upload):
# UPLOAD_IMAGE_MAX_MB=25
# UPLOAD_DOC_MAX_MB=100
# Hard cap for the multipart parser (multer fileSize):
# UPLOAD_MAX_MB=100
# Bot login token TTL (access / refresh) — см. этап bot API keys:
# JWT_BOT_LOGIN_EXPIRES=30d
# JWT_BOT_LOGIN_REFRESH_EXPIRES=90d