LoVisual/backend/.env.example
loki5512344 c57f851a8b
feat(accounts): outgoing mail over SMTP (Resend), email verification, fail-closed password reset
- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL
- migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified
- reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503
- forgot-password and resend-verification do their work in a background task (no timing oracle)
- device linking requires a verified email; email_verified exposed via /me and gRPC
- gateway rate limits, SMTP_* in compose and .env.example
- frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
2026-10-09 21:08:33 +02:00

51 lines
2.2 KiB
Text

DATABASE_URL=postgres://lovisual:lovisual@localhost:5432/accounts_db
# at least 32 random bytes, e.g. `openssl rand -hex 32`
JWT_SECRET=
PORT=8081
GRPC_PORT=50051
S3_ENDPOINT=http://localhost:9000
S3_BUCKET=lovisual-avatars
S3_ACCESS_KEY=minioadmin
S3_SECRET_KEY=minioadmin
# Optional browser-facing avatar prefix (e.g. https://visual.loki-code.dev/api/media).
# Leave empty for local dev: avatars then resolve to <S3_ENDPOINT>/<S3_BUCKET> directly.
AVATAR_PUBLIC_BASE_URL=
# Shared secret between gateway and internal services (openssl rand -hex 32)
INTERNAL_KEY=
# Secure cookie flag: leave unset (or true) in production (HTTPS); false for local HTTP dev
COOKIE_SECURE=false
# gateway
GATEWAY_PORT=8080
ACCOUNTS_HTTP_URL=http://127.0.0.1:8081
ACCOUNTS_GRPC_URL=http://127.0.0.1:50051
CONFIGS_HTTP_URL=http://127.0.0.1:8082
CHAT_HTTP_URL=http://127.0.0.1:8083
SITE_ORIGIN=http://localhost:5173
# true ONLY when the gateway is behind a reverse proxy that sets
# X-Forwarded-For (nginx in deploy/): per-IP rate limits then key on the
# real client. docker-compose.prod.yml overrides this to "true" itself;
# direct exposure must keep it false, or clients could spoof the header.
TRUST_PROXY=false
# Directory the gateway serves under GET /downloads/* (lovisual.jar lives here;
# docker-compose.prod.yml mounts it as /srv/downloads and sets the variable itself)
DOWNLOADS_DIR=downloads
# configs-service
CONFIGS_DATABASE_URL=postgres://lovisual:lovisual@localhost:5432/configs_db
CONFIGS_PORT=8082
# --- outgoing mail (accounts-service) ---
# Empty SMTP_HOST = mail switched off: /auth/forgot-password answers 503 and
# verification emails are skipped (fail-closed). Resend: host smtp.resend.com,
# user "resend", password = API key. 587 = STARTTLS (default), 465 = implicit TLS.
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASSWORD=
# Sender mailbox shown to recipients, e.g. LoVisual <noreply@loki-code.dev>
MAIL_FROM=
# The only origin email links may carry, e.g. https://visual.loki-code.dev
PUBLIC_BASE_URL=
# Email template language: ru (default) or en
MAIL_LANG=ru
# Development-only logging mailer (prints NO tokens): RESET_MAIL_MODE=log.
# Refused at startup when COOKIE_SECURE=true; tests use the queue instead.
RESET_MAIL_MODE=