.env.example 2.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354
  1. # Database
  2. DATABASE_URL="postgresql://torqvoice:torqvoice@db:5432/torqvoice"
  3. # Authentication (generate with: openssl rand -hex 32)
  4. BETTER_AUTH_SECRET="your-secret-here"
  5. # App URL (used by both the app and Better Auth)
  6. NEXT_PUBLIC_APP_URL="http://localhost:3000"
  7. # Where uploaded files and the app's other data live. Unset, it is `data`
  8. # beside the app, which is where everything has always been written; set it to
  9. # put uploads on a disk with room on them. Files already written to the old
  10. # place keep being found, so this can be turned on at any time.
  11. #
  12. # In Docker, move the volume with it: the compose file mounts
  13. # `/app/data/uploads`, and a DATA_ROOT pointing anywhere else would write into
  14. # the container instead, where a redeploy loses it.
  15. # DATA_ROOT="/var/lib/torqvoice"
  16. # Set to true only when Cloudflare proxies every request AND the origin
  17. # refuses traffic that did not come through it (Cloudflare IP ranges allowed
  18. # at the firewall or in nginx).
  19. #
  20. # Behind Cloudflare this is required, not optional: the proxy sets X-Real-IP
  21. # from the connection it sees, which is a Cloudflare edge address shared by
  22. # thousands of visitors, so leaving this off collapses everyone into a handful
  23. # of rate-limit buckets and real users start getting 429s.
  24. #
  25. # Without the origin lock it is worse than useless, because cf-connecting-ip is
  26. # then just a header anyone reaching the box directly can write for themselves.
  27. TRUST_CF_CONNECTING_IP=false
  28. # Integrations (Settings → Integrations)
  29. # Key that seals third-party tokens at rest (generate with: openssl rand -hex 32).
  30. # Without it the key is derived from BETTER_AUTH_SECRET, with a warning at startup.
  31. INTEGRATIONS_ENCRYPTION_KEY=""
  32. # OAuth apps the platform registers with each provider. Leave empty on a
  33. # self-hosted install to have each workshop enter its own app credentials.
  34. GOOGLE_INTEGRATION_CLIENT_ID=""
  35. GOOGLE_INTEGRATION_CLIENT_SECRET=""
  36. # Google sign-in (cloud mode only). A web OAuth client in the Google Cloud console
  37. # with this authorised redirect URI: <NEXT_PUBLIC_APP_URL>/api/public/auth/callback/google
  38. # Separate from the calendar connector client above, which requests calendar scopes.
  39. GOOGLE_AUTH_CLIENT_ID=""
  40. GOOGLE_AUTH_CLIENT_SECRET=""
  41. MICROSOFT_INTEGRATION_CLIENT_ID=""
  42. MICROSOFT_INTEGRATION_CLIENT_SECRET=""
  43. ZOOM_INTEGRATION_CLIENT_ID=""
  44. ZOOM_INTEGRATION_CLIENT_SECRET=""
  45. # Intuit development keys reach sandbox companies, production keys live ones;
  46. # the connector works out which it was given.
  47. QUICKBOOKS_INTEGRATION_CLIENT_ID=""
  48. QUICKBOOKS_INTEGRATION_CLIENT_SECRET=""