Files
plumber/.env.example
T
codegirl007 59513ab75e Harden auth: setup secret, throttling, session destroy, secure cookies.
Replace username-based admin bootstrap with a one-time setup secret, rate-limit login/register, equalize login bcrypt timing, cap passwords at 72 bytes, destroy sessions on logout, and require Secure cookies when PORT is set.
2026-08-22 11:47:42 -07:00

23 lines
1.2 KiB
Bash

# Local listen address (ignored when PORT is set, e.g. on App Platform)
LISTEN=:8080
# Required: PlanetScale Postgres URI (port 5432 so the app can create tables on boot).
# Switch to 6432 (PgBouncer) later if you need pooling.
DATABASE_URL=postgresql://user:password@host.example.com:5432/postgres?sslmode=verify-full
# Required for integration tests (do not point at the runtime DATABASE_URL).
# TEST_DATABASE_URL=postgresql://user:password@host.example.com:5432/plumber_test?sslmode=verify-full
# One-time first-admin bootstrap: registrant must also POST setup_secret matching this value,
# and only while no admin exists yet. Leave unset after bootstrap. Prefer a long random string.
# ADMIN_SETUP_SECRET=
# When PORT is set (App Platform), cookies are Secure by default; SECURE_COOKIE=0 is rejected.
# Locally, set to 1 when serving over HTTPS:
SECURE_COOKIE=0
# Set to 1 only behind a trusted reverse proxy that sets X-Forwarded-For.
# TRUST_PROXY=0
# DigitalOcean Spaces (profile avatars). Leave unset to disable uploads.
# SPACES_KEY=
# SPACES_SECRET=
# SPACES_REGION=nyc3
# SPACES_BUCKET=your-bucket
# SPACES_ENDPOINT=https://nyc3.digitaloceanspaces.com
# SPACES_CDN_BASE=https://your-bucket.nyc3.cdn.digitaloceanspaces.com